On Norse’s public attack map, the internet never slept. Colored arcs leapt across a dark globe. Numbers climbed. Locations flashed. The display could make a quiet office feel like the bridge of a ship under fire. For many people, it was their first memorable picture of cybercrime. For Norse, it was also the most persuasive advertisement imaginable: if all this was happening before your eyes, surely somebody ought to pay to know more.
- Norse sold IP risk scores, threat feeds, and analyst-backed intelligence to businesses and security teams.
- Its public map showed activity against Norse sensors - a vivid sample, not a census of all attacks.
- It announced $42 million in total venture funding by September 2015. Layoffs and a leadership change followed in early 2016.
- The domain now hosts consumer security reviews; continuity with the original company is unverified.
The company behind the show was founded in 2010 by Sam Glines and Tommy Stiansen. Its first problem was practical and rather less cinematic. An online business sees an IP address trying to open an account, place an order, or reach a web application. Is it a customer or a risk? Norse proposed to answer in real time. Its IPViking service scored addresses using observations from a network of sensors and honeypots. The score could help a client block traffic, investigate it, or let it through.
The early package also included nGate, a payment gateway that used those signals to fight fraud. By 2013 the pitch had widened. Norse was selling Darklist, a feed of high-risk IP addresses, and positioning IPViking as a cloud-delivered intelligence layer for enterprise security. It had moved from a fraud question - should we trust this transaction? - toward a broader security question: what can we learn about trouble before it reaches us?
A map is a remarkable salesman
Most threat intelligence is hard to display. A risk score is a number in a log. A firewall rule is a line in a console. Norse gave the category a visual language. Its map turned encounters with suspicious traffic into bursts of color crossing borders. It made the premise of “live attack intelligence” understandable to a non-specialist in about five seconds.

That closer reading matters. The map displayed attacks observed by Norse’s own infrastructure, including honeypots designed to attract hostile probes. It did not show every attack on the internet, and the source country of a probing machine did not necessarily identify the person operating it. A compromised computer in one country can be used by someone in another. The map’s strength was immediacy; its limit was coverage. Confusing the two made a dazzling picture feel like a complete measurement.
This was Norse’s difference from a plain blacklist. It promised fresher signals, context, and human analysis, all collected from an unusually broad sensor network. A buyer could feed that information into existing security systems instead of building its own worldwide set of decoys. The subscription economics were attractive in theory: gather once, sell intelligence many times. In practice, the test was severe. How often did Norse identify a truly dangerous address that a customer would otherwise miss? How many legitimate users would a hurried block catch? The public map could not answer either question.
The year the map met the boardroom
Money and distribution arrived quickly. Oak Investment Partners led a $10 million Series A in December 2013. NEC and its security subsidiary Infosec announced a partnership in March 2015, planning to combine Norse’s intelligence with NEC’s security services. That September, KPMG Capital led an $11.4 million Series A1 round. KPMG member firms were expected to offer Norse products and services through their cybersecurity practice. Norse said total venture funding had reached $42 million.
The partnerships made sense. Norse had intelligence to distribute; larger firms had established relationships with the people who bought security services. It is tempting to read such announcements as proof of a business model. They are better read as access to a test. A channel partner can introduce a feed to customers, but the feed must still help those customers make better choices. No announcement can shorten the time it takes to prove that at scale.
Norse also knew the power of proximity to a famous event. A four-person team visited Sony Pictures in November 2014 to pitch security services, weeks before the studio’s devastating hack became public. That timing later placed Norse in the story of a breach everyone remembered. It established that the company saw a potential customer; it did not establish that its product would have prevented the intrusion. Security marketing often turns a near miss into a parable. Buyers have to ask for the mechanism.
“What did the signal change?” is a better buying question than “How much activity can you show me?”For anyone evaluating a threat feed
The first failure was ordinary
The collapse was faster than the brand’s ascent. In early January 2016, Norse cut a substantial portion of its staff. Later that month, Glines was asked to step down and board member Howard Bain took over as interim CEO. The website went offline around the same period. In a subsequent public statement, Glines said that delays in developing new products, missed sales targets in the second half of 2015, and delays to a Series B financing had forced the layoffs. He described an aggressive monthly cash burn.
That account does not settle every argument about Norse’s data. A former chief data scientist told investigative reporter Brian Krebs that, when she finally inspected the attack data in late 2015, it looked less rich than she had expected. Former employees quoted by The Register described delays to a new threat-information product and expansion of the sensor network. These are reported accounts, not a full technical audit. They point to the same commercial bind: the next version was late while the cost of building and selling the promise kept arriving on time.
By March 2016, Bain told the Christian Science Monitor that Norse was still serving customers while he sought a buyer for its technology and assets. The venture-backed company is now listed as closed. No public source here establishes a final sale price, a customer count, or a definitive reckoning of what each investor recovered. The quoted $42 million was money raised, not the price of the failure. Its more immediate cost was the staff cut, an interrupted service, and customers left to decide whether their intelligence feed would survive.
What a buyer can take from the wreckage
There is a useful playbook inside this story, if it is kept modest. Norse made an abstract product concrete. Any company selling difficult data can borrow that move: show the raw observation, show the interpretation, then show the action. The last step is the one most demos hurry past. Put a measured customer decision beside the animation. Record how often the signal was useful, how often it was wrong, and what it cost to operate.
For a buyer, the test is equally portable. Run the feed against your own traffic for a fixed period. Count detections you would otherwise have missed. Review false positives by hand. Check how quickly a newly observed address appears, and whether its explanation is strong enough for an analyst to trust. Work out what happens if the supplier disappears. A sensor network can be valuable under those conditions. A glowing globe alone cannot satisfy them.
The domain has had another life. Today norse-corp.com presents consumer cybersecurity articles and antivirus and VPN reviews, including pages published years after the original company’s crisis. Those pages tell readers about products to consider; they do not establish that the old enterprise intelligence business returned. The name remains. The meaning changed. Perhaps that is the neatest ending for a company that taught people to look closely at signals: even a familiar label deserves a second inspection.