Cybersecurity: what are startups building now?

Last updated: 11 September 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity startups are currently building the control systems for autonomous computing: security for AI agents, machine identities, AI-written software, automated security operations, sensitive data access and software that can take actions without waiting for a human.

AI security is becoming a center of startup activity, but it is already splitting into several markets. Seven of the ten RSAC Innovation Sandbox finalists in 2026 either secured AI systems, used AI as a core security engine or addressed attacks amplified by AI.

The biggest change is the move from protecting model outputs to controlling agent behavior. Once an AI agent can reach GitHub, corporate files, shell commands or transaction systems, security has to govern what the software can access and do, not only what it says.

Machine identity is becoming a foundational layer because service accounts, API keys, workloads, automation and AI agents now make security decisions and use credentials at enormous scale. That pushes authorization and temporary access closer to the center of the security stack.

Autonomous pentesting and SOC investigation are among the clearest AI-native cybersecurity products because they replace measurable chunks of human work. Horizon3, XBOW, Torq and Dropzone AI are all trying to turn expensive, repetitive security workflows into continuously running software.

Data security is attracting some of the largest checks because enterprise AI becomes useful only when it can reach valuable corporate information. Cyera’s rise shows how data discovery, classification, access policy and AI governance are starting to converge into one control layer.

The browser, the software supply chain and the coding environment are also becoming security enforcement points. Employees increasingly work through SaaS sessions while coding agents can select dependencies, access secrets and execute commands, so security products are moving closer to the exact moment an action happens.

Prevention is returning in a more granular form. Startups are removing unused privileges, issuing temporary access, supplying hardened software artifacts, restricting agent tools and blocking risky data movement instead of relying only on another detection alert after the fact.

The most crowded areas are likely to be generic AI-security gateways and AI-powered SOC copilots, where incumbent platforms can copy surface-level features quickly. The more defensible startups tend to own proprietary context or an actual control point such as identity relationships, classified data, work sessions, trusted software artifacts or real attack paths.

Capital is clustering around those deeper control points. Cybersecurity and privacy startups raised about $10.6 billion in the first half of 2026, while Cyera, Horizon3, Torq, XBOW and Oasis alone accounted for more than $1.2 billion of recent financing across data, autonomous testing, security operations and machine identity.

The broader pattern is that machines are becoming users, developers, attackers and defenders at the same time. The startups with the strongest chance of lasting will be the ones that decide what those machines can see, trust, execute and change.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Cybersecurity: what are startups building now?

Cybersecurity startups are no longer concentrating on one obvious new category. The most important shift is broader: security is being rebuilt around software and AI systems that act on their own, generate code, hold credentials, query sensitive data and make decisions at machine speed. That is changing both what needs protection and what a security product is expected to do.

The market is pulling in two directions at once. Some of the fastest-growing cybersecurity companies are expanding familiar categories such as data security, identity and application security. A younger group is creating new control points around AI agents, autonomous hacking, machine identities and human manipulation. Counting companies with “AI security” in their description tells us very little. The useful question is where products, customers and capital are actually moving.

Is AI security really becoming the center of cybersecurity startups?

Yes. AI security has moved from a specialist corner of cybersecurity into one of the main places where new companies are being created, although “AI security” now describes several different businesses rather than one market.

The clearest early-stage evidence comes from the RSAC Innovation Sandbox, one of the industry's longest-running startup competitions. Seven of its ten finalists in 2026 either protected AI systems, used AI as a central security engine or defended people against AI-amplified attacks, according to an analysis of the cohort by security researcher Lenny Zeltser. The winner, Geordie AI, built a platform specifically to discover AI agents, map what tools and systems they can reach, observe what they do and intervene when their behavior becomes dangerous.

The financing market points in the same direction. Cyera raised $600 million at a $12 billion valuation while expanding data security into AI governance and agentic security. Torq raised $140 million at a $1.2 billion valuation around its AI-driven security operations platform. Autonomous pentesting companies XBOW and Horizon3 raised $120 million and $250 million respectively. Oasis Security raised $120 million to manage non-human and AI-agent identities.

Still, cybersecurity is not collapsing into one giant AI-security category. AI is being inserted into nearly every important control plane: identity, SOC operations, pentesting, code review, fraud detection and data protection.

Area being rebuilt Representative startups What AI changes
AI-agent security Geordie, NeuralTrust, Pillar, Tenet Software itself becomes an autonomous actor
Security operations Torq, Dropzone AI Investigation and response become partially autonomous
Offensive security Horizon3, XBOW Penetration tests can run continuously
Identity Oasis, Token Security, Opal Machines and agents need governed identities
Application security Clearly AI, ZeroPath, Endor Labs AI writes and reviews more software
Human security Humanix, Charm AI scales impersonation and social engineering

If you want more recent data on this point, please see our latest cybersecurity market report.

Are startups mainly protecting AI models, or AI agents now?

Cybersecurity startups are increasingly protecting AI agents rather than models alone. The important attack surface is moving from what an AI says to what it can actually do.

The distinction is fundamental. A chatbot that produces a bad response creates one type of risk. An agent that can access GitHub, run shell commands, retrieve corporate files or approve transactions can turn the same manipulation into an operational security event.

Microsoft demonstrated the difference while studying its Semantic Kernel framework. Researchers found vulnerabilities through which prompt injection could ultimately cause unauthorized code execution. OpenAI has made a similar argument in its own work on prompt injection: once an agent can browse outside content and take actions, merely filtering suspicious text is insufficient because an attacker can manipulate the agent through contextual instructions that resemble social engineering.

Startups have responded by building an entirely new set of controls. Geordie discovers agents and maps their tools, skills and connections. NeuralTrust has built runtime controls around agent interactions. Pillar Security focuses on AI applications from development through runtime. Tenet Security is aimed specifically at autonomous agents. Protectt.ai has even introduced security around Model Context Protocol connections, scanning MCP servers and filtering agent-to-tool interactions.

Geordie provides a useful commercialization signal. The company reported 1,300% ARR growth during the first five months of 2026 before raising a $30 million Series A. That does not prove the whole category will become large, but it does show agent security has already moved beyond conference demos.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Why are machine identities suddenly so important, and is identity overtaking endpoint security?

Machine identity is becoming one of cybersecurity's most important startup opportunities because companies increasingly have more software identities than human identities, while attackers increasingly care about authorization rather than the device itself.

Traditional identity systems were designed around employees. A person logs in, receives permissions, changes jobs and eventually leaves. Modern infrastructure also contains service accounts, API keys, cloud roles, CI/CD credentials, workloads, automation scripts and AI agents. These identities can appear and disappear automatically and often operate without anyone actively watching them.

That has created a distinct startup cluster. Oasis Security manages non-human identities and raised $120 million in 2026, bringing its disclosed funding to roughly $190 million. Token Security discovers and governs machine identities and AI agents. Opal has expanded access governance across human, non-human and agent identities and raised another $23 million, taking total funding to $59 million.

The customer behavior is more important than the labels. Opal says Databricks has processed 86,000 just-in-time access requests through its platform, while one customer reduced standing access by 88%. Those numbers point toward credentials that exist only when necessary rather than permanent privileges attached to thousands of people and machines.

Endpoint security still matters because devices still execute malicious code. But a stolen credential can unlock SaaS applications, cloud consoles, developer systems and data without malware ever behaving like a traditional endpoint threat. AI agents intensify that problem because they can execute more actions, far faster, than a human user.

Are autonomous AI hackers becoming real cybersecurity products?

Yes. Autonomous hacking is already one of the clearest examples of AI changing an established security workflow rather than simply adding a chatbot to it.

Traditional penetration tests are expensive and periodic. A consultant or red team examines an environment, identifies weaknesses and produces findings. Companies such as Horizon3 and XBOW are turning that process into continuously running software.

Horizon3's NodeZero autonomously attempts to exploit weaknesses to show which vulnerabilities can actually be chained into an attack. The company says it has surpassed 7,000 customers and reported 120% ARR growth before raising $250 million at a valuation above $2 billion. XBOW raised $120 million at a valuation above $1 billion to expand its autonomous offensive-security platform.

The attraction is straightforward. Enterprises already receive enormous numbers of vulnerability alerts. Another scanner telling a CISO that 30,000 vulnerabilities exist has limited value if only a handful provide usable attack paths. Autonomous pentesting tries to answer the more valuable question: which weaknesses can actually be exploited together?

