Startups

Pitch Deck Teardown: MedCrypt’s $25M Series B deck

Comment

Image Credits: Medcrypt (opens in a new window)

In September, the FBI warned that more than half of connected medical devices in hospitals had known critical security vulnerabilities, and these flaws are leading to a surge in attacks on the healthcare industry. As Carly Page reported, MedCrypt raised a $25 million round to help device manufacturers think security-by-design when creating the next generation of medical devices.

The company is a Y Combinator graduate that provides software for anything the U.S. Food and Drug Administration would consider a medical device where cybersecurity could be a concern, from insulin pumps and heart rate monitors to AI-based radiology tools and autonomous robots. I’m sure we can all agree that we don’t want to live in a world where people get blackmailed so hackers won’t send their critical health devices on the fritz, so let’s take a look at the story MedCrypt shared with its investors to raise its Series B.


We’re looking for more unique pitch decks to tear down, so if you want to submit your own, here’s how you can do that


Slides in this deck

The MedCrypt Series B deck is a tidy 12-slide deck. The company’s COO, Vidya Murthy, who shared the deck with me, said that it’s as-pitched, except that some of the customer adoption information has been redacted. Makes sense; security is sensitive business, and I imagine keeping the customer list under your hat might be a smart move. The company does claim that three of the top five device manufacturers use their products.

  1. Cover slide
  2. Problem slide
  3. Target audience/market size slide
  4. Opportunity slide
  5. Mission slide
  6. Product slide: Vulnerability tracking
  7. Product slide: Behavior monitoring
  8. Product slide: Cryptography
  9. Product slide: MedISAO
  10.  Team slide
  11.  Summary/traction slide
  12.  Closing slide

Three things to love

MedCrypt’s slide deck shows that it is a mature organization with a broad product lineup and even the beginnings of an ecosystem influence play. The deck is pretty unusual in that it is missing a fair amount of information that I’d expect to see in a deck from a company at this stage, but the narrative is clean and (mostly) easy to follow.

A surprising amount of the deck focuses on the company’s product lineup, with four of the 10 content slides dedicated to that. It makes sense to tell the story of a company through its products, but the deck itself doesn’t do a great job of that; it’s obvious that it needs a voice-over to contextualize this information.

Rallying the industry

[Slide 9] Mediwhatnow? Image Credits: MedCrypt

This slide is at once very good and pretty lacking. When it first came up, I was confused about what MedISAO was and why it was on the company’s slide deck. It shows that this deck was designed with a voice-over in mind rather than being readable on its own. This slide comes after three slides that explain MedCrypt’s products and uses the same design. Perhaps that should have been the tip-off that this is also one of the company’s products, but I found it confusing at first. Why is it good that the FDA recommends ISAO memberships? What the hell even is an ISAO? (I had to Google it; it’s an information sharing and analysis organization). Why is it important that MedISAO is good for MDM? (I know, I know. I had to Google that, too: medical device manufacturer). Yay, sales pipeline, I suppose?

When I visited the MedISAO website, it finally clicked. The site’s FAQ states that “MedISAO is organized by MedCrypt, Inc., a healthcare-first cybersecurity company.”

So! We got there in the end, which isn’t really a good thing to say about a pitch deck. What is tremendously impressive, though, is that if MedCrypt is able to be the central repository for sharing security information across all medical devices, it has an opportunity to keep a finger on everything that’s going on across its entire industry. It’s a really powerful position to be in.

Of course, there’s nothing on this slide about how successful it is so far, and its website says “MedISAO does not publish a complete list of member organizations, but you can see a partial list of members on the home page.” It’s hard to gauge whether this is a mature, successful initiative that’s helping cement MedCrypt in its space or a website the company flung up over a couple of afternoons. I would have loved to see some metrics here, specifically about the value of the sales pipeline from the site and what impact it has.

A gut punch of an opportunity slide

[Slide 4] Yeah, that seems important. Image Credits: MedCrypt

One of the big questions an investor asks themselves is whether there is a market for a product or company. Regulatory shifts can be a powerful driver for adoption. For example, before GDPR legislation went into effect in May 2018, every website in Europe and every company that wanted to do business with EU countries very quickly needed to make changes. That created a booming industry for web development houses that specialized in privacy.

Well, it seems like the same is happening in the medical device industry; this slide claims that more than $1 trillion worth of devices need to get secured to be in compliance. Unlike web development, however, this is a pretty specialized industry. If you thought GDPR was wild, get a load of HIPAA. On top of that, it’s often non-trivial to update the firmware on embedded electronic devices (that’s part of the reason we are in this mess in the first place).

