The firewall maker is buying and building its way across corporate cybersecurity. Its pitch is less busywork for defenders - with a bigger share of the budget flowing to Palo Alto.
The British cybersecurity company spent two decades turning raw change logs into answers. Now it is betting that permissions cleanup - not another wall of alerts - is what lean security teams will pay for.
Most security vendors promise to stop the intruder. Semperis made its name by asking the uglier question: if the keys to the company are already stolen, how fast can you safely turn the business back on?
Nessus made Tenable famous for finding weaknesses. Tenable One is the nearly $1 billion-revenue company’s bet that the real product is judgment: connecting IT, cloud, identity, OT and AI risk, then showing an overworked security team what to fix first.
Cyera turned a five-minute cloud connection into a map of the enterprise's most awkward secrets. Five years, seven funding rounds and a string of acquisitions later, its wager is bigger: that no company can trust AI until it knows exactly what every human and machine can see.
Most identity tools guard the front door. Silverfort built a checkpoint for the side doors - legacy apps, service accounts, command lines and now AI agents - without asking companies to rebuild the house.
BeyondTrust spent four decades assembling the locks, vaults and cameras of enterprise access. Its next act is harder: proving one platform can govern humans, machines and AI agents without becoming another all-powerful key.
The startup's first route to market sputtered. Its 2023 pivot to MSPs turned that miss into a useful lesson: for small-business security, the trusted reseller may matter as much as the software.
A two-night coding sprint became a profitable security business. After 12 acquisitions and three investment chapters, Netwrix is trying to turn a crowded toolbox into one coherent answer to a hard question: who can touch the company’s most sensitive data?
The enterprise-security company built one control room for human access. Now a fast-growing population of AI agents is testing whether that converged model can govern machines moving at machine speed.
The company that put six-digit codes on key fobs is rebuilding itself for passkeys, AI agents and help-desk deepfakes. Its bet is that the future of identity will still have to work with the stubborn machinery of the past.
Its direct-routed Zero Trust software promised to remove the chokepoints created by legacy VPNs. After a public-market detour ended in Chapter 11, Appgate is testing whether a cleaner balance sheet can do the same for the business.
Entersekt built a global financial-authentication business around a stubborn idea: the best security step is often the one a legitimate customer never sees. Now its bet is moving from a protected phone to one context-aware layer across banking and payments.
Passwords were only the opening act. SpyCloud built an enterprise security business around the messier evidence criminals leave behind - and the narrow window defenders have to use it.
Rita Gurevich spent the financial crisis untangling Lehman Brothers’ technology estate. Her company now sells the same hard-won discipline as software - finding forgotten access, assigning owners and cleaning it up before an auditor or attacker does.
Employees can adopt an app in minutes; security teams may need months to notice. Grip built a business around closing that gap - and around turning an unruly SaaS inventory into actions a small team can actually finish.
Most security tools check the badge at the door. WideField followed the badge through every room - a post-login bet that carried the three-year-old startup into Cisco and Splunk.
A firm run entirely by cybersecurity operators, backing the founders trying to defend everything from cloud workloads to synthetic media - one narrow thesis, executed at scale.
Every tap on an Okta tile hides a difficult bargain: make access effortless for the right person, and impossible for everyone else. Now the identity company is extending that bargain to machines and AI agents.
Aware spent decades teaching machines to recognize a person. Now the small, public biometrics company is betting that the bigger business lies in deciding which identity system to trust - and when.
Lumos began by replacing the IT ticket queue with an internal app store. Six years later, it is betting that the next identity administrator will be a coordinated crew of software agents - with humans reserved for the judgment calls.
Beyond Identity is a New York-based identity security company that eliminates passwords and identity-based attacks by binding authentication to cryptographic, device-resident credentials. Its Identity Defense Platform delivers phishing-resistant MFA, continuous device trust, and deepfake protection for meetings, giving enterprises deterministic proof of who - and what device - is accessing their systems. Founded in 2019 by Silicon Valley veterans, the company has raised $205M and reached a $1.1B valuation.