Company Current model Recent commercial signal
Horizon3 Autonomous pentesting across enterprise environments More than 7,000 customers; $250M Series E
XBOW Autonomous offensive-security agent $120M Series C; valuation above $1B
ProjectDiscovery Continuous exposure discovery and testing Won RSAC Innovation Sandbox in 2025
ZeroPath AI-native code vulnerability detection RSAC 2026 finalist
Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Will AI replace security analysts and fix alert overload in the SOC?

AI is starting to replace chunks of SOC analyst work, but startups are building autonomous investigation systems before they are building completely human-free security operations centers.

The first target is repetitive alert investigation. A conventional SOC can ingest signals from endpoint, cloud, identity and network products, leaving analysts to open tickets, gather context, check logs and determine whether an alert is real.

Dropzone AI builds AI SOC analysts that investigate alerts autonomously and had more than 100 enterprise customers when it announced a $37 million Series B. Torq has moved from security automation toward an “AI SOC” in which agents investigate, prioritize and respond. Its $140 million Series D brought total funding to $332 million and valued the business at $1.2 billion.

Cybersecurity has spent years adding detection products, each generating another stream of findings. The better AI SOC startups are trying to remove work from the queue rather than just summarize it. Dropzone investigates alerts instead of only describing them. Torq connects investigation with response. Fig Security focuses on whether detection and response workflows themselves are broken as infrastructure changes.

The meaningful test is operational: fewer tickets touched, shorter investigations, fewer unnecessary escalations and more incidents resolved without analysts. That is the bit customers can actually measure.

If you want more recent data on this point, please see our latest cybersecurity market report.

Why is data security attracting so much cybersecurity money?

Data security is attracting extraordinary capital because AI has made the old question “where is our sensitive data?” far more economically important.

Cyera is the clearest example. The company began around data security posture management: finding sensitive information across cloud systems, classifying it and understanding who can access it. It has since expanded into data-loss prevention, identity, privacy and AI governance.

Its financing trajectory has been exceptional. Cyera was valued at $3 billion in late 2024, $6 billion in mid-2025, $9 billion around the beginning of 2026 and $12 billion after raising another $600 million. The company says it shipped more than 100 new capabilities across data security, privacy, identity, DLP and agentic security in roughly a year.

More revealing is the commercial scale behind the financing. TechCrunch reported that Cyera had exceeded roughly $150 million of ARR before the $12 billion financing discussion. The company had also said earlier that it was serving about one-fifth of the Fortune 500.

AI strengthens the underlying problem because models and agents are valuable precisely when they can reach corporate information. A company can keep AI away from sensitive systems and lose much of the usefulness, or understand the data well enough to make granular access decisions.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Are enterprise browsers becoming a real cybersecurity platform?

Yes. The enterprise browser has grown from an unusual startup idea into a serious attempt to move security enforcement directly into the application through which employees perform much of their work.

Island is the strongest proof. Founded in 2020, the company reached a $4.8 billion valuation after raising $250 million in 2025, bringing outside financing at that point to roughly $730 million. Its original product embedded enterprise security directly into a Chromium-based browser.

The scope has since expanded. Island's newer enterprise platform applies security policies across its browser, consumer browsers, desktop applications and networks. That allows it to combine application access, data protection, identity, networking and AI governance around the user's working environment.

The attraction is particularly strong in a SaaS-heavy company. Much employee activity already happens through browsers: Salesforce, Workday, Google Workspace, Microsoft 365, ChatGPT, internal applications and countless SaaS tools. Security controls placed inside that session can see who is accessing an application, from which device, what data is copied and which AI service receives it.

A Forrester study commissioned by Island estimated a 344% three-year return for a composite 5,000-person organization, partly because browser controls could reduce dependence on technologies such as VPN, VDI and endpoint DLP. As a commissioned study, that number should not be treated as independent proof of universal economics.

Is AI-generated code forcing startups to rebuild application and software-supply-chain security?

Yes. AI coding is forcing application security and software-supply-chain security to operate at machine speed because agents can now write code, choose dependencies, install packages and execute workflows with much less human involvement.

The old AppSec workflow already struggled with developer velocity. Security scanners produced findings, developers fixed some of them and security teams reviewed high-risk applications. Coding agents make that mismatch worse because software can now be generated and changed much faster.

