The Business of Cyber Security

Venture Capital

Venture capital funds the supply of future acquisition targets in cybersecurity. VC-backed companies approaching scale are the founders who eventually seek an exit, and VC-backed scale-ups building a corporate-development function for the first time form a distinct segment within that population.

The dedicated sub-pages cover the cyber-specialist funds (07a), generalist VCs active in cyber (07b), company formation and the Israeli foundry model (07c), the time-to-trust problem for early security startups (07d), category creation (07e), growth-stage metrics and diligence (07f), and a tracker of VC-backed scale-ups approaching an exit decision (07g).

H1 2026 financing

Financing in H1 2026 stayed healthy but increasingly selective: 383 financing rounds and $7.5B deployed~24% below the rolling three-year average by deal count — at a median deal size of ~$12M. Capital concentrated hard: ~40% of all financing value went to AI Security companies, and just five deals accounted for ~23% of the capital deployed (the largest rounds ran ~$600M, ~$400M, ~$260M, and two at ~$250M). June alone delivered 69 rounds and $2.8B, led by Cyera, DREAM, and Coralogix. The most-financed sectors were Risk & Compliance (84 rounds, the most active) and AI Security, followed by Identity & Access (36) and Security Operations (26).

The AI-security financing market is financing-led and late-stage-driven: >$15B deployed since 2022 across ~330 early-stage rounds and ~$3.4B of Series C+ capital, with a median Series C+ valuation of ~$1.5B and AI-native leaders commanding ~15–20x+ EV/revenue (median founding year ~2022). Capital clusters around a small set of AI-native leaders while the long tail thins.

(Source: cybersecurity mid-year 2026 market review — Wall Street research, published Jul 1 2026; see Deals.)

June 2026 mega-rounds. Wall Street research's June review lists headline private rounds in the hottest niches: a $600M Series G at a $12B valuation (DSPM — Cyera), a $260M Series C at $3B (AI-native sovereign cyber — DREAM), and a $200M Series F at $1.6B (AI-native observability and security analytics — Coralogix), alongside a full early-stage sheet ($100M Seed, $100M Series B, €60M Series C, $66M Seed, two Series A at $64M/$60M). Capital continued to concentrate in data security, sovereign/agentic AI, and AI-analytics — the same niches carrying the widest public-to-private multiple spread (12). On the debt side, the research notes leveraged-finance issuance running ~39% M&A/LBO, ~44% refinancing, new-issue loan spreads around S+315bps (single-B), and private-credit dry powder still deep — supportive for the PE/sponsor buyers who complete roughly a third of cyber M&A.

July 2026 mid-month. Neo (Security for AI / agentic-identity — a real-time control layer that inventories and enforces policy on AI agents, MCP servers, and browser extensions; founded by ex-SentinelOne, ex-Wiz, and ex-Palo Alto Networks executives) raised $100M on Jul 20, 2026 — a $75M Series A led by Andreessen Horowitz and Bessemer Venture Partners (Craft Ventures, Merlin Ventures) on top of a previously undisclosed $25M seed completed in 2025 — a conviction round at the entry of the H2 cycle, signaling continued capital availability for AI-security leaders despite the overall financing selectivity (company profile on 20g). Empirical Security (exposure management / risk prioritization, founded by Kenna Security alumni Ed Bellis and Michael Roytman) raised $25M Series A on Jul 20, 2026 (Brightmind Partners led; total funding $37M). Both rounds landed within the established hot-niches pattern: AI-security / agentic-identity and exposure management / prioritization remain the capital-intensive, acquirer-adjacent layers of the market.

Late July 2026 — agentic-identity funding cluster. Two Tel Aviv rounds closed on the same day (Jul 28, 2026) in the agentic / non-human-identity lane, extending the Neo signal into a cluster. Hush Security raised a $30M Series A (total $41M) with Akamai Technologies joining as a strategic investor alongside Battery Ventures and YL Ventures; founded in 2024 by the ex-Meta Networks team, Hush operates a machine-access platform that governs enterprise AI agents and their underlying infrastructure. Act Security emerged from stealth with $60M total — a $20M seed led by Team8 and Bessemer Venture Partners (Hetz Ventures, Claltech) plus a $40M Series A led by Notable Capital (Startpoint Capital, SVCI); founded by the team behind Medigate (acquired by Claroty for $400M), Act reduces the cloud access surface by enforcing boundaries for humans, workloads, and AI agents. The two rounds — with a strategic acquirer (Akamai) already on the Hush cap table and repeat AI-security backers (Bessemer, Team8) leading Act — concentrate capital in the same securing-the-AI-workforce thesis carrying the widest private-to-public multiple spread (12); company profiles on 20g.

