Putting a price tag on the cyberattack that hasn't happened yet - and telling you which fix is worth paying for.
Most cybersecurity tools answer one question: are we vulnerable? DeNexus was built around a harder one - what would it actually cost us? The Boston-based company quantifies the financial impact of cyber threats to operational technology (OT): the industrial control systems that run power grids, factories, pipelines, data centers and transportation networks. These are the systems where a breach is measured not in leaked records but in halted turbines, stalled production lines and regulatory fines.
Founded in 2019 by Jose M. Seara, DeNexus sits at an unusual intersection - between cybersecurity, actuarial science and industrial engineering. Its flagship platform, DeRISK, predicts where breaches are likely to occur in OT/ICS environments, runs millions of simulations to calculate their probability and dollar impact, and then ranks mitigation projects by financial return. In doing so it hands two people who rarely agree - the CISO and the CFO - the same number to argue over.
Industrial systems run on operational technology that, in many cases, was designed decades before the internet was a security concern. It is expensive to replace, hard to patch, and increasingly connected. Executives know it is a risk. Almost none can say how big a risk - in dollars.
Scanners produce endless lists of flaws ranked by severity score. That tells you what is broken, not which broken thing will actually cost you money.
Security teams speak in threats and controls; finance speaks in dollars and ROI. Without a shared language, cyber budgets get set by fear or by guesswork.
Insurers have struggled to price industrial cyber risk because the underlying data - OT threats, downtime costs - was scarce and unstandardized.
DeRISK is described by the company as a self-adaptive, cloud-based platform that combines internal and external data with AI, machine learning and large-scale simulation. The pipeline turns raw exposure into decisions a board can make.
Map the OT/ICS environment and where breaches are most likely to occur.
Run millions of simulations to estimate likelihood and financial impact.
Rank mitigation projects by return, not just severity score.
Compare posture to peers and optimize insurance / risk transfer.
Illustrative. DeNexus models economic impact across operational downtime, regulatory penalties, reputational damage and recovery timelines. Bar widths are schematic, not measured values.
DeRISK is the world's first self-adaptive, cloud-based technology that predicts where cyber breaches are likely to occur in OT/ICS environments, quantifies their impact on business, and guides risk stakeholders toward the best mitigation paths.
Cyber Risk Quantification - the core engine that predicts likely breaches, prices their business impact, and benchmarks risk posture against industry peers.
Quantified Vulnerability Management - translates technical vulnerabilities into business-risk visibility and prioritizes fixes by financial ROI rather than raw severity.
Agentic-AI underwriting platform for industrial cyber insurance. Five specialist AI agents, coordinated by an orchestrator, produce an actuarially grounded assessment in 10-20 minutes - compliant across US/NAIC, UK/FCA, Lloyd's and EU/EIOPA.
An aggregated OT/ICS threat-intelligence foundation that feeds the models, plus advisory and managed services to operationalize cyber risk quantification and risk-transfer strategy.
DeNexus says Global 1000 companies across three continents have used its platform to reduce cyber risk. Its customers cluster in the industries where OT failure is most expensive - and its users span the org chart, from the server room to the boardroom to the insurance desk.
Data centers, power generation, energy transmission & distribution, manufacturing and transportation infrastructure.
CISOs, OT facility managers, risk managers, executives and boards of directors seeking a defensible risk number.
Underwriters and carriers using DeNexus data - and now the UWA platform - to price and transfer industrial cyber risk.
The market has plenty of OT-security and risk-scoring vendors - Dragos, Claroty and Nozomi on the detection side, Axio, Safe Security and BitSight on quantification. DeNexus's distinction is its narrow, deliberate focus: the financial quantification of OT/ICS risk, carried all the way through to insurance underwriting.
Output is financial impact and ROI-ranked mitigation, not a color-coded risk rating.
Purpose-built for operational technology and cyber-physical systems, not retrofitted from IT security.
The same models that guide a CISO can underwrite a policy - a loop few competitors close.
Boston Consulting Group placed most insurers at "Horizon 0-1" on agentic AI. DeNexus says its UWA platform deploys at Horizon 2-3 on day one.
Jose M. Seara did not come from cybersecurity. He built and ran critical-infrastructure companies in the energy sector across Europe and North America - and kept running into the same wall: no one could tell him what a cyberattack on his operations would actually cost, or how to insure against it. That unanswered question became DeNexus.
Seara remains Founder and CEO. The company is headquartered in Boston with its engineering base in Madrid, and describes an international footprint spanning Spain, Switzerland, the UK, Europe and the Middle East. It highlights a workforce that is roughly 30% women and frames its mission around protecting the infrastructure society quietly depends on.
We empower CISOs, risk managers, executives, boards and insurers to grasp the financial impact of cyber incidents and optimize cybersecurity programs.
DeNexus has raised about $32.8M to date. The tell is not the total but the roster: an insurer and a physical-security giant chose to invest in the risk they most want to price.
| Round | Amount | Date | Lead / Investors |
|---|---|---|---|
| Pre-seed / Seed | $15.3M | 2019-2023 | HCS Capital & strategic angels |
| Series A | $17.5M | Oct 2024 | Punja Global Ventures (lead), AXA XL, Prosegur Tech Ventures, HCS Capital |
| Total | $32.8M | - | Rimmo Jolly (Punja) joined board; Libby Benet (AXA XL) board observer |
Jose Seara launches the company to measure the financial impact of cyber risk in OT environments.
The self-adaptive risk model and OT/ICS threat-intelligence foundation are built out.
Early funding matures the CRQ platform ahead of an institutional raise.
Punja Global Ventures leads with AXA XL and Prosegur; DeNexus extends into data-center physical security.
The company debuts what it calls the first agentic-AI underwriting platform for industrial cyber insurance.