There is a peculiar ritual in corporate security. A company buys a firewall, an endpoint product, a mail filter and a handsome dashboard that turns anxiety into colored circles. Then everyone admires the architecture and quietly avoids the rude question. If a real attacker tried the door, which lock would actually hold?
SafeBreach exists to be rude on schedule. Its software runs controlled versions of real attack techniques across an enterprise network, endpoint, cloud and email environment. It watches whether the installed controls prevent or detect them, correlates the resulting alerts and points the security team toward the gaps. The sales pitch is not another shield. It is an examination for the shields already on the payroll.
The short breach
- What it does: safely simulates attacks, tests controls and maps post-breach movement.
- Who buys it: large enterprises with complicated security stacks and regulated risk.
- What went wrong first: security leaders could count tools, but not confidently prove preparedness.
- The practical lesson: assign every failed test, fix it and rerun the same test.
A CISO and a hacker walk into the same problem
The origin story is tidy because the mismatch was genuine. Before co-founding SafeBreach in 2014, Guy Bejerano had been a chief information security officer. He knew the view from the person signing the purchase orders and explaining risk upstairs. Itzik Kotler brought the attacker's habits. When they met, the shared irritation was immediate: companies could spend lavishly on defense and still have no continuous way to say whether those defenses were ready for a particular threat.
Their change of mind was subtle but important. The answer was not merely more prevention. It was evidence. Combine a CISO's need to measure with a hacker's instinct to probe, then make the probing repeatable enough to run in production. SafeBreach helped give that practice its commercial name: breach and attack simulation, or BAS.
“We needed to know what is working and what is not working.”Guy Bejerano, on the founding problem
The first platform turned offensive knowledge into an attack library and a system of lightweight simulators. By July 2026, SafeBreach described more than 33,000 real attack simulations in its Hacker's Playbook. A user can select a threat actor, ransomware family, MITRE ATT&CK technique or custom scenario, launch a controlled test and see where the security chain broke. Breach Studio lets teams build their own scenarios. A REST API and integrations pull the exercise into the machinery of ordinary work.
The useful failure is the one somebody owns
Simulation is easy to describe and difficult to operationalize. A finding that merely joins the alert swamp is not a product; it is litter. SafeBreach's more interesting work happens after the attack. It correlates the simulated behavior with events in tools such as Microsoft Defender, CrowdStrike, Splunk and other SIEMs. It can open workflow tickets and offer control-specific remediation. The same scenario can then run again to confirm that a fix survived contact with the attack.
The loop that makes a simulation useful
A published case study supplies the useful counterexample. One global bank had already bought a BAS platform, but its analysts did not trust the readings. They manually checked whether controls had really blocked each test. The automation had failed first at credibility. The bank ran a proof of concept, chose SafeBreach for its reported accuracy and integrations, and connected it to Splunk within weeks. It later reported a 30% improvement in threat coverage and time savings equivalent to one full-time analyst.
“The difference in accuracy was night and day.”CISO of the anonymized global bank
That result is vendor-reported and one customer is not a referendum. Still, it identifies the real competitive hinge. SafeBreach competes with Cymulate, Picus Security, AttackIQ and Pentera, among others. Every serious platform can run adversarial tests. The durable question is whether a security team trusts the finding, can see which tool failed, can send the work to an owner and can prove the repair. An enormous attack library is impressive. An accepted ticket followed by a clean retest is useful.
After patient zero
In February 2025 the company widened its answer. SafeBreach Validate became the name for the familiar control-testing product. SafeBreach Propagate addressed the next question: suppose an attacker has already landed on one machine. How far can that attacker move?
Propagate starts from a controlled “patient zero.” It inventories the local environment, tests credential-harvesting techniques, validates credentials without tripping lockouts, scans the nearby subnet and attempts lateral movement through methods such as pass-the-hash, WMI, WinRM and remote desktop. The resulting map is less concerned with the existence of a vulnerability than with consequence: which route reaches a sensitive asset, and which endpoint creates the largest blast radius?
Validate asks
Did the firewall, endpoint, email, cloud or detection control stop and report this behavior?
Propagate asks
Once one endpoint falls, which credentials, trust links and network paths lead to the crown jewels?
This pairing matters because perimeter testing and post-breach testing reveal different failures. A control may miss an initial technique, but segmentation can still contain the damage. Conversely, an organization may block most known entry behavior while leaving one privileged route disastrously open. SafeBreach sells both products as a shared platform, simulator infrastructure and management console. Its clients are chiefly large, distributed enterprises - banks, health insurers, biopharma companies, technology providers and organizations spanning IT and operational technology.
From a test bench to an operating system
In 2026 SafeBreach placed a larger frame around the same principle. Its Continuous Threat Exposure Management platform uses Helm, an AI infrastructure layer, to coordinate three agents. The Analyst Agent collects and prioritizes exposure data. The Validation Agent runs the relevant attack behaviors. The SecOps Agent turns proven gaps into remediation work. Users can ask questions in plain language rather than assemble every workflow by hand.
The Anvilogic partnership shows what the company wants this to become. A failed SafeBreach simulation can trigger Anvilogic to examine existing detections, create and tune a missing rule, pause for human approval, deploy it and send the scenario back for another test. The simulation then runs daily. If the detection drifts, the loop notices. The concept is appealing because it moves security from a pile of findings toward a controlled process.
It also reveals the business model. SafeBreach is enterprise software, sold by quote through direct, channel and managed-service relationships. There is no public list price. The economic argument is instead framed around avoided manual validation, better use of existing controls, fewer redundant tools and more focused remediation. The company has raised $106.5 million, including a $53.5 million Series D in 2021, to build product and global distribution around that argument.
What another security team can steal
The transferable lesson does not require buying SafeBreach. Stop measuring a security program by inventory. Pick a consequential threat, express it as observable behavior, run a controlled test, name the control expected to respond, give the failure an owner and repeat the identical test after remediation. Keep the evidence. A modest loop completed every week is more persuasive than a heroic red-team report aging in a shared drive.
- Start narrow. One ransomware chain tied to critical assets beats a thousand untended findings.
- Define “worked.” Prevention, detection and response are different outcomes.
- Connect the queue. A gap without an owner and due date is merely an anecdote.
- Retest the exact behavior. Closure is evidence, not a changed ticket status.
The approach has boundaries. A small company with a simple stack and no dedicated detection team may create more findings than it can digest. An immature organization without asset context, remediation ownership or stable controls can automate confusion with remarkable efficiency. Simulations of known behavior also do not replace creative human testing of business logic, social engineering or a genuinely novel exploit. SafeBreach is most persuasive where there is already something substantial to test and somebody capable of fixing it.
For the right enterprise, however, the proposition has the clean logic of a fire drill. A drill does not prove a building can never burn. It reveals whether the alarm sounds, whether the doors open and whether people know where to go. SafeBreach has spent twelve years turning that rehearsal into software. The breach is pretend. The answer is not.