LLenny's Podcast
← All episodes
Ben Williams (VP of Product at Snyk)06 November 2022

How Snyk built a product-led growth juggernaut

8Frameworks
15Insights

Frameworks in this episode

Insights & moments

The myth-busts, hot takes, explainers, and tools worth keeping.

Hot Take· 2

Hot Take39:30

Why Snyk Calls It 'Decision Science,' Not Data Science

Snyk started with a standard BI/data-analyst function but wanted deeper analysis — building predictive models that could power in-product experiences and drive better decisions. So they spun up a 'decision science' function rather than a data science one. Lenny points out the name itself implies a bias toward action rather than just pursuing cool things with data.

  • Evolved from a basic BI/data-analyst starting point toward predictive modeling
  • Predictive models feed and power in-product experiences, not just reporting
  • The 'decision science' label is deliberately more action-oriented than 'data science'
  • The naming implies a bias toward decisions and action over open-ended data exploration

we wanted to apply a much deeper level of analysis on the data such that we could start to build in predictive models that could…

Ben Williams · 40:00

it's cooler you call them decision signs people versus data science because that's so much more actionable

Lenny Rachitsky · 40:00
#data#decision-making#growth-team#org-design
Hot Take39:30

Put a Growth Marketer on Every Product Team

Snyk puts a growth marketer inside each cross-functional growth team, alongside engineers, an EM, a PM, a designer, and decision science support. Ben was surprised to learn this is uncommon and thinks a lot of opportunity is being missed. The payoff is a broader palette of ideas and a bigger execution toolbox — for example, a growth marketer independently shipped a high-performing SEO page with no engineering resources, which then led the team to build a full sidecar 'try before you sign up' product.

  • Each cross-functional growth team includes a growth marketer, not just eng/PM/design
  • Embedding growth marketers in product teams is uncommon — Ben expects that to flip over time
  • The benefit: a broader palette of ideas and a bigger toolbox for parallel, aligned experiments
  • A growth marketer shipped a high-converting SEO page with zero engineering resources
  • That success led to a sidecar product letting users try Snyk by pasting code — sign-up rate dipped but overall new users and activation rose with higher-intent users

inclusion of growth marketers in the product teams is not all that common and I personally think there's um just a lot of opportunity being…

Ben Williams · 39:30

having a growth marketer in an acquisition focused team led us to some lightweight experimentation on the website in creating an SEO optimized page

Ben Williams · 41:30
#growth-team#org-design#growth-marketing#experimentation

Explainer· 3

Explainer25:30

Free Security Education as a Growth Loop

Unlike incumbents that paywall their security training, Snyk publishes high-quality, bite-sized lessons about developer security in the public domain with no sign-up and no paywall. Ben frames Snyk as a change agent for devsecops transformations, and free education both advances that mission and functions as another company-generated, company-distributed growth loop.

  • Snyk sees itself as a change agent in devsecops transformations
  • The goal is developers who truly understand how to prevent vulnerabilities, not just tools that catch them
  • Lessons are high-quality, bite-sized, and fully public — no paywall, no sign-up required
  • Traditional incumbents let you access only a couple of lessons before requiring payment
  • Free education doubles as a company-generated, company-distributed acquisition loop

we believe it's really important to democratize security education

Ben Williams · 26:00
#content-marketing#growth-loops#developer-education#security
Explainer1:16:30

The 'Product-Driven Revenue' Metric

Snyk tracks a metric it calls product-driven revenue: all revenue from customers where they saw meaningful value-based product activity before any sales contact. Ben says it tells a story about the PLG efficiency of the whole company across both self-serve and sales-led channels. Notably, the product-driven cohort contributes a relatively greater amount to net retention.

  • Product-driven revenue = revenue from customers who showed value-based product activity before sales ever engaged
  • It measures PLG efficiency across all revenue channels, self-serve and sales-led alike
  • The product-driven cohort contributes disproportionately to net revenue retention
  • A strong PLG foundation that includes product-led sales yields a high volume of highly qualified, product-sourced leads
  • Ben admits he can't fully explain why product-led customers retain better — it's still an open question

we actually track a metric that we call product driven Revenue which basically accounts for all revenue in customers where we saw meaningful value-based activity…

Ben Williams · 1:16:30

the product driven cohort contribute a relatively greater amount to net retention

Ben Williams · 1:17:00
#metrics#plg#product-led-sales#net-retention
Explainer1:19:30

Snyk's Activation Metric: A Team Fixing Vulnerabilities Within 30 Days

For Snyk, activation isn't logging in or even finding vulnerabilities — it's a team forming a habit of fixing them. They define the 'habit moment' as a team fixing a vulnerability within 30 days of team creation, because that strongly correlates with three-month retention. They base activation on teams rather than individual users because security is a team sport, and a decision scientist derived the 30-day threshold from baseline data and ML analysis.

  • Activation = a team deriving core value, which for Snyk means fixing vulnerabilities, not just logging in or finding them
  • The 'habit moment': a team fixes a vulnerability within 30 days of team creation
  • Teams that fix within their first 30 days are far more likely to still be fixing three months later
  • Activation is defined around teams, not users, because security is a team sport
  • A decision scientist derived the threshold after collecting baseline data and running ML analysis; 30 is a clean round number close to the real inflection

activation is indicative of the team forming a habit around the usage of sneak and when I say the usage I actually mean deriving core…

Ben Williams · 1:19:30

teams that fix the vulnerability within their first 30 days are much much more likely to still be fixing three months later

Ben Williams · 1:21:00
#activation#metrics#retention#data

Story· 3

Story12:30

How Snyk Got Its First 100 Users From the Node.js Community

Snyk's founders started with a deliberately narrow target: node.js developers pulling open-source dependencies into their apps. They embedded themselves deeply in that community — speaking at Dev conferences and meetups, building content — and repeatedly asked one question: do you have known vulnerabilities in your code? The first ~100 users came purely from that community engagement, and Snyk had roughly 5,000 free users before any monetization attempt.

  • Narrow early focus: single persona, single context, single use case — node.js devs using open-source components
  • Node.js was chosen because the community was big enough to matter but small enough that Snyk could meaningfully influence it
  • Early growth came from evangelism at conferences and meetups, not a specific forum or platform
  • The repeated hook to the community: 'do you have known vulnerabilities in your apps?'
  • ~5,000 free users existed before any monetization was attempted

and the question that they repeatedly posed to the community was do you have known vulnerabilities in your apps and seek was there to help…

Ben Williams · 12:30

the first hundred or so users really just came from the founders engaging with the node.js community in the interest that drove

Ben Williams · 14:30
#community-led-growth#developer-tools#product-market-fit#node-js
Story20:30

The GitHub Fixed-PR Loop That Was Both Acquisition and Engagement

Snyk built a company-generated, company-distributed content loop: a new user connects their GitHub account, Snyk scans their code, and automatically raises Snyk-branded pull requests that fix the vulnerabilities. Other developers in the repo see those PRs, follow the links, and create their own accounts. Because Snyk controlled the PR description — explaining the vulnerability and educating the reader — it worked as both an acquisition loop and an engagement loop, and was later extended beyond GitHub.

  • New users connect GitHub; Snyk scans and auto-raises branded PRs that fix vulnerabilities
  • Other devs in the repo see the PRs, follow links, and sign up — the loop compounds
  • First-of-its-kind integration: no one had connected code scanning to fixes that way before
  • Snyk controlled the content — every PR description educated the reader and was Snyk-branded with a CTA
  • It functioned simultaneously as an acquisition loop and a re-engagement loop for existing users
  • Later extended to other source control systems beyond GitHub

sneak will scan their code or find vulnerabilities will automatically create sneak branded pull requests to fix those vulnerabilities

Ben Williams · 20:30

all of the description of the pull request was explaining about the vulnerability educating users and it was all sneak branded

Ben Williams · 22:30
#growth-loops#plg#developer-tools#distribution
Story27:00

Why Self-Serve Monetization Failed Early — and What Fixed It

Snyk had a valuable product, strong developer growth, and strong retention — but its first self-serve monetization efforts only landed individual developers paying ~$100/month. Purchases inside larger companies didn't happen as hoped, and some investors shied away from the lack of a proven monetization path. The team learned they had to cater to enterprise governance needs (reporting, user management), move beyond the depth-first approach to support more languages, and bring in their first sales and marketing hires — after which growth became 'rocket ship time.'

