This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by Origin and SpectorOps.

Hope you had a great weekend!

This week’s issue is coming at you live and direct from Portugal, where, despite it being the first day of fall, it is most certainly not cooling off! 🥵

Also, finally all is right in the Frontier AI lab world when it comes to security, now that all major labs have had agent swarms breach their sandboxes and hack other companies.

Well done, everyone!

I was really starting to get worried there!

In other news, I’ll be at the AppSec Days Portugal conference this week, so please feel free to stop me and say hello if you’re there!

PARTNER

The analyst report that put AI agents on the endpoint security map

A live walk-through with the analyst who wrote it

SACR's Endpoint Control and Prevention report maps five zones for securing the layer where AI agents now work, and Origin sits in the zone that answers what your agents actually did. On October 1 at 11 AM ET, the analyst who wrote the report, Lawrence Pingree, and Origin founder Spencer Thompson walk through it live, then go deep on Origin's zone, the trace, and what you can do with it.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Why do security categories converge on the same roadmap within 18 months of inception?

Login or Subscribe to participate

Last issue’s vibe check:
Where is capital in the security industry most obviously overbuilding for the same set of problems?
🟩🟩🟩🟩🟩🟩 AI red teaming
🟨🟨🟨⬜️⬜️⬜️ Agentic runtime security
🟨🟨🟨🟨⬜️⬜️ Agent Identity
🟨🟨🟨🟨🟨⬜️ AI agent governance
🟨⬜️⬜️⬜️⬜️⬜️ Agentic remediation
🟨🟨⬜️⬜️⬜️⬜️ Other (leave a comment)

Strong vote spread last week, and this was closer in a few places than I expected! With more votes than I normally get, I think it’s safe to say the industry has grown a bit tired of hearing about AI.

There’s a growing consensus that AI red teaming is going the way of human pentesting, where “value” and “outcomes” are perceived very differently depending on who is doing the purchasing. Some view it as a compliance checkbox you have to check once a year, while others see it as an invaluable part of a security program that should run continuously.

AI Agent Governance has a wholly different problem. The challenges here are in the perceptual world, rather than the technical one. It comes down to philosophy, your influences, and what you “believe” as a security person or organization. That’s before we even get to the “What can I afford?” part of the story.

I think we’re still early in the game here with understanding how to secure the different parts of AI, and how to use AI for security purposes beyond bug discovery.

Alas, the [AI] horrors persist, and so too must we. 🫡

Some of the top comments from last week’s vibe check:

💬 “AI Agent Governance" - Don't know if I've ever seen our crazy industry hype such a capability so much while actually building so little. The gold rush is real, and we're suffering for it by having to filter through an ever-increasing pile of BS to seek real value.”

💬 “Way too many AI red teaming companies being funded, pivoting, and popping up. Pentesting is the cyber world’s equivalent of needing “taste” to determine what is good vs. what is just a vulnerability scan.“

💰 Market Summary

Private Markets

  • 14 deals from 13 companies across 6 countries raised $462.2M across 12 unique categories

  • Average disclosed deal size was $38.5M (median: $9.7M)

  • 85% of funded companies were product companies

  • 6 companies from 5 countries were acquired across 3 unique categories

  • 83% of acquired companies were service companies

Public Markets

  • No pure-play public cyber company had an earnings report

  • Perhaps counterintuitively, all markets went back up last week because the US Fed chief raised interest rates, which let the bond market and the 10-year Treasury rate drop back down and the AI Trade rebuff deceleration claims.

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.5B across 148 deals over the past quarter, up 9% from a year ago.

92 acquisitions over the past quarter, up 3% from a year ago.

PARTNER

Your AI agents are already part of the attack graph

Attack path management for the hybrid AI enterprise

AI agents are non-human identities with permissions and trust relationships attackers can chain across cloud and SaaS. BloodHound Enterprise maps those paths across AWS, Entra Agent ID, AD, Okta, and more, then pinpoints the choke points where one fix can eliminate up to 17,000 paths. BloodHound Hunter puts that intelligence into trusted AI workflows.

🧩 Funding By Product Category

  • $270.0M for Internet of Things (IoT) Security across 2 deals

  • $72.0M for Data Loss Prevention (DLP) across 1 deal

  • $40.0M for AI Security across 1 deal

  • $34.0M for Security and Compliance Automation across 1 deal

  • $19.0M for Threat & Vulnerability Management (TVM) across 1 deal

  • $14.9M for Secure Access Service Edge (SASE) across 1 deal

  • $7.5M for AI Governance across 2 deals

  • $2.5M for Cyber Insurance across 1 deal

  • $1.4M for Professional Services across 1 deal

  • $644.5K for Brand Protection across 1 deal

  • $235.0K for Software Supply Chain Security across 1 deal

  • An undisclosed amount for Security Operations across 1 deal

🏢 Funding By Company

» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.

Product Companies:

Service Companies:

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $270.0M for Italy across 2 deals

  • $155.2M for the United States across 8 deals

  • $19.0M for France across 1 deal

  • $14.9M for China across 1 deal

  • $2.5M for Bermuda across 1 deal

  • $644.5K for Japan across 1 deal

🤝 Mergers & Acquisitions

Product Companies:

  • OpenZeppelin, a United Kingdom-based smart contract security company providing open-source libraries, security audits, and developer tooling for onchain applications, was acquired by S&P Global for an undisclosed amount. OpenZeppelin has not previously disclosed funding. (more)

Service Companies:

  • 4Elitech, a Spain-based professional services firm focused on industrial cybersecurity and critical infrastructure protection, was acquired by Aiuken for an undisclosed amount. 4Elitech has not previously disclosed funding. (more)

  • Avertium, a United States-based cybersecurity services firm providing GRC, offensive security, security architecture, and Microsoft security services, was acquired by CyberMaxx for an undisclosed amount. Avertium has not previously disclosed funding. (more)

  • Ontinue, a Switzerland-based managed extended detection and response service provider, was acquired by Quorum Cyber for an undisclosed amount. Ontinue has not previously disclosed funding. (more)

  • Red Alert Labs, a France-based professional services firm specializing in IoT security assessment certification services, was acquired by FIME for an undisclosed amount. Red Alert Labs has not previously disclosed funding. (more)

  • RedTrace Technologies, a United States-based professional services firm focused on cyber risk management, was acquired by Worldwide NFT for an undisclosed amount. RedTrace Technologies has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

Layoffs

  • None 😮‍💨

📚 Great Reads

*Sponsored

🧪 Labs

Watchamacalling it, and such

🫡 Signing Off

Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate