Risk is a gifted traveler. It slips through a supplier, borrows an employee's password, leaves a secret in public code, and turns up for sale in a forum most executives will never visit. Norman Menz has spent his career following it. The scenery has changed. The question has not: how do you notice the danger outside the walls before it becomes a crisis inside them?
This is the thread connecting three chapters of his working life. At Prevalent, which he co-founded in 2004, it was the risk carried by vendors and other third parties. At Delve Labs, where he became chief operating officer in 2019, it was the untidy business of deciding which software vulnerabilities deserved attention first. At Flare, the Montreal company he joined in 2021 and now leads, the field widens to exposed identities, leaked credentials, public code and criminal communities across the clear and dark web.
The categories sound technical. The instinct behind them is almost domestic: check the doors, know who has a key, and notice when a copy appears where it should not. Cybersecurity likes the drama of the intruder. Menz has kept returning to the less theatrical work that precedes one.
A business student enters the risk business
Menz studied business management at Seton Hall University from 1994 to 1998. His early years add a nice wrinkle: his entrepreneurial experiments in technology began before he became, in the university's parlance, a Pirate. He then developed information-security and IT-risk programs, work that exposed a recurring weakness. A company might secure its own systems with great care and still inherit the habits of every vendor, supplier and partner it trusted.
In 2004, Menz and Jonathan Dambrot founded Prevalent. Menz served as chief technology officer, translating that inherited risk into a product category. The timing mattered. Corporate networks were becoming ecosystems, and ecosystems are full of other people's decisions. In 2014, Prevalent took a $4 million growth investment. By that period, Menz was serving as president, executive officer and director. He would remain CTO through 2019 and continue as chairman.
One question, three operating chapters
Prevalent
Make third-party risk visible.
Delve Labs
Turn vulnerability data into priorities.
Flare
Find external exposure across the clear and dark web.
CEO
Scale the idea across markets and borders.
There is a modest but important difference between detecting a problem and helping someone decide what to do about it. Menz's career sits in that gap. He has worked in an industry capable of producing infinite alerts for security teams that possess only finite time. The practical question is never merely whether a threat exists. It is whether this threat, attached to this identity or asset, matters now.
“Detection without remediation is surveillance theater.”Norman Menz, on what threat intelligence should accomplish
Montreal, by way of New Jersey
When Menz joined Delve Labs as COO in 2019, he crossed into a distinctly Canadian cybersecurity orbit while remaining based around New York and New Jersey. Delve was headquartered in Montreal and used artificial intelligence to assess and prioritize vulnerabilities. His brief was unabashedly operational: help growth, build sales and marketing programs, and support new offices in New York City and San Francisco.
The role also sharpened a pattern. Prevalent organized risk in relationships. Delve organized risk in software flaws. Both demanded triage. A list is not intelligence simply because it is long, and a dashboard is not wisdom because it glows at night. Someone must decide which signal earns a scarce hour from a security analyst.
Flare was founded in Montreal in 2017 by Mathieu Lavoie, Israël Hallé and Yohan Trépanier Montpetit after work on red teams in financial services. The founders wanted to put sophisticated security capabilities within reach of organizations that lacked large specialist staffs. Menz joined four years later and became CEO in February 2022. He did not invent Flare, a distinction worth preserving. His assignment was to turn the founders' technical premise into a larger company.
What counts as “outside” when identity travels everywhere?
The perimeter becomes a person
Flare's evolution under Menz follows the industry's. Once, the perimeter meant a network boundary. Then software moved to the cloud, employees acquired dozens of logins, and contractors touched systems from everywhere. Today an identity can be more consequential than a machine. A stolen credential or session cookie may offer a cleaner route into a business than a flamboyant technical exploit.
Menz has condensed that shift into a crisp line: “We've entered a new era where identity is the new perimeter.” It sounds tidy enough for a conference screen, but its consequences are messy. Security teams must look beyond their own logs and into places where attackers exchange information. They need to connect an exposed credential to the person, application and business process behind it. Then they need to close the door.
That explains his impatience with passive intelligence. A platform that merely observes a stolen identity has produced an interesting fact, not a security outcome. Flare's pitch increasingly joins detection to validation and remediation. The company has also pushed for accessibility. In 2022, it launched a self-service trial in a market that often keeps useful information behind a sales appointment. The gesture was commercial, certainly, but it also matched the founders' old idea that sophisticated security should not be reserved for the largest teams.
The patient idea meets fast growth
By December 2024, the long thesis had acquired venture-scale numbers. Flare raised a $30 million Series B led by Base10 Partners, with Inovia Capital, White Star Capital and Fonds de solidarité FTQ participating. The company reported triple-digit year-over-year growth in both 2023 and 2024 and said the money would support expansion in North America and Europe, as well as work with language models and data science.
Eleven months later came another $30 million: a $15 million Series B extension led by Inovia's Growth Fund and $15 million in debt financing from BMO. Flare said it now served customers and partners in more than 50 countries, while year-over-year growth in Europe, the Middle East and Africa had reached 136%. The fresh capital was earmarked for identity-exposure capabilities, product development and possible acquisitions.
The same autumn, Flare placed 38th in Deloitte Canada's Technology Fast 50 after recording 639% revenue growth between 2021 and 2024. Awards can be decorative. This one supplied a useful measurement of the distance between a Montreal startup's premise and the company Menz was now steering.
Yet rapid growth creates its own risk of confusion. Categories converge, acronyms multiply, and every adjacent product begins to claim the same patch of turf. Menz's answer is threat exposure management, a broad frame connecting threat intelligence, digital-risk protection, exposure validation and remediation. The test is not whether the category wins a naming contest. It is whether a security team can get from evidence to action with fewer detours.
“We've entered a new era where identity is the new perimeter.”Norman Menz, as Flare entered the 2025 Technology Fast 50
An information advantage, briefly held
Menz's public work often returns to asymmetry. At RSA Conference in 2023, his session title was “Attackers Shouldn't Have the Information Advantage.” He has also hosted conversations with former acting CIA director Michael Morell about cyber conflict and with former FBI deputy director Andrew McCabe about incident response. These appearances place corporate security inside a wider field of criminal markets, geopolitics and public policy.
By 2026, artificial intelligence had complicated the picture again. Menz warned that autonomous shopping agents, equipped to transact for people and businesses, would create a new fraud target. Criminal tools, he wrote, were already being designed for the opportunity and offered with the familiar amenities of any software market: instructions, reviews and support channels. The detail is darkly funny until one remembers that convenience is not a moral category. It serves whoever arrives first.
At Hacker Week in August 2026, Flare put Menz on a panel with Anthropic cyber-policy leader Rob Bair and security trainer Jason Haddix to examine how AI changes both attacker and defender behavior. It is a fitting new edge for a career spent watching the boundary move. Vendors became ecosystems. Networks became identities. Software agents may now become economic actors, each carrying permission, money and a fresh collection of ways to be fooled.
Menz's response has been notably consistent. Look outside. Collect the evidence. Add enough context to distinguish the consequential from the merely alarming. Then do something. The romance of cybersecurity belongs to the chase; the value belongs to the handoff.
There is no final perimeter in this story, only another ring to watch. From Warren, New Jersey, Menz leads a Canadian company serving a global market whose adversaries observe no geography at all. He has spent roughly twenty years making external risk legible. The work has become faster, larger and better funded. The old question is still waiting each morning: what can they see that you cannot?