Late July 2026 — ThreatLocker $190M Series F. ThreatLocker (Orlando, Florida; Zero Trust endpoint control — application allowlisting and ringfencing that operates deny-by-default) raised a $190M Series F on Jul 29, 2026, led by Elephant, with D. E. Shaw Ventures and Arthur Ventures continuing and Koch Disruptive Technologies joining as a new investor. The round brings total funding to nearly $500M; the company was last valued at ~$1.6B (2024), and no updated valuation was disclosed. Proceeds are earmarked for product development, controls for AI-related risk, and international expansion (a UK office in Reading). The positioning is notable for the AI thread: ThreatLocker frames its deny-by-default control model as extending to what AI agents are permitted to execute on an endpoint — an access-governance posture adjacent to, but distinct from, the identity-centric agentic lane (Neo/Hush/Act), and a larger, later-stage US round than that Israeli cluster. (SecurityWeek · PR Newswire)

Late July 2026 — Onyx Security $113M Series B. Onyx Security (Tel Aviv and US; founded 2024 by Maxim Bar Kogan and Gil Elbaz) raised a $113M Series B on Jul 29, 2026, led by Bessemer Venture Partners with Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared, at a $640M valuation; total funding reaches $153M. Onyx builds an "AI control plane" — a supervisory layer that discovers, monitors, and remediates the risks created by AI agents granted access to corporate systems without built-in oversight — and reports quadrupling revenue in the roughly four months since leaving stealth, with Fortune 500 customers and 80-plus staff across Israel, the US, and Canada. The round sits in the same securing-the-AI-workforce thesis as the Neo/Hush/Act agentic-identity cluster, but from the governance-and-control angle (what AI agents may do and access) rather than issuing agent identities; it is the largest AI-agent-governance round of the July cluster. (SecurityWeek · CTech · BusinessWire)

Late July–early August 2026 — agentic security-operations and posture funding. A second AI-security funding lane ran alongside the agentic-identity cluster (Neo/Hush/Act/Onyx): rounds aimed at using AI agents to run and improve security operations rather than to secure the agents themselves. Mate Security raised a $35M Series A on Jul 28, 2026, led by Canaan Partners with Microsoft's M12, Insight Partners, and Team8, bringing total funding beyond $50M; Mate builds an AI-driven agentic security-operations platform that detects, investigates, and responds to threats with autonomous agents. Discern Security raised a $13M Series A on Jul 30, 2026, led by cyber specialist Forgepoint Capital (First Rays Ventures, Growth Enjin Partners, Vela Ventures), launching alongside "Agentic Loops" — a platform that continuously evaluates and improves an organization's existing security controls, combining AI agents with human-approved workflows to identify control gaps and prioritize remediation (founded 2023, California). Both sit on the AI-for-Security side of the framework — agents making the security function faster and cheaper — distinct from the Security-for-AI agentic-identity rounds that secure the agents (see 20, 04c). (Mate — CTech · Discern — SecurityWeek · PR Newswire, Jul 30 2026)

A third infrastructure layer in the same lane drew capital the same week: DataBahn raised a $40M Series B on Jul 30, 2026, led by Insight Partners with Forgepoint Capital, GTM Capital, and S3 Ventures continuing, bringing total funding to about $59M. DataBahn builds an agentic "data control plane" that ingests, filters, enriches, and routes enterprise security and observability telemetry before it reaches the SIEM or SOC, reducing data volume and cost while feeding AI-driven detection. It sits on the AI-for-Security side as well, but on the data-pipeline layer that supplies the agentic SOC rather than the detection/response or posture agents — a reminder that the AI-for-Security build-out is capitalizing at multiple layers (data plane, SOC agents, posture/control) at once. (SecurityWeek · PR Newswire)

Early August 2026 — Horizon3.ai $250M Series E at a $2B valuation. Horizon3.ai (founded 2019) raised a $250M Series E on Aug 3, 2026, co-led by returning investors NightDragon and NEA, with seven new and five returning backers; the valuation more than tripled from roughly $650M in June 2025 to $2B. The company runs NodeZero, an autonomous-pentest platform whose "friendly agents" continuously probe a customer's own network with attacker techniques and report exploitable paths and remediations — positioning continuous, machine-speed validation against AI-scaled attacks. It reports 7,000-plus customers (four Fortune 10) and 120% YoY ARR growth, with proceeds directed at go-to-market (MSP and telco channels) and R&D. This is a distinct AI-security lane from the agentic-identity and agentic-SOC rounds above — autonomous offensive validation — and the largest financing in that category to date, a data point that the market is capitalizing continuous validation as a standalone category rather than a suite feature (see 04f, 11). (SecurityWeek · TechCrunch · SiliconANGLE)

