This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by The Signal.

Hope you had a great weekend!

As per my usual custom, I’m writing the intro to this week’s newsletter 35,000 feet in the air on the way to Black Hat / DEF CON. Let’s hope this WiFi lasts before we fly over Greenland! 🇬🇱 📶

Last week, the frontier AI labs kept sharing how their unconstrained models hacked their way out of their sandboxes and proceeded to hack other companies. The fact that it happened once (that we know of) was surprising enough. But then OpenAI and Anthropic (inexplicably?!) went back and forth about how their models did this as well, how it happened a long time ago, but how they really care about security… It’s quite an interesting marketing and FUD time in the world of AI right now, but with the usual dashes of truth.

I have to admit, these “confessions” from the AI companies got me thinking about my own sandbox escapes over the years…

I’m not proud of it, but I did what had to be done!

The schedule this week is jam-packed, but please stop me and say hello (or “Hell yeah, brother”) if you see me around Vegas!

PARTNER

The cybersecurity market moves faster than anyone can track by hand

The market intelligence layer for the cybersecurity economy.

Tracking the cybersecurity market usually means stitching together outdated exports, generic filters, and a lot of manual cross-referencing just to answer one question. The Signal changes that. Available via dashboard, MCP, and API, so it plugs directly into Claude and other AI tools.

No more rebuilding this by hand or wrestling with clunky filters in legacy platforms that weren't built for this market. It's less a data export and more a power-up: suddenly you can ask the market a question and just get an answer.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Last issue’s vibe check:
Which security category will be a feature, not a company, in two years?
🟨🟨🟨⬜️⬜️⬜️ Threat exposure management
🟩🟩🟩🟩🟩🟩 Automated pentesting
🟨🟨🟨⬜️⬜️⬜️ Agent identity
🟨🟨⬜️⬜️⬜️⬜️ AI SOC
🟨⬜️⬜️⬜️⬜️⬜️ Other (tell me)

Super interesting results from last week’s vibe check. Why am I not surprised that the segment raising the most money in cyber right now is the one that most people believe won’t be viable as a standalone business in two years?

I think part of it comes down to how we saw this play out with human penetration testing 10-15 years ago. Services are an inherently hard thing to understand the value of before you buy them and get the results. Each iteration of a service is unique, even if it's productized in some way. Implementations always have sharp edges you can’t see before you buy, and even after you get the results, you may not really fully realize if the output is “good.”

It’s also very easy to hide or hand-wave capabilities behind the greater services narrative, which makes cost one of the easier things to compare on. A low price is often a poor proxy for value in the cyber world, but if quality isn’t your goal (which is, admittedly, not always the case with pentesting), then it may not matter to you. That’s bad for the industry and bad for the company. The cheaper the better, some would argue, but they say beauty is in the eye of the be(er)holder.

Now expand that to AI-assisted and autonomous pentesting, and it’s easy to see why people lean to this being a feature and not a company.

Some of the top comments from last week’s vibe check:

💬 "There is no reason to separate out "agent identity" and build non-human IAM from scratch if agents are supposed to be doing all the same things as humans. We just need better IAM, for all users.”

💬 “Feels like "automated pentesting" (for some definition of the term) has almost already made it to feature status as part of some larger red teaming focused company.”

💬 “All of the above”

💰 Market Summary

Private Markets

  • 19 companies from 6 countries raised $731.1M across 16 unique categories

  • Average disclosed deal size was $48.7M (median: $20.0M)

  • 84% of funded companies were product companies

  • 7 companies from 3 countries were acquired for $1.0B across 5 unique categories

  • 57% of acquired companies were product companies

Public Markets

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.8B across 162 deals over the past quarter, down 7% from the same time period a year ago, but showing a rebound happening for a year that has been perpetually behind.

73 acquisitions over the past quarter, down 35% from the same time period a year ago. When asked my thoughts about the difference between this year and last year in M&A markets, here is my take.

