💰 Security, Funded #188 - When Tariffs Hit the Fan

Get cybersecurity market and intelligence insights, including key trends and industry analysis, for the week of March 31, 2025.

Security, Funded by Return on Security, is a weekly analysis of economic activity in the cybersecurity market. This week’s issue is brought to you by Tines, Intruder, and Dropzone AI.


THIS WEEK’S LEAD SPONSOR
Tines

Hey there,

I hope you had a great weekend, and welcome to The Uncertainty Era.

How will a trade war, tariffs, and a global market selloff affect the cybersecurity industry? That’s the question I was thinking about all weekend after companies on the S&P 500 wiped out $5 trillion in stock market value.

Just because most things we deal with in this industry are based on 1s and 0s doesn’t mean we’re out of the woods. The world is entering a new macro phase, and cyber will soon feel the impact.

Remember how COVID-19 disrupted global supply chains, slowed hiring, jammed up procurement cycles, and prevented companies from forecasting and planning? Remember how any vendor selling hardware-based products saw a slowdown in ordering followed by over-ordering because companies could no longer plan as they used to?

We’re about to be right back there again, but this time, it’s self-inflicted, driven by policy, not a pandemic.

The cyber industry won’t be hit first, but its customers will be, and they are already getting hit hard. Don’t even get me started if this bleeds into the AI chip world! And if there is anything true in life, it’s that investors, businesses, and consumers alike hate uncertainty. Uncertainty at this scale changes forecasting, changes roadmaps, changes investment decisions, and changes headcount planning.

While not a global pandemic, this self-inflicted wound has global knock-on effects. Some of these effects can be reversed with policy, but not without a hangover period. Uncertainty is now ruling the day, and hope is an awful hedge.

🪦 RIP to The Expense Management Era (2023 - 2024). It’s time for The Uncertainty Era (2025 - ???). See the full timeline of cybersecurity market eras. I’ll continue to track this in real time, and reply back and let me know what you’re seeing on your end.

And in perfectly coincidental timing, I’m backing the UK’s first cybersecurity seed stage fund, led by Osney Capital. You can read more about it here.

Uncertainty is defining the macro landscape, but the strategic capital is still flowing.

TOGETHER WITH

Take the fear out of phishing response - Register now!

According to GreatHorn, 57% of organizations experience phishing attempts on a weekly or daily basis. What can be done about this?

It’s time to take the fear out of phishing response. Register for this webinar on April 22 with Tines and Material Security to learn:

  • The evolution and current state of phishing attacks

  • Common challenges in phishing defense 

  • How automation enhances phishing response

  • How to build a phishing-resistant culture with other teams across your organization

😎 Vibe Check

Make sure to click on the options below to vote in this week’s poll, whether you’re a practitioner, founder, or investor!

What’s the strongest early signal a security tool will succeed in your org?

Login or Subscribe to participate in polls.

Last issue’s vibe check:
What’s the first sign a security tool won’t deliver value?
🟨⬜️⬜️⬜️⬜️⬜️ ⏳ No early value shown (19)
🟨🟨🟨🟨⬜️⬜️ 🔌 Integration delays or issues (22)
🟩🟩🟩🟩🟩🟩 📝 Team sticks to manual work (30)
🟩🟩🟩🟩🟩🟩 🧍‍♂️ No clear owner after purchase (30)

101 Votes (newsletter + LinkedIn 🆕 )

We’ve got a two-way tie! Last week, I also launched the Vibe Check poll on LinkedIn to get a broader perspective on the commentary, and the results say a lot.

Continuing with manual work and having no clear owner of a security solution after it’s been purchased make a security tool dead on arrival. These aren’t product issues, this is internal friction. The real threat to adoption? The Change Management Final Boss.

Some of the top comments from last week’s vibe check:

Manual Work - “Change management failure is the biggest pitfall of any tool, security or otherwise.”

💰 Market Summary

Private Markets

  • 14 companies from 6 countries raised $824.8M across 12 unique product categories

  • 4 companies were acquired or had a merger event across 2 unique product categories

  • 100% of funding went to product-based cybersecurity companies

Public Markets

  • No public cyber companies had an earnings report

  • Public market moves last week

Top cyber companies compared to major stock index

As of market close on April 4, 2025.