  • Valuable product + strong dev growth + strong retention still didn't produce enterprise self-serve revenue
  • Only individual developers converted early, at around $100/month
  • Boldstart's Ed Sim was an early true believer who helped provide runway during this period
  • The fix: build table-stakes governance features (reporting, robust user management) for enterprise buyers
  • It was also time to move past depth-first and support additional languages and ecosystems
  • Security teams — not developers — were still the only buyers, so Snyk hired its first sales and marketing people

the first self-serve monetization efforts I only really saw traction with individual developers paying a hundred dollars a month or purchases in in larger companies…

Ben Williams · 27:00

really learned about the importance of catering for the broader governance needs of the Enterprise buyer

Ben Williams · 27:30
#monetization#plg#enterprise-sales#developer-tools

Q&A· 1

Q&A55:30

Are 'Learnings' Really an Outcome? Ben on the Impact Tension

Lenny pushes back on the popular idea that learnings are a valid outcome — leaders don't want 'we learned a lot but nothing got done.' Ben's answer: impact is the goal, but learnings are the means. He borrows a quote about focusing on the user's path to value rather than monetization, because the form follows. If you fixate on impact directly you may struggle; if you focus on the learnings you need step by step, you pave the path to impact.

  • The objection: learnings can become an excuse for no measurable business impact
  • Ben's stance: impact is the goal, learnings are the means to get there
  • Experimentation isn't about delivering outcomes — it's about generating learnings the org can leverage
  • Analogy to focusing on the user's path to value rather than monetization — the form follows
  • OKRs still target moving a metric, but that's the output; the input is deliberate learning

focus on the user's path to Value not on monetization because if you focus on the form of the latter will follow

Ben Williams · 56:30

if you try and focus on the impact itself might struggle if you focus on the things you need in terms of learnings to take…

Ben Williams · 57:00
#experimentation#growth-strategy#learnings#metrics

Tool· 3

Tool23:30

Snyk Advisor: A Programmatic-SEO Loop From Package Health Scores

Snyk Advisor is a sidecar product that indexes every package manager, augments each package with metadata — security scans, how actively maintained the repo is — and builds a 'package health score.' This generates hundreds of thousands of automatically-created package pages, so anyone Googling a package by name or capability lands on a Snyk-owned page with a CTA to secure their app. It's a purely programmatic content loop that's been instrumental for new-user growth.

  • Indexes all package managers and augments each package with security scans and maintenance activity data
  • Builds a 'package health score' that becomes valuable search-landing content
  • Hundreds of thousands of package pages are generated automatically and continuously
  • Ranks in Google for package-name and 'package that does X' searches, funneling to a Snyk CTA
  • The data (security + maintenance activity) is stuff Snyk can gather programmatically

so anyone searching on Google for a package that does XYZ or a specific package by name sneak advisor will be right up there in…

Ben Williams · 24:30

there are hundreds of thousands of these package pages but they're just automatically being generated continuously

Ben Williams · 25:00
#seo#growth-loops#programmatic-content#developer-tools
Tool1:23:00

Ben's Most Valuable SaaS Tools for Growth and Product

Asked for the most valuable SaaS products to his organization, Ben names his growth stack: Amplitude for analytics, Segment to pipe data everywhere, FullStory for session replay that bridges qual and quant, userinterviews.com for fast curated research participants, and Sprig for in-app surveys and UX testing. For the wider product and growth team he adds Coda, where they keep experiment plans, the knowledge base, and user research.

