FIELD NOTES ✦ MORPHISEC MOVES THE TARGET ✦ 7,000+ ORGANIZATIONS ✦ 9 MILLION+ ENDPOINTS ✦ SECURITY BEFORE EXECUTION ✦
Company profile / Cybersecurity

The Security Company That Moves the Target

Morphisec changes the memory an attacker expects to find. Its bet is that the best time to stop ransomware is before the first malicious instruction lands.

inXf

There is an old trick in combat: move the target. It is less glamorous than a heroic interception, but it has the advantage of making the first shot miss. Morphisec, a cybersecurity company founded in 2014, took that idea into the memory of a computer. When an application loads, its software changes the structures an attacker expects to find. The point is not to guess which piece of malware will arrive. It is to make a familiar route into a machine suddenly unfamiliar.

In four lines
  • Morphisec protects endpoints and servers with automated moving target defense.
  • It sells to organizations that need ransomware protection without replacing their existing EDR.
  • Its Anti-Ransomware Assurance Suite adds exposure, infiltration and impact controls.
  • The company reports more than 7,000 organizations and 9 million protected endpoints worldwide.

Cybersecurity has long rewarded the person who can recognize a villain. Antivirus looks for known signatures; detection and response systems look for suspicious behavior. Both are useful. Both have a timing problem when an exploit is new, fileless or clever enough to appear ordinary until it runs. Morphisec's wager is that a machine can frustrate the attempt before the security team has a name for it.

A door that changes its address

The company's method is called automated moving target defense, or AMTD. As programs enter memory, Morphisec says it relocates and transforms parts of their runtime structure. An exploit built around an expected address or process layout may then point at the wrong place. Morphisec calls this “memory morphing.” The phrase is theatrical; the engineering is practical. It changes the conditions under which some attacks must execute.

That matters most during the awkward interval between a vulnerability becoming useful to criminals and a patch reaching every machine. It also matters on old systems whose owners cannot easily reboot or upgrade them. The product is installed as a lightweight agent, managed through a console and sold as a layer alongside endpoint detection and response tools. Morphisec says about 99% of its customers already have EDR. That is a revealing statistic: the company is selling a missing action in an existing stack, not a new stack in a box.

That three-part sequence is the company's Anti-Ransomware Assurance Suite, launched in 2024 with input from customers and design partners. Adaptive Exposure Management helps teams decide which weaknesses to address first. Infiltration Protection uses moving target defense at the execution stage. Impact Protection aims to stop encryption and other destructive steps. Later additions addressed exfiltration, the data theft that often gives ransomware gangs a second bargaining chip.

Morphisec diagram showing protections before, during and after ransomware execution
Product map / MorphisecThe attack has a beginning, middle and expensive end. Morphisec tries to interfere at all three.

The customer who had no spare analyst

Tom Merkle, then CIO at Houston Eye Associates, had a very ordinary cybersecurity problem: too much responsibility and too few people. The practice already used several security vendors. During the pandemic, phishing attempts rose while revenue tightened. In a Morphisec case study, Merkle described losing sleep over the possibility of a successful ransomware attack. He wanted protection against threats that signatures might not yet recognize, without adding a stream of alerts for a small team to investigate.

“I was losing a lot of sleep wondering when we were going to get hammered.”Tom Merkle / Houston Eye Associates

Merkle's case for buying the tool was hardly the usual blank-check technology pitch. He asked his board to approve Morphisec within an existing IT budget and said he would not ask for another cent. The company says Houston Eye Associates later reduced overall cybersecurity costs by 40%. That figure belongs to one customer account, not a general promise. Still, the reasoning is transferable: identify the gap in an already layered defense, then ask whether closing it saves more staff time and incident cost than the software consumes.

Morphisec also names Merrick Bank, TruGreen and healthcare systems among its users. The work differs by buyer. A bank may care about keeping payments available and satisfying auditors. A hospital worries that an encrypted computer can interrupt care. A managed security provider cares about the cost of every alert across many tenants. Morphisec's pitch travels because each of those buyers can put a price on a machine that stays usable.

7,000+Organizations protected, company reported
9M+Endpoints and workloads, company reported
$31MSeries C raised in 2021

A research idea meets the purchasing department

Morphisec began around security research associated with Ben-Gurion University in Beer-Sheva, Israel. Its founders include Ronen Yehoshua, Dudu Mimran, Mordechai Guri and Kobi Katzir; Katzir remains Head of Product. The company raised a $7 million Series A in 2015. Six years later, JVP led a $31 million round with Orange and Deutsche Telekom Capital Partners participating. Morphisec said it would use the money to hire in the United States and Israel. It now lists New York as its corporate headquarters and Beer-Sheva as its R&D center.

Ronen Yehoshua, Morphisec co-founder and former CEO
Early days / Ronen YehoshuaA company that sells uncertainty to attackers had to explain certainty to buyers. Yehoshua helped turn the lab idea into a business.

The cost to a buyer is less neatly documented: Morphisec does not publish a simple list price. Its sales process runs through demos and quotes, with subscriptions sold directly and through partners. Integrations with Microsoft Defender and Acronis help it sit inside a familiar operating environment. There is a certain humility in that positioning. Security leaders rarely retire an endpoint platform because a newcomer has an elegant theory. They may add a tool that handles a threat their current platform can miss.

The company's newer products keep testing that theory. In 2025 it added Exfiltration Prevention. In 2026 it announced Adaptive AI Defense and AI Usage Control, which aims to find and govern local AI tools, agents and connectors on employee devices. These are newer claims than the original memory-defense mechanism. Their common thread is a wish to act at the endpoint, close to the moment software does something consequential.

The useful question to steal

Morphisec is strongest as an example of precise positioning. It did not invent ransomware, and it cannot make patching, backups or identity controls irrelevant. Its distinctive claim is narrower: change the runtime terrain, stop certain attacks before execution, and reduce the cleanup that follows. That distinction gives a security buyer a practical test. Which attacks reach the machine after our existing controls? Where do we still depend on an analyst noticing in time? What would we measure in a pilot: blocked execution, false alerts, machine performance, or recovery time?

The answer will differ for a hospital with aging Windows machines, a bank with a large security team and a small company already comfortable with its existing tools. The broader lesson is not to collect protective products like charms. It is to find the interval where a threat can still act, and ask whether the target can be moved before the attacker gets there.