Four security startups announced nearly $46 million in their Series A and seed funding rounds this week over a period of four days.
The fact that venture capital firms are writing huge checks to security companies isn’t exactly new. Momentum Cyber’s mid-year review published this week found total security-sector financing activity (some 228 transactions) in the first half of 2019 hit a record $4.7 billion, representing a 10% increase from the first half of 2018. Last year broke the record for the most money invested in security companies, and 2019 is on-pace to be another record-breaking year with transaction volumes up 59%.
But there’s something about seeing four early-stage rounds over four days netting nearly $46 million that puts it in perspective. It’s also noteworthy that three big companies (Capital One, Sephora, and Pearson) all experienced major data breaches this week. This shows why organizations need to be concerned about their security posture. And it helps explain why VCs are pumping all this money into security startups.
Here’s a closer look at the four companies that announced funding rounds this week.
Trinity CyberTrinity Cyber closed a $23 million Series A round led by Intel Capital. The startup calls its technology Proactive Threat Interference, and says it can stop attacks before they reach internal networks thus reducing risk and increasing cost to adversaries.
“Having a Series A led by Intel Capital is important — especially being a technology company focused on innovation,” said Trinity Cyber President Marie “Neill” Sciarrone. “The other piece is the amount raised, which is not only above industry averages but only 42% of startups make it past their seed round. So having a Series A that is that substantial says a lot about who we are and where we are heading.”
The company has a “handful” of customers and more in trials, according to executives. But it won’t name them and it’s equally tight lipped about how its technology works.
“There’s a little bit of magic,” said CEO Steve Ryan. “A lot of cybersecurity companies’ websites go into painful detail about how their systems work and all the companies they do it for.” While that’s great advertising, it’s also great information for hackers, he explained. “You’ll never see exactly what we do and you’ll never see who we do it for.”
But he will say it uses “adversary interference,” and that involves “getting in the adversary’s way and offering outcomes so the adversary isn’t really aware of what’s going on. So the client gets an advantage.”
At a high level this involves identifying threats in flight via traffic entering and exiting a customer’s network. “We have the ability to recognize what those threats look like and change them into something else. That something else is designed to render what the bad guy is doing as useless and something that is advantageous to the client.”
For example, if a hacker is trying to install malware, Trinity not only neutralizes the malware, but it also “messes around with the authentication so that the bad guys will try to authenticate over and over,” Ryan said. “We like that better than blocking it.”
Simply blocking the malware alerts the hacker, who can then diagnose what triggered the block — and then come up with ways to get around it. “Our view is you shouldn’t be telling the adversary anything,” Ryan said. “It’s about adding friction, adding up their time and resources. Every keystroke in an attempt to diagnose why his hack isn’t working is a keystroke he isn’t using against his target.”
Ryan is clear that this isn’t hacking back, which he calls “a remarkably stupid thing to do. We’re not hacking the hacker, we’re hacking his hack. And it’s about time somebody does that.”
Intel seems to agree. In a statement, Wendell Brooks, senior vice president of Intel and President of Intel Capital, calls the technology “cutting edge” in terms of protecting organizations’ data. “As cyberattacks become more sophisticated, technology to counter them needs to stay one step ahead,” Brooks said.
ConflueraConfluera said it raised $9 million in its Series A with the oversubscribed round led by Lightspeed Venture Partners founder and managing partner Ravi Mhatre. It also saw “significant participation” by Microsoft Chairman and former Symantec CEO John Thompson, former ServiceNow CEO Frank Slootman, and former Palo Alto Networks CEO Lane Bess.
Like Trinity, it says its technology intercepts and responds to threats in real time, but Confluera takes a different approach. Its platform uses agents installed across a customer’s infrastructure to monitor and identify attack progressions. It also aggregates signals from security tools across the infrastructure to prioritize risky activity sequences, and it responds to attacks.
“The industry is overwhelmed with point solutions, but these solutions do not have enough visibility,” said co-founder and CEO Abhijit Ghosh. “They are all isolated and unconnected to each other. There is no platform that can detect and respond to an attack in real time as it spreads through the infrastructure and that is the problem we want to solve with Confluera.”
Before starting Confluera, Ghosh was an engineering leader at Juniper Networks, as well as Azanda Networks and Siemens before that.
Three customers including CohnReznick and American Showa have already deployed the platform, and it’s in trials at others, Ghosh said. The startup will formally launch the platform at next week’s annual Black Hat security conference where it will also announce an early-access program for customers.
When asked why he invested in Confluera, Thompson said in an email: “It is the technology that addresses a real need and caliber of the leadership team to execute on it. In a little over a year, they have been able to build the product, deploy at a few customers, and bring it to market. It is a testament to what this team is capable of.”
He said the company’s approach to real-time prevention as opposed to real-time detection sets Confluera’s technology apart from the plethora of others. “Confluera ties multiple manifestations of bad behavior to identify and stop the attack in real-time,” Thompson said, adding that the platform “brings determinism into how events across the infrastructure are related to each other in real time. … This stops multistage sophisticated attacks while simplifying security operations.”
Altitude NetworksAltitude Networks closed a $9 million Series A funding round led by Felicis Ventures with participation from Slack Fund, previous investor Accomplice, and a personal investment from Alex Stamos, former chief security officer at Facebook. The startup says it will use the capital to fund its growth and win customers for its cloud collaboration security platform.
The platform aims to prevent data leaks and theft in the cloud. Beyond personally identifiable information (PII) or payment information, Altitude monitors privileged and sensitive materials for potentially damaging sharing, such as legal documents, internal financial data, or confidential product roadmaps shared with unauthorized internal or external accounts or even personal Gmail accounts. It supports multiple software- as-a- service (SaaS) applications, including G Suite, Box, Office 365, Slack, and Salesforce.
Former Twitter CISO Michael Coates co-founded the company (he’s also its CEO) with Amir Kavousian, who most recently was a lead data scientist at Capital One.
CymaticCymatic, a startup that developed a user and entity behavior analytics (UEBA) pre-endpoint platform, said it raised $4.5 million in seed funding from “prominent private angel investors.”
The platform provides web applications with visibility into and proactive remediation of the threats from human and non-human attacks, as well as the vulnerabilities users bring with them on their devices. It uses contextual-based machine learning and autonomous remediation to secure web applications and block threats at the browser before they reach the network. This helps ensure that a user’s security hygiene does not adversely affect the cyberhealth of a company’s web properties. And it also automatically scans the device for vulnerabilities and blocks risky devices from entering the network without endpoint agents.
The company says its platform can preemptively determine — before a breach — if the credentials are vulnerable to be used in an attack. It also gives complete visibility into shared credentials, blocking malicious sessions, and alerting shared usage for auditing purposes.
Jason Hollander is Cymantic’s co-founder and CEO, and the company this week announced that former Cylance senior executive Malcolm Harkins joined Cymatic as chief security and trust officer.
Comments