  • Amplitude — core product analytics
  • Segment — pipes data from the product to Amplitude, Snowflake, Marketo, and elsewhere
  • FullStory — session replays that bridge the gap between qual and quant
  • userinterviews.com (comparable to usertesting.com) — fast curated access to research participants
  • Sprig — in-app survey platform, also used for testing UX designs in-app
  • Coda — flexible workspace for experiment plans, knowledge base, and user research

I'm going to say amplitude first of all uh segment as a means to be able to get our data from the products to amplitude

Ben Williams · 1:23:30
#tools#growth-stack#analytics#user-research
Tool1:25:30

Ben Williams' Book Recommendations

In the lightning round, Ben recommends three books he's enjoyed recently: How to Measure Anything by Douglas Hubbard for product and growth people who care about data; Make Time by Jake Knapp and John Zeratsky, which he says radically changed his relationship with information (over their better-known book Sprint); and This Is How They Tell Me the World Ends by Nicole Perlroth for its view into digital espionage.

  • How to Measure Anything by Douglas Hubbard — for anyone with more than a passing interest in data
  • Make Time by Jake Knapp and John Zeratsky — changed his relationship with information; recommended over Sprint
  • This Is How They Tell Me the World Ends by Nicole Perlroth — a view into digital espionage

I'll recommend how to measure anything by Douglas Hubbard

Ben Williams · 1:26:00
#books#recommendations#lightning-round

Takeaway· 3

Takeaway17:30

Go Narrow and Deep Before Going Wide

Ben argues the key to Snyk's early product-market fit was resisting the temptation to expand. A JavaScript developer doesn't care whether you support Go or Rust — they care whether a core feature works for their ecosystem. Nailing one narrow use case deeply, rather than spreading thin across every language, is what let Snyk validate the solution and build momentum before casting a wider net.

  • Depth-first beats breadth-first when validating a solution on the path to product-market fit
  • Users only care that YOUR specific feature works for THEIR ecosystem, not that you cover many ecosystems
  • The narrow slice must still be wide enough to be viable from a growth perspective
  • The lure of the bigger market is tempting but you have to build the service to capture it well
  • New Relic ran the same narrow-community playbook with the Ruby community

a JavaScript developer just won't care if you support golang or rust but will absolutely care if a key feature like automated package upgrades just…

Ben Williams · 17:30

the key for sneak I think was just not to go too wide too early

Ben Williams · 18:00
#product-market-fit#focus#growth-strategy
Takeaway32:30

Win Developers by Meeting Them Where They Already Work

Ben's advice for winning developers' hearts and minds: they have to actually care about the problem, and then you make the job as painless as possible by meeting them in their existing tools rather than pulling them out of their workflows. Flow is a critical concept for developers, and the GitHub PR integration is a prime example — one person can connect a repo and protect a thousand developers working in it without any of them needing to sign up.

  • First, developers must genuinely care — they need a problem you actually solve
  • Integrate with their existing tools; take security to them rather than pulling them out
  • 'Flow' is an incredibly important concept for developers — protect it
  • One user connecting a repo can secure a thousand developers who never sign up
  • Taking the product to users inside their workflow is critical to adoption

finding ways to take security to them instead of trying to pull them out of their workflows

Ben Williams · 32:30

flow is just this incredibly important concept for developers and you want to strive to keep them in that flow for as long as possible

Ben Williams · 33:00
#developer-experience#adoption#plg#product-strategy
Takeaway1:14:00

What to Put Free vs. Paid in a Freemium Product

On the perennial free-vs-paid question, Ben's guidance is to map each plan to a target customer and use cases, and to be crystal clear about the real drivers that motivate a user to move from one plan to the next. For Snyk, the real driver from free to paid is wanting to secure business-critical code and needing governance and compliance. Cost of service also matters — features too expensive to give free users (as with Heroku dropping its free plan) belong in paid.

  • Map every plan, free through top tier, to a well-defined target customer and use cases
  • Be explicit about the real drivers that move someone from one plan to the next
  • Snyk's free-to-paid driver: securing business-critical code plus governance and compliance needs
  • Cost of service is a factor — features too costly to offer free (à la Heroku's removed free plan) should be paid
  • Good guidance: free should promote your growth model; friction-adding things go behind the paywall

the real drivers to move from free to a paid plan for example is when you want to secure business critical code and you start…

Ben Williams · 1:14:30
#freemium#pricing#packaging#monetization