Discover the ins and outs of building your own information security company in this 48-minute conference talk from nullcon Goa 2019. Explore the current landscape of InfoSec companies, comparing the advantages of boutique firms to larger corporations. Learn about the bootstrapping phase, securing your first client, and essential organizational tools. Gain insights on implementing effective practices like Mailbox Zero and ensuring security and redundancy. Develop strategies for handling criticism, partnering up, and managing stress to prevent burnout. Benefit from Dr.-Ing. Mario Heiderich's expertise as he shares his experience leading the pen-test company Cure53 and offers valuable advice for aspiring InfoSec entrepreneurs.