Breaking: Native emerges with $42M to turn cloud policy into active defense Seattle / Tel Aviv · AWS, Azure, Google Cloud, OCI Breaking: Native emerges with $42M to turn cloud policy into active defense Seattle / Tel Aviv · AWS, Azure, Google Cloud, OCI

Founder Profile · Cloud Security

Amit Megiddo Wants Cloud Security to Stop Watching and Start Building

After years building Amazon GuardDuty and listening to security teams describe the same operational gap, Amit Megiddo is betting that the next era of cloud defense will be enforced in the architecture - before another alert becomes another ticket.

The security industry has spent years perfecting the art of the concerned notification. A cloud resource drifts out of policy. A dashboard lights up. A ticket is filed. Somewhere, a well-meaning engineer inherits a new chore from a machine that has completed its own job by announcing that work remains. Amit Megiddo has lived inside this loop at uncommon scale. He helped lead Amazon GuardDuty from its early years into a threat-detection service used by tens of thousands of customers. What stayed with him was not a shortage of controls. It was the distance between owning those controls and making them work, continuously, across a living enterprise.

That distance is the founding subject of Native, the company Megiddo started in 2024 with Gal Ordo and Eyal Faingold. Native emerged from stealth in March 2026 with $42 million in announced funding, including a $31 million Series A led by Ballistic Ventures. Its proposed unit of work is not another finding. A security team states an outcome, the software translates it into the built-in controls of AWS, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure, then simulates the effect before anything changes. If the policy survives contact with production, Native keeps it aligned as the environment evolves.

4major clouds addressed by one control plane
$42Mtotal funding announced at the 2026 launch
2018the year Megiddo began leading GuardDuty product work

The education of an operator

Megiddo’s route to Seattle’s cloud industry began in Israeli Military Intelligence, where he served for more than eleven years and moved through roles spanning external relations, intelligence production, communications research, planning and department leadership. In his final intelligence role, he led a group of computer scientists, data analysts and linguists working on high-priority national-security questions. The experience gave him a compact test for leadership: an officer’s performance was judged in the officer’s absence. The team had to function when authority was not hovering over it.

He later described the practical consequence on the CISO Series Podcast. Trust is not an ornament added after a process has been designed. It determines how much responsibility can sit near the work. At an early company, he said, the balance begins with trusting the people closest to him. It is a revealing preference for a founder working in cybersecurity, a field whose commercial vocabulary can make distrust sound like a feature request.

Harvard Business School followed from 2016 to 2018. During that period he also worked as a senior product manager intern in Amazon’s self-service advertising group. In 2018, he joined the GuardDuty product organization. The service continuously analyzes activity in AWS environments for suspicious behavior, but Megiddo’s public reflections on the product tend to celebrate discipline more than volume. When GuardDuty introduced its first critical-severity finding seven years after launch, he pointed to the long wait as evidence of a deliberately high bar. In a market prone to treating every flashing light as a fire, restraint was part of the product.

“Complexity is a vulnerability.”Amit Megiddo, CISO Series Podcast

The line works because it describes software and organizations at once. A control can be technically capable and operationally useless. A security policy can be perfectly written and quietly lost between the team that defines it and the team asked to implement it. A cloud provider can offer a formidable set of primitives while a customer still lacks the hours, expertise or confidence to assemble them safely. Complexity turns all three gaps into places where intent can leak away.

The slide no one could operate

At AWS, Megiddo sat with security leaders and practitioners from nearly every Fortune 500. The ritual included what he calls “the slide”: a dense grid of security services and controls, each box concealing its own APIs and configuration layers. It was impressive in the way a cockpit is impressive. It was also, as he later wrote, unreasonable to expect any customer to master in full. One customer supplied the plainest diagnosis: there were not enough hours in the day.

The controls were real. So were the manuals, scattered across documentation, videos, blog posts and institutional memory. Yet one cloud was difficult to operationalize and several clouds multiplied the translation. AWS, Azure, Google Cloud and OCI each express policy through their own architecture. The security team could define what should be true, but platform engineers still had to interpret that intent, test the implementation, negotiate exceptions and repeat the exercise when either the business or the provider changed.

Native is an attempt to make that translation a product. The team can express a requirement in plain language - sensitive data should not be exposed to the internet, for example - and map it into each provider’s native controls. Before deployment, the platform replays historical cloud activity against the proposed change to reveal which services and identities would be affected. Enforcement can then move through infrastructure-as-code pipelines or Native’s console, with rollback and drift tracking built in.

The simulation step matters because a technically correct policy can still be operationally disastrous. Security teams are often accused of slowing the business, but the deeper problem is uncertainty: nobody wants to approve a control that might stop production. Megiddo’s stated ambition is to make security a business enabler. Give the team enough foresight to act with precision and the conversation changes from whether a control is too risky to whether it can be introduced safely.

Native co-founders Eyal Faingold, Amit Megiddo and Gal Ordo together
Three cloud-security résumés, one stubborn question. Eyal Faingold, Amit Megiddo and Gal Ordo built Native around the gap between seeing a risk and preventing it. Photo: Native.

A founding trio with useful scars

The co-founders arrived with complementary views of the same machinery. Megiddo had led GuardDuty. Ordo had led AWS Security Hub, and tells a wonderfully unglamorous origin story: even as the product leader, installing his own product from scratch took four or five days. Faingold had served as vice president of cloud security products at Check Point after engineering leadership at Dome9. Between them, they had shipped products used by tens of thousands of enterprise customers. They also knew exactly where knowledgeable users could still get stuck.

Native remained in stealth while building its core research and development team and working with large enterprises. The initial $11 million seed round supported that period. By launch, the company said Fortune 100 customers were already using the platform in production. The $31 million Series A added Ballistic Ventures to a group that included General Catalyst, YL Ventures and Merlin Ventures; former Google Cloud CISO Phil Venables joined Native’s board.

The capital behind the control plane

Seed
$11M
Series A
$31M
Total
$42M

Announced funding at Native’s March 2026 emergence from stealth.

There is a personal connection inside the cap table, too. YL Ventures co-founder Ofer Schreiber says he and Megiddo have been friends for more than twenty years. Schreiber was present for the early conversations while Native was still an idea, first as a friend and later as an investor. In venture-backed mythology, capital often arrives as a dramatic verdict. Here it reads more like a long conversation acquiring paperwork.

Machines have shortened the afternoon

Megiddo’s case for acting now rests on three converging pressures: AI accelerates both attackers and infrastructure change; multi-cloud has become a deliberate enterprise strategy; and specialists who can master every provider remain scarce. AI agents can write code, provision resources and alter configurations without waiting for a weekly review. A security workflow designed around a person noticing, routing and approving every deviation begins to look like a sundial in a server room.

His answer is architectural. Detection remains necessary, but he does not want it carrying the whole strategy. In this view, security should define the permissible shape of the environment and enforce that shape through controls already native to the platform. The system needs to adapt as services change, exceptions appear and business requirements move. An alert becomes the last line of defense rather than the opening move.

“The easy part is turning controls on. The hard part is making sure they consistently deliver security results.”Amit Megiddo, The Security Strategist

This is less a rejection of dashboards than a demotion. Visibility tells a team what exists. It does not make the desired state durable. Megiddo calls the space between policy and dependable action the execution gap. The phrase is usefully free of menace. Most recurring misconfigurations are not acts of cinematic sabotage. They are the residue of competing priorities, complicated systems and manual handoffs. Fixing them permanently is a design problem.

At Black Hat USA in August, Native’s demonstration followed the same quiet sequence: map the perimeter, simulate a proposed control, enforce it in the providers’ own primitives. The booth promised coffee, bagels and “no pitch theater.” That last detail suits Megiddo’s public voice. He writes in declarative sentences, thanks collaborators by name and ends big announcements without lingering for applause. His launch post closed with: “This is step one. Back to work.”

The wager ahead is demanding. Translating intent across four giant, continuously changing cloud platforms is not a one-time integration project. Enterprises will judge the system by whether it avoids breaking production, handles exceptions and earns the authority to make changes. Trust, the old leadership lesson, returns as the central product challenge. A control plane cannot merely know what to do. Teams must be willing to let it do the work.

Megiddo’s career has moved from intelligence operations to business school, from a global cloud platform to a startup split between Seattle and Tel Aviv. The scale and setting keep changing. The question underneath has remained remarkably stable: how do capable people operate a complex system without requiring a hero at every junction? Native is his latest answer. Give the system a clear intent, put guardrails close to the work, and make success possible even when the officer is absent.