In 2014, cybersecurity was important, technical and still oddly easy for the investment establishment to file under “software.” Alex Doll and Mark Hatfield thought the label missed the point. Security had its own buyers, product cycles, trust problems and talent networks. It would grow more complicated as the world digitized. So the two former operators started Ten Eleven Ventures with a constraint that sounded narrow and proved expansive: cybersecurity only.
The firm does not sell a firewall, scan a cloud or hunt an intruder. It finds and finances the companies that do. From offices in California, Colorado, Massachusetts and London, Ten Eleven invests globally and at multiple stages, from a first institutional check to growth capital. By September 2025 it said it had made more than 60 cybersecurity investments. Its 2022 third-generation fund, TE3, raised $600 million and took total capital raised across its funds beyond $1 billion.
That makes Ten Eleven a useful lens on a market that no longer fits in the server room. Its portfolio covers identity, firmware, cloud forensics, bot defense, threat intelligence, human readiness, encryption, cryptocurrency custody, secure communications and AI governance. A security budget may be finite. The number of things worth protecting is not.
A narrow thesis with a wide field of view
Specialization is the first difference. Stage range is the second. Many venture firms organize themselves around company maturity: seed funds live with prototypes, growth funds live with spreadsheets. Ten Eleven built separate venture and growth vehicles while keeping one sector lens. That lets its partners see what a young product may become and what a mature buyer will eventually demand.
The model also produces a feedback loop. Conversations with chief information security officers reveal where existing tools are failing. Work with later-stage companies shows which sales motions survive procurement. Early investments expose new technical architectures. Exits demonstrate which capabilities strategic buyers consider essential. Generalist firms can build similar knowledge, but they must spread attention across many categories. Ten Eleven keeps feeding the same map.
“Our competitive advantage in investing at any stage derives from our insights into all stages.”Alex Doll, writing about Ten Eleven's growth strategy
Its alternatives are not scarce. Ballistic Ventures, YL Ventures, Team8, SYN Ventures, NightDragon and Forgepoint Capital also offer specialist security capital, while larger firms maintain formidable cyber practices. Ten Eleven's claim is more specific: an exclusively cyber mandate, a seed-to-growth platform and a staff crowded with people who have already occupied the founder's side of the table.
Money with an operating manual
A venture fund's economic product is capital. Its less measurable product is judgment. Doll co-founded encryption company PGP Corporation. Hatfield has spent decades investing in early-stage technology. The broader partnership includes former founders, security executives and functional operators. Scott Lundgren joined as CTO in 2024 after helping take Carbon Black from startup to public company and through its acquisition by VMware. Megan Dubofsky, the firm's partner and CMO, works with companies on go-to-market. Other team members cover finance, recruiting, events and portfolio analysis.
For founders, that bench translates into mundane but decisive work: pressure-testing a technical roadmap, introducing a credible first buyer, recruiting an executive, positioning a category, entering Europe or preparing for an acquisition. Security products are especially dependent on trust. A technically elegant tool still has to pass enterprise scrutiny, fit a crowded stack and convince a cautious executive that a young vendor will be alive years from now.
Ten Eleven's own site describes an ecosystem of co-investors, bankers, analysts, marketing and public-relations experts, channel partners, lawyers and recruiters. The firm also operates a Security Trust and Resilience leaders network, connecting practitioners with innovators and discussions that reach beyond software into geopolitics and markets. The practical value is access: founders can hear what security leaders will actually buy before spending a year building the wrong thing.
The portfolio is a history of new anxieties
Look down the portfolio and the evolution of cybersecurity appears in company form. Cylance applied machine learning to endpoint defense before “AI” became a default slide in every pitch deck; BlackBerry agreed to acquire it for $1.4 billion in 2018. Twistlock secured containers and cloud-native applications before Palo Alto Networks bought it in 2019. Verodin tested whether security controls really worked before FireEye acquired it. KnowBe4 turned employee behavior into a security category and went public in 2021.
Newer checks reveal the next set of concerns. Eclypsium looks below the operating system at firmware and hardware supply chains. Silent Push maps attacker infrastructure before campaigns launch. Twine builds “digital cybersecurity employees” to tackle identity tasks and the industry's talent shortage. Harmonic Security protects sensitive data as workers adopt generative AI. Geordie, founded in 2025, gives enterprises visibility and governance over autonomous AI agents. Darkhive extends the thesis into secure drones and battlefield situational awareness.
These businesses do not share one customer. Some sell to enterprise security teams, some to developers and IT departments, some to governments, telecom operators or consumers. Ten Eleven therefore sits one layer above the end user. Founders and limited partners are its direct constituencies; the portfolio's products carry the firm's thesis into the market.
Its business model remains classic venture capital. Limited partners commit money to funds. Ten Eleven buys equity in private companies and works to increase their value. Returns arrive through acquisitions, public offerings and other liquidity events. The operating support is not a separate consultancy invoice. It is part of the effort to make the equity more valuable.
A name built for people who notice details
The firm's name is a small piece of security-world humor. The digits evoke binary, the zeros and ones underneath digital technology. Read 1011 as an integer and it factors into two primes, 3 and 337, nodding to the mathematical building blocks of cryptography. The first fund also closed on October 11, Alex Doll's grandfather's birthday. It is a brand story with three layers: machine, mathematics, family.
That blend mirrors the firm's market position. Cybersecurity is deeply technical but ultimately human. Attackers exploit software flaws and distracted employees. Buyers want innovation but fear vendor risk. Founders need conviction and introductions in roughly equal measure. A specialist investor earns its keep by translating among those worlds.
The useful question is not whether cybersecurity is a big enough category. It is how many new categories security keeps creating.
The concentration carries risk. Security budgets can consolidate around large platforms. Startup categories can become crowded before customer demand catches up. A focused firm cannot escape a downturn by discovering consumer snacks. Yet focus also prevents casual tourism. Ten Eleven has to understand where spending will persist, which technical claims are defensible and which founder can endure a long enterprise sale.
It also has to resist its own familiarity. A deep network can improve diligence, but it can tempt an investor to back a familiar pattern after the market has moved. The firm's newer bets on autonomous agents, mobile credentials and defense systems show an effort to stretch the thesis without diluting it.
In 2024 the firm deployed more than $68 million into companies including Eclypsium, Twine and Darkhive, according to SC Media, which named Ten Eleven its 2025 Investor of the Year. The award is one marker. Repeat founders are another. Alastair Paterson worked with the firm at Digital Shadows, then returned when he launched Harmonic Security. That kind of return engagement is harder to advertise and more revealing.
Where the next check may land
Ten Eleven's recent activity suggests it expects security to move closer to autonomous systems and further into physical infrastructure. AI agents need identity, permissioning, monitoring and remediation. Telecom credentials need to be issued on demand without surrendering control. Drones need secure software delivery. Threat intelligence needs to find the staging ground before an attack rather than document the wreckage afterward.
For a founder, Ten Eleven can be useful when the product is technically specific, the buyer is demanding and the market requires more than a warm introduction to a generic software executive. For a limited partner, the proposition is concentrated exposure to the security economy through a team that has watched several generations of it develop. Neither offer is universal. Both are legible.
The original bet now looks less like a niche and more like a choice of altitude. Ten Eleven does not need to predict every attack. It needs to recognize the company that turns a newly visible risk into a product customers will trust. The attack surface keeps moving. The firm has arranged itself to move with it.