Early August 2026 — Zenity $125M Series C. On Aug 3, 2026 — the same day as the Horizon3.ai round — Zenity (research in Tel Aviv, operations in New York; co-founders Michael Bargury and CEO Ben Kliger; ~230 staff) raised a $125M Series C led by Norwest, with SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, and Qumra Capital joining as new investors alongside existing backers Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital; total funding reaches roughly $185M (post-money valuation undisclosed). Zenity secures AI agents inside enterprise systems — mapping how agents are embedded, monitoring their actions in real time, and blocking or altering behavior that deviates from an agent's intended purpose or corporate policy. It sits on the Security-for-AI side of the framework, on the agent-security/governance frontier — securing the agents, distinct from the agentic-identity issuance rounds (Neo/Hush/Act/Onyx/Oak) and the AI-for-Security SOC/posture lane (Mate/Discern). Two features distinguish it from the July agent-security cluster: it is one of the largest dedicated Security-for-AI rounds to date, and it carries strategic corporate backers (SoftBank, Hitachi, LG) whose participation is tied to their own enterprise agent adoption, particularly in Asia-Pacific. As the largest independent capital raise on the agent-governance frontier, it is a direct data point in the open question of whether Security-for-AI produces a durable independent category or is absorbed into adjacent platforms pre-scale (see 03l, 20). (Fortune · SiliconANGLE · BusinessWire)

Early August 2026 — Obsidian Security $85M Series D at a ~$1.1B valuation, and Oligo Security $60M. The day after the Zenity and Horizon3.ai rounds, two more AI-security financings printed on Aug 4, 2026. Obsidian Security (Palo Alto, CA; CEO Hasan Imam) raised an $85M Series D led by Crescent Cove Advisors, with existing backers Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, GV, and Wing; total funding passes $200M at a first reported unicorn valuation (~$1.1B). Obsidian discovers and governs AI agents, MCP servers, and models running inside third-party SaaS applications, blocking privilege escalation, excessive data access, and policy violations at runtime — the same Security-for-AI agent-governance lane as Zenity and Onyx, and the second nine-figure agent-governance round in two days. Separately, Oligo Security (founded 2022, Tel Aviv) raised $60M (total funding ~$140M; valuation reported more than doubled since its Series B) from Ballistic Ventures, Canon Capital, Greenfield Partners, Lightspeed Venture Partners, Red Dot Capital, TLV Partners, and angels; Oligo provides runtime protection across application code, cloud workloads, and AI systems (application detection & response) and was recently named AWS's exclusive AI-runtime-security partner for AWS Security Hub Extended — an AI-for-Security runtime-protection play, distinct from the agent-governance lane. Across the two-day Aug 3–4 window, the four rounds total roughly $520M — about $210M into the Security-for-AI agent-governance sliver (Zenity $125M, Obsidian $85M) and about $310M into AI-for-Security validation and runtime protection (Horizon3.ai $250M, Oligo $60M) — the clearest evidence yet that both lenses of the AI-security frontier are capitalizing at once (see 03l, 11, 20). (SecurityWeek — Obsidian · SecurityWeek — Oligo · SiliconANGLE — Obsidian)

Early August 2026 — Corma $60M seed for a defensive-cyber foundation model. On Aug 10, 2026, Corma (founded 2025; Tel Aviv and San Francisco; ~20 staff in Tel Aviv; co-founder and CEO Alon Pluda) raised a $60M seed led by Sequoia Capital, with Khosla Ventures and Coatue (valuation undisclosed). Corma is building what it calls the first frontier defensive cybersecurity AI lab: rather than applying a general-purpose model to security, it is training a foundation model specifically on security telemetry (logs, audits, pattern detection) and shipping it as AI agents that operate across a customer's existing security tools as an end-to-end virtual analyst, with reported early Fortune 100/500 deployments cutting threat-response times by more than 94% and expanding coverage roughly 15x. The round is notable for its archetype: a seed-stage, nine-figure-adjacent bet on a security-specific base model as the substrate for defensive autonomy — distinct from the agentic-identity rounds (Neo/Hush/Act/Onyx/Oak), the agentic-SOC posture lane (Mate/Discern), and the runtime and validation rounds (Oligo/Horizon3.ai) that build on general-purpose frontier models. It sits firmly on the AI-for-Security side of the framework and, in delivering the model as working agents, on the software-eats-services thread (see 20, 04c, 11). (Sequoia, Aug 10 2026 · Fortune · Calcalist/CTech)

