A new piece of enterprise software once arrived with a contract, a rollout plan, and enough meetings to qualify as a minor diplomatic summit. Now it arrives through a signup form. Someone in sales needs a prospecting tool. Someone in design finds a clever image app. A developer tries an AI assistant before lunch. By the time the security team learns the product's name, it may already contain company data, a dozen user identities, and a credit-card charge no one recognizes.
Lior Yaari built Grip Security around that lag. His point is not that employees have become reckless. It is that the old model of corporate computing - IT chooses, IT installs, IT controls - has been overtaken by ordinary behavior. Software as a service made the browser a procurement department. Artificial intelligence has made the department hyperactive.
“Every employee can essentially be their own CIO,” Yaari has said. It is a neat line because it sounds empowering until you picture a thousand tiny CIOs, each maintaining a private application portfolio and none particularly interested in the audit.
The useful sort of detour
Yaari did not reach this problem by following a tidy founder's syllabus. He spent six years as an officer in Israel's military cyber corps and commanded cyber training in Unit 8200. Training is an underrated preparation for company-building: it requires turning expert instinct into systems other people can use. A brilliant operator may solve a problem once. A trainer has to make the solution repeatable.
After military service, his attention moved into machines with wheels. At CYMOTIVE Technologies, he researched vulnerabilities in vehicle electronic control units and studied modern automotive attack surfaces. He also founded Imperium Security, advising on secure development for embedded devices and teaching the subject at security conferences. In 2019, he spoke internationally about connected-car risk while completing a computer science degree, magna cum laude, at the Open University of Israel.
Cars and cloud apps may seem like distant neighborhoods. The shared lesson is less exotic: a system becomes dangerous where its parts connect. The glossy interface is rarely the whole attack surface. There are identities, integrations, forgotten privileges, unmanaged components, and human shortcuts underneath.
The investor becomes the pitch
In April 2020, Yaari joined YL Ventures as chief technology officer. The cybersecurity-focused venture firm put him close to founders, technical research, investment decisions, and a wide network of security executives. He evaluated ideas and helped entrepreneurs test whether a technical insight could survive contact with an actual buyer.
He later described the job as developing an internal seismometer for industry pain: rapid meetings with specialists and customers, market mapping, and the search for a point where technology and business finally agree. The seismometer kept twitching around SaaS. Enterprises were adopting more cloud applications while the tools designed to find and secure them saw only fractions of the picture. The official inventory had become a work of corporate fiction - carefully maintained, professionally formatted, and wrong.
“In a world where data is everywhere and accessed from anywhere, the value of legacy security controls have eroded, and identity has emerged as the primary control point for cybersecurity.”Lior Yaari
At some point, the investor's observation became the founder's obligation. Yaari formed Grip with Idan Fast and Alon Shenkler, two colleagues from military intelligence. The origin carries a pleasing bit of prophecy. Soldiers who served under the three used to joke that their commanders would start a company together after leaving. Years later, after Grip had done exactly that, the founders hired one of those former soldiers. Yaari messaged to say how exciting it was. The reply: he could not believe the old joke had become real.
Startups prefer the mythology of the solitary flash. Grip's beginning looks more like accumulated trust: three people who had already watched one another make decisions under pressure, now applying that familiarity to a problem without a reliable map.
From browser tab to governed application
A control plane, not a scolding
Grip launched publicly in 2021 with a $6 million seed round led by Yaari's former employer. Its approach was designed to discover SaaS use across an organization, attach that use to real identities, assess the risk, and automate the dreary but essential cleanup. The language has evolved - SaaS security control plane, identity risk management, posture management, AI security - but the behavioral premise remains steady.
Shadow software is generally not introduced by a tiny criminal mastermind in accounting. It is chosen by somebody trying to get work done. Blanket bans punish the instinct a business usually claims to value: initiative. Yaari's preferred architecture accepts decentralized adoption and tries to pair it with centralized policy and context-aware enforcement. Keep the useful speed. Remove the unnecessary blindness.
This is also why identity matters more than the office network. A cloud application can be reached from home, a phone, a contractor's laptop, or an airport lounge. The durable link is the account: who created it, what it can reach, whether multifactor authentication protects it, and whether access disappeared when the user left.
The governance gap widens
The cost of being pleasantly surprised
Grip found demand quickly. Yaari has been unusually candid about the resulting mistake: he did not plan for enough success. Revenue quintupled over a few months, and the presales pipeline passed $10 million shortly after the product became generally available. Founders are expected to confess tasteful failures - hiring too slowly, caring too much - but this one contains a real operating problem. Demand is only flattering until it exceeds the organization built to serve it.
The company expanded, raised a $19 million Series A, and in August 2023 announced a $41 million Series B led by Third Point Ventures, with YL Ventures, Intel Capital, and The Syndicate Group participating. The round brought disclosed funding to $66 million. Yaari said the capital would accelerate product development and go-to-market work. The founder who had once evaluated hundreds of plans was now responsible for making his own plan elastic enough.
His stated leadership advice reflects that pressure. Do not try to do everything yourself. Hire leaders who are better within their disciplines, set clear expectations, and trust them. He also pays attention to a less formal instrument: the small talk inside a company. Everyday conversation, he argues, is a barometer of culture because habits harden quietly, long before they appear in a quarterly presentation.
Identity debt comes due
By 2024, the problem was mutating again. Generative AI tools gave employees a reason to test new services at startling speed, often by pasting in text, documents, or code. Yaari compared them with the old online PDF converters: convenient places to upload a file without a crisp idea of where its contents might go. The analogy is mundane, which is why it works. Corporate risk rarely announces itself with cinematic lighting. Sometimes it is just a useful box that says “upload.”
In 2025, Yaari began speaking publicly about “identity debt,” the residue of fast adoption: stale accounts, local passwords, missed single sign-on coverage, lingering permissions, and former employees who still exist somewhere in the SaaS estate. Like technical debt, it accumulates one reasonable shortcut at a time. Unlike technical debt, it may grant access to a stranger.
Grip has since broadened its product story to include SaaS configuration management, integrations with identity-governance platforms such as SailPoint, and controls aimed at shadow AI. In March 2026, Yaari published analysis about the shift from AI adoption to AI operations. In the summer, he welcomed an early Grip employee back as vice president of products, explicitly tying the role to a new generation of AI-security capabilities.
The useful thing about a map is not that it stops anyone from moving. It lets everyone see where movement has taken them.
The system as people actually use it
There is a general founder lesson hiding inside Yaari's specialized market. Organizations describe themselves through policies, architecture diagrams, and approved-tool lists. Reality lives in browser histories, expense reports, OAuth permissions, abandoned trials, and the shortcuts people invent on Wednesday afternoon. The distance between those two versions of a company is both a liability and a product opportunity.
Yaari's career has repeatedly occupied that distance. Military training translated expert behavior into repeatable practice. Automotive research looked beyond a vehicle's polished controls to the computers underneath. Venture investing tested whether ingenious technology met an urgent market. Grip applies the same instinct to modern work: observe the system as people actually use it, then design controls for that truth.
The aspiration is not a company in which nobody experiments. It is a company where experimentation does not leave an invisible estate of identities and data behind it. Security, in this formulation, should make curiosity safer rather than rarer.
The signup form has already won. Employees will keep choosing tools, AI will keep multiplying them, and the official inventory will keep aging by the hour. Yaari's wager is that the answer begins with humility: admit the perimeter has moved, follow the identities, and draw a better map.