This slide is an absolute slam dunk: It doesn’t take a lot of imagination to see how there’s an enormous market with a lot of money at stake (and a lot of money to spend) — with a ticking clock. It’s a perfect storm, and MedCrypt has built a boat that just might be able to weather it.

Strong summary slide

[Slide 11] Great summary. Image Credits: MedCrypt

Personally, I’m not a fan of READING LARGE AMOUNTS OF TEXT IN ALL CAPS; it’s shouty and reader-unfriendly. It also means that people who are adept at speed-reading aren’t able to use their speed-reading skills. That aside, this slide is a great one to end on. It includes a huge amount of really good information: It summarizes the market opportunity, products, number of customers and previous fundraises, and helps set the tone for the Q&A at the end. Another approach would have been to move the summary slide to the beginning of the deck to set the tone, but it works either way.

In the rest of this teardown, we’ll look at three things MedCrypt could have improved or done differently, along with its full pitch deck!

Three things that could be improved

What struck me was the vast amount of information MedCrypt isn’t sharing. This is a growth deck, which means that the company probably has a tremendous amount of data around its products. Not including any of that seems borderline incompetent.

Where are your metrics?

[Slide 11] Terrible KPI slide. Image Credits: MedCrypt

know I included this slide above as a great example of a summary slide. And it is. The problem is that Slide 11 is the only place where MedCrypt actually includes any numbers at all and only the number of customers, at that. There’s nothing about revenue, number of devices tracked, number of attacks averted, whether customer adoption is increasing or slowing down, etc. Incidentally, the company also doesn’t cover its business model or pricing structure, which seems like quite an oversight.

The long and short of it is that I don’t really know what to make of this; perhaps MedCrypt is a storytelling-forward company that doesn’t rely heavily on metrics. The one thing to be very aware of, however, is that the vast majority of VC firms are very metrics-forward. As Peter Drucker would say: You can’t improve what you don’t measure.

It’s been a long time since I saw a pre-seed pitch deck this devoid of metrics. For a Series B round, the founders should be embarrassed not to include any of this in their deck; this is bread-and-butter, Startups 101 stuff, and as an investor, I’d be skeptical whether this is a company worth taking a closer look at.

So, er, what’s next?

Apart from slides 6-9, which capture the status quo of MedCrypt’s product, there’s nothing about the company’s vision for the future. That’s a pretty damning oversight; fundraising is all about the future, about how much money you are raising and what you’re going to do with the money. MedCrypt already has three products (four, if you include MedISAO), so it isn’t immediately obvious what’s going to happen next. Is the company going to launch three more products? Is it bolstering its existing lineup? Is it conquering new, international markets? Is it going after new customers or is the main go-to-market to expand its footprint with its existing customers? There are precisely zero words in the entire deck about what happens next. 

Good storytellers can weave the past, present and future together, so I’m just about willing to let the team off the hook. Perhaps it is using each product slide to talk about its metrics, status quo and future plans. You know what would have been a really good way of telling these stories though? Slides, with graphs and timelines and plans.

Sort out those acronyms, please

[Slide 8] Wait, why are we suddenly talking about crypto? Image Credits: MedCrypt

Throughout the deck, the slides are littered with acronyms that may be unfamiliar to the reader. I do like a good TLA, and I love brevity on slides even more, but it’s good practice to explain what a three-letter acronym (TLA) is the first time you use it for an audience that may not be 100% familiar with the language used in a particular deck.

In this deck, you may be able to get away with “API” (application programming interfaces are the bread-and-butter of the modern software world) and “FDA” — the federal drug administration should be common enough knowledge. MDM, CRM, SBOM and ISAO were all used throughout. Not making your readers work for it seems like a courtesy.

Worse, on Slide 8 of the deck, the company suddenly uses “crypto.” Ironically, that is probably a correct use of the word; “crypto” is meant to be short for cryptography. However, as someone who sees dozens of decks and oodles of tech stories every week, “crypto” has grown to be shorthand for cryptocurrencies and blockchains. Perhaps that one is a niche complaint, but the point I want to make is that the rule of thumb for good communication is to ensure that the message received is as close as it can be to the message intended. Put yourself in your audience’s shoes, and do a tiny bit of extra work to double down on clarity of communication. Even if the mistakes and misunderstandings are minuscule, they are so fantastically easy to avoid that we may as well avoid them.

The full pitch deck


If you want your own pitch deck teardown featured on TC+, here’s more information. Also, check out all our Pitch Deck Teardowns and other pitching advice, all collected in one handy place for you!

More TechCrunch

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

16 hours ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’

Welcome back to TechCrunch’s Week in Review. This week had two major events from OpenAI and Google. OpenAI’s spring update event saw the reveal of its new model, GPT-4o, which…

OpenAI and Google lay out their competing AI visions

When Jeffrey Wang posted to X asking if anyone wanted to go in on an order of fancy-but-affordable office nap pods, he didn’t expect the post to go viral.

With AI startups booming, nap pods and Silicon Valley hustle culture are back

OpenAI’s Superalignment team, responsible for developing ways to govern and steer “superintelligent” AI systems, was promised 20% of the company’s compute resources, according to a person from that team. But…

OpenAI created a team to control ‘superintelligent’ AI — then let it wither, source says

A new crop of early-stage startups — along with some recent VC investments — illustrates a niche emerging in the autonomous vehicle technology sector. Unlike the companies bringing robotaxis to…

VCs and the military are fueling self-driving startups that don’t need roads

When the founders of Sagetap, Sahil Khanna and Kevin Hughes, started working at early-stage enterprise software startups, they were surprised to find that the companies they worked at were trying…

Deal Dive: Sagetap looks to bring enterprise software sales into the 21st century

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI moves away from safety

After Apple loosened its App Store guidelines to permit game emulators, the retro game emulator Delta — an app 10 years in the making — hit the top of the…

Adobe comes after indie game emulator Delta for copying its logo

Meta is once again taking on its competitors by developing a feature that borrows concepts from others — in this case, BeReal and Snapchat. The company is developing a feature…

Meta’s latest experiment borrows from BeReal’s and Snapchat’s core ideas

Welcome to Startups Weekly! We’ve been drowning in AI news this week, with Google’s I/O setting the pace. And Elon Musk rages against the machine.

Startups Weekly: It’s the dawning of the age of AI — plus,  Musk is raging against the machine

IndieBio’s Bay Area incubator is about to debut its 15th cohort of biotech startups. We took special note of a few, which were making some major, bordering on ludicrous, claims…

IndieBio’s SF incubator lineup is making some wild biotech promises

YouTube TV has announced that its multiview feature for watching four streams at once is now available on Android phones and tablets. The Android launch comes two months after YouTube…

YouTube TV’s ‘multiview’ feature is now available on Android phones and tablets

Featured Article

Two Santa Cruz students uncover security bug that could let millions do their laundry for free

CSC ServiceWorks provides laundry machines to thousands of residential homes and universities, but the company ignored requests to fix a security bug.

3 days ago
Two Santa Cruz students uncover security bug that could let millions do their laundry for free

TechCrunch Disrupt 2024 is just around the corner, and the buzz is palpable. But what if we told you there’s a chance for you to not just attend, but also…

Harness the TechCrunch Effect: Host a Side Event at Disrupt 2024

Decks are all about telling a compelling story and Goodcarbon does a good job on that front. But there’s important information missing too.

Pitch Deck Teardown: Goodcarbon’s $5.5M seed deck

Slack is making it difficult for its customers if they want the company to stop using its data for model training.

Slack under attack over sneaky AI training policy

A Texas-based company that provides health insurance and benefit plans disclosed a data breach affecting almost 2.5 million people, some of whom had their Social Security number stolen. WebTPA said…

Healthcare company WebTPA discloses breach affecting 2.5 million people

Featured Article

Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Microsoft won’t be facing antitrust scrutiny in the U.K. over its recent investment into French AI startup Mistral AI.

3 days ago
Microsoft dodges UK antitrust scrutiny over its Mistral AI stake

Ember has partnered with HSBC in the U.K. so that the bank’s business customers can access Ember’s services from their online accounts.

Embedded finance is still trendy as accounting automation startup Ember partners with HSBC UK

Kudos uses AI to figure out consumer spending habits so it can then provide more personalized financial advice, like maximizing rewards and utilizing credit effectively.

Kudos lands $10M for an AI smart wallet that picks the best credit card for purchases

The EU’s warning comes after Microsoft failed to respond to a legally binding request for information that focused on its generative AI tools.

EU warns Microsoft it could be fined billions over missing GenAI risk info

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies