Breaking profile Lumifi turns alert overload into managed response Scottsdale, Arizona 24/7 U.S.-based SOC ShieldVision inside

Company profile / Cybersecurity

Lumifi Sold Its Cybersecurity Engine - Then Bought It Back for $30 Million to Build a Bigger One

The Scottsdale company spent years proving that security tools are only as useful as the people watching them. Its second act is a buy-and-build wager that one automation layer can make a fragmented cyber stack behave like a single defense team.

Cybersecurity departments have a collecting problem. A company buys a tool to watch endpoints, another to inspect network traffic, one more to collect logs, and perhaps a fourth to guard cloud accounts. Each does its job. Together, they can produce a small weather system of alerts. The rain falls at 3 a.m., when the two people who understand the setup are asleep.

Lumifi sells the night shift, the connective tissue and the judgment call. From Scottsdale, Arizona, its U.S.-based security operations center monitors customer environments around the clock. Its analysts hunt threats, investigate alerts and coordinate response. ShieldVision, Lumifi's proprietary platform, pulls signals from the customer's existing SIEM, endpoint, network, cloud and identity products into repeatable investigation and response workflows.

That distinction matters. Lumifi is not asking every customer to throw away a carefully assembled security stack. Its pitch is that the stack needs an operator - and that the operator should arrive with software purpose-built for the messy handoffs between tools. In a market full of black boxes, Lumifi presents itself as the co-managed adult in the room.

$30MReported price to reacquire Datashield from ADT in 2022
600+Customers added through Netsurion and Critical Insight deals
24/7Monitoring by a U.S.-based security operations center

The company that came home

The story begins in 2009 with Datashield, founded by Michael Malone around log and packet capture. The company moved from monitoring and troubleshooting into real-time threat detection, then into what it describes as a high-touch managed detection and response service in 2013 - before MDR became a standard procurement acronym. In 2016, it began evolving ShieldVision to automate detections and allow analysts to hunt across customers.

ADT bought Datashield in 2017 and made it the core of ADT Cybersecurity. The logic was tidy: a company famous for monitoring doors and windows would also monitor networks. Malone joined ADT as a senior vice president. The sale validated the operation, but it did not end the story.

In 2022, Lumifi reacquired Datashield. Lumifi later described the purchase price as $30 million. HCAP Partners and BOK Financial participated in financing the deal, though their investment terms were not disclosed. The transaction reunited Malone with the platform and SOC that had taken years to build. It also supplied the machinery for a much more aggressive second act.

“The MDR market is too fragmented with too many point solutions.”Michael Malone, CEO and founder

What Lumifi actually does at 3 a.m.

A managed detection provider is paid to notice a credible problem and help contain it before it becomes an expensive one. Lumifi's analysts monitor the familiar visibility trio: logs in a SIEM, activity on endpoints and traffic across networks. Cloud and identity telemetry widen the field. Threat hunters look for behavior that automated rules miss; content engineers tune detections and write customer-specific rules; incident responders enter when an alert becomes an event.

ShieldVision is the coordinator. It correlates evidence, enriches alerts with threat intelligence, runs queries, records investigation steps, reduces duplicate noise and triggers approved responses. Its BackQuery feature can feed the output of one search into the next, chaining an investigation instead of making an analyst copy clues between windows. A 2024 product sheet counted more than 1,000 prebuilt searches, threat flows and reports.

Customers are not merely handed a red notification and wished good luck. Lumifi's published service description includes a client success manager, a technical account manager, escalation procedures and rules of engagement. That is the unflashy work that determines whether “response” means isolating a host or forwarding an email to someone who sees it after breakfast.

David Norlin, Lumifi's chief technology officer
THE HUMAN IN THE LOOP: CTO David Norlin helps run the part of cyber defense no dashboard can settle - what to do next.

The roll-up hiding inside the platform

Once Lumifi controlled its operating layer again, acquisitions arrived quickly. Castra, bought for a reported $14 million in 2023, added enterprise SIEM expertise around Exabeam. Netsurion followed in 2024, bringing more than 400 customers plus engineers, sales staff and account managers. Critical Insight added more than 200 customers later that year, many in healthcare and local government, as well as incident response, assessments, penetration testing, awareness training and virtual CISO work.

This is not acquisition as a scrapbook. The thesis is that customers, specialists and tool expertise become more valuable when moved onto common operating machinery. ShieldVision provides that machinery; the SOC supplies a shared labor pool; client success and account management make the combined service legible to buyers. By the Critical Insight announcement, Lumifi said the workforce had reached 125.

What cost what? The two prices Lumifi has publicly cited are $30 million for Datashield and $14 million for Castra. Terms for Netsurion and Critical Insight were not announced. A supplied company-data record estimates $4 million in total funding and $16.1 million in annual revenue, but public investment announcements leave the terms undisclosed. There is no responsible public valuation to print.

The first failure was the standard approach

Datashield's early diagnosis was blunt: preventative tools were not stopping every advanced threat, and the standard security approach was not designed for rapid response. The operational failure comes before the breach - too many alerts, too little context and too few experienced people available at all hours. Lumifi changed its service accordingly, adding real-time detection, managed response and then automation that could preserve an investigation as reusable logic.

The company's corporate loop suggests another lesson. Selling into a larger distribution machine was not the final form; five years after ADT bought Datashield, Lumifi paid to control the asset again. Public materials do not offer a melodramatic breakup story. What they do show is a changed strategy: own the platform, bolt specialist firms onto it, and let customers retain choice among security vendors.

The old headache

Point tools generate separate clues. Scarce analysts swivel between consoles. Generic rules create noise. The customer still owns the final response problem.

Lumifi's answer

Keep supported tools in place. Correlate their evidence. Give analysts reusable workflows. Agree on response authority before the incident.

Who buys it - and when it fits

Lumifi targets security-conscious midmarket and enterprise organizations, MSPs and regulated operators. Healthcare, local government, finance, manufacturing, energy and critical infrastructure recur across its materials. Publicly named customers include the Arizona Cardinals, the WM Phoenix Open and Barrett-Jackson. In 2026, an agreement with Vizient widened healthcare access, while a NetWitness partnership paired Lumifi's SOC with analytics for both information technology and operational technology environments.

The business model is recurring managed service revenue, described as monthly pricing, plus professional services and incident response. Standard prices are not published because cost depends on endpoints, log volume, integrations and service scope. The economic promise is straightforward: share specialist labor, threat content and automation across many customers so each customer avoids building a complete SOC alone.

That promise has limits. A buyer seeking a fully opaque “make security disappear” service may dislike the co-managed work and upfront rules of engagement. An organization with unsupported legacy tools may still face migration. A tiny company with few systems may find a simpler managed endpoint package more proportionate. And no provider can contain an incident quickly if the customer withholds access, delays decisions or has never agreed who may isolate a device.

What another operator can steal

  1. Build the connective layer first. Integration makes later products, partners and acquisitions easier to absorb.
  2. Automate the repeatable middle. Machines should gather, enrich and route evidence; humans should own ambiguous judgment.
  3. Sell the outcome and the operating ritual. Escalation rules, named account owners and response playbooks are product features.
  4. Acquire a capability, not a logo. Castra brought SIEM depth; Critical Insight brought healthcare and response expertise.
  5. Preserve customer choice where switching costs are high. “Works with your stack” can be a better wedge than “replace your stack.”

A market full of credible alternatives

Lumifi competes with specialists such as Arctic Wolf, Expel, Red Canary and eSentire; managed offerings from CrowdStrike, Sophos, Rapid7 and other platform vendors; MSP-focused services including Huntress and Blackpoint Cyber; and the internal SOC a large company may choose to build. Its point of difference is not the absence of rivals. It is the combination of a vendor-flexible stack, its own multi-tenant orchestration platform and a service team that extends from monitoring into consulting and incident response.

That combination now has visible momentum. Lumifi ranked No. 25 on the 2026 Inc. Regionals Southwest list, which reported 245 percent two-year growth. The number is evidence of expansion, not proof that every acquisition has integrated cleanly or every threat will be caught. Cybersecurity does not permit that kind of guarantee.

The more useful conclusion is smaller. Most companies do not lack security products. They lack the time, staff and shared context to turn a pile of products into a response. Lumifi built a business around operating the pile. Then it bought more expertise, more customers and more routes to market - all while betting that ShieldVision could keep the growing machine coherent. The bet works when software amplifies judgment. It fails when scale outruns the humans who must still make the call.