Zakir Durumeric is a computer security researcher, Stanford assistant professor, and co-founder and CEO of Censys. As a University of Michigan PhD student he built ZMap, a scanner that can survey the entire public IPv4 internet in minutes rather than weeks, then turned that research into Censys, an internet intelligence platform used for threat hunting and exposure management. His work mapping the internet at scale helped expose the reach of vulnerabilities like Heartbleed and earned him a spot on MIT Technology Review's 35 Innovators Under 35.
Danny Brickman is the co-founder and CEO of Oasis Security, a New York and Tel Aviv-based cybersecurity company building the first enterprise platform for non-human identity management and agentic access management. A former Israel Defense Forces cyber R&D leader with 11 years of service and an Israel Defense Prize to his name, Brickman started Oasis in 2022 with Amit Zimerman to tackle the fast-growing security gap around machine identities, which now outnumber human identities by roughly 20 to 1. The company has raised about $195 million, backed by Sequoia, Accel, Cyberstarts and Craft Ventures.
7AI is a Boston-based cybersecurity company building an agentic security platform that deploys autonomous, reasoning-based AI agents to take over the repetitive investigation work that overwhelms security operations centers. Founded in 2024 by Cybereason co-founders Lior Div and Yonatan Striem-Amit, the company ingests alerts from a customer's existing security tools, triages and investigates them at machine speed, and surfaces only real threats with full context and recommended actions - cutting mean time to respond from hours to minutes and eliminating the bulk of false positives. In December 2025 it raised a $130M Series A, described as the largest cybersecurity Series A on record.
ammune.ai (formerly L7 Defense) is a cybersecurity company that builds ammune™, a fully autonomous, AI-based platform for protecting APIs - and, increasingly, AI systems and data centers - from cyberattacks. Using unsupervised machine learning, ammune auto-discovers APIs and builds a tailored protection layer for each one inline from the first request, blocking dozens of attack types (bots, DDoS, business-logic abuse, injection) in real time without pre-training or rule-writing. The platform is platform-agnostic, running on-premises, in the cloud, in Kubernetes clusters, and offloaded onto DPUs such as NVIDIA BlueField-2, and it recently expanded toward offline, air-gapped protection for AI workloads.
Automox is a cloud-native IT automation and endpoint management company that helps organizations patch, configure, and secure Windows, macOS, and Linux devices from a single platform. Founded in 2015 in Boulder, Colorado, its agent-based, server-free approach automates patch management and vulnerability remediation across distributed fleets, and its Otto generative-AI assistant lets IT teams build automation scripts (Worklets) in plain language. The company serves more than 1,500 customers across 30-plus countries and has raised roughly $154 million, including a $110 million Series C led by Insight Partners in 2021.
Beyond Identity is a New York-based identity security company that eliminates passwords and identity-based attacks by binding authentication to cryptographic, device-resident credentials. Its Identity Defense Platform delivers phishing-resistant MFA, continuous device trust, and deepfake protection for meetings, giving enterprises deterministic proof of who - and what device - is accessing their systems. Founded in 2019 by Silicon Valley veterans, the company has raised $205M and reached a $1.1B valuation.
Biometric Signature ID (BSI) is a Texas-based cybersecurity company that turns a short, hand-drawn password into a behavioral biometric. Its flagship BioSig-ID software verifies people by how they draw four characters with a finger or mouse - measuring speed, direction, angle, length and pressure - so no fingerprint reader, phone or extra hardware is needed. Used across higher education, financial services, healthcare, e-commerce and government, the technology fights account fraud, credential sharing and online-exam cheating while staying compliant with biometric-privacy laws.
Black Kite is a Boston-based cybersecurity company that rates and monitors the cyber risk posed by an organization's third-party vendors and supply chain. Built from a hacker's perspective, its platform combines non-intrusive external assessments, ransomware-likelihood scoring, standards-based compliance mapping, and Open FAIR financial-impact modeling so risk teams can see, quantify, and act on the exposure hiding inside their vendor ecosystem.
Blockaid is a web3 security company that acts as a real-time trust layer for onchain finance, simulating and validating blockchain transactions before they execute to stop scams, drainers, exploits, fraud, and compliance risks. Its detection engines are embedded inside major wallets, exchanges, and protocols - including Coinbase, MetaMask, Uniswap, Stellar, and OKX - screening hundreds of millions of transactions a month and protecting hundreds of billions of dollars in digital assets. Founded in 2022 by former Israeli cyber-intelligence operators, the New York- and Tel Aviv-based company has raised roughly $89 million and is expanding from consumer wallet protection into institutional compliance infrastructure.
Business Technology Integrators (BTI) is a Washington, DC-based Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering secure IT solutions to U.S. federal agencies. BTI focuses on cybersecurity, cloud migration, digital transformation, and data modernization, backed by ISO certifications, CMMI Level 3, and CMMC Level 2, and delivers work through vehicles such as GSA MAS, OASIS+ SDVOSB, and NASA SEWP VI.
byteXL is a Hyderabad-based education-technology company that partners with engineering colleges and universities to make students job-ready. Through a hybrid model of on-campus training, a cloud-based coding platform and guided placement support, it teaches emerging technologies such as AI/ML, cloud computing, cybersecurity and full-stack development - focused largely on students in India's tier 2 and tier 3 cities. Founded in 2019 by brothers Karun and Sricharan Tadepalli, byteXL aims to bridge the gap between what colleges teach and what the IT industry hires for.
Compyl is a New York-based SaaS company that unifies governance, risk, and compliance (GRC) on a single platform. Founded in 2020 by former CISOs, it pulls evidence directly from more than 125 integrated systems, maps controls across 70+ frameworks like SOC 2, ISO 27001 and HIPAA, and uses agentic AI to draft evidence, score vendors and answer security questionnaires while keeping humans in control of decisions. Compyl raised a $12M Series A in June 2025 to scale its AI-led platform for mid-market and enterprise security teams.
Cyble is an AI-native threat intelligence company that continuously monitors the surface, deep, and dark web to help enterprises and governments detect, predict, and disrupt cyber threats before they cause damage. Founded in 2019 by Beenu Arora and Manish Chachada, the company packages dark web monitoring, digital risk protection, attack surface management, and agentic AI analysis into a unified platform used by organizations ranging from agile startups to Fortune 50 companies and national agencies.
CYRISMA is a Rochester, New York-based cybersecurity company that builds a unified, cloud-hosted cyber risk management platform for Managed Service Providers (MSPs), MSSPs, and internal IT teams. It consolidates vulnerability and patch management, sensitive data discovery, secure configuration scanning, attack surface visibility, dark web monitoring, compliance tracking, and risk monetization into a single multi-tenant dashboard - replacing a stack of point tools with one affordable, per-endpoint-priced product. Founded in 2018, the company raised a $7M Series A in 2024 and serves thousands of organizations through partners.
DataBahn is an AI-powered, security-native data pipeline and fabric platform that helps enterprises collect, enrich, orchestrate and optimize telemetry across security, observability, application and IoT/OT systems. Its agentic products - Cruz, Reef and Phantom agents - automate data engineering work, cut noise and reduce SIEM/telemetry costs by more than 50% while preserving visibility for security and IT teams.
Evervault is a developer-first encryption platform that lets companies collect, store, process and forward highly sensitive data - especially payment card data - without ever handling it in plaintext. Founded in 2019 by Irish entrepreneur Shane Curran, the New York and Dublin based company pairs a dual-custody encryption model with products for card payments, secure enclaves and network proxying. It processes over $5 billion in transaction volume and generates more than 100 million encrypted tokens per month for customers including Ramp, Rippling and CarTrawler.
iboss is a Boston-based cloud security company that delivers a cloud-native Zero Trust Secure Access Service Edge (SASE) platform. Founded in 2003 by twin brothers Paul and Peter Martini, iboss consolidates network security functions - secure web gateway, ZTNA, CASB, data loss prevention and firewall - into a single SaaS service that connects users to applications from anywhere while replacing legacy VPNs, proxy appliances and VDI. The platform is used by thousands of enterprises, government agencies and school districts, and processes over 100 billion transactions daily.
Ilantus Services is an identity-centric cybersecurity company that designs, implements, and operates Identity and Access Management (IAM) programs on a Zero Trust framework. Founded in 2000 and now a subsidiary of Network Intelligence, it blends advisory, implementation, and 24x7 managed services with AI-powered accelerators - tools like AiA (application onboarding), iAudit (access certification), iDash (monitoring), and iTDR (identity threat detection) - to help enterprises across finance, healthcare, energy, manufacturing, and government control who has access to what, and why.
imper.ai is a New York-based cybersecurity company that builds an identity verification platform purpose-built for the workforce. It prevents impersonation and account takeover across the employee lifecycle - from hiring to help desk account recovery - by pairing an Impersonation Detection Engine that reads hundreds of network, device, and behavioral signals with an AI-driven contextual verification layer that confirms the real person behind a session using role-specific questions that cannot be sourced from breached data. Founded in 2024 by veterans of Israel's Unit 8200, the company launched publicly in December 2025 with $28M in total funding backed by Redpoint Ventures and Battery Ventures.

Debi Dowling is Senior Vice President of Business Operations, Chief Marketing Officer, and Chief of Staff to the CEO at Onapsis, the Boston-based leader in SAP and ERP application security. Wearing three hats at once, she sets the company's marketing strategy, keeps cross-functional priorities aligned as a strategic partner to the CEO, and runs the operational machinery that ties day-to-day work to company goals. Before Onapsis she spent years at Juniper Networks as Chief of Staff and business-enablement leader across Global Services and Sales Engineering, with earlier management roles at Vodafone, Siemens, and Acision in the UK. She is based in Greater Boston.
