N
Nica Furs
Guest
After leading the cybersecurity practice at one of the Big Four consultancies in Israel, Dima Shaposhnykov is taking a deliberately different bet. With co-founder Pavel Sheynkman, he has built MindCypher - a boutique cybersecurity consultancy operating cloud-first and fully remote, serving clients across Israel, the United States, and internationally. The firm’s thesis is straightforward: the discipline of enterprise-grade security can be delivered at a scale and price point that mid-market and high-growth organizations can actually consume.
It is a model that runs counter to much of the industry. Cybersecurity consulting has trended toward large, multi-tiered engagements priced for organizations with deep budgets and in-house security teams. Smaller firms - the kind that nevertheless face the same threat landscape as global enterprises - are often left choosing between generic managed services or hiring talent they cannot retain.
“The gap I kept seeing at PwC wasn’t about capability,” Shaposhnykov says. “It was about fit. A 200-person fintech doesn’t need the same engagement structure as a Fortune 100 company. They need senior practitioners who can walk in, understand the business, and deliver outcomes - not a six-month onboarding to a methodology that was built for someone else.”
Shaposhnykov’s path to founding MindCypher passed through some of the most demanding environments in the field. He completed Israel’s elite military programmer course and went on to manage Microsoft-based infrastructure supporting roughly 150,000 users as a Major in the IDF. After his service he joined the boutique consultancy CST-360, which merged with Cyber Styx and ultimately with PwC Israel in 2022 to form PwC NEXT Technology Solutions. There he led the cybersecurity practice, advising CISOs across regulated industries on Zero Trust adoption, data protection programs, and incident response.
That track record made the move to a two-person firm an unusual one in an industry that tends to reward scale. Shaposhnykov frames it as a return to the work he was originally drawn to.
“When you run a global practice, you spend more time managing the practice than doing the work,” he says. “I wanted to be back in the room with the CISO, looking at the actual telemetry, the actual policies, the actual gaps. MindCypher is structured so that the senior practitioner is the one delivering - not the one selling the next engagement.”
The firm’s practice areas concentrate on four lines of work: managed detection and response (MDR), penetration testing, compliance consulting (including ISO 27001 and PCI DSS), and broader security assessments. The deliberate narrowness is itself the strategy. Where larger firms market a near-complete catalog of services, MindCypher operates closer to a specialist practice - the kind of model more familiar in legal or medical consulting than in cybersecurity.
On the MDR side, the firm provides continuous monitoring and response capabilities through cloud-based tooling, which removes the capital expenditure and staffing burden that historically priced mid-market companies out of round-the-clock security operations. On the offensive side, the firm performs penetration testing and security assessments aligned to the threat profile of the specific client - a contrast to the templated reports that have become common in the industry.
Compliance work is treated as engineering rather than paperwork. Shaposhnykov has consistently argued that frameworks like ISO 27001 and PCI DSS work only when the underlying controls actually function, and his approach to certification engagements reflects that view.
MindCypher operates without an office - a deliberate choice that reflects both the realities of modern security work and the firm’s client base. Clients in Tel Aviv, New York, and elsewhere are served from the same infrastructure, with engagements coordinated through cloud collaboration platforms and remote access to whichever environments the work touches.
The model has practical advantages. Senior talent is not constrained to a single geography. Overhead stays low, which keeps engagement pricing closer to what smaller organizations can absorb. And the firm itself runs on the same control posture it recommends to clients - a useful consistency given that MindCypher has gone through its own ISO 27001:2022 implementation.
“If we’re telling a client they need to document their cloud security policy and audit it annually, we should have done that ourselves first,” Shaposhnykov says. “Otherwise it’s theater.”
Industry data tracks the gap MindCypher is built to fill. ISC2’s 2024 Cybersecurity Workforce Study estimated the global cybersecurity workforce gap at roughly 4.76 million professionals, with demand continuing to outpace supply. The Israeli market alone has more than 500 active cybersecurity companies, yet smaller firms across the region consistently report difficulty accessing senior practitioner time - the very people who tend to be locked inside large consultancies or hyperscaler security teams.
Mid-market organizations face an asymmetric problem. The threat actors targeting them are increasingly the same ones that target large enterprises - ransomware affiliates, business email compromise operators, and, more recently, attackers operationalizing generative AI for reconnaissance and social engineering. The defensive resources available to a 100- or 500-person organization, however, are nothing like what a Fortune 500 can deploy.
Shaposhnykov’s wager is that a small firm built around senior practitioners and modern tooling can close more of that gap than is widely assumed.
Even with MindCypher’s growth, Shaposhnykov has continued the workforce development work that defined the public-facing portion of his time at PwC. The cyber analyst course he created in partnership with Google and Reichman Tech School - designed for candidates from Israel’s peripheral communities who lack access to traditional cybersecurity pipelines - has launched a second cohort. Graduates of the first cohort have placed into roles across the Israeli security sector.
He has also continued to serve in advisory and judging capacities across the industry, most recently as a judge at the Health Insurance AI Hackathon organized by Tantun Holdings, where he evaluated submissions including “The Tokenizer” - a privacy-preserving tokenization engine for AI workflows touching protected health information.
