Early stage startup M&A on fire, funding healthy, and attackers are like lawyers? – ESW #352
In the enterprise security news,
- Axonius raises $200M and is doing $100M ARR!
- Claroty raises $100M and is doing $100M ARR!
- Crowdstrike picks up DSPM with Flow Security
- CyCode picks up Bearer
- Are attackers like lawyers?
- How a bank failed (with no help from a cyber attack)
- the FTC cracks down on customer data collection
- Apple’s car sadly won’t be a thing any time soon
- or maybe ever.
All that and more, on this episode of Enterprise Security Weekly.
Announcements
Join our cybersecurity community on Discord! Connect directly with our expert hosts, join discussions with fellow audience members, and customize your notifications to receive alerts every time an episode of your favorite show publishes. Get your invite at securityweekly.com/discord!
Hosts
- 1. FUNDING: Axonius Announces $200 Million Series E Extension Amid Explosive Growth
$200M Series E extension, led by Accel. Reportedly doing over $100M ARR in 2023, what's next for this unicorn as it continues to grow?
- 2. FUNDING: Claroty Secures $100 Million in Strategic Growth Financing
$100M growth round, bringing funding total to over $700M. Is this OT security startup still a unicorn? I sure hope so, that's a lot of funding to justify! Like Axonius, the company claims over $100M ARR in 2023 - a healthy and confidence inspiring number for a company with this much funding in the can.
- 3. FUNDING: DTEX Systems Raises $50M Led by Alphabet’s CapitalG to Disrupt Insider Risk Management Market Through AI-Enabled Innovations
- 4. FUNDING: OpenCTI maker Filigran raises $16M for its cybersecurity threat management suite
- 5. FUNDING: Security startup, BreachBits, Raises Seed Investment to Disrupt the Cyber Risk Quantification Market
- 6. FUNDING: A Milestone for Prowler: Announcing $6M in Seed Funding – Prowler
- 7. FUNDING: Codified Raises $4M for AI-Powered Data Governance
$4M seed round co-led by Madrona Ventures and Vine Ventures. "Codified aims to simplify the process of data governance by ensuring that the right people have access to the right data."
- 8. FUNDING: ESProfiler Raises £2.8M in Seed Funding
£2.8M in Seed funding, led by Nauta Capital.
"ESProfiler is a cybersecurity firm providing a platform that quantifies what security investments do against the evolving ways adversaries attack organisations. It offers a comprehensive view of an enterprise’s security capabilities, identifies gaps and efficacy, and provides the vital commercial and financial data needed for informed decision-making."
- 9. FUNDING: Enkrypt AI Raises $2.35M in Funding
$2.35M funding round led by Boldcap. This Boston, MA-based company enables safe adoption of Generative AI within enterprises.
- 10. ACQUISITIONS: Cycode Adds Exclamation Point to Its Complete ASPM Platform with Strategic Acquisition of Bearer, AI-Powered SAST & API Discovery Company
Cycode, a Series B ASPM startup with $80.6M in funding, picks up Bearer, a seed-stage SAST, API discovery, and data leak prevention startup.
- 11. ACQUISITIONS: CrowdStrike to Acquire Flow Security, Sets Standard for Modern Data Security
Yet another DSPM picked up! Word on the street (and in Israeli rumor mills) is that the deal value is under $100M. Flow was working with $13M in funding from two funding rounds.
- 12. REPORTS: 2024 State of Cloud Security Report
- 13. HOT TAKES: Kelly Shortridge on LinkedIn: “Attackers are like lawyers”
Hot take queen Kelly is back with another one. Attackers are like lawyers? What an opener!
There's also an acronym you probably shouldn't say out loud. As usual it's a solid, useful perspective that can help defenders outthink their adversaries.
- 14. DATA ANALYSIS: Exploring the GitHub Advisory Database for fun and (no) profit
"Principal Security Engineer Dakota Riley dives into the GitHub Advisory Database, cross referencing with other data sources and looking for interesting trends"
- 15. BANK FAILURE: Material Loss Review of Heartland Tri-State Bank
This involves a crypto-related pig butchering scam, but isn't really a cyber breach. Still, there are some interesting lessons to learn from it, particularly around compliance and the importance of knowing when to speak up (and file a SAR)!
- 16. BREACHES: A leaky database spilled 2FA codes for the world’s tech giants
"A technology company that routes millions of SMS text messages across the world has secured an exposed database that was spilling one-time security codes that may have granted users’ access to their Facebook, Google and TikTok accounts."
- 17. REGULATIONS: Ben Winokur on AVAST vs FTC
"In the recent FTC investigation, Avast claimed that they were entitled to sell and share browsing data because it was anonymized. The FTC found that the anonymization measures employed by Avast were wildly insufficient to actually prevent re-identification -- and even where contracts contained prohibitions on re-identification, the language allowed customers to join their first-party data to the data purchased from Avast."
- 18. SQUIRREL: Apple cancels its autonomous electric car project and is laying off some workers