🧩 Funding By Product Category

  • $200.0M for Threat Intelligence across 1 deal

  • $190.0M for Endpoint Protection across 1 deal

  • $113.0M for AI Governance across 1 deal

  • $50.0M for Security Services Delivery Platform (SSDP) across 1 deal

  • $40.0M for Security Log Data Management (SLDM) across 1 deal

  • $38.0M for Non-Human Identity (NHI) Security across 2 deals

  • $35.0M for Security Operations across 1 deal

  • $28.9M for Identity and Access Management (IAM) across 1 deal

  • $20.0M for Identity Governance & Administration (IGA) across 1 deal

  • $19.0M for Cybersecurity Education & Training across 2 deals

  • $13.0M for Cybersecurity Mesh Architecture (CSMA) across 1 deal

  • $8.0M for Continuous Threat Exposure Management (CTEM) across 1 deal

  • $4.5M for Managed Security Services Provider (MSSP) across 1 deal

  • $3.4M for Breach & Attack Simulation (BAS) across 1 deal

  • $1.5M for Operational Technology (OT) Security across 1 deal

  • $116.0K for Data Security Posture Management (DSPM) across 1 deal

  • An undisclosed amount for Data Protection across 2 deals

  • An undisclosed amount for Security Incident Management across 1 deal

🏢 Funding By Company

» Interact with all the data in real-time on The Signal dashboard or via the MCP.

Product Companies:

Service Companies:

  • Balance Theory, a United States-based knowledge management platform for security programs focused on team collaboration and education, raised a $19.0M Series A from SYN Ventures. (more)

  • Cycurion, a United States-based managed security services provider (MSSP), raised a $4.5M post-IPO equity round from a public offering. (more)

  • Stickley on Security, a United States-based cybersecurity education and compliance solutions provider, raised an undisclosed Corporate Round from Reseda Group. (more)

  • Woodway Assurance, a Canada-based platform for making sensitive data available for AI/ML use cases in a privacy-preserving manner, raised an undisclosed Seed from Nina Capital. (more)

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $609.1M for the United States across 12 deals

  • $65.0M for Israel across 3 deals

  • $50.0M for the United Kingdom across 1 deal

  • $28.9M for France across 1 deal

  • $8.0M for Unknown across 1 deal

  • $3.4M for Italy across 1 deal

  • An undisclosed amount for Canada across 2 deals

🤝 Mergers & Acquisitions

Product Companies:

  • Oasis Security, a United States-based platform for managing the machine and human identity lifecycles, was acquired by Cyera for $1.0B. Oasis Security had previously raised $195.0M in funding. (more)

  • Cofide, a United Kingdom-based non-human identity security platform for application workloads and AI agents, was acquired by Keyfactor for an undisclosed amount. Cofide has not previously disclosed funding. (more)

  • Lansweeper, a Belgium-based attack surface management (ASM) platform, was acquired by Bridgepoint for an undisclosed amount. Lansweeper had previously raised $149.8M in funding. (more)

  • Permiso Security, a United States-based identity and access runtime visibility platform for the cloud, was acquired by Okta for an undisclosed amount. Permiso Security had previously raised $28.5M in funding. (more)

Service Companies:

  • Kinzit Technologies, a United States-based managed security services provider, was acquired by Net at Work for an undisclosed amount. Kinzit Technologies has not previously disclosed funding. (more)

  • Layer27, a United States-based managed security services provider, was acquired by Katalyst for an undisclosed amount. Layer27 has not previously disclosed funding. (more)

  • MDSec, a United Kingdom-based professional services firm focused on , was acquired by Bank of America for an undisclosed amount. MDSec has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

Layoffs

  • None 😮‍💨

📚 Great Reads

  • Cybersecurity is Changing Faster than its Problems - Cybersecurity has never had a shortage of tools. AI is now making it possible to create even more of them, faster than teams can determine which ones are genuinely useful. I sat down with Nicholas Muy (CISO and VP of Engineering at Scrut Automation) to examine the gap between movement and progress.

  • Thoughts on Hacker Summer Camp for Founders - David Endler from Runtime Ventures shares some thoughts and lessons he's learned over the year attending Hacker Summer Camp that will be really timely for a lot of founders out there.

*Sponsored

🧪 Labs

Current mood

🫡 Signing Off

Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate

Keep Reading