ZeroPath is attempting to replace several conventional scanning categories with an AI-native engine that reasons across code and looks for chained or business-logic vulnerabilities. Clearly AI acts more like an automated product-security engineer, performing threat models, architecture reviews and security triage. Endor Labs is extending software-supply-chain protection into AI coding environments through AURI, including controls around the coding agents themselves.

The risk goes beyond insecure generated source code. Coding agents can access secrets, modify files, execute commands and interact with deployment infrastructure. Researchers demonstrated in 2026 that carefully constructed prompt injection through GitHub workflows could cause coding-agent integrations from multiple major AI vendors to expose secrets.

Chainguard approaches the same problem earlier in the chain. Instead of only detecting vulnerable dependencies, it supplies hardened container images and software packages designed to give developers safer building blocks from the beginning. The company raised $356 million at a $3.5 billion valuation in 2025 and has expanded from containers into libraries for Python, Java and JavaScript and deeper CI/CD controls.

Gartner published its first Magic Quadrant dedicated to software supply-chain security in 2026, with Chainguard positioned as a Leader. The category is moving from a narrow DevSecOps feature toward infrastructure for controlling what both humans and AI agents are allowed to put into production.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Are cybersecurity startups moving from detection to prevention again?

Yes, but this version of prevention is more granular. Startups are continuously constraining what identities, software and AI agents are allowed to do.

For years, security products shifted heavily toward detection because perfect prevention was unrealistic. Modern startup products are revisiting prevention using much richer context.

Opal can remove unused privileges and issue temporary access. Chainguard can replace vulnerable open-source artifacts before they enter production. Enterprise browsers can prevent sensitive information from being pasted into unauthorized AI services. Agent-security platforms can restrict which tools an AI system may invoke. Autonomous pentesting can expose an exploitable attack path before an adversary uses it.

The shift is toward putting policy closer to the action itself. In practice, that can be much more powerful than piling another alert onto the SOC queue.

If you want more recent data on this point, please see our latest cybersecurity market report.

Is social engineering becoming a software problem rather than a training problem?

Increasingly, yes. New cybersecurity startups are treating human manipulation as something that can be detected during the attack instead of something companies can solve mainly through annual security-awareness training.

AI raises the stakes because attackers can generate persuasive text, synthetic voices and impersonation attempts at negligible marginal cost. That makes personalized social engineering easier to scale.

Two RSAC 2026 finalists illustrate the response. Humanix analyzes conversations across channels such as voice, messaging and service interactions for manipulation, impersonation, pressure and other social-engineering patterns. Charm Security builds AI agents intended to prevent and resolve scams and human-centric fraud.

Traditional email security primarily evaluates a message or link. Human-threat systems instead try to evaluate the interaction itself: who is asking whom to perform an unusual action, whether urgency or impersonation techniques are appearing, and whether the target is being manipulated into bypassing controls.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Is cybersecurity becoming an AI-versus-AI market?

Partly. The most dynamic parts of cybersecurity are already moving toward machines attacking and defending systems at speeds humans cannot match, though “AI versus AI” still oversimplifies an operational contest between organizations.

On offense, autonomous systems can discover vulnerabilities, generate exploit ideas, personalize phishing and operate at much higher volume. Horizon3 and XBOW demonstrate that many offensive-security steps can already be automated legitimately for defenders.

On defense, Torq and Dropzone investigate alerts, AI-native AppSec systems inspect code, and agent-security platforms continuously monitor autonomous systems. OpenAI and Microsoft have meanwhile shown that the agents themselves can become attack surfaces through prompt injection and unsafe tool use.

Humans still determine objectives, permissions, acceptable risk and incident response, even as more low-level security decisions move to software.

Are startups still building cloud-security companies after Wiz?

Yes, but cloud-security startups are becoming more specialized because the broad “single pane of glass for cloud risk” opportunity is harder to attack directly.

Google completed its $32 billion acquisition of Wiz in 2026 after agreeing to the transaction the previous year. That was an extraordinary validation of cloud security, and it changed the competitive environment. A young startup trying to reproduce a broad CNAPP platform now faces Wiz, Palo Alto Networks, CrowdStrike, Microsoft and other large vendors with increasingly wide security suites.

New companies therefore tend to enter through narrower control points: machine identity, data, runtime behavior, software supply chain, agent security or application risk.

“Cloud” itself is no longer enough of a product thesis.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Does post-quantum security matter to startups yet?

