This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by Optro and Token Security.

Hope you had a great weekend!

I hope you’ve had a chance to recover from all the excitement of the last few weeks if you took part in Black Hat or DEF CON. For most, it’s time to lock back in.

As for me? Well, I’m taking some time to write this week’s intro from the beach, in between data cleanup and making new charts with the original “Al” or “Alcohol.”

We all unwind differently! ¯\_(ツ)_/¯ 🍻

PARTNER

2026 SANS AI Survey Insights Report

The Reality of AI Security in 2026

AI is no longer just an experiment; it’s a core part of cybersecurity. But successful adoption requires governance, visibility, and trust. The 2026 SANS AI Survey Insights report shares findings from over 500 professionals on how organizations are approaching adoption, governance, and AI-enabled threats. Get your free copy here to discover practical recommendations, workforce readiness priorities, and real benchmarks to help you refine your AI security strategy.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Last issue’s vibe check:
Offense is compounding faster than defense. What actually closes the gap?
🟩🟩🟩🟩🟩🟩 Security-trained models for defense
🟨⬜️⬜️⬜️⬜️⬜️ General frontier models for defense
🟨⬜️⬜️⬜️⬜️⬜️ Cyber insurance forces focus via price
🟨🟨🟨⬜️⬜️⬜️ Regulatory teeth force companies' hands
🟨⬜️⬜️⬜️⬜️⬜️ Other (tell me)

Overwhelmingly, last week’s vibe check respondents said that security-trained models for defense and regulatory teeth were the only things that will move the proverbial needle on the offensive cyber side.

What it means to have “security-trained models” is still being determined in the industry, but I suspect it will shake out as many things do in the cyber industry: defense in depth. There is never one approach, tool, or construct that solves it all, but rather a series of layered applications.

And, as much as the industry likes to bemoan regulation, it is one of the very few things that business will respond to. Admittedly, not always to the correct outcomes, since regulation is often a PEBRAR problem (Problem Exists Between Regulation and Reality), but outcomes nonetheless as we chip away at the ever-growing dumpster fires of life. 🫡

Some of the top comments from last week’s vibe check:

💬 "CISA starts talking about offensive security, then New York writes it into regulation, and CISOs get/have to buy it to check the box. Starts with financial services and then begins to seep into all industries as a best practice.”

💬 “Insurance is the only stick that cyber will respond to.”

💬 “Improved harnesses and focused agents together can close this gap. Frontier models are losing efficacy in pushing the boundaries. Adding context to the decisions will improve the outcomes at a faster rate.”

💰 Market Summary

Private Markets

  • 4 companies from 3 countries raised $97.1M across 4 unique categories

  • Average deal size was $24.3M (median: $18.5M)

  • 100% of disclosed funding was product companies

  • 8 companies from 4 countries were acquired for $94.5M across 8 unique categories

  • 75% of acquired companies were product companies

  • 1 company announced layoffs

Public Markets

  • 1 public company raised $2.2B via Post-IPO Debt

  • 1 company had an earnings report last week - $FTNT ( ▼ 2.6% )

    • Fortinet's "SASE Firewall" strategy drives 33% billings growth as AI infrastructure and sovereign security demands create structural tailwinds

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$14.9B across 157 deals over the past quarter, up 34% from a year ago. Remember, I track both private company funding and public company equity and debt raises, so this number can sometimes be skewed.

Although M&A saw an uptick this past week, we are at 80 acquisitions over the past quarter, down 25% from the same period last year.

PARTNER

When Your AI Agent Acts Out, Who Foots the Bill?

Discover, scope, and remediate every AI agent identity

In 17 days, five disclosures showed AI agents leaving their sandboxes, minting credentials, and reaching production at real companies. One published malware that ran on 15 systems. Another scanned 9,000 targets. Cleanup isn't theoretical: Hugging Face rotated every token in its infrastructure, including clusters the agent never touched. 

When your agent causes the breach, the remediation and liability fall to you. Identity decides the blast radius and the invoice; luckily, Token Security holds the line.

🧩 Funding By Product Category

  • $2.2B for Secure Networking across 1 deal

  • $60.0M for Security Operations across 1 deal

  • $30.0M for AI Adversary Simulation across 1 deal

  • $7.0M for Application Security Testing (AST) across 1 deal

  • $100.0K for Privileged Access Management (PAM) across 1 deal

🏢 Funding By Company

» Interact with all the data in real-time on The Signal dashboard or via the MCP.

Product Companies:

  • Cloudflare, a United States-based platform of secure networking and website security tools, raised 2.2 B in post-IPO debt offering from undisclosed Qualified Institutional Buyers. (more)

  • Corma, an Israel-based frontier AI model company for security operations, raised a $60.0M Seed from Sequoia Capital. (more)

  • Mindgard, a United Kingdom-based threat detection, red teaming, and security platform for AI models, raised a $30.0M Series A from Album VC. (more)

  • Cytix, a United Kingdom-based AI-powered penetration testing and vulnerability management platform, raised a $7.0M Series A from Northern Gritstone. (more)

  • AlpacaX, a United States-based privileged access management platform for developers and agents, raised a $100.0K Seed round. (SEC Filing - may be incomplete)

Service Companies:

  • None

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $2.2B for the United States across 2 deals

  • $60.0M for Israel across 1 deal

  • $37.0M for the United Kingdom across 2 deals

🤝 Mergers & Acquisitions

Product Companies:

  • CyberCatch, a United States-based security and compliance automation platform for defense contractors, was acquired by Datavault AI for $94.5M. CyberCatch has not previously disclosed funding. (more)

  • CyberPilot, a Denmark-based security awareness training and phishing simulation platform, was acquired by Seppmail for an undisclosed amount. CyberPilot has not previously disclosed funding. (more)

  • EraseMe.app, a United States-based consumer data removal and online reputation management service, was acquired by Privacy Bee for an undisclosed amount. EraseMe.app has not previously disclosed funding. (more)

  • Limbik, a United States-based trust and safety platform focused on identifying and fighting misinformation and disinformation, was acquired by Burson Cohn & Wolfe for an undisclosed amount. Limbik had previously raised $2.3M in funding. (more)

  • Logmanager, a Czechia-based security information and event management platform, was acquired by Guardsix for an undisclosed amount. Logmanager has not previously disclosed funding. (more)

  • Quantumiq, a Canada-based platform for assessing and mitigating post-quantum cryptographic vulnerabilities, was acquired by Redwood AI for an undisclosed amount. Quantumiq has not previously disclosed funding. (more)

Service Companies:

  • BD Emerson, a United States-based professional services firm focused on risk advisory and data privacy, was acquired by Andersen Tax for an undisclosed amount. BD Emerson has not previously disclosed funding. (more)

  • CyberTrust IT Solutions, a United States-based managed security services provider, was acquired by New Charter Technologies for an undisclosed amount. CyberTrust IT Solutions has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

Layoffs

  • Rapid7, a United States-based suite of threat and vulnerability management (TVM) tools, laid off 314 employees, or 12% of its workforce, due to restructuring and AI investments. (more)

📚 Great Reads

  • A Tale of Two Planes - Most AI security focuses on governing agents, but the real risk lies in the data. Discover why unifying your identity and data control planes is the future of AI.

  • Cybersecurity Is Bigger Than a Single Industry - I sat down with Michael Novinson to talk about how cybersecurity has evolved beyond a traditional technology sector into an interconnected economy shaped by geopolitics, public policy, investment trends, and attacker incentives.

*Sponsored

🧪 Labs

No AI model is safe from committing crimes 😔

🫡 Signing Off

Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate