Which cybersecurity startups generate the most revenue today?

In our cybersecurity market deck, you will find everything you need to understand the market
SUMMARY
Tanium generates the most recurring revenue among the broad universe of private venture-backed cybersecurity companies, while Cato Networks leads the newer startup generation on the freshest public ARR evidence.
The ranking is harder than it looks because most private security companies disclose ARR milestones rather than audited annual revenue. Those milestones also arrive at different times, so a clean-looking table can hide a real freshness problem.
The market splits into two groups. Tanium and Arctic Wolf are already mature private vendors with more than $600 million in recurring revenue, while the newer startup cohort starts around the $400 million level.
Cato is the biggest recent mover. Its latest disclosure of more than $415 million ARR puts it narrowly ahead of 1Password's last public milestone above $400 million, even though 1Password could have grown past that level without announcing it.
Vanta's rise is one of the more surprising stories in the ranking. A company that began as a compliance automation tool has crossed $300 million ARR by expanding into vendor risk, trust, monitoring and AI governance.
Huntress stands out less for absolute size than for what is happening on top of an already large base: more than $250 million ARR, 65% year-over-year growth and 130% net revenue retention.
Cyera is the youngest company with a credible shot at climbing several tiers quickly. It has already passed $150 million ARR, raised at a $12 billion valuation and agreed to spend about $1 billion on Oasis Security while still far from profitability.
Revenue scale and financial quality are starting to diverge. 1Password was already free-cash-flow positive at its last major milestone, Axonius says it is approaching that point, while Cyera is still spending aggressively to maximize growth.
The private leaderboard keeps losing its biggest winners. Wiz was acquired, Netskope and Rubrik went public, and public companies such as CrowdStrike and Zscaler now operate at several billion dollars of recurring revenue.
The practical takeaway is that $100 million ARR no longer defines the top tier in cybersecurity. The meaningful race now begins after that milestone: which companies can keep adding another $50 million to $100 million of recurring revenue every year as the base gets larger?

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market
Why is it so hard to know which cybersecurity startup makes the most revenue?
Cybersecurity startup revenue rankings are unusually messy because private companies disclose different financial metrics at different times, so there is no clean public leaderboard.
Most private cybersecurity companies publish annual recurring revenue when they hit an impressive milestone. They rarely disclose audited annual revenue. ARR is useful for subscription businesses because it shows the recurring run rate of signed customer contracts, but it is still different from revenue recognized under accounting rules.
Netskope illustrates the gap. As a public company, it recently reported quarterly revenue of $220.5 million while ARR reached $899 million. One is accounting revenue earned during a period; the other annualizes the recurring business at a particular moment.
Private-company reporting creates another problem: freshness. Cato Networks disclosed more than $350 million ARR earlier this year and then raised that figure to more than $415 million only a few months later. Abnormal Security, by contrast, last publicly confirmed more than $200 million ARR much earlier. We cannot assume that Abnormal stopped growing just because it stopped publishing milestones.
For the ranking below, we therefore use the newest credible ARR or revenue figure we can verify and clearly separate company disclosures from outside estimates. We do not extrapolate a company's old growth rate forward just to manufacture a current number.
What counts as a cybersecurity startup today?
For this ranking, a cybersecurity startup is an independent, privately held, venture-backed technology company whose core business is cybersecurity, identity, security operations, cloud security or a closely related security product.
That definition still leaves an awkward edge case: Tanium. Founded in 2007, Tanium remains private and venture-backed, but a company approaching two decades of operation with roughly 1,900 employees and hundreds of millions of dollars in recurring revenue stretches the normal meaning of “startup.”
Arctic Wolf creates a similar problem. It was founded in 2012 and has grown into a large managed-security company with thousands of employees. Calling it a startup is technically possible, but it now behaves much more like an established private cybersecurity vendor.
So we use two lenses. The broad ranking includes these large private venture-backed companies because excluding them would hide the true revenue leaders. We then separately identify the winner among the newer generation of cybersecurity startups.

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward
Which cybersecurity startups generate the most revenue right now?
Tanium appears to generate the most recurring revenue among private venture-backed cybersecurity companies, while Cato Networks now leads the newer startup generation on the latest publicly disclosed ARR figures.
The gap between those two groups is substantial. Tanium has disclosed more than $700 million in ARR. Recent executive-linked evidence puts Arctic Wolf above $600 million. After those mature private companies, the newer startup cohort begins around the $400 million mark.
Cato is the important recent change. The company announced more than $415 million ARR after previously reporting $350 million, pushing it above 1Password's last disclosed milestone of more than $400 million. Snyk and Vanta sit in the next tier at $300 million or more, followed by Huntress and Axonius.
These are best treated as bands rather than perfectly precise positions because the disclosure dates differ. A company reporting $300 million several months ago may already be larger than another company announcing $320 million today.
| Company | Latest credible recurring-revenue scale | Evidence quality |
|---|---|---|
| Tanium | $700M+ ARR | Company-linked disclosure reported by Forbes |
| Arctic Wolf | $600M+ ARR | Recent executive-linked disclosure |
| Cato Networks | $415M+ ARR | Company disclosed |
| 1Password | $400M+ ARR | Company disclosed |
| Snyk | $300M+ ARR | Forbes reported |
| Vanta | $300M+ ARR | Company disclosed |
| Claroty | Around $300M run rate | Reported externally |
| Huntress | $250M+ ARR | Company disclosed |
| Axonius | $200M+ ARR | Company disclosed |
| Abnormal Security | $200M+ last confirmed | Company disclosed, older figure |
| Cyera | $150M+ ARR | TechCrunch sources |
| Chainguard | Around $100M ARR | Sacra estimate |
If you want more recent data on this point, please see our latest cybersecurity market report.
Is Tanium really the biggest private cybersecurity company?
Tanium is currently the strongest documented candidate for the largest independent private cybersecurity software company, with more than $700 million in annual recurring revenue.
Tanium's corporate material and company-linked reporting put the business above that threshold, alongside roughly 1,900 employees and tens of millions of managed endpoints. Its customer base includes major banks, retailers, government organizations and the U.S. military.
The order of magnitude separates Tanium from almost every newer security startup. Its disclosed recurring revenue is roughly 70% higher than Cato's latest figure and more than twice the $300 million level reached by Vanta and Snyk.
Still, putting Tanium at the top of a “startup” leaderboard feels slightly artificial. Tanium was founded long before today's cloud-security and AI-security wave and has had enough time to build a large enterprise installed base. For the broader question of which private cybersecurity company generates the most revenue, though, Tanium is the clearest answer we have.

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups
How big is Arctic Wolf today?
Arctic Wolf appears to generate more than $600 million in recurring revenue, making it one of the very few private cybersecurity companies operating anywhere near Tanium's scale.
The strongest recent figure comes from Kristin Dean, Arctic Wolf's former chief people officer, discussing the company's growth during her almost eight years there. She described Arctic Wolf growing from roughly $20 million in revenue and 150 employees to more than $600 million ARR and more than 3,500 employees.
That scale also fits what we see elsewhere in the business. Arctic Wolf serves thousands of organizations through managed detection, security operations and its broader security-operations platform. The company built much of its business around customers that want outside specialists to run security operations instead of staffing a full internal security center.
We give this figure less weight than a fresh company financial announcement because it comes from a former senior executive rather than a formal ARR release. Even allowing for some uncertainty, Arctic Wolf clearly belongs in the top tier of private cybersecurity businesses.
Has Cato Networks overtaken 1Password?
Yes. Based on the newest publicly disclosed numbers, Cato Networks has now overtaken 1Password and become the largest modern cybersecurity startup by ARR that we can document confidently.
Cato recently announced that ARR had passed $415 million, up 42% year over year. Only a few months earlier, the company had disclosed $350 million and 43% growth, so the new milestone shows that the earlier momentum continued rather than fading after one strong period.
The business is adding serious amounts of revenue in dollar terms. Growing 42% from roughly the previous year's base means Cato has been adding well over $100 million of recurring revenue annually. A smaller startup can post a higher percentage while adding far fewer actual dollars.
Cato also sells into unusually large budgets because its SASE platform combines networking and security. Customers can replace VPNs, networking appliances and several security products with one cloud platform. That gives Cato more room to expand large enterprise contracts than a narrow security tool would have.
