This week's issue is backed by Origin.
Hope you had a great weekend!
AppSec Days Portugal was a blast, and it was great to meet so many new people! Shoutout to the JScrambler team and all the organizers who pulled together a great event.
There’s nothing like traveling to show you how different countries and cultures are adapting to the current state of the world. With the price of diesel and oil driving up inflation, bond markets around the world demanding higher returns, ongoing conflicts, and all of it inextricably connected to a (potentially already) out-of-control AI ecosystem, much can weigh on the mind. It’s times like these that we need more beacons of light in an otherwise dark landscape.
One such beacon that comes to mind for me is this:

What I mean when I say, “I got that dog in me.”
Stay true to who you are. 😤 👊
PARTNER
October 1, the SACR endpoint report, read by the person who wrote it
A CISO briefing on agent runtime observability, October 1
Antivirus was built for files. EDR was built for processes. Neither was built for an agent that arrives with your credentials and never does the same job twice. SACR's Endpoint Control and Prevention report maps five zones for that layer, with Origin in the zone that reconstructs what agents did. Thursday, October 1 at 11 AM ET, author Lawrence Pingree and Origin founder Spencer Thompson walk through it live, then go deep on Origin's zone and the trace.
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
Which buys down the most security risk these days?
Last issue’s vibe check:
Why do security categories converge on the same roadmap within 18 months of inception?
🟩🟩🟩🟩🟩🟩 Customers all ask for the same thing
🟨⬜️⬜️⬜️⬜️⬜️ Analysts define the category
🟨⬜️⬜️⬜️⬜️⬜️ Investors fund the same pitch
🟨🟨🟨🟨⬜️⬜️ Teams copy what works
🟨⬜️⬜️⬜️⬜️⬜️ Other (tell me)
Not sure I’m buying the winning results from last week’s vibe check, to be honest. At least not as the root cause of why category convergence happens in our industry.
This makes a lot of assumptions that, in my experience, are hard to make true. If you press most security practitioners who are operating on a team in the thick of it all, they’ll have a challenging time pulling themselves out of the quagmire to think about the new things they might need one day. Practitioners can tell you what “good” or “useful” looks like when they see it, but dreaming it up in the first place is a different perspective. That’s the vision gap that founders and VCs are attempting to fill.
No, I think convergence happens through groupthink and because there are many new, narrow entry paths in the cybersecurity market, but few broad greenfield paths to take without stiff competition. This leaves startups facing stiff competition and the pressure to achieve feature parity to remain relevant to potential buyers.
Now add the AI-ification of everything to that. This evolution used to take 12-18 months, but now we’re lucky to get 3 months in before a wave of sameness hits. This isn’t a knock on any companies or practitioners at all; it’s just an acknowledgment that both sides have gotten harder to parse.
Some of the top comments from last week’s vibe check:
💬 “I know this is coming from an old guy and it always gets said about the next generation. We are running out of people who can conjure a new, original thought and turn it into a working solution. Following the other guy that looks like they know what they are doing...”
💬 “Customer demand convergence drives much of this, as they're not really sure what they want, but after enough conversations, a picture starts to emerge. Only that "picture" is what they've told a few other startups, investors, and practitioner friends.”
💬 “Security categories converge because each problem has only one complete control loop (see, judge, stop, prove), and a partial loop is operationally useless, so vendors that start at different segments are each forced to build the missing ones and arrive at the same product from opposite directions. (similar to customers all ask for the same thing, but more of a commentary on the architectural trajectory of any solution)!”
💰 Market Summary
Private Markets
11 companies from 5 countries raised $827.6M across 11 unique categories
Average disclosed deal size was $103.5M (median: $3.3M)
91% of funded companies were product companies
6 companies from 4 countries were acquired across 4 unique categories
67% of acquired companies were service companies
Public Markets
1 public company raised $1.1M via Post-IPO Equity
No pure-play public cyber company had an earnings report

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$9.2B across 154 deals over the past quarter, up 51% from a year ago.

