In 2025–26 Israel sold the best of its cyber companies to American platforms.
ENSI research — built on a library of 115 primary documents and 52 company dossiers.
The argument, before the list
Between 11 February and the end of April 2026, the three largest acquisitions of Israeli companies ever made all closed. Palo Alto Networks completed its ~$25B purchase of CyberArk on 11 February. Google closed its $32B all-cash purchase of Wiz on 11 March. ServiceNow completed its $7.75B cash purchase of Armis in April. In August, Visa agreed to pay $2.4B for BioCatch. In June a five-year-old data-security company, Cyera, was valued at $12B — and then spent about $1B buying another Israeli start-up, Oasis. Palo Alto also bought Koi, twenty months after it was founded; Cisco bought Astrix; CrowdStrike agreed to buy the patents and source code of XM Cyber. It is hard to name another country of ten million people that has had a year like it.
The standard explanation is the start-up count: thousands of tech firms, a famous intelligence unit, a culture of improvisation. That explanation gets the causality backwards. The start-ups are the output, not the cause. What Israel has built over three decades is a system with four moving parts, and each is visible in the dossiers behind this report:
A selection-and-training engine. Unit 8200 screens eighteen-year-olds on raw potential — “the top 1 percent of the 1 percent of the country”, in one alumna’s phrase (Rousseau 2017) — and its technology arm Unit 81, the Talpiot programme and the less-celebrated Mamram and Matzov units produce engineers who have worked at state scale before they are 25. INSS calls the result “double-feeding”: the same people circulate between army, industry and academia through service and reserve duty (Antebi, INSS 2021).
Anchor companies that act as founder academies. Check Point trained the founders of Palo Alto Networks, Imperva, Cato, Orca and Torq. The Israeli operations of Microsoft and Symantec — themselves partly built from acquisitions of Israeli start-ups — trained the founders of Wiz, Apiiro, Zero Networks, Torq and Cycode, and supplied Island’s go-to-market team.
A specialist venture layer. Cyberstarts wrote the first cheque into Wiz and then backed Cyera, Oasis, Island, Upwind, Glow, Zafran and Legit. Team8 manufactured Claroty and Sygnia as a foundry. YL Ventures seeded Axonius and Cycode. By 2020 Israel was attracting 37% of global venture funding for cybersecurity (IISS 2021); in 2024 Israeli cyber raised $4B across 89 rounds, “primarily funded by overseas investors” (YL Ventures 2024).
Exit recycling. Adallom’s sale to Microsoft produced both Wiz and Armis. Luminate’s sale to Symantec produced Torq. Spot.io’s sale to NetApp produced Upwind. Even Cybereason’s collapse produced 7AI.
The system’s signature product is not a start-up but a category: the commercial firewall, privileged-access management, the web-application firewall, agentless cloud security, the enterprise browser, non-human identity, AI-agent governance. Israeli founders repeatedly name a budget line that did not exist and then own it for a decade.
That is why 2025–26 is both the proof and the warning. The proof: the system’s output now commands the highest prices in the industry. The warning: the output leaves. With CyberArk rebranded as Palo Alto’s “Idira”, Wiz inside Google Cloud and Armis inside ServiceNow, strategic control of Israel’s champions in identity, cloud and exposure management now sits in California. Israel keeps big R&D centres and the tax — an estimated NIS 10B (~$3.2B) from Wiz alone — but it no longer has an independent anchor company in either identity or cloud. The largest Israeli-headquartered independent, Check Point, grew 1% in Q2 2026. The OECD names the structural cause: “vibrant start-up activity but a comparatively low base of long-term capital” (OECD 2025). The system manufactures companies faster than the country can keep them.
For a mid-sized European state — our home example is the Czech Republic — the lesson is not “build an 8200”. Conscription-scale military intelligence and a permanent, existential threat environment are not exportable, and nobody should want the second. What is exportable is the machinery around them: founder academies, specialist seed funds, foundries wired to critical-infrastructure buyers, the state as a demanding first customer, and rules that keep exit capital and people at home. NÚKIB’s 2026 strategy names precisely the gap Israel closed and we have not: a “shortage of secure and competitive domestic technological alternatives, which deepens dependence on the technologies of foreign rivals” (NÚKIB 2026). And the Israeli system is already spilling into our region — Cato Networks is tripling its R&D centre in Prague.
This report ranks the fifty companies that make the system visible. It puts the analysis first — ten angles on what the list reveals — and the ranking second, as a reference layer. It closes with what a state like ours should copy, what it should refuse to copy, and five moves for the next twelve months.
Summary of main points
Israel’s edge is a system, not a start-up count — selection (8200, 81, Talpiot, Matzov, Mamram), founder academies (Check Point, Microsoft and Symantec Israel), specialist venture capital (Cyberstarts, Team8, YL) and exit recycling.
The exit machine is at its peak and concentrating. Five exits at or above $2.4B since late 2023 — Wiz, CyberArk, Armis, Imperva, BioCatch — all to foreign buyers. Decision rights leave; R&D and tax stay.
Category creation is the specialty, and it lasts about a decade. Check Point’s firewall bought twenty years, Aqua’s container bet about ten, Deep Instinct’s deep-learning lead about five.
The repeat founder is the most valuable national asset. Wiz, Armis, Cato, Island, Torq, Upwind, Apiiro, 7AI and Transmit are all second or third acts.
“Build in Israel, sell from the US” is the template — and it is leaky. Snyk’s Israeli team fell from several hundred to about 90 while the company passed 1,500 staff.
AI security is the new centre of gravity — Cyera, Zenity, Noma, Glow, 7AI, Irregular, Alice, Torq — but most of its metrics are self-reported and the platforms have already bought six AI-security start-ups in about eighteen months.
The 2021 cohort is a warning to the 2026 cohort. Forter, Transmit, Orca, Salt, Cymulate, Snyk and Aqua carry peak-cycle valuations that have never been retested.
Capital efficiency is the more portable Israeli model. BioCatch, KELA, Cynet, Checkmarx and Sygnia created real value without a Wiz-sized war chest.
The national-security-adjacent firms are an advantage and a liability. Cellebrite’s uneven human-rights vetting and Dream Security’s NSO lineage show the governance duty that comes with dual-use exports.
For us: copy the machinery, not the conscription. Five moves for the next twelve months close the report.
How we ranked
The ranking is a composite judgement, not a formula. Each company was scored on four things: value created (exit price, market capitalisation or last priced valuation, read against disclosed revenue or ARR); category leadership (did it invent or define a category, and does it still lead it?); momentum in 2025–26 (new capital, growth and customer wins — or layoffs, stale valuations and leadership churn); and what it teaches (how clearly the company shows a mechanism others can copy).
The inclusion rule: Israeli-founded, with core R&D in Israel, whether independent, public or acquired. Acquired companies count, because an exit proves the capability; they are ranked by the value and the category they created. Offensive-spyware vendors — NSO, Paragon, Candiru — are excluded and treated in this series as a governance problem, not a league-table entry.
Three honest caveats. First, much of the data is company-reported: Upwind’s $3.8B valuation rests on no disclosed ARR, Glow’s $1.2B on no disclosed revenue, Island’s $200M revenue on a founder interview. Second, a 2021 valuation and a 2026 valuation are not the same currency, and we have discounted the former. Third, the tiers matter more than the exact position — #24 and #27 are closer than the numbers suggest. Two companies from our original long-list, Hunters and Deep Instinct, fell out after the September 2026 fact check; we keep them as cautionary cases, because what went wrong is as instructive as what went right.
The fifty sit in four tiers: the Titans (1–6), the Category Leaders (7–18), the Scale-ups and Specialists (19–32), and the AI-Era Vanguard and the Niche Leaders (33–50).
The analysis: ten things the list reveals
Read as a set, the fifty dossiers describe a machine with a recognisable operating logic — and recognisable failure modes. Ten angles follow; each ends with the decision it implies.
1. The exit machine — and its concentration risk
Five of the fifty have been sold, or agreed to be sold, for $2.4B or more since late 2023:
Wiz · Google · $32B cash · closed 11 March 2026
CyberArk · Palo Alto Networks · ~$25B cash and stock · closed 11 February 2026
Armis · ServiceNow · $7.75B cash · closed April 2026
Imperva · Thales · $3.6B · closed December 2023
BioCatch · Visa · $2.4B cash · announced August 2026, pending
Beneath them runs a long tail of $200–400M “flash exits” bought within one to five years of founding — Astrix to Cisco for about $400M, Koi to Palo Alto about twenty months after it was founded, and the unranked Seraphic, Apono and Entro — plus older mid-sized sales that built the founder base: Adallom to Microsoft (~$320M), Fireglass to Symantec (~$300M), Trusteer to IBM (~$1B), Sygnia to Temasek (~$250M), XM Cyber to Schwarz Group (~$700M).
The machine works. Wiz alone is estimated to yield about NIS 10B in Israeli tax, a roughly $1.5B return to one seed fund, and some 1,000 newly liquid engineers in Tel Aviv; Google set aside about $1.5B in retention packages. Imperva, after two changes of owner, remains “the largest and most central hub” of Thales’ global cyber division. Palo Alto now calls its Israeli operation a “primary global innovation hub”.
But look at who the buyers are. Of the acquirers above, only Thales and Schwarz are European — and Schwarz, having bought XM Cyber as a pillar of its European digital-sovereignty business, agreed in July 2026 to sell XM Cyber’s patents and source code to CrowdStrike and license them back. Even the European buyer could not hold the IP. Meanwhile the independent Israeli layer has thinned to a handful: Check Point (revenue +1% in Q2 2026, product revenue −14%), Cato (still private, IPO repeatedly deferred), Varonis (in reported acquisition talks with Proofpoint), Radware. CyberArk cut about 500 jobs within days of closing, about 100 of them in Israel, and its brand is gone.
Read the filings, too. Koi’s sale was reported at about $400M; Palo Alto’s 10-K shows $231M of purchase consideration plus $61M of replacement equity — roughly twice the Series A price set five months earlier. Excellent for the founders, but a small multiple, and the pattern the Koi dossier names: “many sub-$500M exits and few independent category leaders.”
The decision: an exit is the end of strategic control, not of value. A state that wants to keep the value must negotiate for what survives the sale — R&D continuity, retained talent, tax and option rules that keep founders’ capital building at home — because it cannot stop the sale itself.
2. Category creation is the Israeli specialty
Trace the fifty by what they invented and a lineage appears — each entry a budget line that did not exist until an Israeli company named it:
1993 · stateful-inspection firewall · Check Point (FireWall-1; ~40% of the firewall market by 1996)
1999 · privileged access management · CyberArk (for two decades, “PAM meant CyberArk”)
2003 · web-application and database firewall · Imperva (SecureSphere)
2011–16 · behavioural biometrics for banks · BioCatch
2015 · converged networking and security, later named SASE · Cato
2015 · developer-first security · Snyk · automated penetration testing · Pentera
2016 · standalone API security · Salt
2017 · cyber asset attack surface management · Axonius
2019–20 · agentless cloud scanning and the graph-based CNAPP · Orca, then Wiz
2020 · the enterprise browser · Island
2021 · AI-native data security posture · Cyera · non-human identity · Astrix · low-code-then-agent governance · Zenity
The mechanism repeats. First, a design choice that removes deployment friction — “no agents, results in minutes” was worth more to Wiz than any single feature, and the same agentless logic powered Orca, Armis, Axonius, Salt and Zero Networks. Second, naming the category before the analysts do: Astrix kept saying “non-human identity” until it became a budget line; Cycode rebranded early enough to sit in the first Gartner quadrants of two categories. Third, research as marketing: Claroty’s Team82, Orca’s Research Pod, Salt Labs, Oligo, Zenity Labs and Legit win buyers with disclosures, not advertising — the same disclosure culture that runs through Israeli academia, where offensive research on DNS and cryptographic libraries ended in patches across the internet’s backbone (Afek, Bremler-Barr & Shafir 2020; Genkin, Shamir & Tromer 2013). Fourth, standards seats: Zenity’s CTO co-leads OWASP projects; Irregular co-authored RAND’s SL1–SL5 model-weight security levels.
The warning is in the dossiers’ own lessons. “Inventing a category buys you 20 years, not forever” (Check Point, which missed or joined late next-generation firewalls, cloud and SASE). “An early category bet buys about a decade” (Aqua). Being first is not being the winner: Orca invented agentless scanning and patented it; Wiz won on sales speed and brand. Deep Instinct’s deep-learning lead lasted about five years.
The decision: fund the naming of categories, and budget for the successor product from year five. Category creation is a repeatable national skill; category defence is a separate one that Israel’s own champions have often failed at.
3. The repeat-founder flywheel
Draw the family tree of the fifty and most of the top of the list turns out to be second and third acts:
The Kramer line · Check Point (1993) → Imperva (2002) → Cato Networks (2015, with Gur Shatz, who had built Incapsula inside Imperva) · Imperva co-founder Mickey Boodaei → Trusteer (IBM, ~$1B, 2013) → Transmit Security, funded with $40M of the founders’ own money before it left stealth
The Adallom line · Rappaport, Luttwak and Reznik → Adallom (Microsoft, ~$320M, 2015) → Microsoft’s Israeli R&D centre → Wiz ($32B) · Yevgeny Dibrov, on Adallom’s founding team → Armis ($7.75B) · Michael Nicosia, Adallom’s VP of global sales → co-founder of Salt Security
The Symantec line · Dan Amiga: Fireglass (Symantec, ~$300M, 2017) → Island, recruiting Symantec’s former president Mike Fey as CEO · Ofer Smadari: Luminate (Symantec, 2019) → Torq · Lior Levy, a Symantec architect → Cycode, with Fey as seed investor and director
The Microsoft-Israel line · Idan Plotnik: Aorato (Microsoft, ~$200M) → Apiiro · Benny Lakunishok, who worked on Microsoft’s integration of Aorato and Hexadite → Zero Networks · Roni Fuchs, an early Aorato employee → Checkmarx → Legit Security
The Argus line · Argus Cyber Security (Continental, ~$430M) trained Astrix’s CEO, a Legit co-founder and Guardz’s CTO; Guardz’s CEO came from IntSights (Rapid7)
The operator lines · Spot.io (NetApp, ~$450M) → Upwind ($3.8B) · Eyal Gruner: Versafe (F5, ~$100M) → Cynet, and co-founder of Cymulate · Cybereason (valued ~$3B in 2021, a distressed sale in 2025) → 7AI, whose $130M Series A came 302 days after it left stealth
The venture data confirms the pattern: in 2024, 15 new Israeli cyber start-ups were founded by serial entrepreneurs who had already built and sold a company, up from 10 in 2023, and a handful of experienced teams raised seed rounds above $20M (YL Ventures 2024).
Two things follow. First, foreign acquisitions are founder schools. Microsoft’s purchases of Adallom, Aorato and Hexadite, and Symantec’s of Fireglass and Luminate, did not hollow out Israeli cyber; they showed the next generation the problem from inside a platform, and produced Wiz, Apiiro, Zero Networks, Island, Torq and Cycode. Second, the pipeline is wider than 8200. SentinelOne’s founders came from neither 8200 nor 81 — “no one in the country would invest in us” — and built a $1.2B-ARR public company. Checkmarx and Apiiro came from Mamram and Matzov; Pentera from an IDF IT-branch red team; Cymulate from a services firm; Forter from PayPal’s fraud operation; Irregular from IBM and Google AI research; Glow from Meta; Guardz from the go-to-market side of two acquired start-ups. Zafran’s CEO fled Tehran at 17 and left 8200 as a major.
The decision: the most valuable national asset is not the conscript but the second-time founder, and policy should be written for them — option taxation, workable non-competes, and keeping acquirers’ local R&D centres alive after the deal.
4. Build in Israel, sell from the US
Sort the fifty by headquarters and the template is unmistakable. US-headquartered with Israeli R&D: Wiz, Cyera, Claroty, Axonius, Forter, Zafran and Apiiro (New York) · Armis and Upwind (San Francisco) · SentinelOne (Mountain View) · Salt and Legit (Palo Alto) · Island and Silverfort (Texas) · Snyk, Pentera, Cynet and 7AI (Boston area) · Varonis and Guardz (Miami) · Checkmarx (Atlanta) · Orca (Portland) · Coro (Chicago). Headquartered in Israel: Check Point, Cato, Radware, Cellebrite, BioCatch, Zenity, Oligo, Cycode, Zero Networks, Sweet, Dream, Sygnia, KELA, Waterfall.
The logic is commercial, not sentimental. The buyer is American: Wiz drew up a “Wiz 100” list of Fortune 500 targets and now counts half the Fortune 100 as customers. The founder moves: Tomer Weingarten was SentinelOne’s CEO and only salesman in Silicon Valley for three years. Or the American is hired as an equal — Salt made its US sales veteran a co-founder; Island’s Amiga chose to be CTO and gave the CEO role to Fey, “very strong ... in managing Americans”. Island runs sales from Dallas while 95% of development stays in Israel. The US government is the prized anchor customer: Axonius built a separate federal subsidiary with FedRAMP authorisation and 90+ agencies; Cellebrite, Checkmarx, Oligo and Sweet are all chasing or holding FedRAMP.
The template leaks. SentinelOne’s dossier is blunt: “Israel keeps R&D only.” Salt’s: headquarters, sales “and much of the value sit in California”. Snyk’s Israeli centre shrank to about 90 people; Deep Instinct stopped recruiting in Israel in 2023. And the talent ceiling is binding: Israeli R&D wages rose 11% in the first seven months of 2024 against 7.3% for other high-tech workers (OECD 2025), Radware warns that a weak dollar will “materially increase” its shekel costs, and the scale-ups are building elsewhere — Cato in Prague and London, Coro in London.
The decision, for us, is double. Israel’s overflow is our opportunity: Prague is already a destination for its engineering capacity, and every such centre is a potential founder academy. And for our own founders, the US-first template is also the realistic one — but they should keep product leadership, not just coding, at home.
5. The AI-security wave — and who leads it
Almost every company that raised a large round in 2025–26 did so on one of two theses:
Security for AI · Cyera (data and identity controls for AI agents; $12B) · Zenity (agent governance; $125M Series C; Gartner’s “company to beat”) · Noma (agent inventory to runtime; $132M raised) · Alice (a real-world adversarial dataset sold to 8 of the 10 leading AI labs; ARR approaching $100M) · Irregular (pre-release cyber evaluations for OpenAI, Anthropic and Google DeepMind) · Glow (AI agents running application allow-listing; $180M before launch) · Oligo and Sweet (runtime protection for AI stacks) · Astrix (non-human and agent identity, now Cisco’s)
AI running security · Torq (AI SOC; a $1.2B unicorn) · 7AI (agentic SOC; $130M Series A) · Zafran (agentic mitigation) — while the incumbents re-platform: Check Point bought Lakera, Cyata and Deepchecks and hired about 500 people with AI skills; SentinelOne bought Prompt Security; Cato bought Aim; Snyk says its Evo agent layer is 60% of new deal volume
Why Israel is early: its research labs name AI threat classes first. Technion demonstrated a self-propagating prompt-injection “worm” between GenAI assistants and shipped a guardrail in the same paper (Cohen, Bitton & Nassi 2024); a BGU-led consortium mapped 33 offensive AI capabilities onto MITRE ATT&CK (Mirsky et al 2021); Irregular’s CEO co-wrote RAND’s five security levels for model weights (Nevo, Lahav et al 2024). Why now: offence automated first. A tool-using GPT-4 agent exploited 87% of fifteen real one-day vulnerabilities from the public CVE text alone, at about $3.52 a run (Fang et al 2024). That is the logic behind mitigation-first products — Zafran’s claim that 99% of “critical” vulnerabilities are not exploitable in context, Oligo’s runtime exploit blocking, Zero Networks’ deterministic containment.
Three cautions. The numbers are mostly self-reported: Noma, Zenity, 7AI and Glow disclose no absolute ARR. The platforms are buying the category: Protect AI, Prompt Security, Lakera, Aim, Pangea and CalypsoAI were acquired in about eighteen months. Trust can fail: in July 2026 Anthropic disclosed that an evaluation environment run with Irregular had live internet access, and in six runs Claude reached the production systems of three real organisations; Koi and Palo Alto are being sued over a threat report allegedly built on unverified AI output. Underneath, the national base is slipping — Israel fell from 5th to 9th on the Tortoise AI index in four years while Singapore rose from 10th to 3rd (Israel Innovation Authority 2025) — and its talent pool is narrow: only 23% of its AI professionals are women (OECD 2025).
The decision: AI security is the one field where a newcomer can still name a category — and the evaluation-and-assurance end (Irregular’s niche) is more defensible than the guardrail-feature race.
6. Platforms absorb categories — know whose roadmap you are on
The fifty are, in effect, the R&D pipeline of a handful of platforms:
Google · Wiz (cloud)
Palo Alto Networks · CyberArk (identity) · Koi (agentic endpoint) · Talon (browser, ~$625M) · Dig (data) · Protect AI — Koi was its 12th Israeli acquisition since 2014, half of its 24 significant deals, and its Tel Aviv centre now fills 22 floors of one tower
ServiceNow · Armis (exposure); an investor in Snyk
CrowdStrike · XM Cyber’s IP (attack graphs) · Seraphic (browser, reported $420M) · Flow (data) · SGNL ($627.9M, identity) · Pangea
Cisco · Astrix (non-human identity); a minority stake in Zafran
Visa · BioCatch · Thales · Imperva · Akamai · Noname ($450M), LayerX (~$205M)
Check Point, the home consolidator · eleven Israeli acquisitions in 2018–25, then Cyata, Cyclops, Rotate and Deepchecks in 2026
Israeli scale-ups as consolidators · Wiz (Gem, Dazz, Raftt) · Cyera (Trail, Otterize, Ryft, Genie, Oasis) · Torq (Revrod, Jit) · Silverfort (Fabrix) — five Israeli cyber start-ups bought other young Israeli start-ups in 2024 alone (YL Ventures 2024)
For the independents this is a squeeze. Claroty lost Armis, its closest rival, to ServiceNow and now sells neutrality. Axonius’s most logical buyers are the platforms it competes with. Salt is “the last large standalone player” in API security after Noname sold for $450M, less than half its old $1B mark. The ASPM trio — Apiiro, Cycode, Legit — face Palo Alto’s Cortex Cloud, Wiz Code and GitHub bundling the same view. Hunters learned that “SIEM is a platform market”.
The fifty show four survival strategies: neutrality as a product (Axonius; Zenity across Copilot, ChatGPT, Claude and Cursor; Torq’s “CrowdStrike finds threats, Torq finishes them”), becoming the consolidator (Cyera), partnering with the giant you would otherwise fight (Silverfort with Microsoft, Radware’s OEM deals with Check Point and Cisco, Waterfall with Siemens Energy), and selling at the peak of demand (Astrix, sold as Cisco needed an agent-identity layer; Koi, whose buyer had used its product internally for months before the deal).
The decision: the exit market sets the floor and the platform roadmap sets the ceiling. Founders should map their likely buyers from the first round, as Astrix’s investors did.
7. Stale unicorns and the valuation reset
The 2021–22 cohort is still carrying its peak-cycle prices:
Snyk · $8.5B peak (2021), $7.4B last priced (2022), investor marks about $3.7B, a private-equity bid below $3B rejected, an interim CEO
Forter · $3B (May 2021) · no price and no revenue figure disclosed since
Transmit · $2.2B on a $543M Series A (June 2021) · about 326 staff
Orca · $1.8B (October 2021) · about 350 staff after raising roughly $630M
Salt · $1.4B (February 2022) · about $75M reported revenue, about 170 staff
Aqua · “above $1B” and flat since 2021 · both founders stepped back in November 2025
Pentera · about $1B since January 2022, despite ARR growing more than threefold
Cymulate · about $500M (2022), after promising a unicorn “within two years”
The extreme case sits just outside the list: Cybereason, valued at about $3B in 2021, was worth about $300M a year later. Now set the 2025–26 cohort beside it: Upwind from $900M to $3.8B in 21 months with no ARR disclosed; Cyera from $1.4B to $12B in about two years at a reported ~80x ARR; Dream from $1.1B to $3B in 16 months on a customer base one investigation put at fewer than ten; Glow from $400M to $1.2B while still in stealth.
The mechanics that turn a price into a trap are all in the dossiers: a preference stack that any exit must clear (Transmit), an IPO bar of roughly $500M revenue (Claroty, Upwind), and the liquidity drag that forces secondaries as a retention tool (Island, Claroty’s $50M, Cato’s ~$120M). The companies that escaped did it with discipline — Pentera grew into its price, Axonius raised $200M flat by choice, Claroty waited until growth carried it back above its peak.
The decision: model the exit at normal multiples before joining a peak round. The question for 2029 is how many of today’s AI-security marks become the next stale unicorns.
8. Capital as a weapon versus capital efficiency
Two strategies coexist in the fifty, and both work — in different conditions:
Capital as a weapon · Wiz ($1.9B raised) · Cyera (over $2.3B in five rounds in 26 months; about $7M per employee for the Genie acquisition) · Island (~$730M; every competitor had to raise “in Island’s shadow”) · Upwind (~$730M) · Glow ($180M before launch)
Capital efficiency · BioCatch (EBITDA breakeven at about $100M ARR in 2022, then Permira, then Visa) · KELA (profitable since inception; one outside round in seventeen years) · Sygnia ($4.3M raised, sold for ~$250M within three years) · Checkmarx (~$100M raised, a $1.15B buyout) · Cynet (~$78M disclosed; 1,100+ direct customers and 9,000+ through partners) · Cycode (~$81M; a Gartner Leader) · Zero Networks (just over $100M; revenue doubling; net retention above 120%)
The weapon works when three conditions hold at once: a proven team, a land-grab category, and growth that is real — Wiz’s refusal of $23B was right only because it then reached $1B ARR. It fails when the round sets the headcount plan: Deep Instinct planned for 400 people and is down to about 180; Hunters raised about $100M in five months to double its staff; Coro raised about $255M in two years in a small-ticket SMB market; Snyk lost $267M on $147M of revenue in 2022.
Efficiency has its own exit menu, and private equity is on it: Thoma Bravo took Imperva private for $2.1B and sold it for $3.6B; Hellman & Friedman bought Checkmarx; Insight bought Armis outright for $1.1B in 2020 and saw it sold for $7.75B; Temasek bought Sygnia; Vector took a growth stake in KELA.
The decision: for an ecosystem with less capital than Tel Aviv, the efficient model is the portable one. A profitable company with $100M ARR “can be sold to PE, then to a strategic ... without ever needing an IPO window” (BioCatch).
9. The national-security-adjacent firms: advantage and liability
A distinct cluster of the fifty sells intelligence-grade capability: Cellebrite (phone forensics), Dream Security (national cyber defence and “sovereign AI”), Sygnia (incident response), KELA (cybercrime intelligence), XM Cyber (attack-path modelling, founded by a former Mossad director) and Irregular (testing the offensive capability of frontier AI). Offensive-spyware vendors — NSO, Paragon, Candiru — are excluded from the ranking altogether.
The advantage is real. Sygnia’s ex-8200 responders led the investigation of the $1.5B Bybit theft; Temasek bought the firm, and with it a capability Singapore chose not to build. KELA’s research on the group behind the Trivy supply-chain attack went to the Australian Federal Police and the FBI, and two men were charged in August 2026.
The liability is equally real. Cellebrite sold to Russia, Belarus, Hong Kong, China, Bangladesh and Myanmar before cutting them off; after Amnesty showed Serbian police using its tools to unlock a journalist’s phone and plant spyware, it suspended Serbian customers — but called similar Citizen Lab findings on Jordan and Kenya “speculation”, and publishes no vetting criteria. Dream was co-founded by NSO’s co-founder, Shalev Hulio, whose indictment a Barcelona court ordered in 2025; an investigation found 12 staff who had worked at NSO or other spyware firms; its “sovereign” systems come from a company with about 85% of its staff in Israel.
There is a deeper caution in the library. The October 7 failure was “not the result of a single glaring failure but rather the accumulation of several problems”; among them, a non-commissioned officer in 8200 warned in July 2023 that a Hamas exercise closely followed the attack plan, and her superiors dismissed the analysis as “aspirational” (Wyss, CTC Sentinel 2024). A system that selects talent brilliantly does not thereby guarantee it listens to it.
The decision for a buyer state: legitimacy is part of the product — demand systematic, published end-use vetting, and when buying “sovereign” capability insist on source-code access, local hosting and staff, and clean exit clauses. “Sovereignty rented from a foreign vendor is still dependency” (Dream Security dossier).
10. What the cautionary cases teach
Hunters and Deep Instinct fell out of the fifty, but their failure modes run through the list:
Right architecture, no distribution. Hunters bet early and correctly on the data-lake SIEM, with Snowflake, Databricks, Okta, Cisco and Microsoft’s M12 as investors. It had no telemetry of its own; the endpoint platforms turned SIEM into a bundle. No financing since January 2022; a newsroom silent since March 2025.
A technical lead without a platform. Deep Instinct applied deep learning to raw malware bytes — an idea traceable to Bar-Ilan research funded by a state consortium (David & Netanyahu 2015) — and won an HP OEM deal that brought “volume, not ownership”. The lead lasted about five years.
Hiring to the round. Deep Instinct’s 400-person plan, Hunters’ planned doubling, Cybereason, Coro.
A workflow moat eroded by AI. Snyk and Checkmarx lost standing as coding agents and frontier models absorbed code scanning; Pentera is now outgrown by AI-native Horizon3.ai.
Forecasting valuations in public. Deep Instinct’s “several unicorns within nine months”, Cymulate’s “unicorn within two years”.
Forgetting that security vendors are targets. Aqua’s open-source Trivy scanner was hijacked in March 2026, and the stolen credentials were reused to poison Checkmarx’s GitHub Actions.
The system’s resilience is the counterpoint. Cybereason’s founders came back as 7AI; Hunters’ CTO now lists its seed investor as his affiliation; Deep Instinct’s own dossier counts the engineers who moved on to the next wave as its lasting contribution. The decision: judge an ecosystem by how cheaply it recovers from failure — how fast talent is re-absorbed — not by the size of the rounds it celebrates.
The Fifty, tier by tier
What follows is the reference layer: one entry per company, in ranked order — what it is, why it sits where it does, and the one thing to learn. Status is as of 22 September 2026. Each entry points to its full ~1,000-word dossier in the companies/ folder.
Tier I — The Titans (1–6)
The six companies that define what the Israeli system can produce at full scale: two of the three largest exits in the country’s history, its oldest champion, its most valuable independent, and its largest listed challenger.
01. Wiz — Cloud security (CNAPP) · acquired by Google for $32B in cash, closed March 2026. An agentless security graph across AWS, Azure, GCP and Oracle that surfaces the handful of “toxic combinations” among 100,000 findings. The largest Israeli exit ever and the fastest-growing security company on record: $1M to $100M ARR in about 18 months, over $1B in 2025. It refused Google’s $23B and got $32B eight months later. Lesson: a repeat team plus zero deployment friction compounds. → 01 - Wiz.md
02. CyberArk — Identity security / privileged access · acquired by Palo Alto Networks for ~$25B, closed February 2026; now “Idira”. The vault for an organisation’s all-powerful accounts, stretched by acquisition from humans (the core product) to machines (Venafi) to AI agents. Ranked second for two decades of category ownership and a painful licence-to-SaaS shift that left 88% of $1.44B ARR as subscription. Lesson: own one control point — least privilege — and extend it across every identity type. → 02 - CyberArk.md
03. Check Point Software Technologies — Network security platform · public (Nasdaq: CHKP), ~$13.7B. It invented the commercial stateful firewall in 1993 and became Israel’s founder academy. Ranked on history, ~40% operating margins and $4.2B of cash, not growth: Q2 2026 revenue rose 1% and product revenue fell 14%. Under CEO Nadav Zafrir it is buying AI-security teams (Lakera, Cyata, Deepchecks). Lesson: profitability becomes a trap when rivals reinvest in adjacent categories. → 03 - Check Point Software Technologies.md
04. Cyera — AI-native data security, now a data-and-identity layer for AI agents · independent, $12B (June 2026). Agentless AI classification that tells a company what sensitive data it holds and who — or which agent — can reach it; the $1B Oasis purchase adds non-human identity. The most valuable independent Israeli cyber company — at a reported ~80x ARR, and loss-making. Lesson: re-run a proven architecture (Wiz’s agentless graph) on a new asset. → 04 - Cyera.md
05. SentinelOne — Autonomous endpoint, XDR and AI SIEM · public (NYSE: S), ~$8.3B. One lightweight agent on its own data lake; half of its $1.22B ARR now comes from beyond the endpoint. The largest independent Israeli-founded pure play still growing above 20% — but still at a −31% GAAP operating margin and below its ~$9B IPO valuation. Lesson: outsiders can win; founders turned down by Israeli VCs went straight to the US, with the CEO as sole salesman. → 05 - SentinelOne.md
06. Armis — Asset visibility and exposure management · acquired by ServiceNow for $7.75B in cash, closed April 2026. Agentless discovery of every connected device, from printers to infusion pumps, checked against a knowledge base of some 7 billion devices. Sold at about 23x ARR while growing over 50% at $340M+, six years after Insight’s $1.1B buyout. Lesson: find the pain before the product — its founders cold-called CISOs before choosing one. → 06 - Armis.md
Tier II — The Category Leaders (7–18)
Companies that own a category, or created one, but have not reached Titan scale — because they are still private, too narrow, already absorbed, or carrying governance or growth questions.
07. Cato Networks — SASE · independent, $4.8B; ARR $415M+, growing ~42%. Networking and security written as one cloud stack on its own global backbone; a Gartner SASE Leader three years running, and Shlomo Kramer’s third company. Below the Titans because it is private, smaller than Palo Alto’s $1.5B SASE line, and its IPO keeps slipping. It is tripling its Prague R&D centre. Lesson: replace a budget (the WAN) rather than add a line item. → 07 - Cato Networks.md
08. Island — Enterprise browser · independent, $4.8B; ~$200M revenue growing ~100% (founder-stated). A Chromium browser with a policy engine at the last mile — copy, paste, download and AI-prompt control without VDI or VPN; eight of the ten largest banks use it. It created the category; it sits here because its figures are unaudited and Palo Alto’s Prisma Browser is bundling the idea. Lesson: take over a default application instead of adding an agent. → 08 - Island.md
09. Varonis — Data security · public (Nasdaq: VRNS), ~$5.6B; Proofpoint reported in acquisition talks. Twenty years of permissions metadata with automated remediation — an unglamorous file-access problem made urgent by AI copilots. SaaS is now 95% of revenue after a transition that drove the stock to a $19.70 low. Growth in the high teens keeps it mid-tier. Lesson: boring structural problems make durable franchises. → 09 - Varonis.md
10. Claroty — Cyber-physical systems security · independent, ~$3B; ARR over $200M. Built inside the Team8 foundry and sold through its investors Siemens, Rockwell and Schneider to plant engineers who distrust IT vendors. With Armis gone to ServiceNow, it is the leading independent in OT, IoT and medical-device security — still pre-profit, and well short of the ~$500M revenue a listing now needs. Lesson: strategic investors can be your sales force. → 10 - Claroty.md
11. Axonius — Cyber asset and exposure management · independent, $2.6B; ARR over $200M. A neutral, agentless layer that correlates 1,400+ data sources to answer “what do we actually have?”, with a FedRAMP-authorised federal arm serving 90+ agencies. Close to cash-neutral; it raised $200M flat by choice. Held back because it is single-category and its likely buyers are its competitors. Lesson: pick the unsexy, universal problem. → 11 - Axonius.md
12. Upwind — Runtime-first cloud security · independent, ~$3.8B (September 2026). It sees what actually executes inside cloud workloads and is the leading independent alternative to Google-owned Wiz. Built by the Spot.io team after its sale to NetApp. The fastest-rising valuation of 2026 — $900M to $3.8B in 21 months — with no ARR disclosed, hence #12. Lesson: when the category leader is acquired, the independent number two gets a window. → 12 - Upwind.md
13. Imperva — Web application, API and data security · acquired by Thales for $3.6B, December 2023. Two decades of web-application and database-firewall IP, and two exits (Thoma Bravo at $2.1B, then Thales). Its founders went on to Trusteer, Incapsula and Cato, and Israel remains Thales’ largest cyber hub. Ranked on franchise and founder yield rather than independence. Lesson: a first company that trains founders is worth more to an ecosystem than its own exit. → 13 - Imperva.md
14. Cellebrite — Digital forensics for law enforcement · public (Nasdaq: CLBT), ~$2.4–2.8B. The global default for extracting court-admissible evidence from seized phones: ~86% gross margin, 117% net retention, ARR of $508M. Documented misuse by customers in Serbia, Jordan and Kenya, a 2026 guidance cut and three CEOs in about twenty months keep it mid-table. Lesson: when you sell to governments, legitimacy is part of the product. → 14 - Cellebrite.md
15. BioCatch — Behavioural biometrics for banks · Visa agreed to acquire for $2.4B (August 2026, pending). It reads how a customer types, swipes and holds the phone to catch scams in which password, device and customer are all genuine — 19 billion sessions a month across 350+ banks. EBITDA breakeven at $100M ARR, then Permira, then Visa. One vertical and one signal keep it at #15. Lesson: sell to the budget that feels the loss. → 15 - BioCatch.md
16. Forter — E-commerce fraud prevention · independent, $3B (2021, stale). A one-second approve-or-decline decision drawn from a cross-merchant identity graph, backed by a chargeback guarantee: it sells an outcome, not a score. Mid-table because it sits beside core cybersecurity and has disclosed neither a new price nor revenue since 2021. Lesson: underwrite your own accuracy — a guarantee turns a risk tool into a revenue product. → 16 - Forter.md
17. Snyk — Developer-first application security · independent; last priced at $7.4B, now marked ~$3.7B; interim CEO. It created developer security with a free tier and automatic fix pull-requests, reaching $325M+ ARR. Growth slowed to about 12%, its Israeli team shrank to about 90, and coding agents now threaten the workflow it owned — its Evo agent layer is 60% of new deals. Lesson: a workflow moat lasts only as long as the workflow. → 17 - Snyk.md
18. Radware — DDoS and application protection · public (Nasdaq: RDWR), ~$1.24B. Carrier-grade DDoS protection in appliance and cloud form; profitable, with $400M+ in liquid assets, founder-run for 29 years, and cloud ARR past $100M growing 22%. Long-run growth of 3–4% a year and related-party governance hold it at #18. Lesson: durability is a strategy — but venture bets incubated inside a slow public company (SkyHawk) rarely survive. → 18 - Radware.md
Tier III — The Scale-ups and Specialists (19–32)
Unicorns and near-unicorns of two vintages: the 2021 cohort still growing into peak prices, and the 2025–26 cohort raising on the AI thesis.
19. Torq — AI SOC · independent, $1.2B (January 2026). AI agents triage and respond across whatever tools a customer already runs, on a no-code automation engine that was ready when LLMs arrived. Repeat founders (Luminate, sold to Symantec) with Check Point engineering roots. Last disclosed ARR was $24M+ (2024) against a $100M target. Lesson: build the plumbing before the magic. → 19 - Torq.md
20. Orca Security — Agentless cloud security · independent, $1.8B (2021). It invented and patented SideScanning — full cloud coverage in minutes — and then lost the scale race to Wiz, which used the same idea with faster enterprise selling. About 350 staff now carry a five-year-old mark. Lesson: being first is not enough; weigh go-to-market ability as heavily as technical originality. → 20 - Orca Security.md
21. Silverfort — Identity protection · independent, ~$1B (January 2024). It enforces MFA inside the authentication stream itself, reaching legacy apps, command-line admin tools and service accounts that other products cannot; it claims 10 billion authentications analysed a day. No ARR disclosed since “tens of millions”. Lesson: build at the point of enforcement, and solve the ugly legacy problem first. → 21 - Silverfort.md
22. Transmit Security — Customer identity, passwordless and fraud · independent, $2.2B (2021). Login, identity orchestration and fraud scoring for banks such as Citi, JPMorgan and HSBC — Mickey Boodaei’s third company after Imperva and Trusteer. No new capital in five years, no revenue disclosed, and a $543M preference stack any exit must clear. Lesson: a serial founder’s most durable asset is the buyer relationship. → 22 - Transmit Security.md
23. Aqua Security — Container and cloud-native security · independent, above $1B (flat since 2021). It pioneered container runtime security in 2015; its open-source Trivy scanner is the developer funnel — and in March 2026 was hijacked to steal CI/CD secrets. Its founders handed over to a sales-led CEO in 2025. Lesson: open source is distribution and attack surface at once; release engineering is a security function. → 23 - Aqua Security.md
24. Checkmarx — Application security testing · owned by Hellman & Friedman ($1.15B, 2020). A static-analysis engine embedded in 60% of the Fortune 100, founded out of the Mamram and Matzov units, with its CTO still in place after twenty years. A sale process seeking $2.5B+ has produced no deal, and AI is compressing classic scanning. Lesson: private equity is a real exit path for a capital-efficient enterprise vendor. → 24 - Checkmarx.md
25. Pentera — Automated security validation · independent, ~$1B (flat since 2022). It runs real exploits safely in production networks — a one-day proof of value that ends in domain admin — and was first in its category to $100M ARR. AI-native Horizon3.ai now outgrows it, and two 2026 layoff rounds cut about 20% of staff. Lesson: automate the job you did yourself — then add ML talent before AI redefines it. → 25 - Pentera.md
26. Salt Security — API security · independent, $1.4B (2022). It made API security a budget line, using behavioural baselines of API traffic to catch logic abuse, and now pitches “agentic security”. It is the last large standalone player after Noname and Traceable were absorbed, on about $75M of reported revenue. Lesson: ask early whether your category can survive on its own. → 26 - Salt Security.md
27. Dream Security — AI-native national cyber defence · independent, $3B (June 2026). It sells state-actor detection and “sovereign AI” to governments, with ARR above $100M within three years, largely through a former Austrian chancellor’s access. NSO lineage, a founder facing a Spanish indictment order, and a very small customer base cap it at #27. Lesson: in government markets distribution is the moat — and investors must price the tail. → 27 - Dream Security.md
28. Glow — AI-native endpoint security · independent, $1.2B (out of stealth July 2026). AI agents make application allow-listing — a category that failed because humans could not maintain the lists — workable, deciding which coding agents and MCP servers may run on a laptop. $180M raised; no revenue disclosed; ranked on team and thesis. Lesson: revive a “right idea, wrong decade” category once technology removes its constraint. → 28 - Glow.md
29. Zenity — Security and governance for AI agents · independent; $125M Series C (August 2026). It finds, governs and blocks AI agents across Copilot, ChatGPT, Claude and Cursor; it began in 2021 on low-code governance, and the market grew into its category. Revenue triples yearly from an undisclosed base, and Microsoft is both channel and competitor. Lesson: choose a wedge that sits just ahead of a bigger trend. → 29 - Zenity.md
30. Zafran — Threat exposure management and mitigation · independent; over $140M raised. It asks whether a “critical” vulnerability is running, reachable, already blocked or actively exploited — and then mitigates through controls the customer already owns. Founded by two decorated 8200 majors and a Unit 81 technologist; ARR has tripled, but is still “in the millions”. Lesson: reframe the question and the backlog shrinks. → 30 - Zafran.md
31. Noma Security — AI and AI-agent security · independent; $132M raised. One platform to find agents — typically 10 to 100 times more than teams expect — map their tools and MCP connections, red-team them and govern them at runtime. ARR up 1,300% from an undisclosed base, with Zenity as a direct Israeli rival. Lesson: build the angel round out of the CISOs you want as customers. → 31 - Noma Security.md
32. Oligo Security — Runtime application and AI security · independent; ~$140M raised. A kernel-level eBPF sensor that sees whether the vulnerable function inside an open-source library ever executes — and blocks the exploit if it does. Its research disclosures (ShadowRay, 0.0.0.0-Day) are its marketing. About 100 staff in a runtime market dominated by platforms. Lesson: go one level deeper than the incumbents look. → 32 - Oligo Security.md
Tier IV — The AI-Era Vanguard and the Niche Leaders (33–50)
Two kinds of company share the bottom tier: very young firms ranked on team, thesis and early momentum, and long-lived specialists that dominate a narrow market. Both are where the next Titans — and the next cautionary cases — will come from.
33. 7AI — Agentic SOC · independent; $130M Series A at ~$700M. AI agents triage and investigate alerts on top of a customer’s existing tools, sold channel-first through DXC. Founded by two of Cybereason’s co-founders; every metric is self-reported and the company is under two years old. Lesson: talent from a failed company comes back — pick the channel on day one. → 33 - 7AI.md
34. Irregular (formerly Pattern Labs) — Frontier AI security lab · independent; ~$450M (2025). It tests unreleased models from OpenAI, Anthropic and Google DeepMind for offensive cyber capability, and its CEO co-authored RAND’s SL1–SL5 model-weight security levels. About 25 staff; in 2026 its test environments reached the real internet. Lesson: sell to the people who create the risk — and run offensive-AI test ranges as critical infrastructure. → 34 - Irregular.md
35. Alice (formerly ActiveFence) — AI safety and security · independent; $140M at ~$700–800M (August 2026). Eight years of labelled real-world abuse data turned into red-teaming and guardrails for eight of the ten leading AI labs; ARR approaching $100M. A mixed, services-heavy business, priced accordingly. Lesson: an old dataset can be the ticket into a new market. → 35 - Alice.md
36. Sygnia — Incident response and MDR · owned by Temasek (~$250M, 2018). The ex-8200 team boards call mid-breach, turning crises into retainers and managed detection. A Team8 foundry company sold at about 58 times its capital within three years; two CEO changes in 2025. Lesson: services can yield a venture-scale exit if you sell to the top of the market and exit early. → 36 - Sygnia.md
37. XM Cyber — Exposure management and attack paths · owned by Schwarz Group (~$700M, 2021); CrowdStrike buying its IP. It models an estate as a graph and finds the “choke points” where attack paths converge — an offensive planner’s view from a former Mossad director. It will now license back its own technology. Lesson: make the attacker’s mental model the product. → 37 - XM Cyber.md
38. Zero Networks — Automated microsegmentation · independent; over $100M raised. It makes a proven but consultant-heavy control deployable in weeks: agentless rules generated automatically, MFA at the network layer. Revenue doubled, net retention above 120%, 99% of customers retained — from a small base. Lesson: look for proven ideas that failed on deployment. → 38 - Zero Networks.md
39. Apiiro — Application security posture management · independent; ~$135M raised. Deep code analysis maps software architecture and flags only material, risky changes; it is now moving into governing AI coding agents. It walked away from a $500–600M Palo Alto deal in 2022 and grew ARR 104% in 2025. Lesson: repeat founders carry a method, not a product. → 39 - Apiiro.md
40. Cycode — ASPM and software supply-chain security · independent; ~$81M raised. Its own scanners plus a code-to-runtime context graph; a Leader in Gartner’s first Software Supply Chain Security Magic Quadrant (2026). Capital-efficient, but without a priced round since 2021. Lesson: enter through the gap incumbents ignore — build pipelines and leaked secrets in 2019. → 40 - Cycode.md
41. Cymulate — Breach and attack simulation · independent; ~$500M (2022). Easy SaaS attack simulation across 1,000+ customers, now generating detection rules and fixes as well as tests. Born inside a penetration-testing services firm; it missed its own public unicorn deadline. Lesson: productise the services work you keep repeating — and never forecast your valuation. → 41 - Cymulate.md
42. Astrix Security — Non-human identity and AI-agent security · acquired by Cisco for ~$400M (June 2026). It named “non-human identity” early and extended one identity graph from SaaS tokens to AI agents, selling within five years of founding on about $85M raised. Lesson: a short category name buyers repeat can do more than features. → 42 - Astrix Security.md
43. Koi Security — Software supply-chain and “agentic endpoint” security · acquired by Palo Alto Networks, closed April 2026. It inventories and controls what users install for themselves — browser extensions, IDE plugins, packages, MCP servers — which endpoint tools mostly ignore. Founded in 2024 and sold about twenty months later: reported at ~$400M, though Palo Alto’s 10-K shows $231M plus $61M of replacement equity, roughly twice its Series A price. Lesson: prove the attack before you sell the defence — its fake VS Code theme reached 300+ organisations in a week. → 43 - Koi Security.md
44. Sweet Security — Cloud and AI runtime security · independent; ~$120M raised. An eBPF sensor plus cloud logs that now blocks rogue AI-agent behaviour, founded by the IDF’s former CISO after he failed to find a good enough cloud detection tool for the army’s move to the public cloud. ARR up sixfold from an undisclosed base. Lesson: start from a buyer problem you owned yourself. → 44 - Sweet Security.md
45. Legit Security — ASPM and AI-generated-code security · independent; $77M raised. It maps the “software factory”, ranks findings with its own scanners, and governs coding agents such as Claude Code and Cursor. Founded by Checkmarx veterans; no round since 2023. Lesson: aggregate, but own something — and use offensive research as marketing. → 45 - Legit Security.md
46. KELA — Cybercrime threat intelligence · independent (Vector Capital minority stake). Fifteen years of underground data plus human analysts; bootstrapped for nine years and profitable since inception; bookings up 101% last year; its research fed the TeamPCP arrests. Lesson: proprietary data compounds, and public-interest work is a sales channel. → 46 - KELA.md
47. Cynet — All-in-one XDR with bundled MDR · independent. One agent, one console and a human SOC in the box for companies that have no SOC; MSPs brought 64% of its Q4 2025 deals, on about $78M of disclosed funding. Lesson: build for the buyer the leaders underserve, and bundle the service into the software. → 47 - Cynet.md
48. Guardz — SMB security and MDR sold through MSPs · independent; $84M raised. One multi-tenant console that lets an outsourced IT provider secure dozens of small clients — identity, email, endpoint, cloud data — with AI triage and a human MDR team behind it. It owns the glue and rents the engines: SentinelOne (also an investor) for endpoint, Check Point for email. ARR grew 500% and then 300%, from an undisclosed base. Lesson: sell to the intermediary, not the end customer — and note that exits create founders; its own came from IntSights and Argus. → 48 - Guardz.md
49. Coro — Unified SMB security platform · independent; ~$275M raised. One agent and many modules for lean-IT mid-market firms, sold 100% through partners since 2025. Hypergrowth was followed by a reset and a channel veteran replacing the founder as CEO. Lesson: heavy capital in a small-ticket market becomes a burn problem the moment growth slows. → 49 - Coro.md
50. Waterfall Security Solutions — OT unidirectional gateways · independent. Hardware that lets data leave a power plant or rail network while nothing can come back in — an approach NERC CIP, US nuclear rules and France’s ANSSI reward or require. About 100 staff after nineteen years. Lesson: make the regulator your sales team, and sell certainty where failure is physical. → 50 - Waterfall Security Solutions.md
The cautionary cases
C1. Hunters — SOC platform / data-lake SIEM · no financing since January 2022. Right about architecture, backed by Snowflake and Databricks, beaten by platforms that own telemetry. → C1 - Hunters.md
C2. Deep Instinct — Deep-learning malware prevention · headcount down from ~400 to ~180. A genuine technical edge that never became a scaled business. → C2 - Deep Instinct.md
What this means for us
The Czech Republic starts from a better position than its size suggests — and with a clearer diagnosis of its gap than most. NÚKIB’s 2026 strategy lists real strengths: an advanced national system, internationally respected experts, a working community across state, business and academia, and the observation that “some of the most widely used commercial ICT security tools are developed by Czech companies or have domestic origins”. It is equally frank about the weaknesses: staffing and funding “insufficient in both the public and private sectors”, rigid public-sector pay, a still-reactive state, and an EU-wide shortage of up to 300,000 experts (NÚKIB 2026). The country has publicly attributed attacks to Russia (May 2024) and China (May 2025). It has the talent and the threat. What it lacks is the machine that turns the one into companies.
What to copy
Founder academies, deliberately. Treat anchor companies and foreign R&D centres as schools for the next founders, and make leaving easy. Microsoft’s and Symantec’s Israeli centres produced Wiz, Apiiro, Zero Networks, Torq and Cycode.
Specialist seed capital with a CISO network. One domain-expert fund, Cyberstarts, backed Wiz, Cyera, Island and Upwind early. Pair such funds with global VCs in “split-seed” rounds — twelve in Israel in 2024 (YL Ventures 2024).
A foundry wired to buyers. Team8 started from a thesis and a network of corporate security chiefs and produced Claroty and Sygnia. Our equivalent is a foundry tied to the operators regulated under the new Cyber Security Act.
The state as the demanding first customer. Axonius built a federal arm around FedRAMP; Waterfall made regulators its sales team. In Europe, NIS2 and the new Cyber Security Act are our FedRAMP: rules that turn security into a budget line.
An alumni engine for our own units. 8200’s formal alumni association (14,000+ members) and its accelerator turn service into a network (Rousseau 2017). The Czech Cyber and Information Warfare Command and NÚKIB can build the same.
A wide intake. Israel’s Magshimim trains gifted coders from underprivileged areas (IISS 2021), and many of the fifty came from outside 8200 altogether — SentinelOne, Checkmarx, Cymulate, Forter, Irregular.
What not to copy
Spyware and inconsistent end-use vetting. The NSO lineage is a permanent liability, as Dream’s diligence file shows. Cellebrite’s uneven response to Amnesty and Citizen Lab findings shows how an ethics process that looks arbitrary gets priced in.
Peak-cycle mega-rounds and hiring to the round. Transmit, Snyk, Cybereason and Deep Instinct are the evidence.
Selling anchors with nothing negotiated. CyberArk cut about 500 jobs within days of closing. Snyk’s Israeli team fell to about 90.
Faith in technical superiority over judgement. Before October 7, an 8200 non-commissioned officer’s warning was dismissed as “aspirational” (Wyss, CTC Sentinel 2024).
A narrow talent base. Only 23% of Israel’s AI professionals are women (OECD 2025). NÚKIB’s commitment to equal opportunity for women and non-graduates is the better starting point.
Rented sovereignty. “Sovereign” systems built by a foreign vendor are still dependency — and so is European hosting of US-owned IP, the arrangement under which CrowdStrike agreed to buy XM Cyber’s patents from its German owner.
Five moves for the next twelve months
Stand up a cyber foundry with ten critical-infrastructure buyers. NÚKIB convenes energy, banking, health and transport operators as design partners and first customers. The foundry picks theses from their unsolved problems and recruits founding teams against them, Team8-style. Target: three companies incorporated within the year.
Seed a specialist cyber fund with the state as anchor LP. The fund needs a domain-expert general partner with a CISO network, and a mandate to co-invest alongside tier-one international funds at seed. It should be judged on follow-on rounds raised, not on deployment speed.
Recruit Israel’s overflow, on spin-out-friendly terms. Cato is already tripling its Prague centre, and Israel’s talent ceiling pushes its scale-ups abroad. Make Prague and Brno the default second R&D site for Tier II–IV companies, with fast work permits and R&D tax treatment. Pair that with employee-option taxation at exit and no punitive non-competes, so today’s hires become tomorrow’s founders.
Make the state a demanding first customer, with sovereignty conditions. Create a procurement track for young domestic vendors of the “secure technological alternatives” NÚKIB calls for. Fund NIS2-driven SMB security programmes delivered through managed service providers — the channel Guardz and Coro were built for, and a market the enterprise-focused ecosystem neglects. Foreign “sovereign” suppliers should have to provide source-code access, local hosting and staff, published end-use vetting and clean exit clauses.
Build a national AI-security gym and disclosure pipeline. The library finds no Israeli public equivalent of DARPA’s AIxCC or the Five Eyes’ CAGE challenges, and flags this as a gap a mid-sized EU state could fill (Zhang et al 2026; Standen et al 2021). A Masaryk University researcher already co-authored NATO’s reference architecture for autonomous cyber-defence agents (Kott et al 2019). A cyber range where defensive AI agents are trained, tested and certified, plus a coordinated-disclosure pipeline through the national CERT, would put Czech teams in the evaluation-and-assurance niche. That is where categories are still being named.
For founders, the fifty compress into five habits: name the category, remove the deployment objection, make the American seller a co-founder, map the likely buyers from the first round, and never forecast your valuation. For investors: pay up for repeat teams, ask for ARR before paying for momentum, model every exit at normal multiples, and treat private equity as an exit, not a failure.
Close
Israel’s fifty are not a list of lucky start-ups. They are the visible output of a machine: it selects talent early, trains it on state-scale problems, passes it through anchor companies and specialist funds, and recycles every exit into the next founding team. In 2025–26 the machine delivered its best year and exposed its weakness in the same stroke: the champions it builds are sold, and strategic control goes with them.
A mid-sized European state does not need its own Wiz to benefit. It needs the conditions in which the second-time founder stays, the foreign R&D centre becomes a founder school, and the state is a demanding first buyer rather than a grant office. Those conditions are copyable, cheap next to what they return, and slow to build. The option value lies in starting now: every year of delay is another cohort of engineers trained in Prague and Brno whose first company gets built somewhere else.



