Data Security
The AI era has moved data security onto the board agenda. Cyera's valuation rose from ~$1.4B to ~$6B to ~$9B to ~$12B in roughly eighteen months, on the argument that enterprise AI cannot be deployed safely without knowing where sensitive data sits and which users or agents can access it. The most recent capital arrived without extending that series: a $600M first close in June 2026 priced at $12B was followed by a $400M extension from Goldman Sachs in September 2026 at a mark the company describes only as "over $12 billion". A central question is whether data security is consolidating into a single platform or remains a set of separate features.
Scope: data security
Data security protects the data itself — at rest, in motion, and increasingly in use by AI — independent of the network, endpoint, or app it lives on. The historically fragmented tool categories are converging into "data security platforms":
- DSPM (Data Security Posture Management): discovers and classifies sensitive data across cloud, SaaS, and on-prem stores, then maps who/what can access it and where it's exposed. The fast-growing, AI-era control plane — Cyera, BigID, Sentra, Dig (Palo Alto), Laminar (Rubrik), Concentric AI, Symmetry.
- DLP (Data Loss Prevention): enforces policy to stop sensitive data from leaving — email, endpoint, web, and now GenAI prompts. The legacy, often-hated category being re-platformed: Forcepoint, Symantec/Broadcom, Microsoft Purview, Zscaler, Proofpoint, Cyberhaven (data-lineage approach).
- Encryption / key management / tokenization: protects data cryptographically and controls the keys — Thales, Entrust, Fortanix, HashiCorp Vault (IBM), AWS/Azure KMS.
- Data access governance & privacy: governs entitlements, consent, and data-subject rights — Varonis (unstructured-data access), BigID, Securiti, OneTrust (privacy adjacency).
- Backup / recovery / cyber-resilience: increasingly counted as data security because ransomware made recoverability a security control — Rubrik, Cohesity (+Veritas), Veeam, Commvault.
The strategic significance: data is the one asset that doesn't move when the perimeter dissolves — so as workloads scatter across multi-cloud and SaaS, data-centric controls become the durable control point. AI super-charges this: every enterprise GenAI deployment is a data-governance problem (what can the model see? what can an agent exfiltrate?), which is exactly why DSPM re-rated from a "nice-to-have inventory tool" into the "trust layer for AI." Whoever owns the classified data map owns the substrate that DLP, access governance, and agentic-security policies all run on.
How each actor makes money and how they differ
| Vendor | Owner | Posture | Differentiation / economics |
|---|---|---|---|
| Cyera | Private (VC) | DSPM platform / leader | AI-native DSPM expanded into DLP, identity, privacy, and agentic security — "trust layer for AI"; $12B valuation at the Jun 2026 first close of a Series G that reached $1.0B with a $400M Goldman Sachs extension in Sep 2026 at an undisclosed mark (company-stated: 1,500+ employees, use by 20% of the Fortune 500, more than $2.7B raised in total; no ARR disclosed); ~8.6x from ~$1.4B in ~18 months; Frank Slootman on board; the most prominent asset in the category |
| Varonis | Public (VRNS) | Data access / unstructured | Long-standing unstructured-data access governance + behavioral analytics; transitioned to SaaS + MDDR; the scaled public pure-play in data security |
| BigID | Private (PE/VC) | DSPM + privacy | Privacy-first, deep classification of structured/unstructured incl. mainframes/data lakes; pairs DSPM with consent and data-rights workflows |
| Rubrik (Laminar) | Public (RBRK) | Resilience + DSPM | Backup/cyber-resilience leader that bought Laminar (DSPM) — "data security from backup outward"; bundles posture with recoverability |
| Palo Alto (Dig) | PANW | Platform / bundler | Bought Dig Security (2024) to fold DSPM into Prisma Cloud — DSPM as a CNAPP feature, the bundler threat to standalones |
| Forcepoint | TPG | DLP consolidator | Legacy DLP re-platformed into a data-security suite; bought GetVisibility (DSPM, 2025); PE-owned roll-up engine |
| Microsoft (Purview) | MSFT | Bundler | DLP + classification + insider risk bundled into M365/E5 — the "free with the license" threat that commoditizes baseline DLP |
