THE CLOUD FILE
APR 2024 · WIZ ACQUIRES GEM SECURITYDEC 2024 · GEM REBUILT INTO WIZ DEFENDSEP 2026 · THE INVESTIGATION CONTINUES

COMPANY / CLOUD SECURITY01 · THE INVESTIGATION

Gem Security found the intruder. Wiz bought the investigation.

Cloud security had become very good at listing what might go wrong. Gem built for the moment something actually did - and Wiz acquired it in a deal reportedly worth $350 million.

A stolen access key does not look like a burglar. It looks like a perfectly respectable request to a cloud service. The credentials are valid. The door opens. Somewhere, a security analyst receives an alert and must decide whether this is ordinary work or the beginning of a very expensive afternoon. Gem Security built its business around that decision.

  • The job: detect, investigate, and contain attacks across cloud environments.
  • The bet: security teams needed the relationships between events, identities, and resources.
  • The outcome: $34 million raised; acquired by Wiz in April 2024 for a reported $350 million.
  • The afterlife: rebuilt into Wiz Defend, rather than left as a separate dashboard.

The alarm is only the beginning

Cloud security had developed a respectable talent for inspection. Find a vulnerable machine. Spot an exposed database. Flag excessive permissions. These are useful answers to the question of what could go wrong. Gem concentrated on what was going wrong, right now. Its customer was the security operations center, where an unexplained alert is a task assigned to somebody who already has too many tasks.

The distinction matters because cloud attacks can cross boundaries that traditional tools examine separately. An identity touches a service; that service accesses data; another account appears in the trail. A workload alert may describe one part of the episode. The analyst needs to connect the parts before deciding what to stop. Gem’s proposition was to supply that cloud-specific context.

Three founders, one awkward question

Arie Zilberstein, Ron Konigsberg, and Ofir Brukner founded Gem in 2022. Zilberstein became CEO, Konigsberg CTO, and Brukner led product. Their background included Israeli intelligence and cybersecurity work. Zilberstein’s public account of the company’s beginnings centers on incident response: cloud customers were struggling to prepare, detect, and contain breaches with the tools and practices available to them.

What failed first in that account was the operating model. Infrastructure had moved into cloud services, while investigations still demanded laborious assembly of evidence. The founders saw an opportunity to package knowledge that otherwise arrived with an expert consultant. The result was an agentless platform launched publicly in February 2023, alongside an $11 million seed round led by Team8.

Gem Security’s three co-founders photographed together
Three founders, considerably more than three cloud problems. Gem’s co-founders brought security experience to the investigation desk. Photograph: Adi Lam.

“Where others end, we begin,” Zilberstein said at launch. The line neatly described the boundary Gem chose: assume prevention can fail, then equip the people who must respond. Its expertise appeared in detection rules, behavioral analytics, investigation context, and containment options. The intended buyer was an enterprise security team, rather than a consumer seeking protection for a laptop.

Repsol wanted the context

Repsol, the energy company, supplied a useful explanation of the appeal. In a public customer account, its cybersecurity architecture leader David Corral described how Gem helped distinguish normal behavior from unusual or suspicious activity. A warning acquires a different meaning when the analyst can see how the entities involved usually behave.

“The biggest differentiation for Gem is the context.”

David Corral · Repsol

A March 2024 Black Hat webinar outlined the machinery behind Repsol’s use: cloud logs collected into a data lake, events correlated across identity, compute, data, network, and control layers, and rules combined with behavioral analysis. Containment included deactivating access keys and isolating instances. Those are concrete actions, with consequences more useful than a red badge on a screen.

Gem’s public product listing also featured Allan Gray, OpenWeb, Booking.com, Bloomreach, Thirty Madison, and Kaltura. The company reported dozens of global customer organizations by September 2023. The range suggests a common operational problem across industries: businesses could have very different products while their analysts faced similar difficulties reconstructing cloud activity.

Gem also worked inside existing security routines. Its February 2024 IBM QRadar integration brought cloud detection and response information into a SIEM, the system many teams already used to gather and manage security events. The product lesson is refreshingly practical: an analyst should not have to abandon the investigation desk to obtain the missing evidence.

The price of joining the dots

In July 2023, Gem announced an investment involving more than 30 security chiefs through Silicon Valley CISO Investments. In September, it announced a $23 million Series A led by GGV Capital, with IBM Ventures, SVCI, Team8, and angel investors participating. Disclosed total funding reached $34 million. These are financing figures, rather than a measure of sales.

THREE NUMBERS, THREE DIFFERENT MEANINGS
$11mSeed announced
February 2023
$23mSeries A announced
September 2023
~$350mReported acquisition
April 2024

Wiz announced the acquisition on April 10, 2024. Press reports placed the consideration at about $350 million; the companies did not disclose official financial terms. That price bought a company and its capabilities. Enterprise software purchasing was a separate, sales-led conversation. A prospective customer today would approach Wiz for the successor offering, with scope and terms settled through its sales process.

The rationale was visible: Wiz wanted to bring live detection and response alongside cloud posture management. Its announcement emphasized customers’ frustration with tool sprawl and visibility gaps. Gem’s founders and staff joined Wiz. The public record supports a complementary product strategy; it offers no reason to invent a dramatic last-minute change of heart by the founders.

The investigation gets a bigger map

In December 2024, Wiz introduced the public preview of Wiz Defend. It explicitly described Defend as Gem rebuilt on the Wiz Security Graph. That distinction matters: the successor combined Gem’s approach with Wiz’s risk context and runtime sensor signals. The original agentless product and today’s broader Defend offering should not be treated as identical.

By September 2026, Wiz was publishing examples of automated investigations spanning AWS and GitHub, and expanding integration with Google Security Operations. Gem’s central idea remained recognizable: follow the relationships, explain the activity, and give responders a useful next step. Later AI features belong to that successor product, rather than being retroactively credited to Gem’s launch.

There is a lesson readers can copy without buying anything: work backward from containment. Identify the logs an investigation requires, check their coverage, and agree who can disable a compromised credential. The limits follow from the same logic. Missing telemetry leaves holes in the account; unclear response authority leaves an analyst waiting. Context earns its keep when somebody can act on it.