Welcome back to the Trident Radar.
A quieter week on the tape after a frantic fortnight, but the direction of travel has not changed as AI security took the two biggest cheques again… Straiker raised $64 million to test and secure enterprise AI, and Nebulock took $25 million for autonomous threat hunting.
Identity kept consolidating, with the verification unicorn Incode buying Identiq, and private equity carried on quietly rolling up the less glamorous corners of the market, with Goldman Sachs taking the audit firm Schellman and CyberFox absorbing the network-security player Timus.
This week we also pull back the curtain a little on how we work.
Let's dive in.
TL;DR
Straiker raises $64M for AI security. A Series A to discover and stress-test enterprise AI, led by Citi Ventures and Workday Ventures.
Nebulock takes $25M. Autonomous threat hunting, led by FirstMark Capital, at a $107.5M pre-money valuation.
Incode acquires Identiq. The identity-verification unicorn buys a privacy-first validation network.
Goldman Sachs buys Schellman, CyberFox buys Timus Networks. Private equity and strategics keep rolling up cyber assurance and MSP security.
Wultra raises $7.8M for post-quantum authentication in banking.
This week's Trident View: where hires breakdown.
THE TRIDENT VIEW

Where Hires Actually Break Down
Ask most people why a hire fell through, and they will blame the pipeline. Not enough good candidates they say.
Well they’re almost always wrong. We know that its the time it takes that makes the most difference.
Measured across hundreds of searches, finding strong people is rarely where a search dies. Cyber go-to-market talent is scarce, true, but the search dies later: at the interview, at the offer, or in that nervous gap between an offer going out and a candidate saying yes. Those are the stages a company can actually control. Most have no idea they are losing there.
That is why we track every search through the whole funnel instead of working on feel. We measure the lot: CVs to first interviews, interviews to offers, offers to start dates, reasons why people say no. We know what healthy looks like at every step because we have the history to compare against, so when a search slows we can see whether the culprit is the brief, the interview loop, or an offer that simply is not competitive, before weeks vanish guessing.
Newsflash, most other agencies do guess, and that’s why so many fail or have terrible repeat business.
Strong cyber go-to-market candidates rarely have one option. They are weighing two or three at once, so the question is not whether you can find the right person. It is whether you can move fast enough, and commit hard enough, to win them. Hesitate and you do not get a slower hire. You get no hire, because someone else just took yours.
So we treat our own speed as a number, not a hope. A senior search is usually quoted in months. Ours run to around 40 days from brief to getting the start day booked in. Not because we rush anyone, but because nothing is allowed to drift, we know when to slow and when to speed up, and in a market like this, drift is what costs you the person.
Most of recruitment still runs on gut feel and a good black book. We keep the black book. We just add the evidence, because a search you can measure is a search you can fix, and a company that can see where it loses candidates is one that stops losing them.
That is the firm we have built. Not just people who find the right person, but people who can tell you, almost to the day, where and why a hire is won or lost.
Funding Spotlight
Straiker
Series A, $64M (Citi Ventures, Workday Ventures, Illuminate Financial, Marathon Management Partners)
AI-native security platform that discovers an organisation's AI footprint and stress-tests it for vulnerabilities, with one-off or continuous red-teaming as enterprises push AI and agents into production. Other investors: Lightspeed Venture Partners, Bain Capital Ventures, Rain Capital and GTM Capital.
Category: AI Security
HQ: Sunnyvale, CA
Nebulock
Series A, $25M (FirstMark Capital)
Autonomous threat-hunting platform that surfaces the false negatives other tools miss and turns each hunt into a hardened behavioural detection, at a $107.5 million pre-money valuation. Other investors: Decibel Partners, Bain Capital Ventures, Zetta Venture Partners and Step Function.
Category: Threat Hunting
HQ: Boston, MA
Wultra
Series A, $7.8M (Seventure)
Digital identity and authentication for financial applications, built on post-quantum cryptography and multi-factor authentication to future-proof banking logins. Other investors: Elevator Ventures and J&T Ventures.
Category: Authentication / Post-Quantum
HQ: Prague, Czech Republic
Identione
Venture Funding, Undisclosed (Partnerinvest Norr)
Secure, modular digital identity management built around attribute-based verification.
Category: Identity
HQ: Stockholm, Sweden
ENTRYZERO
Seed, Undisclosed (Neoteq Ventures)
Threat exposure management that automates offensive security to test perimeters and prioritise the risks that actually matter.
Category: Exposure Management
HQ: Bochum, Germany
MediaMiner
Angel, $0.6M
AI multimedia threat detection that scans images and video to head off media-driven breaches and deepfake attacks.
Category: Deepfake / Media Security
HQ: Turin, Italy
VulNow
Angel, $0.07M
Predictive vulnerability intelligence that flags software supply-chain flaws before they are publicly disclosed as CVEs.
Category: Vulnerability Intelligence
HQ: Amsterdam, Netherlands
M&A Intelligence
Incode Acquires Identiq
Identiq → Acquired by Incode Technologies
Deal Type: Acquisition
Deal Date: June 25, 2026
Deal Size: Undisclosed
Incode, the identity-verification unicorn, buys a privacy-first identity network. Identiq lets companies validate new users by drawing on the collective knowledge of other businesses without ever sharing personal data between them. It hands Incode a privacy-preserving layer for fraud prevention and onboarding, and adds another name to a busy month of identity consolidation.
CyberFox Acquires Timus Networks
Timus Networks → Acquired by CyberFox
Deal Type: Acquisition
Deal Date: June 29, 2026
Deal Size: Undisclosed
Consolidation in the MSP channel. Timus builds SASE and zero-trust network access aimed at managed service providers and smaller enterprises. CyberFox, backed by Level Equity and Radian Capital, folds it into its MSP security and IT-management stack through an LBO.
PE / LBO Activity
Schellman & Company → Buyout by Goldman Sachs Asset Management. One of the largest independent cybersecurity audit and attestation firms, handling SOC 2, FedRAMP, ISO and penetration testing, taken private. It is the second cyber-assurance business Goldman's asset-management arm has moved on in a fortnight, after the LRQA deal (Tampa, FL).
Companies That Ceased Operations
One cybersecurity company went out of business this week:
Cybrize - Cybersecurity management and programme platform (Irving, TX)
Insider Insight

AI or Nothing
Strip out the non-cyber noise and roughly $2.5 billion of venture funding went into cybersecurity this quarter. Of every disclosed dollar, 86% went to companies built around artificial intelligence. Of every round, 69% went the same way. The AI-native label has stopped being a differentiator and become an entry ticket. If your pitch does not have AI at its core, the data says you are not raising.
The dominance is close to total. Data security, identity, threat detection, penetration testing, the biggest rounds in every category had an AI engine at the centre of the story, from Cyera and Dream to XBOW and Exaforce. The non-AI raises that did get done were small and few. Capital has picked a side, and it is not being subtle about it.
But the harder truth sits underneath that headline, because it was not simply AI that won, it was a handful of AI companies. The ten largest rounds took 66% of all the venture money raised in the quarter. The median round was just $5.8 million. Seven companies raised more than $100 million each, while fifty-three raised less than $5 million. The market has become a barbell: a few giants at one end, a long tail of tiny seeds at the other, and very little in between.
That missing middle is the part worth dwelling on. The $20 to $50 million growth round, the money that used to carry a cyber company from product-market fit to real scale, has become much harder to find. Put that next to the quarter's other defining feature, more cyber companies acquired or taken private than were funded at all, and the message to any mid-stage company is blunt. Break out into a mega-round, become an acquisition target, or run out of road. There is very little comfortable ground left between those three.
For founders, the implications are practical. The AI-native positioning is not optional, and the financing path has split in two: raise big and fast off a breakout story, or stay lean enough that you never need the round that might not be there. For investors, conviction is concentrating into fewer and larger bets. And for the market as a whole, this is simply what maturity looks like, the winners compounding while the middle gets absorbed.
The Trident Take: this is a map of where the durable jobs are. The hiring that lasts sits at the well-funded AI-native breakouts and at the acquirers consolidating around them, not at the squeezed middle that could be sold or shut within a year. We read this data closely for exactly that reason, so we can point candidates and clients toward the companies with the runway to keep building, and away from those about to be absorbed. In a market this concentrated, knowing which side of that line a company sits on is most of the job.
Company Spotlight

Website - straiker.ai
This spring, attackers did not break into Meta. They simply talked its AI support agent into resetting account details and walked away with more than twenty thousand Instagram accounts, no malware, no stolen passwords, no breach of the core systems at all. That is the problem Straiker exists to solve, and this week it raised $64 million to go after it.
The Founders. Straiker is the second act of two people who have built security businesses before. Co-founder and chief executive Ankur Shah ran Prisma Cloud at Palo Alto Networks as its SVP and general manager, growing it from a single module into a cloud-security platform doing around half a billion dollars in annual recurring revenue across most of the Fortune 100. Co-founder and chief technology officer Sreenath Kurupati founded the fraud-detection startup Cyberfend, sold it to Akamai in 2016, and went on to lead AI and security research there, after fifteen years at Intel. This is not a first-time team learning the category on the job.
The Thesis. Their bet is that the real AI security problem was never the model, it is the agent. Enterprises are now handing autonomous AI agents the ability to write code, move money, answer customers and act across internal systems on their own, and those agents can be manipulated in ways that traditional, rule-based security was never designed to catch. An attacker no longer has to breach a network, they just have to convince an agent to do the wrong thing. With IDC projecting more than a billion enterprise AI agents in use by 2029, up from a few tens of millions today, Straiker is wagering that securing this new workforce becomes as fundamental as securing laptops or cloud.
