Cybersecurity: what are the top startups now?

Last updated: 29 June 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity: what are the top startups now? The strongest names are Wiz, Cyera, Armis, Island, Abnormal AI, Chainguard, Axonius, Oasis Security, Noma Security, and Dragos.

The top of the market is no longer one single cybersecurity category. The strongest companies are spread across cloud security, data security, enterprise browsers, exposure management, AI security, identity, software supply chain, email security, and OT security.

Wiz still sets the benchmark because its $32 billion acquisition by Google created the clearest exit signal of this cycle. Even after the deal, it remains the reference point for what a category-defining cybersecurity startup can become.

Cyera looks like the hottest private company because data security has become newly important in the AI era. The market is no longer just asking where sensitive data sits, but what AI tools and agents can see, move, learn from, or leak.

Armis and Axonius show that “boring” visibility problems are still huge. Asset discovery, exposure management, and device visibility may not sound as shiny as AI security, but the revenue and acquisition signals are very strong.

Island is probably the cleanest category-control story. Enterprise browsers used to sound narrow, but work now happens inside SaaS apps, AI tools, shared documents, and contractor environments, which makes the browser a serious security layer.

Abnormal AI is one of the most proven AI-native security companies because it is not selling a vague future category. It sells into a painful existing budget: email, account behavior, vendor fraud, and human risk.

Chainguard stands out because software supply-chain security has moved from abstract fear to enterprise buying. Its disclosed ARR, customer base, and path toward a much larger revenue base make it the strongest breakout in that lane.

Oasis Security and Linx show where identity security is moving next. The biggest new problem is not only employee access, but API keys, service accounts, bots, workload identities, and AI agents acting inside the company.

Noma Security, WitnessAI, Prompt Security, Lakera, Pangea, HiddenLayer, and Corridor make AI security feel real rather than just noisy. The strongest proof is not the buzzword itself, but funding velocity, acquisitions, and buyer urgency around AI agents and GenAI deployment.

Dragos has the strongest current OT-security signal because Accenture’s move around Dragos, runZero, and NetRise turns critical-infrastructure security into a platform story. Nozomi is also acquisition-validated, while Claroty remains relevant but less freshly visible.

All together, the current leaders are not just the biggest valuations. The better answer comes from aggregating valuation, ARR, exit outcomes, customer proof, strategic buyer interest, and whether each company controls a category that security teams are only now starting to budget for seriously.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Which cybersecurity startups are already in the heavyweight league?

Wiz, Cyera, Armis, Island, Abnormal AI, and Axonius stand out.

Wiz is still the reference point. Google completed its $32 billion acquisition of Wiz in March 2026, which makes it the biggest cybersecurity startup exit of this cycle.

The headline price is not even the only interesting part. Reports around the deal said Wiz had roughly $500 million ARR in 2024 and was targeting around $1 billion ARR in 2025. Even if we use the more aggressive forward number, Google paid around 32x ARR. That says Google was buying a cloud-security platform it did not want anyone else to own.

Cyera is one of the hottest private names right now. Its major 2025 round put the company at a multi-billion-dollar valuation, and reporting around the business suggested it had already passed meaningful ARR scale. The exact multiple depends on which revenue number you use, but the point is clear enough: investors are not just rewarding “data security” as an old category. They are paying for the layer that tells companies what sensitive data their AI systems can see, move, and potentially leak.

Armis is the mature version of the same story in another category. In November 2025, it raised $435 million at a $6.1 billion valuation. One month later, ServiceNow agreed to acquire it for $7.75 billion. Reports said Armis had more than $340 million ARR and was growing more than 50% year over year. Compared with Cyera, Armis looks less explosive but more proven. The multiple is lower, but the operating proof is stronger.

Island is the enterprise-browser winner so far. In March 2025, it raised $250 million at a $4.8 billion valuation. Reports at the time said it had about 450 business customers and around 500 employees. The big thing here is category control. A few years ago, “enterprise browser” sounded like a niche. Today, with work happening inside SaaS apps, AI tools, unmanaged devices, and contractor environments, the browser has become a place where security teams can actually enforce policy.

Abnormal AI is the clearest AI-native email and human-behavior security leader. Around its 2024 Series D, it reported more than $200 million ARR, more than 2,400 customers, and 17% Fortune 500 penetration. It was also named again to the Forbes Cloud 100 in September 2025. Compared with many AI-security names, Abnormal is less speculative. It has real scale, real enterprise penetration, and a category that still has budget.

Axonius is less loud, but the business is very real. In May 2026, Calcalist reported that Axonius had passed $200 million ARR, with 35% year-over-year growth and revenue doubling over two years. That is not as flashy as Cyera’s valuation, but at this size it is a strong sign. Asset visibility and exposure management are still core security problems, not yesterday’s category.

At the top end, we see three different types of leaders. Wiz is the landmark exit. Cyera is the hottest private valuation story. Armis, Abnormal, and Axonius bring stronger proof of revenue scale. Island is the clearest category king in a newer surface area.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which data-security startups are becoming essential because of AI?

Cyera is the clear leader. But Noma Security, WitnessAI, Prompt Security, Lakera, and Pangea are the names that make the category feel real.

Today, data security is hot again because AI changed the problem. It is no longer only about where sensitive data lives, but whether AI systems can touch it, learn from it, reveal it, or send it outside the company’s control.

That is why Cyera is ahead. Its recent funding and valuation make the comparison more useful. If Cyera is already well into nine-figure ARR territory, it is far beyond most young security startups. But the valuation still runs ahead of the revenue. That gap tells us investors believe Cyera can become a core control plane for enterprise AI, not just another data-classification tool.

Noma Security is much earlier, but it has one of the sharpest growth stories in AI security. In July 2025, it raised a $100 million Series B less than a year after its previous round. Globes reported that Noma had grown ARR by more than 1,300% over the previous year and had dozens of customers in financial services, life sciences, retail, and technology. We should be careful with the percentage because it likely starts from a small base. Still, compared with most AI-security startups, Noma gives us more than a vague “enterprise interest” story. It gives us a fast commercial ramp.

WitnessAI is earlier again, but the timing is excellent. In January 2026, it raised $58 million to secure enterprise AI and AI agents. It does not yet have Cyera’s valuation or Noma’s reported growth story, but it sits exactly where security buyers are getting nervous: AI governance, AI-agent behavior, and the risks created when non-human systems act inside the company.

Prompt Security, Lakera, and Pangea are important for a different reason. They are no longer independent breakout candidates, but their acquisitions validate the market. SentinelOne agreed to acquire Prompt Security in August 2025. Check Point agreed to acquire Lakera in September 2025. CrowdStrike acquired Pangea in 2025. When three major public cybersecurity vendors buy into the same theme in the same period, the category is not imaginary.

All things considered, Cyera is the current data-security winner. Noma is the most interesting emerging independent company. WitnessAI is the cleanest early AI-governance bet. Prompt Security, Lakera, and Pangea show that the large vendors do not want to build everything from scratch.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Which cloud-security startups still matter after Wiz?

Cyera, Chainguard, Island, and Clover matter most after Wiz, but for different reasons.

After Google bought Wiz, the lazy question is “who is the next Wiz?” The better question is where cloud security is expanding next.

Right now, the money looks like it is moving toward four control points: data, software supply chain, browser access, and product-security automation.

Cyera belongs here because data security has become the AI-era extension of cloud security. Wiz helped companies understand cloud risk across workloads and infrastructure. Cyera is trying to answer the next question: what sensitive data exists across the environment, and what can AI systems do with it? That is why its valuation signal is so powerful today. Investors are treating data visibility as part of the future cloud-security stack.

Chainguard is the stronger software-supply-chain comparison. In April 2025, it raised $356 million at a $3.5 billion valuation. More importantly, the company disclosed $40 million ARR and said it expected to cross $100 million ARR before the end of fiscal 2026. That gives us context. The round looked expensive on current ARR, but if the company really gets past $100 million ARR, the forward multiple becomes much easier to understand. Compared with younger supply-chain startups, Chainguard has the rare advantage of both a clear category and disclosed revenue momentum.

Island matters because the browser is becoming a cloud-work control point. People do not just “use the cloud” through infrastructure dashboards. They work inside Salesforce, Workday, Slack, Google Workspace, GitHub, AI tools, and dozens of internal apps. Island’s argument is that security teams need a safer browser layer around that work. The March 2025 valuation and customer count make it the clear leader in that specific lane.

Clover is much earlier, so we should not put it in the same proof bucket. But it is worth watching because of who backed it. In November 2025, Axios reported it raised $36 million from Notable Capital, Team8, Wiz founders, and executives from CrowdStrike, Snyk, Palo Alto Networks, Atlassian, and Google. That is a strong insider signal that product security is about to be automated more aggressively.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which identity-security startups are getting hotter because of AI agents?

Oasis Security, Linx Security, Veza, Silverfort, and Aembit are the group to watch. Oasis and Linx have the freshest signals.

Identity security used to be mostly about employees, admins, and privileged access. These days, the scarier question is different: which bots, service accounts, API keys, machine identities, and AI agents can act inside the company?

Oasis Security is the strongest current signal in non-human identity. In March 2026, it raised $120 million, bringing total funding to $190 million. The company focuses on API keys, service accounts, bot tokens, and AI-agent identities. Compared with older identity-security vendors, Oasis is more directly built around the machine-identity mess companies are discovering now.

Linx Security is smaller, but the investor signal is very interesting. In March 2026, Business Insider reported that Linx raised $50 million from Index Ventures, Cyberstarts, and Insight Partners. That matters because this is the same kind of investor network that backed some of the biggest Israeli cyber winners. Linx positions itself as an AI-powered identity-security agent that monitors and fixes identity risk. We do not yet have enough public revenue evidence to call it a leader, but it is one of the cleanest emerging bets.

Veza is more mature and broader. In April 2025, it raised $108 million at an $808 million valuation, with strategic participation from Atlassian Ventures, Workday Ventures, and Snowflake Ventures. That is a useful comparison point. Veza is less “AI-agent hype” than Oasis or Linx, but it has a strong enterprise-access story across SaaS, cloud, and data systems.

Silverfort is also a real leader, although its freshest public funding signal is older. It raised $116 million in January 2024 at a $1 billion valuation. It still matters because it protects identities across hybrid environments, including legacy systems and service accounts. But if we focus only on the last 12 months, Oasis and Linx are clearly more current.

Aembit is worth mentioning because workload identity is becoming more important as applications, services, and AI agents talk to each other. Public evidence is thinner than for Oasis or Veza, so it belongs on the watchlist rather than in the top tier.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Which cybersecurity startups are winning the enterprise-browser category?

Island is the clear leader. For now, there is no public challenger with comparable evidence.

This one is unusually straightforward. Island raised $250 million at a $4.8 billion valuation in March 2025, with reports citing about 450 business customers and roughly 500 employees. In a category that is still young, those numbers create a big gap with everyone else.

The reason Island is interesting today is that the category has become easier to understand. Enterprise work now happens inside web apps, AI tools, shared documents, and SaaS dashboards. If a company cannot control the device, the app, or the network perfectly, the browser becomes one of the few places where it can still enforce security rules.

That gives Island a cleaner story than many security startups. It is trying to own one daily workflow that almost every employee uses. Compared with other young security categories, that makes the buying logic easier: companies already know where the product lives.

The market also has strategic validation. Palo Alto Networks bought Talon Cyber Security in 2023. That deal showed large security vendors believed the browser could become a serious enterprise-control layer. Island’s later valuation then showed that the remaining independent leader could still command a platform-level price.

For now, Island is the category. That may change if another enterprise-browser startup discloses real customer, revenue, or deployment numbers, but we do not see a public leading pack yet.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which software supply-chain security startups are actually breaking out?

Chainguard is the clear leader; Koi, Socket, Endor Labs, Semgrep, and NetRise are the names to watch around it.

