API-security startup Neosec, founded by a former Palo Alto Networks executive, launched today with $20.7 million in funding and paying customers using its application security platform.
Neosec CEO Giora Engel previously founded LightCyber, which Palo Alto Networks bought for $105 million in early 2017 before using that company’s technology as the basis for its Cortex extended detection and response (XDR) platform. LightCyber developed machine-learning based behavioral analytics that identify anomalies inside the network and then identify attacks.
With his new venture, Engel and co-founder Ziv Sivan who is CTO at Neosec want to bring these same behavioral analytics and big-data techniques to find threats in APIs. “Neosec is like an XDR for APIs, or a CrowdStrike for application security,” Engel said.
How Neosec WorksThe startup’s software-as-a-service (SaaS) platform first discovers every API and then it audits risk. It also uses behavioral analytics to determine abnormal API traffic, identify APIs transferring sensitive data, and hunt for other threats. And finally, it flags vulnerabilities and can also automate remediation.
“The vast majority of traffic is APIs,” Engel said, citing an Akamai study that found API calls represent 83% of all web traffic. So although it’s still a newer technology, API security is rapidly becoming a must-have tool. “In the long term, it’s going to supersede or replace the need for a lot of existing technologies today,” Engel said.
And while it’s not there yet, one of these technologies that Neosec sees its platform replacing in the future is the web application firewall (WAF). Neosec shares this view with Traceable, one of its competitors in the still-emerging API security field. Salt Security and Noname Security are a couple others.
Why SaaS Matters for API SecurityThere are a few things that differentiate Neosec from its competitors, Engel said. “First, we’re based on data, much more than the others, and I’ll explain how: We’re the only 100% SaaS company. We don’t have an on-prem solution and we never have.”
This makes a big difference, and it’s about more than just a deployment model, Engel added. “XDR companies are all 100% SaaS companies,” he said. “The ones that were hybrid, the Carbon Blacks, they practically don’t exist anymore because it’s impossible to have behavioral analytics at scale when you’re not 100% SaaS. You can’t do the same processes, you can’t do the same kind of detection technologies.”
In addition to enabling faster speeds and data analytics at scale, being a SaaS platform allows Neosec to store historical data for investigations and threat hunting, Engel said.
Also, customers don’t need to install any sensors or sidecars. “As light as they may seem, they still need to be installed in every application environment,” Engel said. “And you can imagine, in a large financial institution, for example, they have thousands of microservices, so they would need development teams to install sensors in each of these production environments — now that’s a big deal.”
Instead, Neosec uses existing log data for enterprise-wide API discovery.
It’s worth noting that Engel knows something about large financial institutions and security threats against their APIs. He serves as the chair of the fraud prevention task force at Financial Data Exchange within FS-ISAC.
‘CrowdStrike for Application Security’Neosec also recently completed a $20.7 million Series A funding round with investments from True Ventures, New Era Capital Partners, TLV, and SixThirty in addition to cybersecurity veterans Mark Anderson, Gary Fish, Mickey Boodaei, Rakesh Loonkar, and Shailesh Rao. Anderson, former president of Palo Alto Networks, is also chairman of the Neosec board.
The startup has signed about 10 customers, and its platform is generally available.
Neosec is based in Palo Alto, California with research and development in Tel Aviv, Israel. While it currently counts about 20 employees, Engel says the company plans to double that number over the next few months.
It’s still early days for the startup and the API security space as a whole, but Engel doesn’t see Neosec following in the footsteps of his former company and becoming a piece of a larger vendor’s portfolio. “This is different for many reasons,” he said. For one, “this space is developing much, much faster.” Engel attributes this to companies’ digital transformation efforts, which shifted into hyperdrive at the start of the COVID-19 pandemic. “We know for sure we are going to be a big company.”
He compared Neosec to CrowdStrike, and how endpoint detection and response (EDR) eventually ate the endpoint security market. “When [CrowdStrike] started, EDR didn’t really compete with endpoint security,” Engel said. “It was kind of an add-on, but over time, because that add-on was actually a superset and worked much better, it replaced the need for endpoint security. So they swallowed the larger companies that were doing endpoint security like Symantec.”
Engels said he sees the same thing happening in the web application and API security market. “A few years from now the focus is no longer going to be web applications,” he said. “It’s going be mostly APIs, and we see ourselves leading that market that is going to be much bigger than it is today.”
Comments