Yes, although post-quantum cybersecurity is currently a smaller and more infrastructure-heavy startup opportunity than AI security.

The commercial work starts long before quantum computers can break enterprise encryption. Organizations first have to find cryptography buried across large technology estates, understand where vulnerable algorithms are used and build a migration path.

That creates products around cryptographic discovery, inventory, migration and crypto-agility. QIZ Security raised a $17 million seed round in 2026 to develop cryptographic posture and post-quantum migration tools. Singapore-based pQCee raised another $3.9 million and develops quantum-safe security and key-management products.

The category also overlaps increasingly with machine identity because certificates and cryptographic keys authenticate enormous numbers of services and devices. Keyfactor, a much more mature private security company, received a strategic investment exceeding $1 billion in 2026 around machine identity and post-quantum trust infrastructure.

For startups, this looks like a long infrastructure migration. It is less flashy than agent security, but the migration work can last for years.

If you want more recent data on this point, please see our latest cybersecurity market report.

Are all these cybersecurity startups just features that Microsoft or Palo Alto Networks will copy?

Some will be. Cybersecurity has always produced startup categories that eventually become features inside broader platforms, and the current AI wave will be no exception.

The difficult part is identifying which products own a sufficiently important control point to remain independent.

A standalone alert summarizer is easy to imagine being absorbed into Microsoft Sentinel, CrowdStrike or Palo Alto Networks. The same is true for basic prompt filtering. Products sitting on deeper operational layers are harder to replace casually. Cyera builds a classification and policy layer around enterprise data. Island tries to own the work environment itself. Chainguard supplies trusted software artifacts. Identity startups map complicated permission relationships across heterogeneous infrastructure.

Recent acquisitions reinforce the distinction. Google paid $32 billion for Wiz rather than relying solely on internally built cloud-security functionality. Veeam completed a $1.725 billion acquisition of Securiti AI. F5 bought AI-security startup CalypsoAI for $180 million after it had appeared in the RSAC Innovation Sandbox only months earlier.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

Where is cybersecurity startup money actually going now?

Cybersecurity funding remains substantial, but investors are disproportionately rewarding companies that control one of a small number of strategically important layers rather than every company attaching AI to an existing product.

Crunchbase counted about $10.6 billion of financing for cybersecurity and privacy startups in the first half of 2026. Q2 was weaker than Q1, but the six-month total remained historically high.

Several of the largest disclosed rounds tell us more than the aggregate. Cyera raised $600 million around data and AI security. Horizon3 raised $250 million around autonomous security validation. Torq raised $140 million around AI-driven security operations. XBOW raised $120 million around autonomous offensive security. Oasis raised $120 million around non-human identity.

That group alone represents more than $1.2 billion of financing, and every company sits at the intersection of AI with another foundational security problem rather than selling generic “AI cybersecurity.”

Startup Major recent financing Core bet
Cyera $600M Data becomes the trust layer for enterprise AI
Horizon3 $250M Penetration testing becomes autonomous
Torq $140M SOC investigations become agent-driven
XBOW $120M Offensive security becomes software
Oasis Security $120M Machine and AI identities require their own control plane
Geordie AI $30M AI agents require runtime governance

Which cybersecurity categories look most crowded already?

AI-security gateways and generic AI-powered SOC products risk becoming crowded fastest because their initial features are relatively easy to imitate.

Hundreds of companies now describe themselves as AI-security vendors. One industry-maintained startup map counted more than 400 companies across 14 AI-security categories by early September 2026. That is better read as evidence of founder convergence than as proof of 400 durable markets.

The greatest pressure will fall on products whose differentiation consists mainly of placing an LLM in front of existing security data. Summarizing alerts, producing compliance answers or generating remediation advice can increasingly be incorporated into incumbent platforms.

More defensible categories require proprietary context or control. An identity platform understands permission relationships. A data-security platform has classified corporate information. A browser sees work sessions. A supply-chain provider controls the artifacts entering production. An autonomous testing platform accumulates knowledge about real attack paths.

If you want more recent data on this point, please see our latest cybersecurity market report.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

What are cybersecurity startups actually building now?

Cybersecurity startups are building the control systems for a world in which software no longer waits for humans to tell it what to do.