Chainguard has the best evidence. It disclosed $40 million ARR around its April 2025 Series D and said it expected to cross $100 million ARR before the end of fiscal 2026. Later in 2025, it also reported more than 200 customers, including ANZ Bank, Canva, GitLab, Hewlett Packard Enterprise, VPBank, and Wiz. Compared with most software supply-chain startups, Chainguard has moved past “developers like the idea” and into real enterprise buying.

Koi is much smaller, but it is one of the freshest early-stage signals. In September 2025, Business Insider reported that Koi had raised $48 million across a seed and Series A. The company came out of a white-hat experiment showing how malicious extensions could infiltrate organizations through tools like the Visual Studio Code Marketplace. The report also said Koi had reached more than $1 million ARR and served Fortune 50 and Fortune 500 companies. That is early, yes, but it is concrete. In a market full of theoretical supply-chain fear, Koi found a very specific attack surface.

Socket is another important name, especially around open-source package risk. It has been visible for longer, and its product focus is very close to how modern software teams actually get compromised: dependency updates, malicious packages, and risky code pulled into the build process. The recent public evidence is not as strong as Chainguard’s ARR disclosure or Koi’s fresh funding, so it sits below them in this ranking.

Endor Labs and Semgrep still matter because application security is moving closer to developers. Semgrep, in particular, announced a Series D in February 2025 and framed itself as a way to make exploitation more expensive through AppSec automation. But again, without the same public revenue context, we should not pretend the evidence is equal.

NetRise is different. Its inclusion in Accenture’s June 2026 OT-security push around Dragos, runZero, and NetRise matters because firmware and embedded-device software are now part of the supply-chain conversation. It is less of a classic developer-security story and more of a “what is inside all these connected devices?” story.

Chainguard is the breakout leader. Koi is the fresh early-stage name we would watch closely. Socket, Endor Labs, and Semgrep remain important developer-security players, while NetRise shows the category extending into OT and device software.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Which AI-security startups are real, and which ones are just riding the buzzword?

Noma Security, WitnessAI, Prompt Security, Lakera, Pangea, HiddenLayer, and Corridor have the strongest real signals.

AI security is noisy right now. Many startups can say they secure AI. The question is who has evidence that buyers or acquirers are actually moving.

Noma Security is the strongest independent signal. Its July 2025 $100 million Series B came with a reported 1,300% ARR growth number over the previous year. Again, we should not compare that percentage to a mature company, because the base was probably small. But compared with most AI-security startups, Noma gives us a real commercial acceleration signal.

WitnessAI is also credible because of timing and positioning. Its January 2026 $58 million round came exactly as companies started worrying more about AI agents, AI governance, and non-human decision-making inside enterprise systems. It is not yet in the same proof tier as Cyera or Noma, but it is one of the better-funded independent AI-security bets.

Prompt Security, Lakera, and Pangea matter because of buyer behavior. SentinelOne, Check Point, and CrowdStrike all moved into AI security through acquisitions in 2025. That tells us large vendors see the same gap. They do not want to wait two years to build everything internally while customers are already deploying GenAI tools.

HiddenLayer is more focused on AI model and application protection. Its biggest public funding signal is older, with a $50 million Series A announced in 2023, so we should not call it one of the freshest names. Still, it remains relevant because model discovery, AI attack simulation, and runtime AI security are real technical problems.

Corridor is the early radar name. In August 2025, Axios reported that it raised $5.4 million and hired Alex Stamos as chief security officer. Its focus is AI-assisted vulnerability discovery and bug-bounty triage. This is not a market-leader signal yet. It is a smart founder-market signal in a world where AI-generated code is increasing the amount of software security teams need to review.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which email and human-security startups are still exciting?

Abnormal AI is the clear leader. We do not see an equally strong recent public challenger in the same lane.

Email security is not a new category, which is exactly why Abnormal AI is interesting. It managed to make the category feel current again by moving the center of gravity from spam and phishing filters to behavioral AI.

The company had already crossed $200 million ARR by its 2024 Series D. It also reported more than 2,400 customers and 17% Fortune 500 penetration. Those numbers put it far ahead of most cybersecurity startups that talk about AI but do not disclose much scale. In September 2025, it was again named to the Forbes Cloud 100, and the company pointed to autonomous AI agents, Japan expansion, and FedRAMP Moderate authorization as part of its momentum.