📸 YoY Snapshot

Rolling 12-week charts that compare funding and acquisitions weekly in a year-over-year (YoY) view between 2024 and 2025.

Funding for Q1 2025 ended on a strong note, rising 32% to $4.1 billion, compared to $3.1 billion in Q1 2024.

M&A activity also finished Q1 2025 strongly, with 65 transactions compared to the 61 transactions in Q1 2024.

It will be interesting to watch how the funding and M&A markets change now that we’re in the Uncertainty Era. Deals are worked out behind the scenes for many months before going live, so based on the rate of deals we’ve seen this year so far, my guess is we’ll see a lot of deals slow down to wait out the turbulence.

TOGETHER WITH

Another Cloud Security Tool? Not Quite

Intruder launched Cloud Security - and immediately turned down a $32bn offer from Google!

Alright, half true. But we’re still excited - and this isn’t just another cloud security tool.

We know that security teams face too many tools, tight budgets, and not enough time to handle all the alerts.

So we’ve combined Cloud Security with VM, ASM, and our signature simplicity and noise reduction - all in one powerful platform.

No alert fatigue. No hefty price tags. Only what you need to stay secure.

☎️ Earnings Reports

Earnings reports from last week: None

Macro Context:

  • More of the same recession fears and global market sell-offs in response to Trump’s tariff plans. Not much else to say here other than re-read the intro.

Earning reports to watch this coming week: None

🧩 Funding By Product Category

Click to see a larger version

  • $500.0M for Security Operations across 1 deal

  • $159.0M for Quantum Security across 2 deals

  • $101.1M for Data Protection across 2 deals

  • $43.0M for Security Awareness across 1 deal

  • $8.2M for Identity and Access Management (IAM) across 1 deal

  • $6.5M for Cloud Security across 1 deal

  • $3.3M for Content Moderation across 1 deal

  • $1.5M for Identity Verification across 1 deal

  • $1.5M for AI Model Security across 1 deal

  • $786.4K for Operational Technology (OT) Security across 1 deal

  • An undisclosed amount for Trust & Safety across 1 deal

  • An undisclosed amount for Digital Footprint Management across 2 deals

🏢 Funding By Company

Product Companies:

Service Companies:

  • None

🌎 Funding By Country

Click to see a larger version

  • $809.2M for the United States across 10 deals

  • $9.0M for Australia across 1 deal

  • $3.3M for France across 1 deal

  • $1.5M for Singapore across 1 deal

  • $1.1M for the Netherlands across 1 deal

  • =$786.4K for Greece across 1 deal

🤝 Mergers & Acquisitions

Product Companies:

  • Altospam, a France-based email security platform, was acquired by Hornetsecurity for an undisclosed amount. Altospam has not publicly disclosed any funding events. (more)

Service Companies:

  • modePUSH, a United States-based professional services firm focused on digital forensics and incident response (DFIR), was acquired by MOXFIVE for an undisclosed amount. modePUSH has not publicly disclosed any funding events. (more)

  • Prime Infoserv, an India-based professional services firm focused on governance, risk, and compliance (GRC) consulting, was acquired by Indus Net Technologies for an undisclosed amount. Prime Infoserv has not publicly disclosed any funding events. (more)

  • SecInfra, a France-based professional services firm focused on incident response and SecOps support, was acquired by Bouygues Telecom for an undisclosed amount. SecInfra has not publicly disclosed any funding events. (more)

📚 Great Reads

*A message from our sponsor

🧪 Labs

You do NOT want to eat the ‘Challengars’! 😳

This is art in meme form

Man, they should have never given me AI…

Security ROI > Coffee ROI

Get value every week? Back the mission.

Or forward this to someone smart.

Data Methodology and Sources

  • All of the data is captured point-in-time from publicly available sources.

  • All financial figures are converted to U.S. dollars (USD) when collected.

  • Company country locations are pulled from publicly available sources.

  • Companies are categorized using our system at Return on Security, and we write all the company descriptions.

  • Sometimes, the details about deals, like who led the round, how much money was raised, or the deal stage, might get updated after the issue is first published.

  • Let us know if you spot any errors, and we’ll fix them.

Reply

or to participate.