Cyber Wire
WireX Systems co-founder Tomer Saban rethinks how SOCs investigate attacks Contextual Capture turns raw packets into readable storylines Unit 8200 alumnus builds forensics platform in Sunnyvale, California Founding team stayed together since 2010 WireX Systems co-founder Tomer Saban rethinks how SOCs investigate attacks Contextual Capture turns raw packets into readable storylines Unit 8200 alumnus builds forensics platform in Sunnyvale, California Founding team stayed together since 2010
Profile · Cybersecurity Founder

Tomer Saban

Co-founder and CEO of WireX Systems, on a fifteen-year mission to make forensic-grade investigation the job of every analyst, not just the experts.

Founder CEO NDR Network Forensics Unit 8200
Tomer Saban, co-founder and CEO of WireX Systems
Tomer Saban — Co-Founder & CEO, WireX Systems
2010
Company Founded
15+
Years in Security
$9.3M
Round Raised (2015)
3
Co-Founders, Intact

A packet is a sentence. String enough of them together and you have the truth.

Ask most people what a network security tool does and they will describe an alarm going off. Something suspicious happened, a light turned red, someone should probably look at it. Tomer Saban has spent the better part of two decades on the far less glamorous question that comes next: look at what, exactly? When the alarm rings at three in the morning, can the analyst on shift actually reconstruct what took place, or are they piecing together fragments and filling the gaps with guesses?

Saban is the co-founder and CEO of WireX Systems, a network detection and response company he started in 2010. The company's headquarters sit in Sunnyvale, California, but its origins and its instincts trace back to Israel, and specifically to the intelligence division of Nice Systems, where Saban spent years as a software engineer and later an R&D team leader. That is where he learned the discipline that would define his company: reading raw network traffic the way a detective reads a scene, and turning packets that mean nothing on their own into a coherent account of events.

A SOC running on assumptions is a SOC running scared. When you can prove what happened instead of guessing, everything changes.

— The premise behind WireX

The idea that became WireX was not a consumer pitch. The company was founded to build security forensics systems for intelligence agencies, the kind of organizations that cannot afford to be wrong about what crossed their networks. Saban assembled the founding team from people he had worked alongside at Nice: Gilboa Davara, who became chief technology officer, and Vadim Lipovetsky, who became head of research and development. More than a decade later, that original trio is still in place, which is rare enough in startup life to be worth noting on its own.

Saban brings a specific pedigree to the work. He is an alumnus of the 8200 Entrepreneurship Program, the accelerator tied to Israel's famous military intelligence unit that has seeded a remarkable share of the world's cybersecurity companies. He also went through the Merage Institute's U.S.-Israel innovation leadership program, and he holds a B.Sc. in computer science from the College of Management in Israel. The combination shows up in how he talks about the field: part engineer who wants the plumbing to work, part operator who understands that a tool nobody can use is not really a tool.

The problem he kept running into

The core frustration that WireX was built to solve is one every security team knows. Modern networks generate an overwhelming volume of data. Logs pile up, alerts fire constantly, and the people expected to make sense of it all are chronically outnumbered by the work. Senior analysts who can dig into packet-level detail are scarce and expensive. Junior analysts often lack the experience to know where to look. And the data that would answer the question - what actually happened here? - is frequently gone, aged out of storage long before anyone thinks to ask.

WireX's answer is a piece of technology the company calls Contextual Capture. Rather than dumping raw traffic on an analyst or storing everything at ruinous cost, the platform continuously watches the network stack and translates packet data into content that is aware of context and behavior. In Saban's own framing, the technology "provides immediate context into security alerts, delivering months of in-depth visibility that augments log based information collected into your SIEM environment." The phrase to sit with there is months of visibility. Most teams keep days. The difference is the difference between remembering an incident and only knowing it occurred.

What WireX tries to compress

Investigation timeminutes, not days
Historical visibilitymonths of retention
Analysts who can investigatethe whole SOC
Storage cost per unit of insightkept low

Illustrative representation of the platform's stated design goals.

Democratizing the hard part

What sets Saban's pitch apart from a lot of security marketing is the audience he keeps pointing at. He is less interested in giving elite analysts a sharper scalpel than in handing a usable one to everyone else. WireX describes its platform as engaging "every single team member in the SOC to conduct faster, better investigations." That is a philosophy as much as a feature. It assumes that the bottleneck in security operations is not detection - plenty of products will tell you something is wrong - but understanding, the slow human work of figuring out what a signal actually means.

If you accept that framing, the shortage of senior talent stops being a hiring problem and becomes a design problem. The goal is not to clone the expert. It is to build a system where a less experienced analyst can arrive at expert-quality answers because the raw material has already been translated into something readable. WireX's own shorthand for this is turning packets into a storyline, converting the alphabet soup of network protocols into an account a human can follow.

Integrating security platforms provides enhanced visibility into threats as well as automatic collection, analysis and visualization of the data to enable response in minutes.

— Tomer Saban

Building slowly, on purpose

WireX has not chased the hyper-growth arc that defines a lot of venture-backed security startups. In 2015 the company closed a $9.3 million round led by Vertex Ventures, with participation from Magma Venture Partners, Entrée Capital, and a group of angels that included Mickey Boodaei, the co-founder of Imperva and Trusteer. It was a credible vote of confidence from people who know the category well. But rather than raising serially and expanding headcount aggressively, WireX has stayed relatively small and focused, a company of a few dozen people rather than a few hundred.

That patience is itself a kind of statement. In 2018 WireX partnered with Gigamon to provide deeper visibility into security threats and speed up incident response, the sort of integration that matters more to practitioners than to headlines. Saban has also stepped outside the vendor role at times, contributing to the World Economic Forum's agenda and to Diplomatic Courier on cybersecurity themes, lending his operator's perspective to the broader conversation about digital defense.

There is a consistency to all of it. The company Saban started to serve intelligence agencies now sells to enterprise security operations centers, but the underlying conviction never moved. The hardest and most valuable thing in security is not knowing that you were attacked. It is being able to prove, quickly and cheaply and by whoever happens to be on shift, exactly what the attacker did. Fifteen years in, Tomer Saban is still building toward that same unglamorous, oddly stubborn idea - and the founding team that started with him is still in the room.

The Vocabulary

What Tomer Saban works on

Network Detection & Response Contextual Capture Network Forensics Incident Response Threat Hunting SOC Investigations Packet Reconstruction Security Analytics Behavioral Baselines Threat Correlation Digital Forensics Data in Transit Network Visibility Insider Risk Automated Investigations
Notable Details

Things worth knowing

1The entire WireX founding team came out of the same intelligence division at Nice Systems - and has stayed together for over a decade.
2WireX began by serving intelligence agencies before bringing its forensics technology to commercial enterprises.
3Saban is an alumnus of Unit 8200's entrepreneurship program, a well-known launchpad for Israeli cybersecurity founders.
4Though Israeli-rooted, WireX is headquartered in Sunnyvale, California, in the heart of Silicon Valley.
Questions

Frequently asked

Who is Tomer Saban?

He is the co-founder and CEO of WireX Systems, a network detection and response and forensics company he started in 2010.

What is WireX Systems known for?

WireX builds a network forensics and NDR platform, notably its Contextual Capture technology that turns network packets into readable, context-rich data so analysts can investigate incidents faster.

What is Tomer Saban's background?

He spent years in Nice Systems' intelligence division as a software engineer and R&D team leader, and is an alumnus of the Israeli 8200 Entrepreneurship Program with a B.Sc. in Computer Science.

Where is WireX Systems located?

The company is headquartered in Sunnyvale, California, with Israeli roots.

How much funding has WireX Systems raised?

WireX closed a $9.3 million round in 2015 led by Vertex Ventures, with participation from Magma Venture Partners, Entrée Capital and several angel investors.

Pass it on