The comparison is important here. Many AI-security startups are still trying to prove that enterprises will buy a new product category. Abnormal already sells into a painful, budgeted category and adds AI where it is easy to understand: unusual messages, strange account behavior, vendor fraud, and risky human workflows.

That does not mean the category is full of hot new winners. It actually looks concentrated. We did not find another private company in the same lane with comparable recent public evidence across ARR, customer count, Fortune 500 penetration, and recognition.

Abnormal is still the company to beat in AI-native human and email security. It is not the newest name, but today it is one of the most proven private cybersecurity companies still operating with startup momentum.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Which exposure-management and asset-security startups are winning?

Armis, Axonius, runZero, and Dragos stand out, but this category is clearly consolidating.

Exposure management is one of those markets that can sound boring until you look at the deals. Companies have too many devices, cloud assets, identities, SaaS apps, unmanaged endpoints, and industrial systems. The problem is no longer just “what do we own?” It is “what can attackers reach, and what should we fix first?”

Armis is the biggest recent signal. Its late-2025 funding and ServiceNow acquisition created one of the strongest cybersecurity exit stories after Wiz. The company also had more than $340 million ARR and was reportedly growing above 50% year over year. Compared with Axonius, Armis got the bigger strategic price. Compared with younger exposure startups, it has much more revenue proof.

Axonius is the durable independent leader. In May 2026, it reported more than $200 million ARR, 35% year-over-year growth, and revenue doubling over two years. That growth rate is not wild for a seed-stage company, but it is strong at this scale. The market is basically saying: even after years of “asset inventory” tools, enterprises still do not have a clean picture of their environment.

runZero became more strategically important in June 2026 when Accenture agreed to acquire it as part of the Dragos, runZero, and NetRise OT-security push. runZero is not the biggest name here, but it is a useful sign that asset discovery is becoming part of a broader exposure-management platform.

Dragos is more OT security than general exposure management, but it belongs in this conversation because industrial environments are now part of the same visibility problem. If attackers can move from IT into OT, the old separation between enterprise security and industrial security becomes less useful.

Putting it together, Armis has the strongest exit signal, Axonius has the strongest independent ARR signal, and runZero plus Dragos show where the market is going. Asset visibility by itself is becoming less interesting. Exposure defense across cloud, IT, and OT is the bigger prize.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which OT and critical-infrastructure cybersecurity startups are still hot?

Dragos is the main current winner. Nozomi Networks and Claroty remain important, but Dragos has the freshest signal.

OT security is having a very different moment from AI security. It is less about shiny demos and more about critical infrastructure, geopolitics, industrial uptime, and insurance-level risk. The companies that win here need trust, deep technical knowledge, and access to hard-to-reach industrial customers.

Dragos became the central story in June 2026 when Accenture agreed to acquire a majority stake in the company while also buying runZero and NetRise. The combined transactions were reported at about $4.18 billion. Dragos will remain an independent business under CEO Robert Lee, but with Accenture’s distribution behind it.

That structure is important. It means Dragos is not just being tucked into a product suite. Accenture is effectively building a serious OT-security platform around it, with asset discovery from runZero and firmware/device-software visibility from NetRise.

Nozomi Networks also had a major validation signal. In September 2025, Mitsubishi Electric agreed to buy it for close to $1 billion. That confirms Nozomi as one of the long-term OT-security leaders. But if we focus on what is freshest right now, Dragos has the louder 2026 signal and the broader platform setup.

Claroty remains relevant in cyber-physical systems security, but its latest public funding, revenue, or acquisition signal is not as strong as Dragos or Nozomi over the same period.

It looks like Dragos is the current OT-security leader by recent strategic signal. Nozomi is acquisition-validated. Claroty still belongs in the leader conversation, but the latest market evidence is not as loud.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Which tiny or emerging cybersecurity startups are most worth watching?

Koi, Clover Security, Corridor, Linx Security, Oasis Security, and WitnessAI are probably the most interesting emerging names.

Koi is interesting because it found a specific, painful problem instead of saying “we secure the software supply chain” in general. Its story started with how malicious extensions could infiltrate organizations through developer tools like the Visual Studio Code Marketplace. In 2025, it raised $48 million and reportedly passed $1 million ARR with Fortune 50 and Fortune 500 customers. That is still small, but compared with many early-stage cyber startups, it has a clearer attack surface and clearer buyer pain.

Clover Security is interesting for a different reason. The November 2025 $36 million round came with backing from Wiz founders and senior people from CrowdStrike, Cato Networks, Snyk, Palo Alto Networks, Atlassian, and Google. Again, this is not proof of revenue leadership. But when that many experienced security operators back an AI product-security startup, we should pay attention.

Corridor is even earlier. It raised $5.4 million in August 2025 and hired Alex Stamos as chief security officer. The company focuses on AI-assisted vulnerability discovery and bug-bounty triage.

We would not call it a leader today. But it sits in a problem that is getting worse quickly: AI can generate more code, but companies still need to find authorization flaws, business-logic bugs, and messy vulnerabilities that scanners often miss.

Linx and Oasis belong here because identity is being rewritten by non-human actors. Oasis is already much better funded, with its March 2026 $120 million round. Linx is earlier but has a strong investor signal and a cleaner AI-agent identity angle. They are not the same stage, but they are chasing the same shift.

WitnessAI is also a strong watchlist name because it is directly tied to enterprise AI adoption. It raised $58 million in January 2026, and its category is easy to explain: companies want AI agents, but they do not fully trust what those agents can access or do.

Finally, this group is not a normal ranking. Oasis and WitnessAI are already much more funded. Koi has early ARR evidence. Clover and Corridor are more about founder-market and investor-quality signals. Linx sits somewhere in between. The common point is that all six are attached to problems that security teams are only starting to budget for seriously.

So, who are the top cybersecurity startups now?

The overall leaders are Wiz, Cyera, Armis, Island, Abnormal AI, Chainguard, Axonius, Oasis Security, Noma Security, and Dragos.

Wiz is the benchmark because it turned cloud security into a $32 billion strategic acquisition. It is no longer independent, but it still defines what a category-winning cyber startup can become.

Cyera is the hottest current private company. Its latest major round is one of the strongest fresh valuation signals we found, and the reported ARR context makes the price even more revealing. The multiple looks aggressive, but that is the point: investors are pricing data security as one of the main control layers for enterprise AI.

Armis is the strongest mature exit signal after Wiz. It combines real ARR scale, strong growth, and a strategic buyer willing to pay a major price. Compared with Cyera, it is less speculative. Compared with Axonius, it had the bigger acquisition outcome.

Island is the clearest category king in enterprise browsers. The company has funding, valuation, customer count, and a simple buying logic. That combination is rare in a young category.

Abnormal AI is the most proven AI-native human-security company. Many startups claim AI security relevance. Abnormal has ARR, customers, Fortune 500 penetration, and a product category buyers already understand.

Chainguard is the strongest software supply-chain breakout. It has a large valuation, disclosed ARR, major customers, and a clear path toward a much bigger revenue base.

Axonius is less trendy but very strong. Passing $200 million ARR in 2026 makes it one of the most credible independent cybersecurity companies in asset visibility and exposure management.

Oasis Security and Noma Security are the two most important emerging-category names. Oasis is the fresh non-human identity signal. Noma is the fresh AI-agent security signal.

Dragos is the OT-security leader by recent strategic evidence. Accenture’s June 2026 move around Dragos, runZero, and NetRise put it at the center of critical-infrastructure cybersecurity.

The final answer is not one company. It is a cluster. If we aggregate the evidence across valuation, ARR, acquisition activity, customer proof, category timing, and recent strategic interest, the current cybersecurity startup leaders are Wiz, Cyera, Armis, Island, Abnormal AI, Chainguard, Axonius, Oasis Security, Noma Security, and Dragos.