The Product. Straiker calls itself the agentic security company, and its platform does three things. It discovers the AI agents already running across an organisation, often more than anyone realised were there. It stress-tests them before deployment, simulating adversarial attacks to find where they break. And it watches them at runtime, blocking threats as they happen. Each part feeds the others, with live threats sharpening the testing and test findings hardening the live defences. Underneath sits STAR Labs, a research team drawn from the likes of Mandiant, Microsoft and Meta, whose own testing found that more than a third of successful attacks on coding agents led to remote code execution.
The Funding Journey. The $64 million Series A was led by Marathon Management Partners alongside Citi Ventures, Workday Ventures and Illuminate Financial, with earlier backers Bain Capital Ventures and Lightspeed returning. It takes total funding to $85 million for a company barely two years old. The cap table is its own endorsement: the earlier round drew cheques from some of the most credible names in the industry, including CrowdStrike chief executive George Kurtz and the former Google Cloud security chief Phil Venables, and Marathon's Gokul Rajaram is joining the board.
The Traction. Straiker says run-rate revenue has grown more than fifteenfold in under a year, with frontier AI labs and Fortune 500 enterprises among its customers across financial services, healthcare and consumer electronics. It has landed on the Fortune Cyber 60 and CB Insights' most-innovative-AI lists. The growth looks real, though it is worth noting that the headline figures are self-reported and the company is, by its own description, still early.
The Takeaway. Straiker is a near-perfect specimen of where the money is going: AI-native, agent-focused, world-class founders, and a $64 million round at a moment when most of cyber is fighting over scraps. The problem it has picked is genuine and the team is about as good as the category has. The open question is the one hanging over the whole agentic-security wave, whether enterprises adopt agents as fast as the forecasts promise, and whether a focused startup can hold its ground before Palo Alto, CrowdStrike and Microsoft decide that securing agents is a feature they should own. If the agents arrive on schedule, Straiker is early, well-funded and well-led, which is a strong place to be standing.
Hot Jobs
Role | Base | Location | Description | Contact |
|---|---|---|---|---|
VP Sales - North America | $250K | US | Threat intelligence and adversary simulation platform with a strong open-source community. Leading the North America build. | |
Channel Director - East | $225K | US | Same threat intelligence platform, standing up the East Coast channel. | |
Enterprise Account Executive | $160K | Israel | Early-stage AI security platform. Enterprise sales. | |
Technical Customer Success Manager | $150K | US | Threat-informed defence platform that maps security coverage against real-world adversary techniques. | |
Sales Director - UK | £130K | UK | Autonomous AI SOC platform automating alert investigation. UK sales lead. | |
Account Executive - East Coast | $130K | US (NYC) | Offensive security and attack surface management platform. | |
Head of Marketing | £100K | UK | UK cyber defence and resilience firm with a national-security pedigree. Leading marketing. |
Ready to make your next move? These roles won't stay open long.
THE BOLD CALL
One prediction per month.
June 2026 Prediction: Microsoft makes a major AI-security acquisition before the end of 2026.
The Logic: Every platform of its size has already bought its way into the layer that secures AI: Google took Wiz for $32 billion, Palo Alto took CyberArk for $25 billion, and the buying has not stopped, with Cisco taking Astrix and WideField, Snowflake taking Natoma, and Accenture spending $4.1 billion last week alone. Microsoft is the holdout. It owns the biggest enterprise identity platform in Entra and ships the most-used enterprise AI in Copilot, yet it keeps building its AI-security stack in-house rather than buying one. That is getting harder to justify when machine identities now outnumber humans by roughly 82 to 1 and the pool of independent targets keeps thinning. If Microsoft wants the best team rather than the leftovers, it has to move while the likes of Oasis Security and Token Security are still standing. What could prove us wrong is Microsoft's real preference for organic builds, which is exactly what makes this a bold call.
Prediction Tracker
Month | Call | Status |
|---|---|---|
May 2026 | Torq acquires again before end of 2026 | 🔵 In Progress |
June 2026 | Microsoft makes a major AI-security acquisition before end of 2026 | 🔵 In Progress |
📥 INBOX INTEL
Have market intelligence to share? Our network sees deals before they're announced, hiring freezes before they're public, and technology shifts before they hit the headlines.
Send us your tips:
Funding rounds in stealth mode
Executive movements and reorganizations
Customer wins/losses that signal market shifts
Technology partnerships before they're announced
Hiring sprees or freezes at specific companies
Email: [email protected]
All sources protected. We verify before we publish.
The Trident Radar - Intelligence that moves faster than your competition
Delivered by Trident Search Research Desk
Editor: Ryan Keeley | London