Denny LeCompte is the CEO of Portnox, an Austin-based cybersecurity company that delivers cloud-native network access control and zero trust access for enterprises. A former cognitive psychology professor with a Ph.D. from Rice University, he spent two decades in product strategy at IT and security vendors including SolarWinds and AlienVault before taking the helm at Portnox in 2022. Under his leadership the company grew roughly 8x, and he was named a 2025 Cyber Leader of the Year. He writes the widely read 'Access Granted' LinkedIn column, arguing that cybersecurity is as much a human problem as a technical one.
Knox Systems is an Austin, Texas company that operates a pre-authorized, AI-managed federal cloud so that commercial SaaS vendors can reach FedRAMP authorization in roughly 90 days for about 90% less than the traditional cost. By running a shared, continuously monitored compliance boundary across AWS, Azure, and GCP, Knox lets customer applications inherit 60-80% of required security controls on day one, then automates evidence collection, documentation, and remediation. Founded in 2023 by Irina Denisenko, the company raised a $25M Series A in March 2026 and serves vendors such as Adobe, Celonis, OutSystems, Armis, and BigID across 15+ federal agency authorizations.
Legit Security is an AI-native Application Security Posture Management (ASPM) company that gives security teams a single platform to discover, prioritize, and remediate risk across the entire software development lifecycle - from a developer's IDE and AI coding assistant to production. Founded in 2020 by three veterans of Israel's elite cyber units, the company consolidates fragmented AppSec findings, cuts false positives with context and reachability analysis, scans for exposed secrets, and now governs AI-generated code before it ships. Legit serves large enterprises including Google, Kraft Heinz, AIG, Freddie Mac, Cboe Global Markets, and ZoomInfo.
Lema AI is a New York-based cybersecurity startup building an agentic AI platform for third-party risk management (TPRM). Founded by three veterans of Israel's Unit 8200, Lema replaces static vendor questionnaires and check-the-box compliance with continuous, behavior-based analysis that maps how vendors actually operate inside an enterprise - tracking data access, permission changes and 'risk drift' to surface real attack paths. The company emerged from stealth in February 2026 with roughly $24M in total funding, including a $17.5M Series A led by Team8.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
Nudge Security is an Austin-based cybersecurity company that helps organizations discover and govern the SaaS and AI applications their employees adopt, often without IT's knowledge. Founded in 2021 by Russell Spitler and Jaime Blasco, the platform combines Day One SaaS and AI app discovery, security posture management, identity governance, third-party risk, and spend management, then reaches employees directly with 'security nudges' via browser, Slack, and Teams to guide safer choices without blocking work. It raised a $22.5M Series A in November 2025 and serves nearly 200 customers.
Oasis Security is a New York and Tel Aviv based cybersecurity company that built the first enterprise platform purpose-built to discover, secure, and govern non-human identities (NHIs) - the service accounts, API keys, tokens, workloads, and increasingly the AI agents that now vastly outnumber human users in modern cloud environments. Founded in 2022 by former Israeli intelligence engineers Danny Brickman and Amit Zimmerman, Oasis gives security teams a single source of truth for machine identities, automating inventory, posture management, threat detection, remediation, and full lifecycle governance. As enterprises race to deploy AI agents that can act autonomously with real credentials, Oasis positions its Agentic Access Management platform as the control layer that lets companies scale AI without losing control of who - and what - has access.
Onapsis is a Boston-based cybersecurity company that secures business-critical applications - the SAP, Oracle and SaaS ERP systems that run the world's largest enterprises. Founded in 2009 by a team of ethical hackers, Onapsis combines a platform for assessing, defending and controlling ERP application-layer security with the threat research of Onapsis Research Labs, which regularly discovers SAP zero-day vulnerabilities and works directly with SAP and CISA. It is the only SAP security and compliance platform certified as a Premium Certified SAP Endorsed App.
OpenClassrooms is a Paris-based online education company that turns coursework into jobs. Founded in 2013 by Pierre Dubuc and Mathieu Nebra out of the tutorial site Le Site du Zéro, it offers hundreds of free courses plus accredited, mentor-supported degree and apprenticeship programs in fields like data, AI, cybersecurity and web development. A certified B Corp with roughly 2.5 million monthly users, the company pairs project-based online learning with real-world work placements and a network of thousands of expert mentors, positioning itself as an education-to-employment platform rather than a video-course catalog.
ORION Security is an AI-native data loss prevention (DLP) company that protects enterprises from data leaks without relying on manually written policies. Founded in 2024 by Nitay Milner and Jonathan Kreiner, ORION uses large language models and specialized AI agents to map how data normally flows across SaaS, email, cloud, endpoints, and AI tools, then analyzes content sensitivity, user identity, behavioral intent, and data lineage to catch exfiltration and insider threats in real time. The platform targets the three core sources of data loss - human error, malicious insiders, and external attackers - while cutting the false positives and maintenance burden that plague legacy DLP.