The pitch takes about one sentence to land, and it makes people uncomfortable, which is the point. Adaptive Security wants to attack your employees. It will study the public trail your staff leave online, clone an executive's voice, write a text message that reads exactly like a panicked vendor, and send it - all before a real criminal does the same thing. The company that does this is not a rogue operation. It is a New York cybersecurity firm that raised $146.5 million in 2025 and counts PayPal, Bose, and the NHL among more than 500 enterprise customers.
The logic is straightforward once you get past the discomfort. Generative AI has made social engineering cheap, fast, and disturbingly convincing. A voice that once took a studio to fake now takes a few seconds of audio. An email that once had telltale typos now reads like it came from your own CFO. Adaptive's bet is that you cannot lecture people out of falling for that. You have to rehearse them against it - using the same tools the attacker would.
01 / What it actually doesReconnaissance, weaponized - politely
Most security-awareness training is a chore: an annual video, a canned phishing email with an obvious typo, a completion checkbox. Adaptive Security threw that model out. Its platform starts where a real attacker starts - with open-source intelligence. It scans the public data a criminal would collect on each employee: job title, reporting lines, recent projects, vendor names, LinkedIn activity, headshots, even voice recordings pulled from public talks. The company says it evaluates more than 1,000 public data points per person.
From that reconnaissance it builds a simulation the target has no obvious reason to doubt. Not a generic "your password expired" template - a scenario tuned to who they are and who they trust. Then it runs the drill across the channels attackers actually use.
When an employee fails a drill, it is not filed away as a statistic. The platform lowers that person's risk score, can restrict access, and delivers targeted training tied to exactly the exposure they showed. Training content runs in 39-plus languages with accessibility controls. The result is less a course and more a live readiness metric for the human layer of a company.
Social engineering accounts for over 95% of successful cyber breaches. Adaptive's argument is that the defense has to start there too.
From Adaptive Security's Series B announcement02 / How the loop runsFrom public data to a retrained employee
Strip away the branding and the product is a closed loop, run continuously rather than once a year.
Gather
Scan 1,000+ public data points per employee - the same OSINT an attacker would use.
Simulate
Generate a personalized attack across email, SMS, voice, or deepfake video.
Score
Measure who engages and adjust a live human risk score - not a completion rate.
Train
Deliver targeted content tied to the exact weakness the drill revealed.
03 / Who is behind itThe Attentive team, doing it again
Adaptive Security was founded in 2024 by Brian Long and Andrew Jones - not first-time founders, and that matters to the story. The two previously co-founded Attentive, the marketing platform they grew to more than 8,000 customers and $500 million-plus in annual revenue. Before that they built TapCommerce, a mobile advertising company they sold to Twitter, where both went on to work. Long is CEO; Jones is Chief Product Officer.
They could have retired. Instead they picked a problem that rhymes with their old one: Attentive was about reaching people at scale through their phones. The dark version of that same capability - reaching people at scale to deceive them - is exactly what generative AI unlocked for criminals. The founders knew the go-to-market playbook and the channel. They pointed it at defense.
04 / The moneyOpenAI's first security bet - and NVIDIA's too
The funding history is unusual for how fast it moved and who showed up. In April 2025, the OpenAI Startup Fund and Andreessen Horowitz led a $43 million Series A - described as OpenAI's first and only cybersecurity investment. In December 2025, Bain Capital Ventures led an $81 million Series B, with NVIDIA's NVentures joining alongside the OpenAI fund, a16z, Abstract Ventures, Capital One Ventures, and Citi Ventures. Total raised: $146.5 million.
Getting both the OpenAI Startup Fund and NVIDIA's venture arm onto one cap table is rare - the two rarely land on the same deal. It signals a shared read: that AI-driven social engineering is a defining breach vector, and that the defense will be built with AI, not against it.
05 / Who buys itEnterprises that got the wake-up call
In under a year of public launch, Adaptive signed more than 500 enterprise customers. The named ones span industries where impersonation is expensive:
The buyer is usually a CISO or a security-awareness lead watching a specific number climb: the share of CISOs reporting sophisticated deepfake attacks rose from roughly 10% to over 50% in 18 months. For those teams, the old annual-video model stopped feeling like coverage. Adaptive sells against that gap.
06 / Where it sitsNext-gen versus the incumbents
Security-awareness training is not a new category. Incumbents like KnowBe4, Proofpoint, and Cofense have sold phishing simulation and training for years, and challengers like Hoxhunt have pushed on personalization. Adaptive's wedge is the part that is hardest to fake with a template library: AI-generated, multi-channel simulation that includes deepfake voice and video, built on OSINT personalization rather than canned scenarios. The competitive question is whether that realism stays a durable edge as the incumbents add their own AI features - and whether enterprises are comfortable, long term, deepfaking their own executives to train their own staff.
The product's job is to fool your own employees - convincingly - so that the real attack, when it comes, does not.
The uncomfortable core of the model07 / What you can take from itThe copyable idea
You do not need Adaptive's platform to use its central move. The idea any security team can borrow is to stop treating awareness as content and start treating it as rehearsal - run the attack you are afraid of, on your own people, before someone else does, and measure who is ready rather than who finished the video. Adaptive productized that instinct and pointed it at the channels AI made dangerous. The limit worth naming honestly: this works when leadership will authorize realistic, sometimes unsettling simulations of their own executives and staff. Where that authorization is missing, the drills soften into the same box-ticking they were meant to replace.
Not everything Adaptive does is enterprise-priced, either. In late 2025 it launched free training to help protect older adults - a group hit hardest by AI voice scams - from the same attacks its paying customers rehearse against.