Oasis Security is a New York and Tel Aviv based cybersecurity company that built the first enterprise platform purpose-built to discover, secure, and govern non-human identities (NHIs) - the service accounts, API keys, tokens, workloads, and increasingly the AI agents that now vastly outnumber human users in modern cloud environments. Founded in 2022 by former Israeli intelligence engineers Danny Brickman and Amit Zimmerman, Oasis gives security teams a single source of truth for machine identities, automating inventory, posture management, threat detection, remediation, and full lifecycle governance. As enterprises race to deploy AI agents that can act autonomously with real credentials, Oasis positions its Agentic Access Management platform as the control layer that lets companies scale AI without losing control of who - and what - has access.
PlainID is an Israeli cybersecurity company and the recognized pioneer of Policy-Based Access Control (PBAC). Its authorization platform lets enterprises define, manage, and enforce who can access what across applications, data, APIs, microservices, and - increasingly - AI agents, replacing the tangle of hard-coded access rules scattered across systems with centralized, dynamic, real-time policy decisions. Founded in 2014 and headquartered in Tel Aviv with a strong New York presence, PlainID has raised roughly $99-100M and serves Fortune 500 organizations across financial services, healthcare, telecom, and government.
Token Security is a New York- and Tel Aviv-based cybersecurity company that secures non-human identities (NHIs) - the service accounts, API tokens, workloads and, increasingly, autonomous AI agents that now vastly outnumber human users inside enterprises. Its agentless platform continuously discovers these machine identities across cloud, SaaS and AI environments, maps their ownership, permissions and access into a unified identity graph, and enforces least-privilege and lifecycle controls. Founded in 2023 by CEO Itamar Apelblat and CTO Ido Shlomo, the company has raised roughly $27M (Seed plus a $20M Series A led by Notable Capital) and counts customers such as GitLab, Bloomreach, HiBob, Dayforce and BetterHelp.
Veza is an identity security company that helps enterprises understand and control who can take what action on what data. Its patented Access Graph maps permissions across cloud platforms, SaaS apps, data systems, and infrastructure for human, machine, and AI identities, letting organizations enforce least privilege, automate access reviews, and govern non-human and AI-agent identities. Founded in 2020 and headquartered in the California Bay Area, Veza agreed to be acquired by ServiceNow in a deal announced December 2025.
Palo Alto Networks is a global cybersecurity company that helps organizations prevent, detect and respond to cyber threats across networks, clouds, endpoints and identities. Founded in 2005 by Nir Zuk, it pioneered the next-generation firewall and has since expanded into an integrated security platform spanning network security (Strata), cloud security (Prisma), and AI-driven security operations (Cortex). Serving roughly 70,000 organizations in more than 150 countries, including most of the Fortune 100, it is one of the largest pure-play cybersecurity vendors in the world.
Delinea is a San Francisco-based cybersecurity company that builds identity and privileged access management (PAM) software. Formed in 2021 from the merger of PAM veterans Thycotic and Centrify and rebranded as Delinea in 2022, the company secures the credentials, secrets, and privileged accounts that human users, machines, applications, and - increasingly - AI agents use to reach an organization's most sensitive systems. Its flagship Secret Server vault, Privilege Manager, DevOps Secrets Vault, and the cloud-native Delinea Platform are used by thousands of enterprises worldwide to enforce least privilege, rotate passwords, record sessions, and detect identity-based threats across hybrid and multi-cloud environments.
BlueFlag Security is a Sunnyvale, California cybersecurity company building an identity-centric security and governance platform for the software development lifecycle (SDLC). Rather than scanning code for vulnerabilities, BlueFlag watches the identities and tools behind the code - developers, service accounts, bots, and increasingly the AI coding assistants and autonomous agents that now write, test, and deploy software. Founded in 2024 by former CloudKnox and Symantec operators Raj Mallempati and Ken Schneider, the company applies AI/ML-based 'Identity Intelligence' to detect risky behavior, enforce least privilege, and govern AI agents across CI/CD pipelines. In March 2026 it announced a $28 million Series A and 300% year-over-year revenue growth.
Permiso Security is a Palo Alto-based cybersecurity company that discovers, protects, and defends identities across cloud and on-prem environments. Founded by former FireEye/Mandiant executives, its identity security platform stitches human, non-human, and AI-agent identities into a single Universal Identity Graph, using 1,400+ detection rules and behavioral analytics to catch account takeovers, credential compromise, and insider threats. Permiso also runs the P0 Labs threat-research team, which has released ten open-source tools including CloudGrappler and YetiHunter.