| Zscaler / Proofpoint / Netskope | various / TB | Inline DLP | Data protection delivered inline through SSE/email — DLP as a feature of the traffic platform |
| Cyberhaven | Private (VC) | Data lineage / DLP | Tracks data lineage (where data came from and went) rather than pattern-matching content — a next-gen attack on legacy DLP's false-positive problem |
| Sentra / Concentric AI / Symmetry | Private (VC) | DSPM specialists | Scaled independent DSPM challengers; classic consolidation supply against Cyera and the platforms |
| Securiti | Private (VC) | Data+AI governance | Unified data command center (DSPM + privacy + AI governance); positioned for the AI-governance wave; reported strategic interest from data-platform buyers |
| Thales / Entrust / Fortanix | various | Encryption / KM | Crypto, HSM, key management, tokenization — the regulated, infrastructure-grade layer; quantum-safe migration is the next demand driver |
Data security has three camps converging on one pool. The DSPM natives (Cyera, BigID, Sentra, Concentric) won the AI-era narrative — they map and classify the data, which is the control plane everything else needs; Cyera's rapid valuation increase reflects the market betting one of them becomes the data-security platform. The legacy DLP and access players (Forcepoint, Varonis, Symantec) own the enforcement install base and the compliance workflows but carry the burden of false positives and brittle policy — their value is the install base and the enforcement rails, which is why they are buying DSPM to modernize. The bundlers (Microsoft Purview, Palo Alto/Dig, Zscaler, Rubrik) fold data security into a bigger platform — Microsoft commoditizes baseline DLP, Palo Alto folds DSPM into CNAPP, Rubrik approaches from resilience. The encryption/key-management layer (Thales, Entrust, Fortanix) is a separate, infrastructure-grade pool with its own driver (post-quantum migration).
Where data-security spend is concentrating
Signature deals & events
- Cyera's valuation run (2024–2026) — ~$1.4B → $6B (Jun 2025) → $9B (Jan 2026) → $12B ($600M first close, Jun 10 2026), a ~8.6x step over roughly eighteen months; the clearest market signal that data security is the AI era's premium control point. (Frank Slootman has sat on Cyera's board since Mar 2025 — a governance signal that predates this round, not part of it.) The bellwether the whole domain is priced against.
- The Series G extension (Sep 22 2026) — $400M from Goldman Sachs, taking the round to $1.0B across two tranches 104 days apart. No new valuation was disclosed; the company states only that it is worth "over $12 billion". Capital intake and a disclosed mark are separate events, and the series above stops at the June figure: a round extension at an undisclosed price is not evidence of a step-up, and any 2026 comparable drawn from this company should be anchored to the $12B June print rather than to the larger cumulative round. The stated uses are AI-security development and expansion into the US federal government and international markets, and the extension follows two agent-security launches — Agent Guardian (agent inventory, vulnerability scanning of agents, tools and MCP servers, and per-action blocking or quarantine) and Cyera Endpoint (agents running on employee devices). See 11, 07.
- Cyera → Oasis Security (~$1B, announced Jul 28 2026, completed Sep 3 2026) — the DSPM leader's move beyond data security into non-human and AI-agent identity governance, pairing its map of what sensitive data exists with Oasis's map of which humans, machines, and agents can access it. The largest non-human-identity acquisition to date; a data-security platform extending into the identity control plane rather than a pure identity vendor consolidating the niche. The acquired business operates as Cyera Identity, the identity pillar of the platform. See 11, 20b.
- Palo Alto Networks → Dig Security (~$400M, 2024) — DSPM folded into Prisma Cloud; the canonical bundler move that put pressure on standalone DSPM valuations and set off the "platform vs. specialist" race.
- Rubrik → Laminar (~$200–250M, 2023) — a backup/resilience leader buying DSPM to attack data security "from the data outward"; validated resilience-plus-posture convergence.
