This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by AegisAI.

Hope you had a great weekend, and a long one if you’re tuning in from the US!

While we didn’t have Labor Day off in the UK, not having to ship the newsletter on Monday did let me play catch-up on all the OpenAI rogue AI agent hacking things and various takes from around the industry.

I’m not one to be a doomer when it comes to AI and Security in general, but there is no doubt we’ve definitely crossed some kind of threshold. I suspect many more of these kinds of extremely goal-oriented agent runs that result in security issues will occur if things don’t change at the frontier labs.

What a time to be an agent alive!

PARTNER

AI Spearphishing is up 4000% and users are clicking 60% of the time

AegisAI.ai: AI-native email security that catches BEC filters miss

LLMs research individuals and write compelling lures that have driven user CTRs up 11% this year. Using compromised vendors, calendar invites, and trusted SaaS tools, they bypass traditional email filters 50.3% of the time.

AegisAI's bespoke LLMs were built by the team behind Google reCAPTCHA, Gmail Security, Chrome Security, and Safe Browsing. Our agents analyze intent and behavior to catch the attacks in your users' inboxes. Investigate every message to find what others miss.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Last issue’s vibe check:
Five years out, who owns security for the mid-market?
🟩🟩🟩🟩🟩🟩 MSSPs / MDRs
🟨🟨🟨⬜️⬜️⬜️ Platform Giants
🟨🟨🟨⬜️⬜️⬜️ AI Agents
🟨⬜️⬜️⬜️⬜️⬜️ Nobody, still DIY

Really interesting poll results from last week! While I expected MSSPs/MDRs to win, I didn’t think it would win by as much as it did. It seems that the only way through the promised Middle Market Land is by way of the last-mile service providers.

Service providers run such a huge part of the industry, and they rarely get the same kind of flashy highlights, praise, or attention as the product companies, but the industry simply couldn’t exist without them. It’s why I specifically call them out in the Return on Security data. To leave them out is to ignore much of what makes the industry a success.

Also, I’m not sure what it says about the state of the mid-market when “Platform Giants” and “AI Agents” had the exact same number of votes. 😅

Some of the top comments from last week’s vibe check:

💬 "There’s so much talent in cybersecurity but also so much pressure to do it right. Many organizations of this size will take the risk of trusting, and paying for, a third party over the headache that DIY cybersecurity has become for many executives and boards. Blaming when the risk probability was wrong is also much more palatable.”

💬 “AI Agents will continue to prove to be (nearly) useless in the SOC, Platform Giants wont want the human-based services on their books, and mid-market CISO's will think they can DIY until they get popped and have to ultimately outsource to the MSSPs.”

💰 Market Summary

Private Markets

  • 9 companies from 5 countries raised $559.6M across 7 unique categories

  • Average deal size was $62.2M (median: $30.0M)

  • 100% of disclosed funding were product companies

  • 12 companies from 6 countries were acquired for $500.0M across 9 unique categories

  • M&A activity was evenly split between product and service companies

  • 1 secondary-market sale

Public Markets

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.8B across 140 deals over the past quarter, down 21% from a year ago.

91 acquisitions over the past quarter, down 1% from a year ago.

🧩 Funding By Product Category

  • $300.0M for Cloud Native Application Protection Platform (CNAPP) across 1 deal

  • $140.0M for AI Model Security across 2 deals

  • $40.0M for Remote Browser Isolation across 1 deal

  • $35.4M for AI Governance across 2 deals

  • $27.0M for Network Security across 1 deal

  • $11.4M for Fraud and Financial Crime Protection across 1 deal

  • $5.8M for Email Security across 1 deal

  • An undisclosed amount for Identity and Access Management (IAM) across 1 deal

🏢 Funding By Company

» Interact with all the data in real-time on The Signal dashboard or via the MCP.

Product Companies:

Service Companies:

  • None

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $397.0M for Israel across 4 deals

  • $140.0M for the United States across 3 deals

  • $11.4M for Australia across 1 deal

  • $5.8M for Switzerland across 1 deal

  • $5.4M for the United Kingdom across 1 deal

🤝 Mergers & Acquisitions

Product Companies:

  • Console, a United States-based agentic AI service and asset management platform, was acquired by Palo Alto Networks for $500.0M. (more)

  • DoControl, a United States-based SaaS security posture management (SSPM) and data access control platform, was acquired by Spin.AI for an undisclosed amount. DoControl had previously raised $43.4M in funding. (more)

  • EDNX, a United Kingdom-based software-defined network management and security platform, was acquired by Viatel for an undisclosed amount. EDNX has not previously disclosed funding. (more)

  • HUGIN AS, a Norway-based cyber risk management and compliance platform, was acquired by Pistachio for an undisclosed amount. HUGIN AS has not previously disclosed funding. (more)

  • RunReveal, a United States-based security analytics and observability platform, was acquired by ClickHouse for an undisclosed amount. RunReveal had previously raised $9.5M in funding. (more)

  • Synack, a United States-based AI-powered penetration testing-as-a-service (PTaaS) platform, merged with NetSPI for an undisclosed amount. Synack had previously raised $54.1M in funding. (more)

Service Companies:

  • Amivero, a United States-based professional services firm focused on digital transformation and cybersecurity advisory for federal government clients, was acquired by Xpect for an undisclosed amount. Amivero has not previously disclosed funding. (more)

  • ForeTech Software, an Israel-based value-added reseller, was acquired by Malam Team for an undisclosed amount. ForeTech Software has not previously disclosed funding. (more)

  • Fortress SRM, a United States-based managed security services provider (MSSP), was acquired by TUSKER for an undisclosed amount. Fortress SRM has not previously disclosed funding. (more)

  • Pathfynder, a United States-based professional services firm providing risk assessments, incident response, and offensive security testing, was acquired by A-LIGN for an undisclosed amount. Pathfynder has not previously disclosed funding. (more)

  • plenticon group, a Germany-based managed security services provider (MSSP), was acquired by Adelis Equity Partners for an undisclosed amount. plenticon group has not previously disclosed funding. (more)

  • Rox Partner, a Brazil-based professional services firm focused on data management and security consulting, was acquired by Dexian for an undisclosed amount. Rox Partner has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

Layoffs

  • None 😮‍💨

📚 Great Reads

*Sponsored

🧪 Labs

This is the only kind of AI agent cybercrime I want to see happen

🫡 Signing Off

Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate