Why I Am Building Bitsfront
Two clocks
When a cyber incident hits a regulated institution, two clocks start at once. The security team starts reconstructing what happened. The legal and compliance team starts counting down to a regulator’s deadline. In most organizations those two clocks are not connected, and the space between them is where trust gets lost.
Over fifteen years in security, I have watched capable teams spend days rebuilding a timeline from logs and chat threads, while counsel works out which regulators need to hear about it, in what format, and by when.
We are building Bitsfront to close that space. A regulator should be able to see how a filing was put together, and a security team should be able to show its work without rebuilding it from scratch every time someone asks.
The law exists. The plumbing does not.
In many countries, and in growth markets especially, cyber incident reporting is already written into law. Data protection acts, central bank directives and sector cybersecurity frameworks all tell institutions to report incidents once they cross set thresholds, within set timelines. Very little has been built to help anyone actually do it.
For a bank or a telco, one incident can trigger several obligations at the same time, each with its own threshold, clock and template. Most teams manage this with spreadsheets, email and the memory of whoever handled the last one. The evidence lives in one place. The filing gets written somewhere else, often by someone who was not in the room when the incident was worked.
Regulators sit on the other end of the same problem. Reports arrive late, in inconsistent formats, frequently as attachments in an inbox. It is hard to see patterns across a sector, follow up with institutions that have not filed, or judge whether a report reflects what really happened. Without that view, a reporting law cannot do the job it was written for.
There is one more wrinkle. Any single institution has serious incidents rarely, so the reporting process gets exercised once or twice a year, under pressure, by people who may be doing it for the first time. Readiness has to exist before the incident. It cannot be assembled after.
Who is building it
Before Bitsfront, I served as Global Insider Risk Lead in Google Cloud’s CISO organization, and before that I built security products for Azure Government at Microsoft. As a Cybersecurity Fellow at New America, I also developed GovSCH, an open-source schema for making cybersecurity and AI governance documents machine-readable. Rules that software can read are rules that software can help people follow.
I am building Bitsfront with Mariojose Palma, our co-founder and CTO. Mario and I worked together at Microsoft and have known each other for more than five years. Mario leads engineering and brings years of building enterprise software at Microsoft and Citrix.
What we are building
Bitsfront is AI-native threat intelligence and cyber governance infrastructure. It builds the evidence record directly from an organization’s environment and generates each regulator’s filing from that one record, with full provenance. A person still approves and signs. These are attested legal filings, and we design for that.
For institutions, the platform covers the path from knowing what you run, including software and AI components, to understanding which incidents matter, which obligations they trigger, and what each regulator needs to see. For regulators, it provides a single intake for those reports and a way to publish requirements that institutions’ systems can read. The full capability list is on bitsfront.com.
Both sides work from the same structured record. A filing is no longer a document someone retypes at midnight. It is a view of evidence that already exists.
Why now, and where we start
The rules are in place and the pressure to make them work is rising. Regulators want reports they can act on, and institutions want a way to comply that does not depend on a few people having a good week.
The technology has also caught up. AI can now read an environment, connect what it finds to specific obligations and draft a filing far faster than anyone could by hand. It is only useful in this setting if a human stays accountable for what gets sent, so that is how we built it.
Bitsfront is meant to be a global company. Reporting rules are tightening in many parts of the world, and the problem we are solving does not stop at any border. We are starting in growth markets, where obligations are new enough that institutions and regulators can build on modern infrastructure from day one instead of retrofitting it onto tools designed for a different era. From there we will expand into broader markets, keeping the same focus on highly regulated sectors.
You can learn more about the company at bitsfront.com.
Ibrahim Waziri Jr.
Founder & CEO, Bitsfront