Skip to main content
35d 23:56:10Fal.Con 2026 — our biggest reveals of the year.See the announcements
← About Vijilan
KayVon Nejad, Founder & CEO of Vijilan Security
FOUNDER & CEO · SINCE 2014
KayVon Nejad
25+ years · incident response, forensics & security operations

Hi, I'm KayVon.

Founder & CEO, Vijilan Security. Also known as Kevin Nejad — KayVon is a Persian name; it means Saturn in Farsi.

I've spent 25+ years as an incident responder and digital forensics analyst — Philip Morris, Kraft Foods, Nabisco, EDS, Hewlett Packard Enterprise, and a global law firm that represented two-thirds of the Fortune 500. In 2014 I founded Vijilan to fix the thing that almost broke me: small and mid-size organizations, and the MSPs who serve them, had no realistic way to get the 24/7 security operations the big companies take for granted.

But the real story starts with a Post-it note, a dead phone line, and two FBI agents. Scroll down — it's worth it.

CISSPB.Sc.Wharton · security data analyticsMIT · information systemsCarnegie Mellon · incident response
Chapter 01

The morning my phone had no dial tone.

August 11, 2011. I was the information security officer at a global law firm in New York City — a firm that represented two-thirds of the Fortune 500 and a third of the Fortune 50. I'd come in as a senior infrastructure security specialist, made security team lead in three months, acting information security officer in six. My first project was implementing the firm's Information Security Management System for ISO 27001.

That morning I walked into my office and found a Post-it on my monitor: "Don't call me. Come and see me. — CIO."

I thought: great, another promotion.

So I did what any intelligent Homo sapiens would do — I picked up the phone. No dial tone. Fine. Second most intelligent move: log in to my desktop. Account disabled.

Okay. This is not a promotion. I started quietly collecting my valuables off my desk, doing the math on how I was about to get fired — for what, I had no idea. As I'm storming out, a security engineer across the hall looks up and says: "Corporate security was here earlier. They were looking for you."

I rushed to see my CIO in midtown Manhattan. He hands me a piece of paper with two names on it and says: "The FBI was here earlier. They want to see you at noon."

So I show up at Federal Plaza. Two agents come down. One asks for my ID, the other validates it. And then one of them turns to me and says: "Mr. Nejad, we have some unfortunate news. A Chinese cyber-espionage group has infiltrated one of your offices in Beijing. Everything you need is in this folder."

"Wait — you're telling me this is just a security breach?"

"Yes. Again — sorry to deliver the bad news."

"No, that's okay. I've got this. This is what I do for a living. Anything else?" They handed me their contact information, and I went back to the office — excited, worried, and a little apprehensive about breaking the news to a CIO who I suspect already knew — and executed our emergency response plan.

Here's the part that still gets me. The intrusion had started five months before I was hired. The intruder knew who I was and what my job was. They suspected our voice system was compromised — which is why my account was disabled and my VoIP line was cut before the FBI meeting: if I found out about them over a wire they were listening to, they'd vanish off the network and we'd never learn their motivation.

Someone had been living in the house for months. And the person whose job it was to know — me — had no way to see them.

We brought in Kevin Mandia's team at Mandiant, who deployed agents at strategic locations across the globe. We ran the response. And years later, in 2023, Forbes named that same firm one of "America's Most Cybersecure Companies." That arc — from breached to benchmark — taught me everything about what good security operations actually take.

Chapter 02

Three decades, three eras.

I started in 1998, in network security and fraud, answering the phone after a breach had already happened. Broadband was just arriving over coax. pcAnywhere shipped with defaults that didn't require a password. Script kiddies were breaking into systems with Back Orifice and L0phtCrack over NetBIOS. My job was purely reactive — I got called when it was already too late. The 1990s were the decade of identification: everyone was accumulating systems and applications and just trying to know what they had.

In 2000, Philip Morris hired me in NYC as a security incident responder for the top twelve executives. That scope grew — to the legal department (and you can imagine the size of a tobacco company's legal department), to the whole NYC office, then across the operating companies: Kraft Foods, Nabisco, Philip Morris USA, PM International. I ended up building global computer security incident response teams across all of them. The 2000s were the decade of protection: more firewalls, more switches, more tools — and more logs than anyone could make sense of. That's when SIM and SEM converged into this new thing called a SIEM.

