Welcome to The Trident Radar. Good to have you back!

People have asked for more information on what we have been doing as a company, so… Trident have been on the road the last few weeks! Including at TD Garden for the Bruins vs. Panthers game!

Let's dive in.

  • CTI gets absorbed into ops: Dataminr agreed to acquire ThreatConnect, pulling threat intel and automation closer to real-time signal. Expect sharper detection pipelines and tighter fusion between external intelligence and the SOC.

  • SIEM-lite analytics keeps climbing: Gravwell raised $15.4M Series A to power full‑stack security analytics across IT and OT sources without heavy centralization.

  • OT rail security goes strategic: Sweden’s Ependion (Westermo) took a £2.7M minority stake in UK rail cyber firm RazorSecure and set a partnership path, including an option to buy later. Rail fleets clearly wants integrated hardware+security.

  • Agentic AI shows up in seed markets again and again: Bricklayer AI raised $5M seed to put collaborating AI agents to work in the SOC.

  • Policy pulse: Singapore hosted the 5th Counter Ransomware Initiative Summit during SICW. Ransomware action is back on ministerial agendas, not just vendor decks.

  • Insider Insight: Trident Disconnect!

FUNDING SPOTLIGHT

Defakto – Series B – $30.75M (XYZ Venture Capital leading)
Palo Alto–based Defakto raised $30.75 million to expand its non-human identity security platform. The company focuses on protecting service accounts, workloads, and AI agents operating in hybrid and multi-cloud environments. Investors include XYZ Venture Capital, Forgepoint Capital, and Dell Technologies Capital.

Bricklayer AI – Seed – $5M (Tech Square Ventures leading)
Atlanta-based Bricklayer AI builds an agentic AI platform for cybersecurity teams. The funding will accelerate development of autonomous security agents capable of triaging alerts, correlating incidents, and executing remediation across SOC environments.

Gravwell – Series A – $15.4M (Two Bear Capital leading)
Data analytics and threat-hunting company Gravwell secured $15.4 million to scale its full-stack log and event analytics platform. The funding supports growth in industrial and operational technology (OT) environments where real-time analysis and compliance are critical.

M&A INTELLIGENCE

Dataminr → ThreatConnect (announced Oct 21, 2025)
Dataminr acquired ThreatConnect in a deal valued at approximately $290 million, marking one of the largest threat intelligence platform consolidations of the year.

The acquisition brings ThreatConnect’s threat intelligence, playbook automation, and risk analytics into Dataminr’s real-time signal intelligence platform. The move expands Dataminr’s reach into enterprise SOC workflows, integrating external threat visibility with internal detection and response capabilities.

Ependion (Westermo) → RazorSecure (announced Oct 21, 2025)
Swedish industrial technology group Ependion AB, through its subsidiary Westermo Network Technologies, completed a £2.7 million strategic minority investment in UK-based RazorSecure. RazorSecure specializes in cybersecurity monitoring for railway and transport networks. The partnership strengthens Westermo’s industrial-cyber portfolio, combining real-time network data with anomaly detection for critical infrastructure systems.

I thought I would include this small deal to further show the same OT moves that have been happening all year.

Breez → JumpCloud (announced Oct 23, 2025)
JumpCloud acquired Breez, an emerging identity threat detection and response (ITDR) vendor, to enhance its identity-lifecycle management suite.

Breez’s platform detects and mitigates identity compromise and behavioral anomalies across SaaS and hybrid environments. The acquisition aligns with JumpCloud’s strategy to unify directory, access, and identity defense under a single architecture.

INSIDER INSIGHT

A bit of a different Insider Insight this week!

(Click below to watch)

In October we had the privilege of bringing together 25 Execs to reflect, rewire and recharge at a leadership retreat like no other: Disconnect.

With sessions on wellbeing, burnout and mindfulness, as well as opportunities to reconnect with nature and take a break from the hectic day-to-day, this bespoke experience provided the space for leaders to tackle their most complex challenges with a fresh perspective.

At Trident we do events differently – and as our biggest and most ambitious event to date, this was no exception. We’re so grateful to everyone who worked with us on this journey and to those who made it possible.

COMPANY SPOTLIGHT


Who they are
Gravwell is a full-stack data analytics and security platform built to ingest, search, and investigate “ground truth” across both IT and OT environments without forcing a heavyweight SIEM migration first. They just closed a 15.4 million dollar Series A led by Two Bear Capital with Gula Tech Adventures and Next Frontier Capital participating. The round was announced on October 21.

How it works
At the core is a structure-on-read data lake and a piped search pipeline, so teams can normalize and pivot at query time rather than pre-define rigid schemas. Gravwell ships first-party “ingesters” for common sources and exposes an open ingest API so customers can bring in anything from Windows logs to ICS protocol traffic and full packet captures. That open approach is visible in their docs and public repos.

Why buyers are leaning in now
Budgets are moving toward platforms that collapse steps and show value fast. Gravwell’s sell is lower lift than a rip-and-replace SIEM, broad ingest out of the box, and quick pivots across heterogeneous data. Their A-round language explicitly targets faster go-to-market and product acceleration on that thesis.

What to watch next

  • Content and connectors. The more turnkey parsers, detections, and OT-friendly packs they ship, the more often they’ll be shortlisted in modernization programs.

  • Ecosystem integrations. Expect deeper hooks into DFIR tooling, EDR, and ticketing so investigations can hand off cleanly to action. Their Interpres listing hints at that trajectory.

  • Industrial momentum. With rail and broader OT security getting strategic attention this month, watch Gravwell case studies and partnerships around ICS analytics.

HOT JOBS

RVP of Sales – Risk Management (Crypto) | Washington DC / Remote
Leading risk management business expanding its US presence. $200K base + commission.
Contact: [email protected]

VP of Sales – Threat Intelligence | New York / US Remote
Global threat intelligence platform scaling commercial operations across North America. Seeking a proven VP of Sales to lead GTM growth and team expansion. $500K OTE.
Contact: [email protected]

Founding Account Executive – AI Security | Tel Aviv
Early-stage security vendor redefining cloud data protection with AI-powered observability. First GTM hire responsible for building the sales function from the ground up. $400K OTE.
Contact: [email protected]

Founding Account Executive | New York / Remote
AI‑powered security platform redefining data and cloud protection for the enterprise. $330K OTE.
Contact: [email protected]

Founding Account Executive | Tel Aviv
Data protection company providing full visibility into sensitive data movement with automated leak detection and seamless deployment. $360K OTE.
Contact: [email protected]

Ready to make your next move? These roles won't stay open long.

FUTURE PREDICTIONS

  • At least one more agentic‑SOC seed pops. Enterprise pilots are converting to rounds, especially where the product “writes back” into the stack. We’re hearing term sheets are out.

  • Another industrial vertical tie‑up. Think transport or energy OEM partnering with a niche cyber vendor to package a secured platform offering. RazorSecure–Westermo won’t be the only one.

  • Noise around intel platforms heats up. Competitors will respond to Dataminr–ThreatConnect with roadmap teasers and “deeper SIEM integrations.” Expect announcements before holiday dead zones.

📥 INBOX INTEL

Have market intelligence to share? Our network sees deals before they're announced, hiring freezes before they're public, and technology shifts before they hit the headlines.

Send us your tips:

  • Funding rounds in stealth mode

  • Executive movements and reorganizations

  • Customer wins/losses that signal market shifts

  • Technology partnerships before they're announced

  • Hiring sprees or freezes at specific companies

Email: [email protected]
All sources protected. We verify before we publish.

The Trident Radar - Intelligence that moves faster than your competition
Delivered by Trident Search Research Desk
Editor: Ryan Keeley | London

Keep Reading