This website uses cookies

Read our Privacy policy and Terms of use for more information.

This week's issue is backed by Speakeasy.

Hope you had a great weekend!

Another week, another string of misaligned AI agents, and another bond market selloff. All of it drives how the tech and cyber industry invests and builds, so there’s no escaping the impacts down the line on cyber.

Meanwhile, the cyber market is putting all its eggs in the offensive basket, betting that the best Defense is good Offensive Security.

PARTNER

82% of enterprises are running AI agents they don't know about

That's from a CSA survey of 418 security teams who reported that 65% of them had already had an AI agent-related incident, most of them causing data exposure.

The Speakeasy AI control plane is the architecture enterprises are adopting to govern agentic actions within their orgs. It ensures that every agent, tool, and MCP server is authenticated, policy-compliant, auditable, and inspected for prompt injection and data exfiltration.

😎 Vibe Check

Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!

Last issue’s vibe check:
Which buys down the most security risk these days?
🟨🟨⬜️⬜️⬜️⬜️ Finding more vulnerabilities
🟨🟨🟨⬜️⬜️⬜️ Fixing what's already there
🟨⬜️⬜️⬜️⬜️⬜️ Proving controls actually work
🟩🟩🟩🟩🟩🟩 Shrinking what's exposed
⬜️⬜️⬜️⬜️⬜️⬜️ Creating fewer security defects
🟨⬜️⬜️⬜️⬜️⬜️ Other (tell me)

Shrinking what is exposed and reducing the existing attack surface was the clear winner in last week’s vibe check. The results are funny to me, because “shrinking exposure” isn’t really an investable domain in the cyber world. I still agree with it being the right approach to take, however.

You can obviously enumerate and identify your exposure better, take steps to secure and patch what’s out there, but shrinking it is a different game altogether. It’s going to require businesses to do things differently from an architectural and go-to-market standpoint.

Some of the top comments from last week’s vibe check:

💬 “Most security spend and energy and effort is focused on reducing risk likelihood. Actions that focus on reducing risk magnitude have a bigger impact at this point, so forensic readiness, incident response planning, exercising, and working stuff out with your insurance carrier and law firm and forensics firm are going to change overall posture more than running faster on the vulnerability hamster wheel …”

💬 “We do NOT need to find more problems. We need to automate the mitigation of the ones we have. Lower risk comes when you give an effort to reduce risk not increase it with findings.”

💰 Market Summary

Private Markets

  • 12 companies from 6 countries raised $419.2M across 12 unique categories

  • Average disclosed deal size was $41.9M (median: $13.7M)

  • 92% of funded companies were product companies

  • 14 companies from 9 countries were acquired for $33.9M across 8 unique categories

  • 71% of acquired companies were service companies

  • 1 company announced layoffs

Public Markets

  • No pure-play public cyber company had an earnings report

📸 YoY Snapshot

Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$9.5B across 160 deals over the past quarter, up 112% from a year ago.

108 acquisitions over the past quarter, up 19% from a year ago.

🧩 Funding By Product Category

  • $255.5M for Continuous Automated Red Teaming (CART) across 1 deal

  • $55.0M for SaaS Security Posture Management (SSPM) across 1 deal

  • $38.0M for Network Security across 1 deal

  • $25.0M for Deepfake Detection across 1 deal

  • $15.4M for Security and Compliance Automation across 1 deal

  • $12.0M for Identity Threat Detection and Response (ITDR) across 1 deal

  • $10.0M for Narrative Intelligence across 1 deal

  • $7.0M for Red Teaming across 1 deal

  • $726.7K for Secure Access Service Edge (SASE) across 1 deal

  • $609.4K for Managed Detection and Response (MDR) across 1 deal

  • An undisclosed amount for Agentic Runtime Security across 1 deal

  • An undisclosed amount for Post-Quantum Cryptography (PQC) across 1 deal

🏢 Funding By Company

» Connect Claude, Cursor, or any MCP client to The Signal via the MCP for free.

Product Companies:

Service Companies:

SEC filings may reflect partial or interim fundraising and can understate the final round numbers.

