Overview of Practical Founders Podcast #214
This episode features Heath Adams, founder of TCM Security, sharing how he turned a small penetration testing services business into a major cybersecurity education and certification company, then sold it to Educate360 after deliberately reducing founder dependency. The conversation covers the evolution from YouTube content and affordable training into a bootstrapped, low-VC, low-eight-figure business with tens of thousands of paying customers, plus the lessons Heath is applying now at his new company, Breachpoint.
How TCM Security Started and Grew
From services to education
- TCM Security began as an offensive security / pen testing services company.
- Heath initially gained traction by posting YouTube videos and helping a military-veteran community interested in cybersecurity.
- That content unexpectedly drove inbound demand for consulting, which then expanded into:
- affordable courses
- certification programs
- a recurring training platform
A practical, affordable training model
- Heath noticed cybersecurity training was often priced in the thousands of dollars.
- TCM Security offered a more accessible alternative, often around $30/month for individuals.
- The company eventually grew to:
- 30+ courses
- 10+ certifications
- 10,000+ paying customers
- 100,000+ one-time students at peak
What made the certifications different
- The certifications were hands-on and practical, not multiple-choice theory tests.
- Students had to prove real ability by:
- hacking a target
- following the rules of engagement
- writing a report
- That practical focus helped TCM stand out in a crowded cybersecurity education market.
Founder Dependency and the Exit Strategy
Deliberately stepping out of the spotlight
- Heath emphasized that preparing for a sale required years of reducing founder dependency.
- The company gradually shifted from “TCM Security = Heath Adams” to a business with:
- other content creators
- a marketing team
- sales support
- a broader brand identity
Why it mattered
- Heath wanted the company to be sellable without him being the face.
- This meant:
- hiring people to create content
- reducing his social media presence
- delegating sales calls
- letting others represent the brand publicly
The Sale to Educate360
Why the buyer wanted TCM Security
- Educate360, backed by private equity/Morgan Stanley, wanted to expand its cybersecurity education footprint.
- TCM brought valuable assets:
- proprietary cybersecurity content
- a certification platform
- consulting/services revenue
- a strong B2C audience and social media presence
Deal process and lessons
- Heath worked with Cherry Tree as his M&A advisor.
- He said the advisor was worth every penny because they:
- handled outreach and negotiation
- ran diligence support
- helped create competition among buyers
- improved the final offer significantly
- The process cost about $1 million all-in, but Heath said it was worth it because it roughly doubled the offer.
Biggest acquisition lesson
- Even very late in the process, a deal can still be derailed.
- Heath shared that the transaction nearly got hung up by a customer relationship issue only a week before closing.
- His takeaway: nothing is final until the money is in the account.
Post-Sale Life and Breachpoint
What he’s building now
- Heath is now working on Breachpoint, a new company focused more on:
- defensive cybersecurity
- vulnerability scanning
- SaaS / recurring revenue
- He’s using lessons from TCM Security from day one:
- build for scale
- use proper accounting
- track data early
- avoid platform lock-in
- set up the business to be diligence-ready
Key operational changes
- Unlike the early TCM days, Breachpoint is built with:
- accrual accounting from day one
- CRM and analytics tools in place
- legal/trademark/operations done early
- a structure ready to absorb growth quickly
Cybersecurity Market Insights
What penetration testing is
- Pen testing means hiring ethical hackers to:
- test networks, apps, or physical security
- find vulnerabilities before attackers do
- document findings and recommend fixes
AI in cybersecurity
- Heath believes AI is useful as an assistant, not a replacement.
- He sees AI helping with:
- code review
- vulnerability detection
- SEO
- marketing
- design
- productivity
- But he does not believe fully autonomous AI pen testing is ready yet.
- His view:
- AI-assisted tools are valuable
- human judgment is still essential
- the best security work still needs expert oversight
Main Founder Lessons
Build what the market actually needs
- Heath’s success came from recognizing gaps in the market:
- affordable cybersecurity education
- practical certifications
- beginner-friendly entry points
- He also followed a strong content strategy:
- answer common questions
- publish useful blog posts and videos
- build community through trust and consistency
Prepare to be replaceable
- If a founder wants to sell, they must reduce reliance on themselves.
- That means building:
- systems
- teams
- repeatable marketing
- customer support processes
- brand equity beyond the founder
Data matters early
- Heath strongly recommends tracking:
- where customers come from
- what they buy
- conversion paths
- customer value by segment
- sales cycle timing
- He said too many early founders rely on spreadsheets and intuition, which becomes painful during diligence.
Advice to Bootstrapped Founders
Heath’s core advice
- Expect a lot of hard work.
- Don’t assume others will immediately understand your vision.
- If you believe in the product, keep going—but:
- keep a financial safety net
- have a backup plan
- communicate clearly with family and stakeholders
- be willing to outwork the market
His biggest mindset takeaway
- Business school is often less useful than real experience.
- Founder knowledge comes from:
- listening to customers
- making mistakes
- iterating quickly
- building one decision at a time
Notable Takeaways
- Affordable, practical education can outperform expensive legacy training.
- Founder dependency is a real risk if you ever want to exit.
- The best time to prepare for diligence is before you think about selling.
- AI is an accelerator, not a full replacement, especially in technical security work.
- Bootstrapped companies can still build massive value with the right niche, timing, and execution.
