Blog

10 Promising Cybersecurity Startups CISOs Should Know About

This article lists 10 notable cybersecurity startups founded after 2020, each addressing trending security challenges and gaining rapid traction with enterprises and investors.

Highlighted Startups:

  • Astrix Security: Focuses on securing non-human identities in enterprise environments; raised $85M since 2021.
  • Chainguard: Provides software supply chain security via a Linux-based platform; $600M+ in funding, $3.5B valuation.
  • Cyera: Specializes in data security posture management, with a significant platform play in the AI era. The company has raised $1.3 billion and is valued at $6 billion.
  • Drata: Automates GRC & trust management, growing quickly post-acquisition of SafeBase; $100M ARR, 7,000+ customers.
  • Island: Developed a secure enterprise browser for safer SaaS access; $730M in funding, 450+ enterprise customers.
  • Mimic: Ransomware detection and deflection at the kernel level, with fast simulation and recovery features; founded in 2023.
  • Noma Security: AI and agent security/governance, rapid growth, and $135M raised since 2023.
  • Reality Defender: Deepfake detection across media types, industry award-winner, strong market backing.
  • Upwind: Cloud-native app protection with runtime-first detection; rapid revenue and feature growth, $180M raised.
  • Zenity: Governs AI agents’ access and behavior in real-time, integrates broad agent discovery/governance, with $38M raised.

https://www.csoonline.com/article/4080699/10-promising-cybersecurity-startups-cisos-should-know-about.html

73% of U.S. CISOs Faced a Significant Cyber Incident in the Past Six Months, According to Nagomi Data

73% of U.S. CISOs experienced significant cyber incidents in the last six months, highlighting internal pressures rather than external threats as the main stressors. Burnout is prevalent, with 87% reporting increased role pressure. Many struggle with managing numerous security tools and face board expectations exceeding their ability to quantify risk. Nagomi Security's CISO Pressure Index reveals the need for shared accountability and support for CISOs to navigate these challenges effectively.

https://www.businesswire.com/news/home/20251105165613/en/73-of-U.S.-CISOs-Faced-a-Significant-Cyber-Incident-in-the-Past-Six-Months-According-to-Nagomi-Data

The Next Evolution Of Cybersecurity Is Preemptive

Cybersecurity is rapidly evolving from reactive responses to proactive prevention as advances in AI enable attacks to occur much faster. Instead of only responding to incidents, the new focus is on detecting early signals—like new domains or infrastructure—that may indicate an impending attack and neutralizing threats before they develop. This shift has led to the development of new metrics that measure how quickly organizations can preempt threats. Both attackers and defenders are leveraging AI to stay ahead, with startups like Malanta designing systems to discover and dismantle potential attacks at the earliest stage. The industry sees prediction and early intervention as key to future cybersecurity.

https://www.forbes.com/sites/tonybradley/2025/11/05/the-next-evolution-of-cybersecurity-is-preemptive/

M365 Copilot Data Processing Goes Local to Meet Sovereignty Demands

Microsoft will process M365 Copilot data locally in 15 countries by utilizing regional data centers, addressing digital sovereignty concerns. The initiative begins in Australia, India, Japan, and the UK, expanding to other countries by 2026, aiming to enhance data governance and reduce latency for customers, especially in regulated industries.

https://www.computerworld.com/article/4085303/m365-copilot-data-processing-goes-local-to-meet-sovereignty-demands.html

To Boost AI Adoption, CIOs Lean on Training, Guardrails

CIOs focus on AI adoption balancing expansion and employee training. Many lack AI governance policies, with training access lagging. Executives emphasize clear use cases, tailored training, and risk management. Jabil's AI Council guides deployment; Deloitte integrates AI training in leadership programs, and Detroit's CIO prioritizes accuracy vigilance. Effective AI tools enhance productivity, shifting mundane tasks to automation.

https://www.hrdive.com/news/CIO-AI-adoption-jabil-deloitte-city-detroit/804735/

The AI Penetration Testing Lie: Why Human Expertise Remains Irreplaceable

AI cannot replace human expertise in penetration testing; it only automates tasks without the creativity needed for real security. Compliance testing has degraded to automated scans, misleading businesses about their security. AI tools are similar to vulnerability scanners and lack human adaptability and innovation. The best approach is a hybrid model, using AI for repetitive tasks but relying on humans for genuine threat emulation. Penetration testing is a crucial investment for security, promising significant ROI by preventing costly breaches.

https://aijourn.com/the-ai-penetration-testing-lie-why-human-expertise-remains-irreplaceable/

To Maximize Their Influence, CISOs Need Diverse Skills

CISOs must possess diverse skills to influence organizational strategy by effectively addressing cybersecurity as a business issue. Key requirements include understanding security technology, aligning cybersecurity with business goals, and communicating risks clearly to stakeholders. Modern CISOs need leadership skills to engage all employees in security practices and a risk-centric mindset to prioritize vulnerabilities. With increased cybersecurity threats, corporate executives are more receptive to CISOs, marking a significant shift in their role from solely tech leaders to strategic business partners.

https://www.techtarget.com/searchsecurity/tip/To-maximize-their-influence-CISOs-need-diverse-skills

Scroll to Top