Mid-August 2026 — Mindgard $30M Series A (Security-for-AI). On Aug 12, 2026, Mindgard (founded 2022, spun out of Lancaster University; HQ London and Boston; CEO James Brear, founder/CTO Dr. Peter Garraghan) raised a $30M Series A led by Album VC, with Karma Ventures and existing backers .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar; total funding reaches roughly $42M. Mindgard runs an automated AI-security and red-teaming platform — shadow-AI discovery, continuous AI red-teaming, and run-time protection across models, agents, and AI applications — and reports uncovering 150-plus publicly disclosed AI vulnerabilities. It sits on the Security-for-AI side of the framework, in the AI red-teaming / AI-SPM lane alongside Protect AI (Palo Alto), Lakera (Check Point), and Enkrypt AI (Anaconda); a non-Israeli, UK-origin entrant in a lane otherwise dominated by Israeli and US teams (see 20, 20g, 11). (SecurityWeek, Aug 13 2026 · BusinessWire, Aug 12 2026)

Mid-August 2026 — Team8 closes $365M for AI-native startups (LP-level fund close). On Aug 11, 2026, the Israeli company-builder and venture firm Team8 announced $365M in new capital — $265M for Team8 Capital's third fund plus more than $100M for follow-on investments in its highest-conviction portfolio companies — bringing total assets under management to nearly $2B across eight funds since 2014. The third fund (managing partners Sarit Firon and Liran Grinberg; partners Ori Barzilay and Hadar Siterman Norris) backs Seed and Series A founders building AI-native companies across cybersecurity, software infrastructure, fintech, and digital health, writing $5–15M lead/co-lead checks primarily into Israeli-founded teams. The firm cites Koi — a Team8-backed AI-agent-security startup it helped fund in a $48M round in late 2025 and which Palo Alto Networks acquired for roughly $400M in April 2026 (11) — as an early exit from the new fund. A fund-level data point (distinct from the portfolio-company rounds above): dedicated cyber/AI-native capital continues to raise at scale even as the exit market runs almost entirely through M&A rather than IPOs (11). (SecurityWeek, Aug 13 2026 · CTech · Jerusalem Post)

(Source: Wall Street research, "Cybersecurity Monthly Review," June 2026. Private-round identities inferred from matching descriptions to the H1 review's June leaders. July private rounds per primary reporting cited on 20g.)

Wall Street research 1H 2026 financing read (mid-year review, 30 Jun 2026). 391 financing rounds YTD, $8.8B deployed — deal count down 20% YoY but dollars up 3%, i.e. fewer, larger rounds (the selectivity the H1 review flagged, quantified). Stage mix skews early: Early-stage 190 · Series A 102 · Series B 58 · Series C+ 32. Named 1H leaders: Cyera ($600M Series G + $400M Series F), NinjaOne ($400M Series C ext.), Cloaked ($375M Series B), Dream ($260M later-stage). Most-financed sectors by count: Risk & Compliance 69 · SecOps/IR/Threat-Intel 43 · Data Security 40 · AI Security 36 · Identity 31.

The IPO window is effectively shut. The research records zero cyber IPOs in 2026 YTD; only 3 cyber IPOs in the last five years (SailPoint + Netskope in 2025, Rubrik 2024) versus 15 in 2018–2021 — and several of that earlier class (Darktrace, ForgeRock, KnowBe4, Ping Identity, Sumo Logic) have since been taken private. Named 2026 pipeline candidates are well-capitalized but not yet filed.

(Source: Wall Street research, "Mid-Year Cybersecurity Market Review, 1H 2026," 30 Jun 2026; see Deals.)

Financing by shape and region. The 2026 capital base is a barbell — a wide base of small early rounds and a thin top of very large late-stage bets, with the middle (Series B) hollowed out. Roughly 19 rounds of $100M+ raised about $4B in 1H, against a 2025 quarterly average of about 6 such rounds / $1.5B — the concentration into a few outsized bets that pulls the average round size up even as deal count falls. Geographically, the US took ~50% of financing volume and ~68% of the dollars, while Israel captured ~18% of all financing dollars on ~10% of deal count — the highest dollar-per-deal concentration in the market, indicating where scaled, capital-efficient companies are forming.

(Source: cybersecurity mid-year 2026 market review — Wall Street research, published Jul 1 2026 — drawing on Pitchbook + 451 Research. Median deal size $12M overall.)

The seed layer

The financing reads above measure the whole stage stack, where a handful of very large late-stage rounds set the totals. The seed layer moves on a different rhythm, and in 2026 it is the part of the market carrying the clearest thematic signal. Per Crunchbase data, companies at the intersection of AI and security raised about $855M across more than 150 reported seed rounds in 2026 to late July — a pace Crunchbase describes as tracking toward an all-time high for the cohort. The implied average is no more than roughly $5.7M per round, and the reported concentration is in the $5M–$10M band, spanning missions from identifying model hallucinations to adversary simulation to verifying agents in financial workflows. Crunchbase separately puts total cybersecurity financing across all stages at $10.6B in H1 2026, which it characterises as roughly in line with recent comparable periods; that figure sits above the $7.5B/383-round and $8.8B/391-round H1 reads from Wall Street research above, and the gap reflects different inclusion universes rather than a revision — the three should be read as separate trackers, not reconciled (Crunchbase News, Jul 28 2026).

Three outsized seeds account for about 16% of the cohort's dollars on their own:

Company Round Announced Lead / notable backers What it does
Oak $60M seed Jul 15 2026 Accel, CRV, Greylock (co-led); Hetz, AlphaDrive AI-native identity control plane governing human, machine and AI-agent identities; founded by Shai Morag (Secdo→Palo Alto; Ermetic→Tenable). Profile on Identity
Cylake $45M seed Mar 5 2026 Greylock Partners AI-native security platform that keeps security data and analytics inside the customer's on-premises or private-cloud environment rather than a vendor-hosted analytics cloud, aimed at government, critical infrastructure and regulated finance and healthcare. Founded by Nir Zuk (Palo Alto Networks founder and long-serving CTO, now Cylake CEO), Wilson Xu (ex-Palo Alto engineering) and Ehud Shamir (SentinelOne co-founder)
JetStream Security $34M seed (oversubscribed) Mar 4 2026 Redpoint Ventures; CrowdStrike Falcon Fund AI governance platform built on "AI Blueprints" — generated graphs mapping AI agents to their models, the data accessed, the tools used and the identities behind them, with runtime behaviour tracking, deviation flags and workflow-cost attribution. Founders drawn from Attivo Networks, CrowdStrike, Cohesity, Dazz, McAfee and SentinelOne; CEO Raj Rajamani

Two structural points follow. First, the seed cohort splits cleanly along the two AI-and-security threads: JetStream governs AI systems (Security for AI, see 03l), while Cylake applies AI to the security function itself (AI for Security, see 20); Oak sits on the agent-identity seam between them. Second, the largest seeds are being written on founder pedigree rather than traction — Cylake and Oak are both repeat-founder rounds, and JetStream's cap table carries a strategic corporate investor at seed, which is the earliest point in the funnel at which an acquirer establishes a position (Corporate Venture). Cylake's sovereignty-first architecture is also a counter-position to the cloud-hosted analytics model that the SIEM and CNAPP incumbents run on, and belongs alongside the sovereign-demand thread on 14f.

Sources: Crunchbase News — AI Seed Investors Flock To Cybersecurity (Jul 28 2026) · SiliconANGLE — Cylake launches with $45M (Mar 5 2026) · Globes — Nir Zuk's Cylake launches with $45m · SecurityWeek — JetStream launches with $34M (Mar 4 2026) · PR Newswire — Oak $60M seed (Jul 15 2026)

Cyber-specialist VCs

Firm Focus / stage Notable portfolio Notes
Evolution Equity Partners Growth-stage cyber; $20–150M checks Arctic Wolf, Pentera, Protect AI, Quantexa, SecurityScorecard, Snyk Closed Fund III at $1.1B; ~30 companies targeted
Forgepoint Capital Early–growth cyber specialist 40+ security startups; >$1B AUM One of the most specialized
AllegisCyber Capital Early-stage infra security & threat intel Long-standing cyber specialist DataTribe co-founder
YL Ventures Israeli seed→lead, cyber-exclusive Orca, Axonius, Cyera, Hunters Tel Aviv; sells positions early
Ten Eleven Ventures Cyber-dedicated, multi-stage Verkada, Cylance, KnowBe4
NightDragon Growth/late cyber & safety Active in scale-ups Founded by Dave DeWalt
Team8 Israeli company-builder/foundry Builds + funds cyber co's
DataTribe Cyber/data startup foundry Maryland/NSA-adjacent talent
Paladin Capital Group Cyber & resilience, dual-use National-security tilt
SYN Ventures Early cyber Founder-led

Generalist VCs with deep cyber books

Sequoia (Wiz early backer), Andreessen Horowitz (a16z), Accel, Greylock, Lightspeed, Index Ventures, Bessemer, Insight Partners (growth), Battery, Norwest, GV (Google Ventures), Coatue, Iconiq, Menlo, Redpoint, Scale Venture Partners, CRV.

Relevance to M&A


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.