95 acquisitions over the past quarter, up 6% from a year ago.
🧩 Funding By Product Category

$400.0M for Data Security Posture Management (DSPM) across 1 deal
$400.0M for Remote Browser Isolation across 1 deal
$16.0M for Agentic Runtime Security across 1 deal
$4.0M for Identity and Access Management (IAM) across 1 deal
$2.5M for Security Awareness across 1 deal
$2.0M for Secure File Sharing across 1 deal
$1.8M for AI Governance across 1 deal
$1.3M for Security and Compliance Automation across 1 deal
$1.1M for Brand Protection across 1 deal
An undisclosed amount for Cyber Risk Management across 1 deal
An undisclosed amount for Professional Services across 1 deal
An undisclosed amount for Crypto-Agility & Migration across 1 deal
🏢 Funding By Company
» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.
Product Companies:
Cyera, a United States-based data security posture management platform, raised a $400.0M Series G from Evolution Equity Partners. (more)
Island, a United States-based remote enterprise browser isolation platform, raised a $400.0M Series F from Evolution Equity Partners. (more)
Outerlimit, a United Kingdom-based guardrails platform for agentic AI at the execution layers, raised a $16.0M Pre-Seed from AlbionVC. (more)
AAIS Armageddon, a France-based employee security awareness training platform, raised a $2.5M Seed.
Qnext Corp, a Canada-based secure file sharing platform, raised a $2.0M Private Equity round from Ascent Capital Partners. (more)
Palma.ai, a United States-based enterprise AI agent governance and identity layer for MCPs, raised a $1.8M Pre-Seed from D11Z.Ventures. (more)
OneClickComply (formerly FAT32), a United Kingdom-based cybersecurity compliance automation platform for continuous monitoring, remediation, and audit evidence, raised a $1.3M Venture Round from Mercia Ventures and Northstar Ventures. (more)
Secur3D (formerly SECUR3D Holdings Inc.), a Canada-based brand security and digital IP protection platform, raised $1.1M in post-IPO equity. (more)
DigitalXForce, a United States-based cyber risk assessment and management platform, raised an undisclosed amount in a venture round. (more)
EnQuanta (formerly VoiceIt Technologies), a United States-based quantum crypto-agility and migration platform, raised an undisclosed amount in Debt Financing. (SEC Filing - may be incomplete)
Service Companies:
CYBR International, a United States-based professional services firm focused on threat detection and response, raised an undisclosed amount in an equity crowdfunding round. (SEC Filing - may be incomplete)
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$801.8M for the United States across 6 deals
$17.3M for the United Kingdom across 2 deals
$4.0M for Germany across 1 deal
$3.1M for Canada across 2 deals
$2.5M for France across 1 deal
🤝 Mergers & Acquisitions

Product Companies:
Aegis Security, a United States-based AI agent discovery and governance platform, was acquired by Upwind Security for an undisclosed amount. Aegis Security has not previously disclosed funding. (more)
Canopy Software, a United States-based data breach response software for compromised-data review, PII identification, and notification preparation, was acquired by Epiq for an undisclosed amount. Canopy Software has not previously disclosed funding. (more)
Service Companies:
assurepoint, an Australia-based professional services firm focused on compliance assessment and virtual CISO services, was acquired by A-LIGN for an undisclosed amount. assurepoint has not previously disclosed funding. (more)
Logiq Consulting, a United Kingdom-based cybersecurity professional services firm, was acquired by IBM for an undisclosed amount. Logiq Consulting has not previously disclosed funding. (more)
STACK Cybersecurity, a United States-based Managed Security Service Provider (MSSP) offering cybersecurity, was acquired by IT Solutions Consulting for an undisclosed amount. STACK Cybersecurity has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
None 😮💨
📚 Great Reads
AI Security Is an Engineering Problem, How to Solve It at Every Layer of the Agent Stack - From Saša Zdjelar, the CISO of NVIDIA - Open research, controls across the agent stack and continuous testing help defenders build and operate more secure AI systems.
The changing security risk calculus in the age of AI - Frank Wang writes about why the age of AI belongs to the technical security doer.
*Sponsored
🧪 Labs
Your move, Francis. 😤
🫡 Signing Off
Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.

