In a series of big moves for the security operations startup, Arctic Wolf elevated its president, Nick Schneider, to CEO less than a month after closing a $150 million Series F funding round that boosted its valuation to $4.3 billion.

Arctic Wolf’s original CEO Brian NeSmith, who co-founded the company in 2012, will move into the executive chairman role as the cybersecurity unicorn eyes an initial public offering (IPO) in the next year — and a $150.4 billion market opportunity.

“It’s a massive market,” Schneider said in an interview with SDxCentral. “And the reason for the market being so significant is that it’s really poised for consolidation. Security’s still looking for that category-defining platform, and that’s our goal. That’s the opportunity for Arctic Wolf.”

Despite the projected spending increase on information security and risk management technology, organizations still suffer breaches, and these attacks are also growing exponentially in scale and cost.

“What we’re hearing from the customers is that they feel like the cybersecurity industry has failed them. And quite frankly, we agree,” Schneider said. “The approach that you can solve for every attack surface, and every threat vector with a new product or a new piece of technology does not work in cybersecurity.”

The answer, he added, is a vendor-agnostic, security-operations approach that provides customers with a platform that works with their existing products and infrastructure.

“You need to be agnostic in the tools and the technology that the customer uses,” Schneider said. “You need to be flexible with the talent that the customer has within their own environment, and you need to unify what has historically been a pretty disparate market. So the manner in which we’re building Arctic Wolf, in which we have built Arctic Wolf from day one, really resonates with customers. At the end of the day, they want to feel safe and know that their business is protected.”

Arctic Wolf CEO Talks Expansion, Boasts 438% YoY Growth

Arctic Wolf developed a cloud-native security operations platform that provides several managed security services including threat detection and response, vulnerability and risk, cloud infrastructure and services monitoring, and security awareness training. It has about 3,000 customers, and while these were traditionally mid-market and small-enterprise companies, over the past year it’s grown its large-enterprise business 438% year over year.

Additionally, the startup boasts 100% revenue growth year over year for each of the last seven years. “And that is not on a small denominator anymore,” Schneider said. “Our plans are to continue on a similar trajectory this year and then continuing forward as we expand into new regions throughout the globe and bring new products and services to bear.”

To date, most of its growth has come from North American companies, but it recently expanded into the Europe, Middle East, and Africa (EMEA) region with a European headquarters in the U.K. and plans to open a European security operations center in Germany later this year.

“And then, we’ll continue to expand into Asia-Pacific and Latin America,” Schneider said. “We’ve seen the resonance that we have in the U.S. is just as robust as what we’re seeing in EMEA if not more favorable for us.” This is because there are fewer competitors in the security and risk management market, “so we’ve seen tremendous uptake in a very short amount of time in those new regions,” he added.

As it expands, the company has also grown its headcount to just under 1,000 employees.

Will Arctic Wolf Follow SentinelOne’s Footsteps?

The CEO transition largely centers around Arctic Wolf’s planned public debut, which is “probably a year out, give or take a quarter,” Schneider said. This will ensure leadership stability in the time leading up to and moving the company forward after the IPO, he explained.

Plus, it’s not a bad time to be a cybersecurity startup eyeing an IPO. SentinelOne made its market debut in June and, at closing, had a market capitalization of more than $10 billion making it the highest-valued cybersecurity IPO ever. A couple months earlier, London-based Darktrace saw its shares surge 43% in its public debut valuing the company at $2.4 billion.

“From a metrics and growth standpoint, we are aligned and, if anything, better on several key metrics than we saw with SentinelOne,” Schneider said. “In addition to that, we’re on a similar trajectory as CrowdStrike was as they were approaching IPO.”

CrowdStrike’s 2019 IPO raised more than $700 million, valuing the endpoint security vendor at $6.7 billion, which, at the time, was the highest-valued cybersecurity IPO until SentinelOne.

Following Arctic Wolf’s recent Series F funding round and valuation, its executives claim it’s the fourth-largest private security company in the U.S. and the fastest growing in valuation this year, moving from unicorn to $4.3 billion in just 10 months. “When we look at the organizations that are high-growth, high-value SaaS companies and benchmark ourselves against the top five to 10 of those, we’re right in the mix,” Schneider said.

‘Significant Investments’ in Product, M&A

Meanwhile, as it marches toward an IPO, the startup also plans to make “significant investments” in both its product and research and development teams, and this will include both organic growth and acquisitions, he added. These will focus on security operations capabilities that Arctic Wolf currently doesn’t offer or wants to make more robust. Schneider names cloud security, endpoint security, and threat hunting among the new and expanding product features.

“There’s probably more we’ll do around security training and around vulnerability management and risk,” he added. “With regard to SOAR technologies: That would be interesting both from the end-user standpoint and the way that we deliver our platform to the customers.”

All of these technologies fit into the emerging extended detection and response (XDR) space, and while that’s a relatively new sector, “Arctic Wolf has been playing in the XDR space almost since our inception,” Schneider said. “For the last 10 years, we’ve been about being able to ingest and provide value across multiple attack surfaces through multiple different feeds and deliver the customer protection, regardless of the mechanism or threat vector. That’s been the cornerstone of the platform that we’ve built and will continue to be what we do moving forward.”