The most dangerous person in a computer system may look perfectly legitimate. They have the right username. Their second factor passed. The token is valid. The policy engine gives a courteous nod and the digital turnstile clicks open. Only then does the trouble begin. This is the small, awkward plot twist around which Abhay Kulkarni built WideField Security: a credential can be authentic while the behavior attached to it is anything but.
Kulkarni had spent a career learning what happens when software meets scale. He worked through the engineering ranks at VERITAS and Symantec, eventually leading Norton Cloud engineering. The estate handled many petabytes of data for more than 40 million users. Later, as vice president of engineering at Netskope, he helped build cloud security while enterprises were scattering their work across apps, devices, and networks. The perimeter was becoming less a wall than a fond memory.
Then came Cisco. Kulkarni led the platform beneath Webex Teams, Meetings, and Devices before taking responsibility for the Webex App business. The assignment joined engineering, product management, support, and customer success. During the pandemic, online meetings changed overnight from useful workplace machinery into civic plumbing. In his farewell note, Kulkarni remembered scaling the service to levels the team had never seen. The sentence is modest. The operational implication is not.
A return disguised as a departure
On his last official day at Cisco Webex in March 2023, Kulkarni published the sort of leaving note that normally comes wrapped in agreeable fog. His was unusually specific. He thanked the team and the leaders who had helped him. Then he wrote, “I am now going back to the place I belong - information security.” He was teaming up with a friend and former colleague to rethink how breaches were handled. More, he promised, would follow.
The colleague was Kartik Kumar, a founding architect at Netskope. Their reunion carried an advantage that cannot be manufactured at an off-site: they had already watched enterprise security migrate into cloud and SaaS from the inside. Both knew the established tool kit. Single sign-on could centralize access. Multifactor authentication could make stolen passwords less useful. Governance could review privileges. Yet a thief with a captured session or OAuth token might bypass the drama of breaking in. Why pick the lock when someone has left a working badge on the pavement?
“Identity security is the biggest unsolved problem in cybersecurity.”Abhay Kulkarni, on founding WideField
Kulkarni and Kumar founded WideField in 2023. They did not immediately pretend that every inch of the map was obvious. Kulkarni later called the route an “idea maze”: assumptions tested, punches taken, thinking revised. That phrase reveals more than the usual account of immaculate founder vision. WideField emerged from repeated conversations with security practitioners, early customers, advisors, and investors. The product thesis became sharper through contact.
Its central question stayed stubbornly plain. What is an identity doing after authentication? Not only a human identity, either. A service account can call an API all night without ever looking tired. A machine credential can outlive its owner. An AI agent can possess approved access, move at machine speed, and take an unsafe action while every login control remains technically satisfied.
The badge is only the prologue
Kulkarni has used an airport to make the idea tangible. Traditional identity tools inspect the passport at the checkpoint. Once the traveler is airside, observation thins out. In an enterprise, the equivalent traveler moves through apps, clouds, sessions, privileges, and data. WideField wanted the itinerary, not merely the boarding pass.
The company's name borrowed from the wide-field telescope: the point was to capture the whole sky instead of fixing on one star. Its platform connected identity attributes, privileges, credentials, sessions, and activity across cloud, SaaS, and on-premises systems. At rest, it mapped accounts and risky relationships. In motion, it watched authentication journeys and policy behavior. In use, it analyzed sessions and calls for hijacking, token theft, privilege abuse, and departures from familiar patterns.
This was less a rejection of authentication than an insistence that authentication deserved a sequel. A well-run front door still matters. But a mature defense also needs to answer who acted, through which credential, inside what session, and with what possible reach. Context turns a pile of logs into a narrative an analyst can investigate.
The approach also carried an old Kulkarni operating principle into a new product. In 2015, while discussing Netskope's DevOps practice, he argued for developer responsibility in running, monitoring, and scaling services. Builders should remain close to the consequences of what they build. WideField applied a related instinct to identity: access should remain connected to the activity it enables.
The company met its moment
WideField formally stepped into public view in 2025. At RSA Conference, the team demonstrated identity detections across users, sessions, and applications. That October, it announced an $11.3 million Series A led by Crosspoint Capital, with Engineering Capital participating. The money was meant for product development and go-to-market expansion. The more revealing part of Kulkarni's announcement was personal. He praised early believers, customers, and teammates who had left comfortable roles to join the mission. He singled out Kumar's drive and clarity.
The timing was useful. Companies were adding non-human identities faster than many could inventory them. AI agents gave the argument a sharper edge. An agent may be authorized and still act in the wrong context. It may inherit too much access, follow a malicious instruction, or carry an action across systems faster than a human reviewer can catch it. Identity becomes a question of authority, session, action, and blast radius all at once.
- Kulkarni leaves Cisco Webex and says he is returning to information security.
- He and Kartik Kumar found WideField Security.
- WideField brings live identity-security demonstrations to RSA Conference.
- The company announces an $11.3 million Series A.
- Cisco announces its intent to acquire WideField.
- Cisco completes the acquisition.
Cisco announced its plan to acquire WideField on June 18, 2026. The proposed destination made architectural sense: identity and session telemetry would feed Cisco Identity Intelligence and Splunk's security products. WideField could help normalize signals from human, machine, and AI-agent activity so security systems could reason from a cleaner, more deterministic record. Cisco completed the deal on July 31. The price was not disclosed.
The transaction made Kulkarni's path into a neat loop, although neat loops are generally visible only after the walking is finished. He had left Cisco to return to security. He came back with a company built from lessons accumulated at Symantec, Netskope, Webex, and in rooms with customers who could describe exactly where their controls went dim.
An operator's version of ambition
Kulkarni's public language is more builderly than theatrical. He calls himself a builder at heart. He writes about teams, technical constraints, and customer problems. His Webex archive moves easily from platform architecture to mute controls and gestures. Even WideField's grand idea is delivered through practical nouns: identities, credentials, sessions, activity, response.
That vocabulary fits a career spent around systems that must continue working while the world piles on. Scale teaches a particular humility. The service does not care how persuasive its creator sounds. It cares whether the dependencies hold, whether the data can be traced, and whether someone takes responsibility at 2 a.m. The same temperament appears in WideField's insistence on session lineage and reproducible telemetry. Security analysts need evidence they can follow, not an oracle clearing its throat.
A valid credential answers who may enter. A useful security system keeps asking what happens next.The operating idea behind WideField
The acquisition ends one version of the startup story. WideField stopped selling new standalone licenses after the deal closed, while existing customers continued under their agreements. Its technology began the slower, less photogenic work of integration. The identity context is intended to strengthen Splunk's agentic security operations and Cisco's broader identity intelligence.
For Kulkarni, the more interesting continuity may be the one he identified before the company had a public name. He wanted to return to hard security problems. WideField found one hiding in plain sight, just beyond a successful login, where a perfectly valid identity can begin doing perfectly alarming things. It is a problem made larger by every new cloud service, machine account, and autonomous agent joining the workplace. The badge still matters. But the story starts when the door opens.