The strongest current pattern is a redistribution of security around new actors and new control points. AI agents need discovery, identities, permissions and runtime monitoring. Security teams are delegating investigation and penetration testing to autonomous systems. Coding agents are forcing AppSec and software-supply-chain security to operate continuously. Enterprise browsers are becoming enforcement points for data and application access. Data-security companies are becoming AI-governance infrastructure. Human-security startups are trying to detect manipulation while it happens.

Older categories remain important, but fewer new companies are trying to win by building a slightly better version of a mature perimeter product. The frontier is moving inward, toward the exact moment software gets permission, accesses data, selects a dependency, writes code or takes an action.

So the answer is pretty clear: cybersecurity startups are currently building security for autonomous computing. Machines are becoming users, developers, attackers and defenders simultaneously.

The startups with the strongest chance of becoming lasting companies will own the infrastructure that decides what these machines can see, trust and do.

OUR METHODOLOGY

We approached this question as a market-mapping problem rather than starting with a fixed view of what “AI cybersecurity” should mean. Cybersecurity is currently changing across several layers at once, so we broke the market into the areas where startup activity is actually concentrating: AI agents, machine identity, security operations, offensive security, data, application and supply-chain security, enterprise access, human threats, cloud security and cryptographic infrastructure.

For each area, we looked for recent evidence that showed more than a product idea. We prioritized launches and product expansion, customer adoption, disclosed operating metrics, major financing rounds, acquisitions, independent security research and the emergence of recognizable new categories. Looking at those signals together helped separate areas attracting real commercial activity from themes that are mostly receiving attention because AI is attached to them.

We also distinguished between AI being added to an existing security product and AI changing what actually needs to be secured or how the security work gets done. An autonomous pentesting system, for example, carries more weight in this analysis when it can test real attack paths than when it simply summarizes vulnerability data. Agent security becomes more significant when software has tools, credentials and permission to act, rather than when the problem is limited to model outputs.

Funding was treated as one signal among several. We looked especially at where large recent rounds were clustering, then checked whether those companies also showed product depth, customer traction or control over an important part of the security stack. That keeps a large valuation or financing announcement from becoming the argument by itself.

The companies highlighted in the article are representative examples rather than a ranking of the “best” cybersecurity startups. We selected companies that made a particular shift unusually visible through their products, adoption, financing or strategic relevance. Startup counts were used to identify crowded areas and founder convergence, rather than as a measure of how many durable markets will ultimately exist.

Where evidence came from commissioned economic research, we used it narrowly. The Island/Forrester study, for example, helps show which existing technologies an enterprise browser may consolidate or replace; we did not use its ROI estimate as a general benchmark for the whole category. For acquisitions, we use announced transaction values when discussing the strategic significance of a deal; post-closing accounting purchase prices can differ because of adjustments.

We gave greater weight to recent primary evidence: company announcements for financing and product changes, original security research for technical risks, official conference and industry material for emerging categories, and high-quality reporting or market databases where the underlying information could not be obtained directly. The final conclusions come from the aggregation of those signals across the different dimensions, rather than from any single funding round, startup, product launch or market narrative.

Key sources used for this analysis include: RSAC Innovation Sandbox on the startup cohort and emerging categories, RSAC on Geordie AI winning the 2026 Innovation Sandbox, Microsoft Security research on prompt injection and code execution in AI-agent frameworks, OpenAI on designing agents to resist prompt injection, Cyera on its $600 million financing and AI/data-security expansion, TechCrunch on Cyera’s reported ARR and financing process, Horizon3 on autonomous pentesting, customer scale and its $250 million Series E, Torq on its $140 million Series D and AI-SOC strategy, XBOW on its $120 million Series C, Opal on identity governance across human, non-human and agent identities, Dropzone AI on autonomous SOC investigation and its $37 million Series B, Island on its $250 million financing and enterprise-browser growth, Chainguard on its $356 million Series D and hardened software supply chain, Google on completing the Wiz acquisition, Veeam on its $1.725 billion Securiti AI acquisition, F5 on its CalypsoAI acquisition, Crunchbase on cybersecurity and privacy startup funding in the first half of 2026, and Keyfactor on machine identity and post-quantum trust infrastructure.

Chart illustrating revenue distribution by region across Europe, Asia, North America, Africa, and South America in the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates revenue distribution by region across Europe, Asia, North America, Africa, and South America in the cybersecurity market

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog