This week's issue is backed by Maze and Token Security.
Hope you had a great weekend!
Did anything crazy or unusual happen in the AI world last week or over the weekend? Not sure if anyone noticed anything concerning on a human or societal level? Nothing about bioweapons or using AI to build military operations, or was that just me?
Surely nothing happened that spooked the bond and stock markets around the world, right? No? I sure hope we don’t experience another whipsawing week of irate claims and declarations from Frontier AI labs and politicians on the Internet.
Oh well, it’s probably nothing, and hey, at least we’re getting a foldable iPhone now. ¯\_(ツ)_/¯
In more positive news, my friend Ayoub Fandi wrote an awesome guest post about The AI-Era GRC Market that you should most definitely read!
PARTNER
The engineering behind a verdict you can trust
Our agents investigate millions of vulnerabilities a week. Making them accurate and consistent without breaking the bank took over a year of engineering.
CTO and co-founder Santiago Castiñeira walks through the toughest challenges, from the context layer to the architecture, between a working MVP and the system we run today. Save your seat, Sep 29
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
Where is capital in the security industry most obviously overbuilding for the same set of problems?
Last issue’s vibe check:
What has AI actually changed about security work so far?
🟨🟨⬜️⬜️⬜️⬜️ Fewer tasks, but harder ones
🟨🟨🟨🟨🟨⬜️ More tasks, but same hours
🟩🟩🟩🟩🟩🟩 Same work with higher expectations
🟨⬜️⬜️⬜️⬜️⬜️ No noticeable changes yet
🟨⬜️⬜️⬜️⬜️⬜️ Other (leave a comment)
“AI will take our jobs,” they said. “Humans will be able to focus on art and leisure instead of work,” they said. This doesn’t seem to be the case in general, and certainly NOT the case in cyber. People are doing more work in the same hours and/or are expected to have greater output and results now that we’ve got all these magic AI tools.
I don’t even think it’s an unreasonable expectation to think an increase in quality or throughput would be a result of using AI tools in your work, but more than anything, I think the security industry has set some pretty heavy expectations on itself to do far more.
You know what I attribute this to? I think it’s because we, as an industry, have always been behind. We’ve never known what it feels like to get to all the work on a security program’s proverbial backlog. It’s a never-ending game, and we know that, but the to-dos have always piled up much faster than the “done” list.
Now it’s much more exacerbated with AI tooling on all fronts. Obviously, the threat actors aren’t helping with this, and neither are the Frontier AI Labs.
Some of the top comments from last week’s vibe check:
💬 “Still "do more with less" as usual... at what point is this mythical man-month going to emerge?”
💬 “A lot of the work I was doing is changing. Completing the same amount of work, but expected to produce a lot more. Once real AI apps/automations started to kick in, I do have more time for higher-level work, but it isn't completely freeing me up. It's more that I still have to review and track my old work that's now partially automated, and newer work is also added on top, making me feel even more behind than before.”
💰 Market Summary
Private Markets
16 companies from 7 countries raised $474.1M across 15 unique categories
Average disclosed deal size was $36.5M (median: $7.3M)
100% of funded companies were product companies
8 companies from 4 countries were acquired for $1.1M across 8 unique categories
88% of acquired companies were product companies
Public Markets
1 pure-play public cyber company had an earnings report - $SAIL ( ▲ 15.55% )

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.7B across 146 deals over the past quarter, up 19% from a year ago.

96 acquisitions over the past quarter, up 8% from a year ago.
PARTNER
Every Acquisition Comes With Agents You've Never Met
Discover, scope, and remediate every AI agent identity
Five AI agent disclosures in 17 days: sandbox escapes, self-minted credentials, malware on 15 systems. Hugging Face rotated every token in its infrastructure, including clusters the agent never touched. Agent identities transfer with the entity, and so does the cleanup bill. Your diligence checklist doesn't have a line for them, but Token Security does.
🧩 Funding By Product Category

$245.0M for Security Operations across 1 deal
$121.0M for Quantum Key Distribution (QKD) across 2 deals
$48.5M for Distributed Ledger Technology (DLT) Security across 1 deal
$25.0M for Identity Risk Management (IRM) across 1 deal
$10.0M for Cyber Risk Management across 1 deal
$7.3M for Governance, Risk, and Compliance (GRC) across 1 deal
$6.8M for Embedded Security across 1 deal
$6.0M for Red Teaming across 1 deal
$2.4M for Continuous Threat Exposure Management (CTEM) across 1 deal
$2.0M for Cybersecurity Education & Training across 1 deal
$26.4K for Deepfake Detection across 1 deal
$7.9K for Cybersecurity Program Management across 1 deal
An undisclosed amount for Identity Governance & Administration (IGA) across 1 deal
An undisclosed amount for Crypto-Agility & Migration across 1 deal
An undisclosed amount for Trust & Safety across 1 deal
🏢 Funding By Company
» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.
Product Companies:
Cylake, a United States-based AI-driven security operations platform for companies that require offline or data sovereignty options, raised a $245.0M Convertible Note from Lightspeed Venture Partners, Picture Capital, and Redpoint. (more)
Quantinuum, a United States-based quantum computing cryptographic key generation platform, raised a $100.0M Grant from U.S. Department of Commerce. (more)
Cube3.ai (formerly Cube Security), a United States-based platform for protecting smart contracts against malicious transactions, raised a $48.5M Venture Round. (SEC Filing - may be incomplete)
cymphony.io, a United States-based identity risk management platform that unifies data access and behaviors of AI agents, raised a $25.0M Series A from Sequoia Capital. (more)
QNu Labs, an India-based quantum-resistant cryptography platform, raised a $21.0M Series A from National Quantum Mission and Speciale Invest. (more)
ZeroRisk, a United States-based cyber risk management platform, raised a $10.0M Series A from Middlegame Ventures. (more)
HelmGuard AI, a United Kingdom-based agentic AI governance, risk, and compliance management platform, raised a $7.3M Seed from Frontline Ventures and Infinity Ventures. (more)
SCI Semiconductor, a United Kingdom-based embedded chip and hardware security company, raised a $6.8M Seed from Mercia Ventures and PXN Ventures. (more)
FAZE Security, an Israel-based agentic offensive security orchestration platform, raised a $6.0M Seed from New Era Capital Partners. (more)
BYNARIO, an Italy-based continuous threat exposure management platform, raised a $2.4M Pre-Seed from 360 Capital. (more)
LeoTrace, a United Kingdom-based security decision layer for ai-generated code, raised a $2.0M Pre-Seed from Outward VC and Twin Path Ventures. (more)
Reagvis Labs, an India-based deepfake detection and KYC platform, raised a $26.4K Pre-Seed from Runway Incubator. (more)
CostObserver, a Singapore-based security-focused financial operations monitoring platform linking cloud and AI spend to security signals, raised a $7.9K Grant from Singapore Management University. (more)
AllSecureX, an India-based quantum cryptography discovery and key management software and hardware platform, raised an undisclosed Pre-Seed from Finvolve and India Accelerator. (more)
Nexis, a Germany-based identity governance and administration platform, raised an undisclosed amount of private equity from Tikehau Capital, which gained a minority stake in the company. (more)
Reality Defender, a United States-based AI deepfake media and content detection platform for media networks, raised an undisclosed Corporate Round from KPMG. (more)
Service Companies:
None
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$428.5M for the United States across 6 deals
$21.0M for India across 3 deals
$16.0M for the United Kingdom across 3 deals
$6.0M for Israel across 1 deal
$2.4M for Italy across 1 deal
$7.9K for Singapore across 1 deal
An undisclosed amount for Germany across 1 deal
🤝 Mergers & Acquisitions

Product Companies:
Guardrails AI, a United States-based platform for safely and securely building AI applications, was acquired by Harvey for an undisclosed amount. Guardrails AI had previously raised $7.5M in funding.
Nexis, a Germany-based identity governance and administration platform, was acquired by InfraVia Capital Partners for an undisclosed amount. Nexis has not previously disclosed funding. (more)
NextGen Security, a United States-based integrated physical and electronic security integrator, was acquired by Apax Partners for an undisclosed amount. NextGen Security has not previously disclosed funding. (more)
Service Companies:
Prime Networks, a United Kingdom-based managed security services provider (MSSP), was acquired by Focus Group (UK) for an undisclosed amount. Prime Networks has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
None 😮💨
📚 Great Reads
50% of CISOs see Mythos as a sign to exit the profession - Some security leaders are feeling the stress that AI is bringing to the role, but I was happy to be able to provide a counter perspective on how I (and many others) think it's one of the most exciting times to be in the role.
The AI-Era GRC Market: What Investors Fund, What Practitioners Need, and Which Platforms Survive - A guest post on Return on Security by Ayoub Fandi - A security practitioner's guide to the GRC software market, the limits of audit automation, and the AI-driven shift toward better decisions.
*Sponsored
🧪 Labs
Relatable
🫡 Signing Off
Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.

![💰 Security, Funded #261 - [AI] Agent Provocateur](https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,quality=80,format=auto,onerror=redirect/uploads/asset/file/fcc75e54-ae48-4ed4-9f0b-82ab70dbc3e2/BeeHiiv_Email_Email_header_image_1200x630.jpg?t=1705675525)