Category Startups selected and why
Heavyweight cybersecurity startups Wiz, Cyera, Armis, Island, Abnormal AI, Axonius. These have the strongest mix of valuation, ARR, acquisition outcomes, customer evidence, and category control.
Data security for AI Cyera, Noma Security, WitnessAI, Prompt Security, Lakera, Pangea. Cyera leads; Noma has the sharpest emerging growth signal; acquisitions validate the category.
Cloud-security successors after Wiz Cyera, Chainguard, Island, Clover. The heat has moved toward data, secure software foundations, browser control, and product-security automation.
Non-human identity and AI-agent identity Oasis Security, Linx Security, Veza, Silverfort, Aembit. Oasis has the freshest funding signal; Linx is the sharper early bet.
Enterprise browser security Island. It is the only independent company with public evidence strong enough to dominate the category today.
Software supply-chain security Chainguard, Koi, Socket, Endor Labs, Semgrep, NetRise. Chainguard leads by scale; Koi is the freshest early-stage signal.
AI security Noma Security, WitnessAI, Prompt Security, Lakera, Pangea, HiddenLayer, Corridor. Noma and WitnessAI lead among independents; acquisitions prove strategic demand.
Email and human-behavior security Abnormal AI. It has the strongest public proof across ARR, customers, Fortune 500 penetration, and category maturity.
Exposure management and asset security Armis, Axonius, runZero, Dragos. Armis has the strongest exit signal; Axonius has the strongest independent ARR signal.
OT and critical infrastructure security Dragos, Nozomi Networks, Claroty. Dragos has the freshest strategic signal; Nozomi is acquisition-validated; Claroty remains relevant but less recently visible.
Emerging names to watch Koi, Clover, Corridor, Linx, Oasis, WitnessAI. They are not all leaders yet, but each has a concrete recent signal tied to a category that is heating up.
Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

OUR METHODOLOGY

This analysis tests which cybersecurity startups look strongest right now based on recent public evidence. We do not treat “top cybersecurity startup” as a simple ranking, because the market is too broad and “top” can mean valuation, revenue scale, acquisition outcome, category leadership, customer proof, strategic buyer interest, or emerging momentum.

So instead of relying on intuition or vague market sentiment, we broke the question into the main analytical dimensions that matter today. For each dimension, we looked at recent public signals, compared the companies inside that specific category, and weighed the evidence point by point.

We prioritized fresh signals because this is a current-market view, not an all-time cybersecurity ranking. A large acquisition, a new valuation, a disclosed ARR figure, a major customer signal, or a strategic buyer move does not always mean the same thing. But when several of these signals point in the same direction, they make the conclusion much stronger.

We gave extra weight to signals that were specific and checkable: acquisition value, funding amount, valuation, ARR, year-over-year growth, customer count, Fortune 500 penetration, strategic acquirer identity, and whether the company appears to control a clearly defined category.

We also separated mature proof from emerging momentum. A company with $200 million ARR is not comparable to a seed-stage company with a sharp investor signal, but both can matter if we are trying to understand where the cybersecurity market is going.

The final list is therefore based on structured aggregation. We used the clearest recent evidence across several dimensions to separate companies with real market momentum from companies that are simply attached to a hot cybersecurity theme.

Key sources used for this analysis include: Business Insider on Google closing the Wiz acquisition, Barron’s on the original Wiz deal context, Axios on Cyera’s funding and valuation signal, MarketWatch on ServiceNow acquiring Armis, ITPro on the Armis acquisition close, The Wall Street Journal on Island’s funding and valuation, The Wall Street Journal on Noma Security’s Series B, Axios on WitnessAI’s funding, ITPro on Check Point acquiring Lakera, TechRadar on CrowdStrike acquiring Pangea, Business Insider on Linx Security’s funding, Business Insider on Koi’s funding and early ARR signal, The Wall Street Journal on Semgrep’s Series D, ITPro on Accenture’s Dragos, runZero, and NetRise move, The Wall Street Journal on Accenture taking a majority stake in Dragos, The Wall Street Journal on Mitsubishi Electric buying Nozomi Networks, and ITPro on the broader AI-agent identity and access-control problem.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog