Welcome back to the Trident Radar

Slightly longer radar this week, hope you enjoy some extended thought leadership!

A strong week at the top of the market. Neo Security came out of stealth with $100 million to secure enterprise AI, Risk Ledger raised $32 million to take supply-chain security into the United States, and the team that invented risk-based vulnerability management resurfaced with $25 million and some unfinished business. Twenty raised again barely a month after its last round, this time at a $1.2 billion valuation.

We also look at the other side of the ledger this week, the companies that quietly disappeared. Shoutout to Silvio at AuthMind for the idea!

Oh and a new layout!

Let's dive in.

TL;DR

Neo Security raises $100M. Out of stealth with backing from Bessemer, Craft Ventures and Andreessen Horowitz, to control and secure enterprise AI.

Risk Ledger takes $32M. The London supply-chain security platform raises a Series B and sets course for the US market.

Empirical Security raises $25M. The Kenna Security and EPSS founders return to rebuild vulnerability management for the AI era.

Twenty raises $30M from Khosla at a $1.2B valuation, a month after its $100M round.

Beacon Security ($13M), Cranium AI ($20M) and Glow (undisclosed, Redpoint) all add to a busy week for AI security.

This week's Trident View: PitchBook records 90+ cyber companies closing their doors this year, and they are not the ones you would expect.

This week's Insider Insight: the model that lasted a week is back, and the precedent it set is the story.

The Trident View

The Companies Nobody Writes About

Every week this newsletter counts the money going in.

Almost nobody counts what goes out.

Since the start of the year PitchBook has recorded over 100 cybersecurity companies ceasing operations across the United States, Europe and Israel. That is more than three a week, every week, all year, and it happens almost entirely without coverage. A funding round gets a press release but a closure gets a quiet notice? Yeah that feels wrong and shows a lack of learning!

Here is the part that surprised me.

You would assume these were mostly startups that never found a market. They were not. The median company on that list was seven years old when it closed and only fifteen were three years old or younger. Sixteen had been trading for more than twelve years, and the oldest, a New Jersey security compliance business, was founded in 1999.

These were not failed experiments. They were companies that found a product, raised money, hired teams and sold to real customers for the better part of a decade. Then the ground moved underneath them.

Why? Three things:

The growth round disappeared. Capital has concentrated so hard at the top that the middle has been hollowed out. Last quarter, roughly 80% of every venture dollar in cyber went to AI-native companies and the ten largest rounds took two thirds of the money. If you were a seven-year-old company with respectable revenue and an unfashionable category, the cheque that used to carry you to the next stage was simply not there and if you have lost your flashiness, the revenue might be disappearing too.

The exit narrowed to one door. With more cyber companies being acquired than funded, acquisition became the expected outcome rather than the exceptional one. That is fine if you are attractive enough to buy but if you are not, there is no exit at all, and a company that cannot raise and cannot sell has only one remaining option.

And AI reset the bar overnight. A product architected in 2019 is now competing against companies built AI-native from the first line of code. A team of 3 can build what a team of 20 had to do back in 2019, and at a faster rate.

One caution against the obvious conclusion: being AI-native is not a shield. Roughly a third of the companies on the list carried an AI label, and two AI-native offensive security firms founded as recently as 2025 were gone inside a year.

This is why we pay as much attention to the companies that fail as to the ones that raise. When a company goes, the people go with it, usually with no warning and rarely with a soft landing. And for anyone weighing up where to build a career, the useful question was never whether a company looks exciting. It is whether it has a route through: funded far enough to reach the next milestone, or valuable enough that somebody wants to buy it.

Our view.

The safe choice has inverted.

For years the sensible advice was that an established company with real revenue was the low-risk move, and the startup was the gamble. Look at that list and the logic no longer holds. A seven-year-old business in a category the market has stopped funding, running a product built before AI reset the bar, with no obvious buyer, is carrying more risk today than a well-funded two-year-old with three years of runway and a thesis investors want. Age used to be a proxy for safety. It is closer to a proxy for exposure now.

We tend to see it before it shows up anywhere public. A company that pauses a live search, quietly stops replacing leavers, or pulls an offer late in the process is usually telling you something months before there is anything to read about it. None of those is proof on its own. All of them are signals, and by the time a closure lands on a database it is a year too late to be useful to anyone.

So the advice we give candidates has changed. Ask an employer the questions an investor would ask. When did you last raise, and how long does it last? Who would buy you, and why would they bother? Is your category growing, or is it being absorbed into somebody's platform? Good companies answer all three without flinching. The ones that bristle have told you what you needed to know.

Because when a company goes, the people go with it, usually with no warning and rarely with a soft landing. More than three a week say that question is worth asking before you accept, not after.

Source: PitchBook records of companies ceasing operations, 1 January to 21 July 2026, covering the United States, Europe and Israel. Non-security businesses have been excluded from our count.

Funding Spotlight

$50M and above

Neo Security
Series A, $100M (Bessemer Venture Partners, Craft Ventures, Andreessen Horowitz)
Out of stealth with the week's biggest cheque. Neo builds a platform for secure collaboration between people and AI, offering private models, controlled AI personas and auditable multi-agent workflows so enterprises can put AI into real decision-making without losing control of it. Other investors: Merlin Ventures.

Category: AI Security
HQ: Boston, MA

MicroAGI
Seed, $55M (Hummingbird Ventures)
An industrial AI platform that analyses machine sensor data in real time to optimise asset performance and harden cybersecurity across operational environments. Other investors: Redalpine, Earthling VC, Village Global, Phoenix Court and Northzone Ventures.

Category: Industrial / OT Security
HQ: Aachen, Germany

$20M to $50M

Risk Ledger
Series B, $32M (Axiom Equity, Mercia Ventures)
Supply-chain security run as a network rather than a questionnaire. Risk Ledger compares client security requirements against suppliers' actual security data, so a supplier joins once and shares with many. The round funds expansion of its UK network, new AI tooling and entry into the US market.

Category: Supply Chain / Third-Party Risk
HQ: London, United Kingdom

Twenty
Venture Funding, $30M (Khosla Ventures)
A cyber-warfighting platform for real-time offensive operations, with battle-hardened automation and AI-driven targeting for defence missions. The round lands at a $1.2 billion post-money valuation, barely a month after its $100 million raise, and funds research, engineering and the offensive capabilities American warfighters need.

Category: Offensive Cyber / Defence
HQ: Arlington, VA

Empirical Security
Series A, $25M (Brightmind Partners)
Predictive exposure management from the team that created risk-based vulnerability management. Other investors: Hyde Park Angels and Costanoa Ventures. (This week's Company Spotlight.)

Category: Vulnerability / Exposure Management
HQ: Chicago, IL

Cranium AI
Series A-3 and A-4, $20M (undisclosed investors)
An AI security and governance platform that discovers, assesses and monitors AI systems across their lifecycle, at a $469 million post-money valuation.

Category: AI Governance
HQ: Short Hills, NJ

$5M to $20M

Beacon Security
Seed, $13M (Notable Capital)
An agentic security platform providing a unified data layer for security operations, with distributed engines, automated normalisation, enrichment and cross-source agentic workflows. Other investors: Holly Ventures, Alpha Drive Ventures, Silicon Valley CISO Investments and Jefferies Financial Group.

Category: Security Data / SecOps
HQ: Tel Aviv, Israel

Defensx
Venture Funding, $12.7M (undisclosed investors)
Zero-trust security for the browser, layering web protection, credential theft prevention and remote browser isolation over everyday web access.

Category: Browser Security
HQ: New York, NY

Sensity
Venture Funding, $5.6M (European Innovation Council)
Deepfake detection and audiovisual media authentication, raised as a mix of equity and grant funding to support international expansion.

Category: Deepfake / Media Integrity
HQ: Amsterdam, Netherlands

Early and undisclosed

Glow
Early Stage VC, Undisclosed (Redpoint Ventures)
AI-powered security for the modern workspace, protecting identities, applications and endpoints.

Category: Workspace Security
HQ: San Francisco, CA

Alocity
Series A, Undisclosed
Unified physical access control and facility management using 3D face verification, cloud access intelligence and AI video analytics. The round funds engineering, sales and marketing expansion and a growing partner network.

Category: Physical Access Control
HQ: Miramar, FL

ARGOS Identity
Pre-A, $3M (Stonebridge Capital, BonAngels Venture Partners)
AI-powered identity verification automating document review, face authentication and AML screening, at a $20.5 million post-money valuation. Other investors: Aton, Asia2G Capital and Kimgisa Lab.

Category: Identity
HQ: Vienna, VA

Mio
Seed, $2.2M (Fabric Ventures, Topology Ventures)
A portable, privacy-first identity and context-sharing platform giving individuals control of their own data across applications.

Category: Identity / Privacy
HQ: Delaware

Quantum Defen5e
Early Stage VC, $0.3M (undisclosed investors)
Secure encryption and information sovereignty technology for data protection and risk mitigation.

Category: Encryption / Post-Quantum
HQ: Rapid City, SD

M&A Intelligence

Fourthline and Veridas Agree to Merge

Fourthline → Merging with Veridas
Deal Type: Merger
Deal Date: July 16, 2026
Deal Size: Undisclosed

Identity consolidation continues, this time across Europe. Amsterdam's Fourthline orchestrates KYC and anti-money-laundering compliance for regulated institutions, while Veridas, headquartered in Pamplona and founded as a joint venture with BBVA, brings proprietary biometric and anti-fraud technology. Note the structure: this is a merger rather than a takeover, with Veridas shareholders including BBVA continuing in the combined business and the transaction part-funded by Finch Capital and Rabo Investments. Completion is expected in the second half of the year, subject to regulatory approval.

VINCI Energies Acquires All for One Group

All for One Group → Acquired by VINCI Energies, a subsidiary of Vinci (PAR: DG)
Deal Type: Acquisition
Deal Date: July 16, 2026
Deal Size: Undisclosed

A public-to-private transaction, and a reminder that the take-private wave is not confined to pure-play security. All for One is a listed German IT services group with a substantial cybersecurity practice, and VINCI Energies, part of the French construction and concessions giant Vinci, is taking it off the market entirely.

Other Notable M&A

Crestline Cybersecurity → Acquired by ITCS. The Welsh consultancy, which does auditing, penetration testing and cloud modernisation, joins a growing UK managed services group.
Camb IT Support → Acquired by Owlis Technology Group, backed by Ansor, through an LBO. Cambridge managed IT and security services.
NiceCloud → Acquired by Futureproof Group, backed by MKB Fonds, through an LBO. A Dutch MSP consolidation play in Overijssel.
AvanGuard → Acquired by Exiptel. French cybersecurity consulting and infrastructure.
Abacus IT → Acquired by Fairdinkum Consulting. Managed IT and security for smaller businesses, extending Fairdinkum's West Coast bench.
Xci → Trifork sold a 5% stake to Verdane. The Danish cybercrime investigation software specialist.

The pattern is unmistakable: five of this week's eight deals were small managed service and consultancy businesses being rolled into larger groups. The unglamorous end of cyber is being consolidated one regional firm at a time.

PE/LBO Activity

Xentra → PE Growth, $3.6M (Maven Capital Partners UK). Development capital for the Leeds-based provider of managed detection and response and security operations services to UK businesses and the public sector.

Also worth noting: Proofpoint entered into a definitive agreement for a debt refinancing this week. Thoma Bravo took the company private for approximately $12.3 billion in 2021. We would not read anything specific into a refinancing on its own, but balance-sheet activity at a portfolio company of that size is worth logging in the context of this month's Bold Call.

Companies that Ceased Operations (According to PB)

One cybersecurity company ceased operations this week:

  • ASolutions - IT security and monitoring services (Warsaw, Poland)

A quiet week by recent standards, though as our Trident View sets out above, the running total since January is anything but quiet.

Insider Insight

The Return of the Fable

Last month we wrote about a model that lasted a week.

It is back. And the way it came back matters more than the fact that it did.

A quick recap. Anthropic released two models on 9 June, Fable 5 for general use and Mythos 5, sharing the same underlying model with fewer safeguards, for a small set of trusted partners doing defensive cybersecurity work. Three days later the US government applied export controls, requiring access to be restricted from foreign nationals. With no way to verify nationality in real time, the company pulled both models for everyone.

Those controls were lifted on 30 June. Fable 5 returned globally on 1 July. Mythos 5 has gone back to a set of US organisations following government approval.

Now the substance, because the trigger was a cybersecurity problem specifically.

Researchers at Amazon found a way around Fable 5's safeguards, prompting it to identify software vulnerabilities and, in one instance, produce code demonstrating how one of them could be exploited. That finding went to the government, and the export controls followed.

Here is the uncomfortable part, and to its credit Anthropic published it itself. Its testing found that less capable models, including older Claude versions, GPT-5.5 and Kimi K2.7, could identify the same vulnerabilities. Every model tested could produce the same exploit demonstration. The capability was never unique to Fable. The company's own assessment is that the technique reached a borderline behaviour involving routine defensive security work.

So a model was pulled from the global market over a capability that several other models already had. Reasonable people can disagree about whether that was proportionate, and that disagreement is precisely the problem the industry is now trying to solve.

The fix itself is instructive. A new classifier blocks the reported technique in over 99% of cases, with blocked requests rerouted to a less capable model. The stated cost is more false positives during routine coding and debugging. That trade is worth sitting with if you build or sell security tooling: the safety margin that protects against misuse also catches legitimate defensive work, and your engineers and researchers will feel it.

Three things follow, and they are bigger than one company.

Frontier AI is now controlled technology. An export control was applied to a model, not a weapon system, and it took effect immediately. Anyone old enough to remember strong encryption being classified as a munition in the 1990s will recognise the shape of this argument. It is the same fight over the same principle, with a new object at the centre of it.

The industry is building a severity standard. Anthropic, Amazon, Microsoft and Google are drafting a shared framework for scoring jailbreaks, rating them on how much capability they unlock, how broadly the technique works, how easily it can be weaponised and how discoverable it is. Effectively a CVSS for model jailbreaks. If it lands, it gives governments a calibrated basis for acting rather than a binary one, which is the gap this whole episode exposed.

And government is now inside the release process. Pre-release access for government evaluators, rapid sharing of jailbreak findings, joint research commitments. Whatever you make of that, it is the new operating reality for frontier models.

The Trident Take: if your product runs on a frontier model, model availability has become a regulatory variable rather than just a commercial one, and "which model do you depend on, and what happens if it disappears for three weeks" is now a fair procurement question. Two consequences for talent follow. Sovereign and self-hosted alternatives get another push, which is more fuel for the national-security tier of this market we wrote about last month. And a genuinely new function is emerging at the intersection of AI capability, security research and policy, staffed by people who can hold a technical conversation and a regulatory one in the same meeting. That combination is rare today. Our guess is that within the year it will be the standard senior hire at every serious AI security vendor. psst we are already seeing this happen!

Company Spotlight

If you have ever prioritised a vulnerability backlog by anything other than raw severity score, you have used an idea these three founders are credited with creating. This week they raised $25 million to do it again, properly, for a world where attackers have AI.

The Founders. Founded in 2024 and based in Chicago, Empirical has one of the most specific pedigrees in the market. Chief executive Ed Bellis co-founded Kenna Security and was its chief technology officer through the company's acquisition by Cisco. Chief technology officer Michael Roytman was Kenna's chief data scientist. Chief data scientist Jay Jacobs co-created EPSS, the Exploit Prediction Scoring System, which Empirical still trains and maintains, whose scores are published daily and free to use, and which Tenable, Qualys, CrowdStrike, Microsoft and Wiz have embedded across their products. Between them they pioneered the category of risk-based vulnerability management. Bellis describes Empirical as his unfinished business.

The Thesis. The original insight at Kenna was that not every flaw deserves equal attention, so security teams should focus on the ones most likely to be exploited. It worked, and the industry adopted it. The problem is the backlog never stopped growing. Cloud, SaaS, APIs and third-party code piled on exposure faster than anyone could remediate it, and now AI is accelerating both the discovery of vulnerabilities and the speed at which they are weaponised. The founders' argument is that a scoring system built for the last era cannot keep pace with this one, and that prediction has to get personal.

The Product. Two models do the work. Foundation is the global engine, monitoring more than 18,000 exploited CVEs to predict what attackers will actually go after. Radiant is the interesting one: a custom predictive model built and fine-tuned for each individual organisation, trained on real-time exploitation data, local telemetry and contextual asset information. The question shifts from what is dangerous in general to what is dangerous here, in this estate, with these systems. Customers are concentrated in technology, healthcare and financial services, the sectors that cannot afford to guess.

The Funding Journey. Empirical started with angel money from Hyde Park Angels, then raised a $12 million seed led by Costanoa Ventures in July 2025 at a $40 million pre-money valuation, with Costanoa's John Cowgill taking a board seat. Twelve months later almost to the day, Brightmind Partners led the $25 million Series A, with Costanoa and Hyde Park Angels following on. That is $37 million raised inside a year, and Brightmind is a new name on the register at a moment when very few unfashionable categories are attracting fresh leads at all.

The Traction. The company is generating revenue and has grown to around 30 people, which is a striking ratio when you consider what they maintain. EPSS is embedded across most of the major security platforms, so Empirical is simultaneously a startup and a piece of the industry's shared infrastructure. There is a real tension in that, and it is the most interesting thing about the company: PitchBook lists Tenable, Qualys, CrowdStrike, Rapid7 and Palo Alto as its nearest comparables, and several of those competitors run Empirical's own scoring system inside their products.

The Takeaway. The pitch that a predictive model tuned to your specific estate beats a generic severity score is a strong one, and the Kenna lineage means it will get heard at CISO level, which is most of the battle. The harder part is displacement. Every enterprise already owns vulnerability management tooling, and buyers consolidating their vendor lists are not looking for another dashboard. The honest caveat is that this is a funding announcement rather than a customer scorecard: no enterprise design partners have been named and no independent benchmark has been published showing how Foundation and Radiant perform against the incumbents. What Empirical has that most challengers do not is a credible claim to have invented the category once already, and the industry's own exploit-scoring standard running under its roof.

Hot Jobs

Role

Base

Location

Description

Contact

CRO

$300K

Boston

Security data platform rethinking how telemetry reaches the SOC. Full commercial leadership.

CEO

£200K

London

UK managed security services business, hiring its next chief executive.

Chief Commercial Officer

$180K

London

UK cyber defence firm with a national-security pedigree, hiring its commercial leader.

Head of Cyber Threat Intelligence

$175K

New York

Threat intelligence and external data business, building out its CTI function.

VP Sales - EMEA

£125K

London

Offensive security and attack surface management platform, leading EMEA.

Sales Engineer - EMEA

€100K

Paris

Credential-phishing defence startup, hiring a pre-sales engineer for EMEA.

Channel Account Lead

£75K

Manchester

Continuous penetration testing platform, building its channel.

Channel Account Manager - UK

£70K

London

Cyber asset management platform, building the UK channel.

Account Executive (2 openings)

£60K

Manchester

The same continuous penetration testing platform, growing UK sales.

Ready to make your next move? These roles won't stay open long.

The Bold Call

One prediction per month.

July 2026 Prediction: A private-equity firm takes a public cybersecurity company private this quarter, in a deal worth $3 billion or more, and Thoma Bravo is the likeliest name on it.

The Logic: Last quarter set it up. Private equity ran 115 cyber deals between April and June, more than any strategic buyer, as the market tipped from building companies to buying them. Consolidation at that scale is Thoma Bravo's home ground. The firm is sitting on a record fund of more than $24 billion, has just pulled back from growth equity to concentrate on buyouts, and has spent twenty years proving that more or less any cyber company valued under about ten billion dollars is fair game, from Proofpoint at $12.3 billion to SailPoint at $6.9 billion to Darktrace at $5 billion. Public cyber valuations have slid well off their peaks, which is exactly the setup private equity waits for: profitable businesses the market has stopped rewarding, cheaper to buy and easier to fix out of the public eye. Keyfactor taking a billion dollars from Summit Partners this month is the same thesis at work in the private markets. What could prove us wrong is timing, since take-privates take months to line up and the next one could just as easily slip into Q4, which is exactly what makes calling it for this quarter bold.

Prediction Tracker

Month

Call

Status

May 2026

Torq acquires again before end of 2026

🔵 In Progress

June 2026

Microsoft makes a major AI-security acquisition before end of 2026

🔵 In Progress

July 2026

A PE firm takes a public cyber company private this quarter, $3B+, likely Thoma Bravo

🔵 In Progress

Note on the June call: we named Oasis Security and Token Security as the obvious independent targets. Cyera bought Oasis this month. The thesis holds, the shelf is just emptying faster than expected.

Inbox Intel

Have market intelligence to share? Our network sees deals before they're announced, hiring freezes before they're public, and technology shifts before they hit the headlines.

Send us your tips:

  • Funding rounds in stealth mode

  • Executive movements and reorganizations

  • Customer wins/losses that signal market shifts

  • Technology partnerships before they're announced

  • Hiring sprees or freezes at specific companies

Email: [email protected]
All sources protected. We verify before we publish.

The Trident Radar - Intelligence that moves faster than your competition
Delivered by Trident Search Research Desk
Editor: Ryan Keeley | London

Keep Reading