- Fortra → Lookout (data security business, 2025) and Forcepoint → GetVisibility (2025) — legacy DLP/security vendors buying DSPM/classification to modernize aging enforcement franchises.
- Concentric AI → Swift Security + Acante (2025) — sub-scale DSPM specialists combining; the consolidation template inside the long tail.
- Kiteworks → Bonfy.AI (announced Sep 10 2026; terms undisclosed, estimated at tens of millions) — the category's enforcement layer being bought rather than built, and the clearest statement yet of where the control point is moving. The DSPM cohort competes on mapping what sensitive data exists; Bonfy classifies an exchange while it is happening and decides whether the transfer completes, using business and behavioural context rather than the content patterns legacy DLP matches on. That distinction is what makes the agent case tractable: an inventory cannot govern a transfer initiated by an autonomous agent, because the agent's authority to hold the data and its authority to move it are not the same question. Kiteworks folds the technology into its Data Control Plane, extending one policy model across human and machine exchange. The acquirer is a serial consolidator — eighth acquisition in five years, 36 days after buying WAMNET Japan for market access — and the commercial consequence for the standalone cohort is that inline enforcement is now a platform feature in at least one credible suite rather than a separate purchase. See 11, 20.
- MIND → $72M Series B led by Crosspoint Capital Partners (Sep 17 2026) — a control-buyout investor taking the lead position in a venture growth round, which is the structural content of the financing rather than the amount. The round follows a $30M Series A a year earlier; the $112M disclosed total against $102M of named rounds implies roughly $10M of earlier, unitemised capital. YL Ventures and Paladin Capital Group participated. The thesis addresses the oldest displacement opportunity in the domain — DLP, the legacy enforcement layer described above — on the argument that sensitive data now leaves the enterprise through generative-AI and agentic tools rather than through email and removable media, making this a replacement cycle in a large installed base rather than a new category. The company reports more than 17× revenue and 8× customer growth over the prior year; both are company-stated multiples on an undisclosed base and cannot be converted into revenue. The presence of a buyout underwriter on the register at Series B compresses the distance between a growth round and a control transaction, and belongs in the diligence view of any DLP-adjacent asset assessing its future buyer universe. (MIND, Sep 17 2026 · SecurityWeek)
- The AI-data-governance pivot — every major data-security vendor (Cyera, BigID, Securiti, Varonis) repositioning around "secure your enterprise AI": classify what models can see, govern what agents can do. The demand catalyst reshaping the category. See AI Security.
The bear case
The data-security bull case is "data is the one asset that survives the death of the perimeter, AI makes knowing your data critical, and the DSPM control plane compounds into the durable data-security platform." The bear case has two prongs. First, DSPM may be a feature, not a platform. Palo Alto folded Dig into CNAPP; Rubrik folds posture into resilience; Microsoft Purview bundles classification and DLP into E5 at near-zero marginal cost. If the natural home for "where is my sensitive data" turns out to be inside the cloud-security platform or the M365 license, then standalone DSPM is a transient category and Cyera's $12B is a private-market valuation untested by the public bid. Second, the legacy DLP install base is large but melting — enforcement is being commoditized by the bundlers and reinvented by data-lineage upstarts, so the incumbents' install-base value erodes even as they buy growth. Falsifiable test: watch whether a standalone DSPM leader reaches durable nine-figure ARR and a public listing at a premium multiple, or whether the category gets absorbed — Palo Alto/Dig, Microsoft Purview, and the CNAPP platforms taking the net-new data-security budget. If the standalones get tucked in below their last private mark while the platforms win the spend, "data security is its own durable platform" is breaking, and the AI-era re-rating was a bubble in a feature.
→ Cross-references: Vendors, Cloud Security, Identity, AI Security, Deals & Comps, Valuation, Bear Case.
Adjacent market: the backup and cyber-resilience industry converging with data security is mapped on Data Protection & Cyber Resilience.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.