“The industry doesn’t need more vendors,” Shaposhnykov says. “It needs more people who actually know how to do the work and are willing to do it for the clients who can’t afford the largest firms. That’s what we’re building.”
This article was published under HackerNoon's Business Blogging program.
It is a model that runs counter to much of the industry. Cybersecurity consulting has trended toward large, multi-tiered engagements priced for organizations with deep budgets and in-house security teams. Smaller firms - the kind that nevertheless face the same threat landscape as global enterprises - are often left choosing between generic managed services or hiring talent they cannot retain.
“The gap I kept seeing at PwC wasn’t about capability,” Shaposhnykov says. “It was about fit. A 200-person fintech doesn’t need the same engagement structure as a Fortune 100 company. They need senior practitioners who can walk in, understand the business, and deliver outcomes - not a six-month onboarding to a methodology that was built for someone else.”
From Big Four to Focused Practice
Shaposhnykov’s path to founding MindCypher passed through some of the most demanding environments in the field. He completed Israel’s elite military programmer course and went on to manage Microsoft-based infrastructure supporting roughly 150,000 users as a Major in the IDF. After his service he joined the boutique consultancy CST-360, which merged with Cyber Styx and ultimately with PwC Israel in 2022 to form PwC NEXT Technology Solutions. There he led the cybersecurity practice, advising CISOs across regulated industries on Zero Trust adoption, data protection programs, and incident response.
That track record made the move to a two-person firm an unusual one in an industry that tends to reward scale. Shaposhnykov frames it as a return to the work he was originally drawn to.
“When you run a global practice, you spend more time managing the practice than doing the work,” he says. “I wanted to be back in the room with the CISO, looking at the actual telemetry, the actual policies, the actual gaps. MindCypher is structured so that the senior practitioner is the one delivering - not the one selling the next engagement.”
What MindCypher Actually Does
The firm’s practice areas concentrate on four lines of work: managed detection and response (MDR), penetration testing, compliance consulting (including ISO 27001 and PCI DSS), and broader security assessments. The deliberate narrowness is itself the strategy. Where larger firms market a near-complete catalog of services, MindCypher operates closer to a specialist practice - the kind of model more familiar in legal or medical consulting than in cybersecurity.
On the MDR side, the firm provides continuous monitoring and response capabilities through cloud-based tooling, which removes the capital expenditure and staffing burden that historically priced mid-market companies out of round-the-clock security operations. On the offensive side, the firm performs penetration testing and security assessments aligned to the threat profile of the specific client - a contrast to the templated reports that have become common in the industry.
Compliance work is treated as engineering rather than paperwork. Shaposhnykov has consistently argued that frameworks like ISO 27001 and PCI DSS work only when the underlying controls actually function, and his approach to certification engagements reflects that view.
Cloud-First, Cross-Border by Default
MindCypher operates without an office - a deliberate choice that reflects both the realities of modern security work and the firm’s client base. Clients in Tel Aviv, New York, and elsewhere are served from the same infrastructure, with engagements coordinated through cloud collaboration platforms and remote access to whichever environments the work touches.
The model has practical advantages. Senior talent is not constrained to a single geography. Overhead stays low, which keeps engagement pricing closer to what smaller organizations can absorb. And the firm itself runs on the same control posture it recommends to clients - a useful consistency given that MindCypher has gone through its own ISO 27001:2022 implementation.
“If we’re telling a client they need to document their cloud security policy and audit it annually, we should have done that ourselves first,” Shaposhnykov says. “Otherwise it’s theater.”
The Market That Brought Him Back
Industry data tracks the gap MindCypher is built to fill. ISC2’s 2024 Cybersecurity Workforce Study estimated the global cybersecurity workforce gap at roughly 4.76 million professionals, with demand continuing to outpace supply. The Israeli market alone has more than 500 active cybersecurity companies, yet smaller firms across the region consistently report difficulty accessing senior practitioner time - the very people who tend to be locked inside large consultancies or hyperscaler security teams.
Mid-market organizations face an asymmetric problem. The threat actors targeting them are increasingly the same ones that target large enterprises - ransomware affiliates, business email compromise operators, and, more recently, attackers operationalizing generative AI for reconnaissance and social engineering. The defensive resources available to a 100- or 500-person organization, however, are nothing like what a Fortune 500 can deploy.
Shaposhnykov’s wager is that a small firm built around senior practitioners and modern tooling can close more of that gap than is widely assumed.
Continuing the Broader Work
Even with MindCypher’s growth, Shaposhnykov has continued the workforce development work that defined the public-facing portion of his time at PwC. The cyber analyst course he created in partnership with Google and Reichman Tech School - designed for candidates from Israel’s peripheral communities who lack access to traditional cybersecurity pipelines - has launched a second cohort. Graduates of the first cohort have placed into roles across the Israeli security sector.
He has also continued to serve in advisory and judging capacities across the industry, most recently as a judge at the Health Insurance AI Hackathon organized by Tantun Holdings, where he evaluated submissions including “The Tokenizer” - a privacy-preserving tokenization engine for AI workflows touching protected health information.
“The industry doesn’t need more vendors,” Shaposhnykov says. “It needs more people who actually know how to do the work and are willing to do it for the clients who can’t afford the largest firms. That’s what we’re building.”
This article was published under HackerNoon's Business Blogging program.