🌎 Funding By Country

  • $380.5M for the United States across 6 deals

  • $15.4M for Italy across 1 deal

  • $12.0M for Israel across 1 deal

  • $10.0M for Luxembourg across 1 deal

  • $726.7K for India across 2 deals

  • $609.4K for Denmark across 1 deal

🤝 Mergers & Acquisitions

Product Companies:

  • Plurilock, a Canada-based behavioral biometric identity and access management platform, was acquired by Quantum eMotion for $23.9M. Plurilock had previously raised $16.5M in funding. (more)

  • msecure, a Germany-based password management platform, was acquired by Sequrio for an undisclosed amount. msecure has not previously disclosed funding. (more)

  • Riva Labs, a Switzerland-based post-quantum cryptography and wallet infrastructure security for digital assets, was acquired by Project Eleven for an undisclosed amount. Riva Labs has not previously disclosed funding. (more)

Service Companies:

  • WithNetworks, a South Korea-based managed security services provider, was acquired by ICTK for $10.1M. WithNetworks has not previously disclosed funding. (more)

  • Aigner Business Solutions, a Germany-based professional services firm focused on data privacy and protection services, was acquired by Sequrio for an undisclosed amount. Aigner Business Solutions has not previously disclosed funding. (more)

  • Althammer & Kill, a Germany-based professional services firm focused on cloud security, data protection, and compliance, was acquired by Sequrio for an undisclosed amount. Althammer & Kill has not previously disclosed funding. (more)

  • CyberStrikeAI, a Singapore-based open-source AI penetration testing platform, was acquired by ThreatBook for an undisclosed amount. CyberStrikeAI has not previously disclosed funding. (more)

  • DATATREE, a Germany-based compliance and data protection services firm, was acquired by Sequrio for an undisclosed amount. DATATREE has not previously disclosed funding. (more)

  • Fentron, a United States-based professional services firm focused on security architecture, incident response preparedness, and CISO advisory services, was acquired by TRG (US) for an undisclosed amount. Fentron has not previously disclosed funding. (more)

  • Myriad360, a United States-based professional services firm focused on cyber and IT advisory, was acquired by One Equity Partners for an undisclosed amount. Myriad360 has not previously disclosed funding. (more)

  • NetSentries, a United Arab Emirates-based professional services firm focused on offensive security consulting, was acquired by SGS for an undisclosed amount. NetSentries has not previously disclosed funding. (more)

  • Nextwork, a Germany-based professional services firm focused on data protection and data privacy, was acquired by Sequrio for an undisclosed amount. Nextwork has not previously disclosed funding. (more)

  • Prescient Security, a United States-based professional services firm focused on compliance audits and penetration testing, was acquired by SGS for an undisclosed amount. Prescient Security has not previously disclosed funding. (more)

  • Wolfpack Information Risk, a South Africa-based professional services firm focused on security awareness training and incident response support, was acquired by Risk X Group for an undisclosed amount. Wolfpack Information Risk has not previously disclosed funding. (more)

🤘 IPO-h Yeah

  • None

🪦 Stop, Drop, Shut’em Down…

  • None 😮‍💨

❌ Layoffs

  • Snyk, a United States-based application security platform, laid off 203 employees, or 20% of its workforce, as part of a restructuring effort. (more)

📚 Great Reads

  • The free AI already on your Mac - macOS Tahoe ships with a 3B parameter LLM. apfel gives you CLI access with one brew install. No model downloads, no API keys, no configuration needed, just works. Not an endorsement, I just thought it was really cool.

  • Security Teams Are Moving Too Slowly for AI Agents - Zach Korman and Chris Hughes discuss the collision between the AI safety conversation and the cybersecurity world, and how that has been playing out since the OpenAI Hugging Face incident.

*Sponsored

🧪 Labs

Neither side stands a chance

🫡 Signing Off

Have questions, comments, or feedback? Just reply back, and let me know.

If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!

Mike P

P.S. Feel free to connect with me on LinkedIn.

Reply

Avatar

or to participate