In 2008, HPE — which had just acquired EDS — brought me in to help build SIEM technology. Two years in, HP bought ArcSight for $1.5 billion. Great technology. But like most SIEMs of that era, you were restricted from your own raw data, restricted in what you could ingest, locked out of using the backend for anything beyond security. The 2010s became the decade of detection and response — and most organizations simply couldn't handle the data volume, the expertise, or the 24/7 coverage it demanded.

Which is exactly what I ran into at the law firm, at noon, at Federal Plaza.

Chapter 03

I couldn't find the vendor I needed. So I became it.

After the breach, I went looking for one vendor who could do what I actually needed: come in, drop sensors, start collecting logs from firewalls, switches, routers, servers, applications and users — north-south and east-west — automatically flag anomalies, help remediate on the fly, enrich the data with threat intelligence and geo-resolution, investigate on my behalf, and still give me access to my own raw logs so I could run my own investigation.

I mean — how hard can that be?

I couldn't find a single one. I read everything I could about how other organizations handled this, and I kept coming back to research from Dr. Larry Ponemon's institute with IBM: small and mid-size organizations were the most underserved segment in security, and intrusions were going unnoticed for an average of 287 days. Two hundred eighty-seven days. That's someone living in your house — eating your food, watching your TV, sleeping in your bed when you're not around — for nine and a half months. And you have no idea.

I spoke with hundreds of MSPs in New York. Not one could point me to a turnkey solution that didn't demand a long-term contract, didn't take days or weeks to deploy, and didn't dump raw noise on a team with no analysts. My bar was: onboard in an hour, triage and investigate on the partner's behalf, and only escalate the things that matter.

It didn't exist. So in 2014, I launched Vijilan — built for IT solution providers and MSSPs from day one, because the big enterprises already had their armies. The MSPs, and the millions of small businesses behind them, had nobody. We've watched a lot of companies enter this space and disappear since. We're still here, and we still only sell through partners.

Chapter 04

We hit a wall. CrowdStrike is how we broke through it.

The first version of Vijilan ran on a commercially available multi-tenant SIEM. It worked — until it didn't. We grew month after month, year after year, and then we hit the threshold. The infrastructure got unstable. Log collection became guesswork: was it the collector, or the source? We couldn't touch our own raw logs and get answers fast. Reports crawled. Audits hurt. We had to get selective about what data we even ingested — which is the one thing a SOC should never have to do. More servers, more licenses, more engineers, more cost.

We couldn't grow anymore. The platform we built the company on had become the ceiling.

Then we discovered Humio: index-free log management built for massive ingest, with the raw-data access and speed we'd been begging every SIEM vendor for. We rebuilt. When CrowdStrike acquired Humio and it became Falcon LogScale, our data foundation and the world's best endpoint telemetry ended up under one roof — and ViSH, the Vijilan Information Security Hub, became what it is today: a multi-tenant SOC platform on CrowdStrike Falcon Next-Gen SIEM and Falcon LogScale, purpose-built for MSPs and MSSPs.

We ported roughly 900 partner organizations onto the new platform. 95% data compression. 35× query performance. The ceiling was gone — and by 2023 we'd launched four new solutions on that foundation, merging observability and security in one platform.

CrowdStrike now tells Vijilan's story as one of its own official customer stories. Given where this journey started — one analyst locked out of his own logs — I'll take that.

Chapter 05

We're the Gucci of managed security. On purpose.

A word on how I run this company. In 2016 I took on four partners to scale. In 2020 I bought back the remaining equity and became the sole owner. Clean cap table, investor-friendly — and here's the part I'm proudest of: revenue has been strong enough that we've never had to bring in an outside investor. No board telling us to chase volume. No pressure to be everything to everyone.

Which means we get to choose who we serve. And we choose the 1%.

The MSP community is the strongest community I've ever worked in. But Vijilan is not a one-size-fits-all company, and we are not cheap. We bring enterprise-grade security — the same platform, the same SOC, the same active remediation the Fortune 500 gets — to the elite 1% of MSPs: the ones who genuinely care about their clients' security and about growing a real security practice. Not the transactional ones shopping for the lowest price.

Every partner gets concierge treatment. White-glove onboarding, a named team, weekly touchpoints when you want them, a founder you can actually reach. That's not scalable the way a self-serve portal is scalable — and that's exactly the point. Read what Layer 8, WCA, Orion Secure and LaScala say about working with us — those are the partners we built this for.

Career timeline

From dial tones to a global SOC.

  1. 1998

    Started at Rogers Communications in network security and fraud, investigating breaches in the early broadband era — the days of pcAnywhere with no password, Back Orifice, and L0phtCrack.

  2. 2000

    Hired by Philip Morris (Altria) in NYC as a security incident responder for the top executives — a scope that grew from 8 people to the legal department, the NYC office, and then global CSIRTs across the operating companies (Kraft Foods, Nabisco, PM USA, PM International).

  3. 2004

    The industry moment: Security Information Management (SIM) and Security Event Management (SEM) converge, and the SIEM is born. Managing one becomes its own full-time discipline — parsers, detections, false positives, and all.

  4. 2008

    Brought into HPE (via the EDS acquisition) to help a team build SIEM technology — two years before HP bought ArcSight for $1.5 billion. Great technology, but locked away from its own raw data.

  5. 2011

    Information security officer at a global law firm in NYC; implemented its ISO 27001 Information Security Management System — and led the response to a nation-state intrusion (the FBI story above).

  6. 2014

    Founded Vijilan Security: turnkey SIEM, SOC and incident response for the most underserved segment in security — MSPs and the small businesses they protect.

  7. 2016

    Took on four partners to scale the company through its first growth phase.

  8. 2019

    Earned SOC 2 Type 2 certification — and hit the scaling wall: the multi-tenant SIEM Vijilan was built on could no longer keep up with growth.

  9. 2020

    Bought out the remaining equity and became sole owner. Clean cap table, investor-friendly, and revenue strong enough that Vijilan has never needed an outside investor. Discovered Humio the same era.

  10. 2021

    CrowdStrike acquired Humio — putting Vijilan's chosen data foundation and the world's best endpoint telemetry under one roof as Falcon LogScale.

  11. 2022

    Became a CrowdStrike Powered Service Provider (CPSP) and ported roughly 900 partner organizations onto the LogScale-based ViSH platform: 95% data compression and 35× query performance over the old stack.

  12. 2023

    Launched four solutions on the new foundation — LogScale-powered managed services that merge observability and security in one platform.

  13. 2024

    Earned ISO 27001 certification. Expanded SOC operations across North America, LATAM, EMEA and APAC.

  14. 2026

    Authored published threat-intelligence research on the Iranian cyber ecosystem that directly informed Operation Lion Surge, Vijilan's free-coverage offer for qualifying MSPs.

Follow along

The story continues on my channels.

Short videos on security operations, the MSP business, and what our SOC is seeing — plus the occasional story like the one above. Booth announcements and the Praxis AI reveal from Fal.Con 2026 get posted here live.

Speaking & expertise

Topics KayVon speaks on.

KayVon speaks at industry events for MSPs, MSSPs and security teams. To inquire about speaking, podcast appearances or analyst briefings, email press@vijilan.com.

Channel-exclusive MSSP business models
Managed XDR operating models: SOC that acts vs. SOC that escalates
CrowdStrike Falcon ecosystem (Falcon Next-Gen SIEM, LogScale, Identity Protection)
Iran cyber operations (IRGC, MOIS, APT33/34/42, MuddyWater, Charming Kitten)
SIEM economics and the death of per-GB pricing
MSP economics: attach rate, MRR growth and NFR programs
"287 days. That's how long an intruder lives in the average environment before anyone notices. I built Vijilan so the businesses that can least afford those 287 days never have to live them."
KayVon Nejad

If you're an MSP and any of this sounds like your story too — the noise, the vendors who are really just license resellers, the clients asking if you're watching their servers — let's talk. That's exactly who we built this for.