Cybersecurity
CAPITAL FIGURES ARE MEDIA-EXTRACTED ESTIMATES, NOT VERIFIED FILINGS.
EXTRACTED FROM 25+ PODCASTS & VC NEWSLETTERS · MEDIA-REPORTED FIGURES, NOT VERIFIED FILINGS
The agentic SOC is replacing the human analyst tier
The agentic SOC thesis has moved from concept to capital magnet. Prophet Security, Legion, Exaforce, and Artemis Global Technologies are all building AI-native platforms that autonomously investigate, triage, and remediate threats — displacing human analyst workflows entirely. The $195M growth round (backed by Craft Ventures, Sequoia, Accel, and Cyberstarts) and the $34M Series A signal that institutional capital is concentrating on full-stack automation rather than point-tool augmentation. The convergence of AI coding agents (like Fable 5, which rewrote 50M lines of Stripe code in a day) with offensive security tooling means the threat surface is expanding at machine speed, making agentic defense a structural necessity rather than a luxury.
Platform-scale acquirers are now paying nine- and ten-figure sums to fill identity and data security gaps at speed. Cyera's $1B acquisition of Oasis Security — after already buying Genie Security for $50M — cements its path to a data-plus-identity superplatform at a $9B VC valuation. Armis was acquired by ServiceNow for $7.8B, Dragos by Accenture for $4.18B, Panther by Databricks, and LayerX by Akamai, while Zscaler is acquiring Symmetry Systems. As one signal noted, well-capitalized platform players are systematically absorbing point-solution startups [44].
Why it matters · Early-stage founders and seed investors in high-specificity security point solutions face a binary outcome: reach platform scale independently or become an acquisition target within 3–5 years.
The explosion of AI agents, API keys, service accounts, and machine credentials has forced identity security to bifurcate. SailPoint acquired Entro Security to enter non-human identity management; 1Password acquired Apono for just-in-time cloud access; Astrix Security monitors AI agent credentials; Opal enables time-bound access for AI workloads; and Onyx Security builds AI-native governance models to oversee other AI agents. The $1B Oasis Security acquisition by Cyera [20, 42] is the clearest signal that NHI is now a platform-level priority, not a niche.
Why it matters · As enterprises deploy hundreds of AI agents with persistent credentials, the NHI attack surface grows faster than traditional IAM tools can cover — creating a durable wedge for specialized vendors.
A new cluster of companies — XBOW, Tenzai, Terra Security, Hex Security, and Astra Security — are rebuilding penetration testing as a continuous, autonomous, AI-driven service rather than a periodic human engagement. The $34M Seed round backed by Lightspeed and the Wiz founding team [11] and a $30M Series A backed by Khosla Ventures [27] both flowed to AI-native security companies in the same week. Developer-facing tools like qsa.sh (104 upvotes on Product Hunt) [39] signal grassroots adoption at the practitioner level, while the launch of AI-enabled cyber warfare and defense systems for military and intelligence agencies [26] confirms the category is reaching institutional buyers.
Why it matters · Continuous autonomous pentesting compresses vulnerability windows from months to minutes, threatening legacy managed security service providers and creating a winner-take-most dynamic for the most capable AI offensive platforms.
The mainstreaming of AI agents, frontier models, and autonomous coding tools is simultaneously expanding the attack surface and legitimizing cybersecurity as core AI infrastructure. Okta is cited as up 57% in 2025 as an AI infrastructure beneficiary; Cloudflare has shipped an MCP server for agentic workflows; CrowdStrike and Palo Alto Networks are embedding AI across their platforms. The broader signal [24] that 'cybersecurity has moved from a peripheral concern to a central pillar of the AI economy' is backed by $6.78B deployed across 28 deals in 28 days.
Why it matters · Cybersecurity platforms with deep AI integration are re-rating as infrastructure plays rather than security tools, commanding revenue multiples closer to cloud hyperscalers than traditional security vendors.