1Password's last disclosed figure remains above $400 million ARR. Unless 1Password has quietly grown well beyond that level without publishing a new milestone, the latest evidence puts Cato narrowly ahead.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity
How much revenue does 1Password generate today?
1Password remains one of cybersecurity's biggest private startups, with more than $400 million in ARR and a business that was already free-cash-flow positive when it disclosed that milestone.
The company has changed considerably from the consumer password manager many people still picture. More than 75% of its revenue now comes from businesses, and 1Password says it protects more than 1.3 billion human and machine credentials. Enterprise products increasingly cover identity, access, devices, SaaS applications and AI agents.
The quality of the revenue is worth paying attention to as well. When 1Password announced the milestone, it also said the company remained free-cash-flow positive. Plenty of cybersecurity startups can buy rapid growth with huge sales spending; fewer can cross $400 million ARR while already generating cash.
The only reason 1Password no longer takes our top spot among modern startups is freshness. Cato has since published a slightly higher number. 1Password could still be larger today, but there is no newer public figure strong enough for us to claim that.
Has Vanta become one of the biggest cybersecurity startups?
Yes. Vanta has grown from a compliance startup into a $300 million-plus ARR cybersecurity company, and it reached that scale much faster than many better-known security unicorns.
Vanta says it took two years to move from $10 million to $100 million ARR, another 15 months to reach $200 million, and only nine more months to cross $300 million. That compression is striking: each additional $100 million arrived faster than the previous one.
The underlying business has also broadened. Vanta initially became popular by automating the tedious work companies needed to complete certifications such as SOC 2. It now covers vendor risk, security questionnaires, trust centers, continuous monitoring and AI-related governance.
That expansion helps explain why a compliance company can end up among the largest cybersecurity startups. Vanta can enter a company through one painful certification workflow and gradually take over more of the work surrounding security assurance and trust.
The $300 million milestone says more than “compliance software got popular.” Vanta has managed to turn compliance into the entry point for a much broader security platform.

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups
Is Snyk still one of cybersecurity's revenue leaders?
Snyk is still comfortably among the largest private cybersecurity startups, with more than $300 million in ARR, although its exact current position is harder to pin down because its public revenue figure is older than Cato's or Vanta's.
Forbes reported that Snyk had passed $300 million ARR while serving more than 4,500 customers. Snyk Code alone was generating around $100 million, an unusually large business inside the broader platform.
Snyk originally grew through developer-focused scanning of open-source vulnerabilities. It later expanded into code, containers, infrastructure-as-code, cloud security and more recently AI application security. That has given the company several ways to sell more products into the same engineering organizations.
What we cannot establish cleanly is how far beyond $300 million Snyk has moved since that disclosure. It could still be ahead of Vanta, but the public evidence no longer gives us enough precision to rank the two confidently.
Snyk belongs in the leading group. The uncertainty is limited to its exact place inside that group.
Is Huntress growing faster than the cybersecurity companies above it?
Huntress is currently one of the fastest-growing cybersecurity startups once we restrict the comparison to companies already generating hundreds of millions of dollars in recurring revenue.
Huntress recently passed $250 million ARR while growing 65% year over year. The company had crossed $100 million only around two years earlier, so it has added more than $150 million of recurring revenue over a short period.
Its customer model is different from many enterprise-focused cybersecurity unicorns. Huntress works heavily through managed service providers and protects more than 270,000 businesses, giving it broad exposure to small and midsized companies that cannot build sophisticated internal security teams.
Huntress also reports 130% net revenue retention. Existing customers as a group are therefore spending substantially more with the company over time, even after accounting for customers that leave. That makes the growth less dependent on endlessly finding new customers.
Among the companies whose recent growth rates we can compare cleanly, Huntress stands out.
| Company | Recent growth evidence |
|---|---|
| Huntress | 65% YoY |
| Cato Networks | 42% YoY |
| Axonius | About 35% YoY |
| Vanta | $200M to $300M ARR in nine months |
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors
Is Axonius still growing quickly?
Axonius is still growing at a healthy pace, but its trajectory now looks more like a maturing cybersecurity company than the explosive growth we see at Huntress or Cyera.
Axonius passed $200 million ARR this year after reaching $100 million in 2023. The company says that means ARR doubled in two years, while reporting around 35% year-over-year growth at the latest milestone. It is approaching 1,000 customers and serves more than 90 U.S. federal agencies.
The company started with a simple problem: security teams often do not know exactly which devices, identities, software and cloud assets exist inside their organizations. Axonius built a business around reconciling that fragmented information and has since expanded into exposure management, SaaS, cyber-physical assets and other security operations.
Axonius also says it is close to becoming free-cash-flow positive. The growth is not as flashy as Cyera's, but the business is becoming large without looking dependent on perpetual cash burn.
How big are Abnormal Security and Cyera now?
Abnormal Security is at least a $200 million-plus ARR company, while Cyera has already crossed $150 million and is closing the gap remarkably quickly.
Abnormal passed $100 million ARR in 2023 and more than $200 million the following year. Customer count later climbed above 4,500, including more than one-quarter of the Fortune 500. Those customer figures make continued revenue growth very likely, but we do not have a sufficiently fresh ARR disclosure to turn that likelihood into a precise current estimate.
Cyera gives us fresher financial evidence. TechCrunch reported from people familiar with the company that ARR had exceeded $150 million. Cyera was founded only a few years ago, making the speed unusually high even by cybersecurity standards.
The company is using that growth aggressively. Cyera raised capital at a $12 billion valuation and subsequently agreed to acquire non-human-identity startup Oasis Security for about $1 billion. The strategy is widening Cyera from data security toward the identities and AI agents that access that data.
The two companies therefore sit in different places despite relatively close disclosed ARR figures. Abnormal has a larger proven base but stale public financial data. Cyera is smaller on the latest number we can verify, while its current expansion is much more aggressive.

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market
Are $100 million cybersecurity startups still rare?
Crossing $100 million ARR is still a major achievement, but among the strongest cybersecurity startups it no longer puts a company anywhere near the top of the revenue ranking.
The numbers have shifted dramatically. Cato and 1Password are above $400 million. Vanta and Snyk have crossed $300 million. Huntress has passed $250 million. Axonius is above $200 million. Abnormal has previously disclosed the same threshold, while Cyera has already moved beyond $150 million.
Even Chainguard, founded in 2021, is now estimated by Sacra at around $100 million ARR. Sacra estimates it was only around $75 million at the end of last year, which would make the recent jump particularly fast.
This changes how we should read a cybersecurity startup announcing $100 million ARR. A few years ago, that milestone almost automatically signaled membership in the industry's elite private companies. These days it tells us that the company has reached serious commercial scale, but there may still be a fourfold gap between it and the modern private leaders.
The more revealing test starts after $100 million: can the company keep adding $50 million to $100 million of ARR every year as the base gets larger?
Are the biggest cybersecurity startups actually profitable?
Some of the biggest cybersecurity startups are already generating cash, while others are still spending heavily to buy growth, so revenue alone gives us an incomplete picture of which businesses are financially strongest.
1Password said it was free-cash-flow positive when it crossed its last major ARR milestone. Axonius says it is approaching that point. Both companies therefore have evidence that hundreds of millions in recurring revenue can translate into a financially sustainable business.
Cyera sits much further toward the aggressive-growth end. People familiar with its finances told TechCrunch that the company remained far from profitable while exceeding $150 million ARR and was spending faster than it generated revenue.
That difference becomes important whenever someone asks which cybersecurity startup “makes the most money.” If they mean revenue, we can build a reasonable ranking. If they mean net profit, the available private-company disclosures are nowhere near good enough.
Revenue scale and financial strength overlap, but they are not interchangeable. We can rank the former with reasonable confidence; a profitability ranking would mostly be guesswork.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time
Why aren't Wiz, Netskope, CrowdStrike and Zscaler in the ranking?
Wiz, Netskope, CrowdStrike and Zscaler are excluded because none of them is currently an independent private cybersecurity startup.
Wiz would otherwise blow past most names in this article. Before Google completed the acquisition, Wiz had reportedly crossed roughly $1 billion ARR. Its disappearance from the ranking is the result of a successful exit, not slower growth.
Netskope also belonged near the top while private. It is now publicly traded and recently reported $899 million ARR alongside $220.5 million of quarterly revenue.
CrowdStrike and Zscaler are much larger again. CrowdStrike finished its latest fiscal year with $5.25 billion ARR and $4.81 billion of annual revenue, while Zscaler recently reached about $3.77 billion of subscription ARR. Those figures are useful reference points for what private companies such as Cato or 1Password could eventually become, but including them would turn this into a ranking of cybersecurity companies generally.
The filtering has a huge effect on the answer. Once acquisitions and IPOs are removed, the private leaderboard becomes far less obvious.
Which cybersecurity startups are actually winning the revenue race today?
Tanium is the clearest revenue leader among private venture-backed cybersecurity companies, while Cato Networks now has the strongest claim to first place among the newer generation of cybersecurity startups.
The distinction is worth keeping. Tanium and Arctic Wolf have built much larger revenue bases, but both are mature private companies that predate most of the current startup wave. If someone asks for the biggest private cybersecurity business, Tanium is our answer.
For modern startups, the race has changed lately. Cato's latest disclosure puts it slightly ahead of 1Password. Vanta and Snyk form the next group around the $300 million-plus level, while Huntress is growing quickly enough from $250 million that it could move much higher. Axonius already has a substantial $200 million-plus business, and Cyera is the youngest company with a credible chance of climbing through these tiers unusually fast.
The broader market also keeps removing its biggest winners from the comparison. Wiz was acquired. Netskope and Rubrik went public. That turnover is one reason a cybersecurity revenue leaderboard can become stale surprisingly quickly.
So the answer depends on what we mean by startup. Tanium generates the most recurring revenue across the broad universe of independent private venture-backed cybersecurity companies. For the newer startup generation, Cato Networks is the best-supported number-one answer.
If you want more recent data on this point, please see our latest cybersecurity market report.

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize
OUR METHODOLOGY
There is no reliable public leaderboard for private cybersecurity company revenue, and the answer changes depending on what we count, which financial signals we compare, and how recent those signals are. Rather than relying on reputation, valuation, company size or market perception, we broke the question into the dimensions that most directly reveal commercial scale.
For each company, we looked for the freshest credible evidence on recurring revenue, recognized revenue, growth, customer scale, financial sustainability and company status. We prioritized first-hand company disclosures and regulatory or investor-relations material, followed by direct executive disclosures and reporting from authoritative financial and technology publications. We used outside estimates only when stronger evidence was unavailable, and we did not project old growth rates forward to create artificial current figures.
Freshness mattered particularly when companies were close. We treated nearby figures disclosed at different moments as evidence of a revenue tier rather than forcing precision the public data cannot support. We also separated mature private cybersecurity businesses from the newer startup generation, because combining the two without distinction can produce a technically correct but misleading answer.
We treated ARR, run rate and recognized revenue as different metrics rather than mixing them as if they were identical. Netskope's public reporting is a useful reference point here: quarterly recognized revenue and ARR can describe the same business at the same moment while measuring different things.
We then assessed the signals together rather than letting any single metric decide the result. Revenue scale established the hierarchy; growth, customer expansion, profitability signals and changes such as acquisitions or IPOs helped us interpret what that hierarchy actually means.
Key sources include Cato Networks on its $415M+ ARR milestone, 1Password on $400M+ ARR and free-cash-flow positivity, Vanta on crossing $300M ARR, Huntress on $250M ARR and recent growth, Axonius on passing $200M ARR, and Abnormal Security on its $200M ARR milestone.
For companies without equally fresh first-hand milestones, we used higher-authority reporting where available: Forbes on Snyk, Forbes on Tanium, Kristin Dean's discussion of Arctic Wolf's scale, and TechCrunch on Cyera's ARR and profitability.
Public-company and exit references were checked against Netskope investor relations, CrowdStrike investor relations, Zscaler investor relations, Google's confirmation that the Wiz acquisition closed, and Rubrik's IPO announcement.

This chart, included in our cybersecurity market deck, illustrates revenue distribution by region across Europe, Asia, North America, Africa, and South America in the cybersecurity market
Related blog posts
Who is the author of this content?
NEW MARKET PITCH TEAM
We track new markets so founders and investors can move fasterWe build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.