2025 - 2026

CYBER60


CISO SURVEY

  • WITH
  • AI REDEFINES THE ATTACK SURFACE AND THE DEFENSE
  • INVESTMENT PATTERNS REVEAL MORE THAN OPTIMISM
  • Presented by
  • AWS

WELCOME TO THE CYBER60, THIRD EDITION

At Lightspeed, we’ve been investing in enterprise founders for over 25 years. Cybersecurity investing is one of the pillars of our global enterprise practice, and a focus area of deep immersion and commitment.

This report also shares insights from our CISO survey, conducted once again with the world’s leading industry research firm, Wakefield Research. Wakefield surveyed 200 CISOs at companies with $500 million or more in revenue on the intersection of AI and cybersecurity.

The results reveal a market at an inflection point. The vast majority of organizations have already experienced AI-related security incidents, yet confidence in defensive capabilities remains strikingly low. Despite this gap—or perhaps because of it—investment signals are unequivocal. The threat is no longer theoretical; it’s operational.

This year’s survey goes deeper than ever, mapping not just where CISOs are struggling, but where they’re placing their bets, which emerging solution categories represent the greatest opportunities for builders, and how the skills gap is reshaping vendor strategy.

Lightspeed is proud to build with several of the companies recognized in this report. 
We congratulate every company in the 2025-26 Cyber 60 for their contributions to safeguarding our world.

  • 7ai.com
    CEO:
    Lior Div

    7AI enables security teams to shift from reactive, manual processes to proactive, autonomous defense. The company's Dynamic Reasoning technology allows AI agents to adapt their decision-making based on contextual understanding of each unique security scenario, eliminating false positives and delivering actionable conclusions at machine speed.

    Founded:
    2024
    Funding:
    $36M
  • Adaptivesecurity.com
    CEO:
    Brian Long

    Adaptive is a next-generation security awareness training, phishing, and human risk platform for AI-powered cyber threats.

    Founded:
    2024
  • Lightspeed Venture Partners 2x
    Andromedasecurity.com
    CEO:
    Murali Basavaiah

    Andromeda Security is an identity security solution for human and non-human identities. The comprehensive solution provides real-time security and operational insights, automates least privilege and just-in-time (JIT) access using context, risk, and behavioral insights, and simplifies identity governance and lifecycle.

    Founded:
    2023
    Lightspeed Venture Partners 2x
  • Lightspeed Venture Partners 2x
    Clutch.security
    CEO:
    Ofir Har-Chen

    Clutch Security delivers enterprise-grade Non-Human Identity protection with complete coverage across cloud, SaaS, on-premise, code, CI/CD, and vaults. Powered by Identity Lineage™ technology, Clutch provides unparalleled visibility and zero-trust security for mission-critical digital infrastructure.

    Founded:
    2023
    Funding:
    $28.5M
    Lightspeed Venture Partners 2x
  • Cogent.security
    CEO:
    Vineet Edupuganti

    Cogent is the world’s first AI Taskforce for enterprise cybersecurity teams that fully automates the Vulnerability Management lifecycle.

    Founded:
    2024
    Funding:
    $11M
  • Dropzone.ai
    CEO:
    Edward Wu

    Developer of an intelligent augmentation platform designed to deliver pre-trained autonomous artificial intelligence security agents. The company offers a platform that handles the frontline work of investigating the mountain of alerts from security systems by investigating each alert without requiring pre-configured playbooks, custom code, or specific prompts, enabling agents to perform end-to-end investigations and clients to focus on real threats and high-value work.

    Founded:
    2023
    Funding:
    $57.25M
  • Fablesecurity.com
    CEO:
    Nicole Jiang

    Fable Security delivers the human risk platform that directly shapes employee behavior. Designed for simplicity and enterprise scale, our agentic platform synthesizes complex employee data, pinpoints risky behaviors, and deploys highly-relevant interventions to people automatically, in real time, right where they work.

    Founded:
    2024
    Funding:
    $31M
  • Koi.security
    CEO:
    Amit Assaraf

    Koi discovers, assesses, and governs all software, packages, MCPs, extensions and AI models your teams install, whether from marketplaces like GitHub, Huggingface, VSCode, Homebrew, or directly from vendors—securing everything before it reaches your endpoints.

    Founded:
    2024
    Funding:
    $48M
  • Legionsecurity.ai
    CEO:
    Ely Abramovitch

    Legion is a browser-native AI SOC analyst that turns in-house expertise into scalable automation. It trains within your organization, observing your team's investigations, learns their patterns, and helps improve them. Then, it automates them at your own pace, at any scale, and without requiring any integrations or APIs.

    Founded:
    2024
    Funding:
    $38M
  • 2x
    Linx.security
    CEO:
    Israel Duanis

    Linx Security is an AI-powered identity governance platform that gives enterprises real-time visibility, risk detection, and automated remediation across all identities.

    Founded:
    2023
    Funding:
    $33M
    2x
  • Lightspeed Venture Partners
    litt.security
    CEO:
    Yossi Torati

    Litt is pioneering autonomous security built for the age of AI, a system that thinks offensively, acts intelligently, and evolves faster than your adversaries.

    Founded:
    2025
    Funding:
    $37M
    Lightspeed Venture Partners
  • 2x
    Oasis.security
    CEO:
    Danny Brickman

    Developer of a non-human identity management platform intended to provide visibility and risk assessment with vulnerability auto-remediation. The company's platform simplifies secret management compliance and automatically discovers all non-human identities to improve security posture and implement strong governance without operational complexity, enabling clients to effectively address security challenges and fortify cybersecurity defenses within the organization.

    Founded:
    2022
    Funding:
    $75M
    2x
  • Outtake.ai
    CEO:
    Alex Dhillon

    Developer of advanced AI-powered cybersecurity tools intended to protect digital identities and prevent cyber threats. The company's platform features real-time threat classification, automated response systems, multi-surface anti-phishing capabilities, and centralized control across various digital surfaces, enabling clients to provide robust security to notable AI research labs and enterprises, offering enhanced protection against sophisticated scams and identity-based attacks.

    Founded:
    2023
    Funding:
    $20M
  • Lightspeed Venture Partners 3x
    P0.Dev
    CEO:
    Shashwat Sehgal

    P0 Security is the next-generation privileged access platform, redefining how security teams manage production access across cloud and hybrid environments. Unlike legacy approaches that rely on a patchwork of PAM, IGA, CIEM, NHIM and IAM tools, P0 delivers orchestration, risk posture and governance for all identities (human and machines) in one unified control plane—built for scale, speed and Zero Standing Privilege. At the core is P0’s continuously updated Identity Graph and Access DNA layer, giving teams real-time insight and control across all identities, resources and environments—including multi-cloud, on-prem and hybrid infrastructure. With P0, access is short-lived, auditable and policy-driven—from humans to service accounts.

    Founded:
    2022
    Funding:
    $20M
    Lightspeed Venture Partners 3x
  • Prophetsecurity.ai
    CEO:
    Kamal Shah

    Prophet Security delivers an Agentic AI SOC Platform that automates the manual and repetitive process of triaging, investigating and responding to alerts. Prophet AI delivers a 10x reduction in mean time to response, eliminates alert fatigue, and enables security teams to focus on security tasks that matter.

    Founded:
    2023
    Funding:
    $41M
  • Lightspeed Venture Partners 2x
    Straiker.ai
    CEO:
    Ankur Shah

    Straiker is an AI-native security platform for agentic AI applications. Our fine tuned models are trained to simulate attacks and defend enterprises against AI threats.

    Founded:
    2024
    Funding:
    $24.5M
    Lightspeed Venture Partners 2x
  • Vega.IO
    CEO:
    Shay Sandler

    Provider of cybersecurity services intended for cyberattack detection. The company is currently operating in stealth mode.

    Founded:
    2023
    Funding:
    $65M
  • Lightspeed Venture Partners
    VirtueAI.com
    CEO:
    Bo Li

    VirtueAI is an enterprise AI security platform that safeguards the full lifecycle of AI agents and models. Using a unified architecture, it delivers real-time protection, red-teaming, and compliance enforcement across modalities, preventing unauthorized actions, hallucinations, leaks, and attacks.

    Founded:
    2014
    Funding:
    $30M
    Lightspeed Venture Partners
  • Witness.ai
    CEO:
    Rick Caccia

    WitnessAI is an enterprise AI security and compliance platform that helps organizations scale AI safely. It monitors AI usage, detects shadow AI, protects models and chatbots, and enforces policy-driven guardrails, delivering unified visibility, control, and measurable risk reduction across the AI ecosystem.

    Founded:
    2023
    Funding:
    $27.5M
  • Zenity.IO
    CEO:
    Ben Kliger

    Developer of a security and governance platform designed to protect AI agents across SaaS, cloud environments, and endpoint devices. The company offers full-lifecycle coverage including agent discovery, posture management, real-time detection, prevention, and response with an agent-centric approach, enabling enterprises to adopt AI while maintaining consistent security and compliance.

    Founded:
    2021
    Funding:
    $59.5M
  • Astrix.security
    CEO:
    Alon Jackson

    Astrix is a security platform for AI agents and non-human identities (NHIs), helping organizations discover, govern, and deploy them securely. It continuously profiles agent behavior, enforces least privilege access with just-in-time credentials, and provides auditability, all in one unified system.

    Founded:
    2021
    Funding:
    $85M
  • Lightspeed Venture Partners 2x
    Blinkops.com
    CEO:
    Gil Barak

    BlinkOps is an agentic security automation platform that enables organizations to build, deploy, and manage security micro agents and workflows without code. It converts natural language prompts into executable security operations, accelerates response across use cases like SOC, IAM, and cloud security, and delivers audit-ready, scalable automation that outpaces traditional SOAR tools.

    Founded:
    2021
    Funding:
    $100M
    Lightspeed Venture Partners 2x
  • 2x
    Conductorone.com
    CEO:
    Alexander Bovee

    ConductorOne is the first multi-agent identity security platform that protects every identity—human, non-human, and AI—by centralizing access visibility, automating compliance, and enforcing fine-grained controls across all apps and infrastructure. With open connectivity, powerful automation, and AI-native capabilities, we make securing identity effortless.

    Founded:
    2022
    Funding:
    $111M
    2x
  • Lightspeed Venture Partners 3x
    Descope.com
    CEO:
    Slavik Markovich

    Descope is the drag & drop external IAM platform. Our no / low code solution helps organizations manage identity journeys for their users, business customers, partners, AI agents, and MCP servers.

    Founded:
    2022
    Funding:
    $53M
    Lightspeed Venture Partners 3x
  • Doppel.com
    CEO:
    Kevin Tian

    Doppel is an AI-native platform for Social Engineering Defense. Purpose-built to stop modern digital deception, Doppel dismantles the infrastructure behind impersonation, fraud, and brand abuse. The Doppel platform maps and disrupts multi-channel attacks across domains, social media, paid ads, messaging apps, the dark web and more– automating takedowns with agentic AI and a real-time threat graph. Doppel helps organizations reduce risk, protect executives, employees, and customers, and stay ahead of the evolving multi-channel threat landscape.

    Founded:
    2022
    Funding:
    $54M
  • Lightspeed Venture Partners 3x
    Endorlabs.com
    CEO:
    Varun Badhwar

    Operator of a lifecycle management platform intended to make software engineering a robust process. The company's platform helps to eliminate the complexity and frustration of selecting, securing, and maintaining software dependencies, enabling clients to keep up by maximizing the reuse of code, adopting microservices architectures, and relying on a vast array of party tools.

    Founded:
    2021
    Funding:
    $160M
    Lightspeed Venture Partners 3x
  • Lightspeed Venture Partners
    Eon.io
    CEO:
    Ofir Ehrlich

    Eon is changing the cloud data backup space by introducing a new storage tier that turns backups into live strategic assets — seamlessly automated, radically cost-efficient, and instantly usable for AI and analytics.

    Founded:
    2024
    Funding:
    $200M
    Lightspeed Venture Partners
  • 2x
    Gitguardian.com
    CEO:
    Eric Fourrier

    GitGuardian is the end-to-end NHI security leader. GitGuardian helps you take control of your NHI security by discovering all your secrets, prioritizing and remediating leaks at scale, ultimately protecting your non-human identities, and reducing breach exposure.

    Founded:
    2017
    Funding:
    $56M
    2x
  • 3x
    Halcyon.ai
    CEO:
    Jon Miller

    Operator of a cybersecurity platform intended to stop ransomware from impacting enterprise customers. The company's platform offers layered ransomware protection that combines pre-execution detection, behavioral modeling and deception techniques, enabling clients to get resiliency, recovery and isolation of impacted nodes for mid-market and enterprise customers.

    Founded:
    2021
    Funding:
    $250M
    3x
  • 3x
    Legitsecurity.com
    CEO:
    Roni Fuchs

    The Legit Security ASPM platform is a new way to manage application security in a world of AI-first development, providing a cleaner way to manage and scale AppSec and address risks.

    Founded:
    2020
    Funding:
    $70M
    3x
  • Lightspeed Venture Partners 2x
    Oligo.security
    CEO:
    Nadav Czerninski

    Oligo is the runtime security company that protects cloud applications where they actually run. Its platform provides deep application-level visibility and real-time protection, enabling organizations to detect and block threats in modern cloud environments.

    Founded:
    2022
    Funding:
    $80M
    Lightspeed Venture Partners 2x
  • Lightspeed Venture Partners
    Saltosystems.com
    CEO:
    Rami Tamir

    Developer of a business application configuration platform designed to simplify and streamline business operations. The company offers an automated sandbox to production deployments, change tracking, configuration backup, and security issue remediation as well as enhances the quality and speed of your deployments, enabling business operations teams to automate tasks and processes that save time and resources and reduce human errors, bugs, and breaks.

    Founded:
    2019
    Funding:
    $94M
    Lightspeed Venture Partners
  • Lightspeed Venture Partners 3x
    Semgrep.dev
    CEO:
    Isaac Evans

    Semgrep is the AppSec platform that makes zero false positives possible, by combining static analysis with LLMs, and enriching results with cloud context so teams can prioritize what actually matters. If findings need tuning, Assistant Memories learns from your triage decisions to stop flagging them again. The more you use Semgrep, the more tailored and noise-free it becomes.

    Founded:
    2017
    Funding:
    $204M
    Lightspeed Venture Partners 3x
  • Sublime.security
    CEO:
    Josh Kamdjou

    Sublime is an agentic email security platform that prevents, detects, and responds to email-borne threats with precision. Sublime dramatically reduces risk, lowers MTTR, and enables the business to operate securely without slowing down.

    Founded:
    2019
    Funding:
    $98M
  • Lightspeed Venture Partners 2x
    Thetalake.com
    CEO:
    Devin Redmond

    Theta Lake is a Cloud and AI Native platform providing compliance and security for unified communication, collaboration, and AI in the modern workplace. In use by 6 of the top 10 North American Banks across millions of users globally.

    Founded:
    2017
    Funding:
    $72M
    Lightspeed Venture Partners 2x
  • 2x
    Torq.IO
    CEO:
    Ofer Smadari

    Torq is the pioneer of the world’s first enterprise-grade security hyperautomation platform, seamlessly automating entire security infrastructures. Purpose-built to eliminate legacy SOAR’s constraints, Torq delivers machine-speed triage, investigation, and remediation.

    Founded:
    2020
    Funding:
    $192M
    2x
  • 3x
    Upwind.IO
    CEO:
    Amiram Shachar

    Upwind is the next-generation cloud security platform built to lead the Runtime revolution. With rapid momentum and a bold vision to unify cloud and application-layer protection, Upwind helps organizations run faster, detect threats earlier, and secure their environments with unmatched precision.

    Founded:
    2022
    Funding:
    $180M
    3x
  • 3x
    Veza.com
    CEO:
    Tarun Thakur

    Veza is the identity security company pioneering the Access Graph™, giving enterprises unified visibility into who can access what across humans, machines, apps, and data. By eliminating excessive and risky permissions, Veza helps organizations reduce breach risk, enforce least privilege, and accelerate Zero Trust initiatives.

    Founded:
    2000
    Funding:
    $235
    3x
  • Xbow.com
    CEO:
    Oege De Moor

    XBOW is an AI-powered penetration testing platform that delivers human-level security testing at machine speed.

    Founded:
    2024
    Funding:
    $117M
  • Zafran.IO
    CEO:
    Sanaz Yashar

    Zafran proactively stops exploitation of vulnerabilities everywhere, calculating applicable risk through deep analysis of threats and your own security tools. It then accelerates mitigation and remediation with a novel agentic workflow that outpaces AI-powered exploits.

    Founded:
    2022
    Funding:
    $70M
  • Lightspeed Venture Partners 3x
    1Password.com
    CEO:
    David Faugno

    1Password pioneered Extended Access Management, a modern cybersecurity category built for the way people and AI agents work today. The 1Password Extended Access Management platform was purpose-built to close the Access Trust Gap by securing every sign-in, to every app, from every device—including the managed and unmanaged ones that legacy IAM, IGA, and MDM tools can’t reach.

    Founded:
    2005
    Funding:
    $920M
    Lightspeed Venture Partners 3x
  • 3x
    Abnormal.ai
    CEO:
    Evan Reiser

    Abnormal AI is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated inbound attacks and detect compromised accounts across email and connected applications.

    Founded:
    2018
    Funding:
    $546M
    3x
  • Lightspeed Venture Partners 3x
    Arcticwolf.com
    CEO:
    Nick Schneider

    Arctic Wolf is a global leader in security operations, delivering the first cloud-native security operations platform to end cyber risk. Built on open XDR architecture, the Arctic Wolf Aurora Platform operates at a massive scale and combines the power of artificial intelligence with world-class security experts to provide 24×7 monitoring, detection, response, and risk management

    Founded:
    2012
    Funding:
    $899M
    Lightspeed Venture Partners 3x
  • 2x
    Armis.com
    CEO:
    Yevgeny Dibrov

    Armis, the cyber exposure management & security company, sees, protects and manages all physical and virtual assets - from the ground to the cloud - ensuring the entire attack surface is both defended and managed in real time.

    Founded:
    2015
    Funding:
    $800M
    2x
  • Lightspeed Venture Partners 3x
    At-bay.com
    CEO:
    Rotem Iram

    At-Bay is making small and mid-market businesses more secure by uniquely combining insurance and cybersecurity into a single risk solution with InsurSec.

    Founded:
    2016
    Funding:
    $292M
    Lightspeed Venture Partners 3x
  • Lightspeed Venture Partners 3x
    Axonius.com
    CEO:
    Dean Sysman

    Axonius is the global leader in cyber asset intelligence™, powering the future of cyber exposure management. The company provides the essential foundation for managing cyber risk, starting with a complete, credible, and always up-to-date inventory of every asset. With this intelligence as its engine, the Axonius platform moves teams beyond mere visibility to true actionability - enabling them to minimize their attack surface, streamline IT and security operations, and simplify compliance.

    Founded:
    2017
    Funding:
    $595M
    Lightspeed Venture Partners 3x
  • Lightspeed Venture Partners 3x
    Catonetworks.com
    CEO:
    Shlomo Kramer

    Cato creates a seamless and elegant customer experience that effortlessly enables threat prevention, data protection, and timely incident detection and response. Using Cato, businesses easily replace costly and rigid legacy infrastructure with an open and modular SASE architecture based on SD-WAN, a purpose-built global cloud network, and an embedded cloud-native security stack to secure and optimize their global hybrid workforce and mission-critical applications and data on premises and in the cloud.

    Founded:
    2015
    Funding:
    $770M
    Lightspeed Venture Partners 3x
  • Lightspeed Venture Partners 3x
    Chainguard.dev
    CEO:
    Dan Lorenc

    Chainguard is the safe source for open source. By delivering hardened, secure, and production-ready builds of all the open source software organizations rely on, we help engineering teams build faster, stay compliant, and eliminate risk.

    Founded:
    2021
    Funding:
    $612M
    Lightspeed Venture Partners 3x
  • 3x
    Cribl.IO
    CEO:
    Clint Sharp

    Cribl, the Data Engine for IT and Security, empowers organizations to transform their data strategy. Customers use Cribl’s vendor-agnostic solutions to analyze, collect, process, and route all IT and security data from any source or to any destination, delivering the choice, control, and flexibility required to adapt to their ever-changing needs.

    Founded:
    2018
    Funding:
    $600M
    3x
  • Lightspeed Venture Partners 2x
    Cyera.com
    CEO:
    Yotam Segev

    Cyera is the world’s leading AI-native data security platform, giving organizations a complete view of where their data lives, how it’s used, and how to keep it safe, so they can reduce risk and unlock the full value of their data, wherever it is.

    Founded:
    2021
    Funding:
    $1.3B
    Lightspeed Venture Partners 2x
  • 3x
    Drata.com
    CEO:
    Adam Markowitz

    Drata is a trust management platform that uses AI-powered automation to modernize governance, risk, compliance, and assurance, helping thousands of businesses develop a more secure, proactive, audit-ready, and risk-aware organization to continuously maintain trust.

    Founded:
    2020
    Funding:
    $328.2M
    3x
  • 3x
    Huntress.com
    CEO:
    Kyle Hanslovan

    Huntress is a global cybersecurity company that protects endpoints, identities, data, and employees with accessible, enterprise-grade products designed to continuously address the unique needs of IT and security teams of ALL SIZES.

    Founded:
    2015
    Funding:
    $268M
    3x
  • 3x
    Island.IO
    CEO:
    Mike Fey

    Island created the Enterprise Browser, a simplified workspace delighting CIOs, CISOs, and end users. It embeds core IT, security, and productivity needs into the browser, making application delivery simple, data fundamentally secure, and work smooth and natural.

    Founded:
    2020
    Funding:
    $730M
    3x
  • 2x
    Onetrust.com
    CEO:
    Kabir Barday

    OneTrust is the leading AI-ready governance platform. Customers rely on OneTrust to accelerate innovation while ensuring responsible data use.

    Founded:
    2016
    Funding:
    $1.1B
    2x
  • Lightspeed Venture Partners 3x
    Cyberresilience.com
    CEO:
    Vishaal "V8" Hariprasad

    Resilience offers a first-of-its-kind platform that integrates risk quantification software, cybersecurity expertise, and highly-rated insurance to help organizations become cyber resilient to material losses by staying ahead of bad actors.

    Founded:
    2016
    Funding:
    $220M
    Lightspeed Venture Partners 3x
  • 2x
    Tailscale.com
    CEO:
    Avery Pennarun

    Tailscale provides secure, identity-first networking, simplifying complex network setups with fast, reliable connections that seamlessly scale across cloud and on-premises environments. Tailscale’s award winning technology enables effortless adoption of Zero Trust principles with secure connectivity that just works.

    Founded:
    2019
    Funding:
    $275.5M
    2x
  • Goteleport.com
    CEO:
    Ev Kontsevoy

    Teleport is the Infrastructure Identity Company, modernizing identity, access, and policy for infrastructure, improving engineering velocity and infrastructure resiliency against human factors and compromise.

    Founded:
    2015
    Funding:
    $165M
  • Tines.com
    CEO:
    Eoin Hinchy

    Tines is the intelligent workflow platform trusted by the world's most advanced organizations. Companies use Tines to power their most important workflows. With Tines, they've built a secure, flexible foundation to operationalize AI and automation, unlocking productivity, moving faster, and future-proofing how work gets done.

    Founded:
    2018
    Funding:
    $272M
  • 3x
    Vanta.com
    CEO:
    Christina Cacioppo

    Vanta is the leading AI trust management platform that helps simplify and centralize security for organizations of all sizes. Over 12,000 companies including Atlassian, Duolingo, Icelandair, Ramp and Synthesia rely on Vanta to build, maintain and demonstrate their trust—all in a way that's real-time and transparent.

    Founded:
    2018
    Funding:
    $504M
    3x
  • Lightspeed Venture Partners
    Verkada.com
    CEO:
    Filip Kaliszan

    Leader in AI-powered physical security technology.

    Founded:
    2017
    Funding:
    $700M
    Lightspeed Venture Partners

The Cyber60 Podcast

Episode TRAILER
The Cyber60 Podcast: Meet the Minds Forging Security for an AI-Powered World | Trailer
Episode 1
Jay Chaudhry on Zero Trust, AI Security, and Building for the Long Term
Jay Chaudhry
Episode 2
Coming 11/05
Creating a Holistic Data Security Platform: Cyera's Yotam Segev Interview
Yotam Segev
Episode 3
Coming 11/12
From Google to Chainguard: Dan Lorenc on Developer-Led Security
Dan Lorenc
Episode 4
Coming 11/19
When AI Writes Code: Rethinking Application Security with Semgrep's Isaac Evans
Issac Evans
Episode 5
Coming 12/03
Netskope's Sanjay Beri: Securing the Enterprise Edge in the AI Era
Sanjay Beri
Episode 6
Coming 12/10
Securing the Future of AI: From Netflix to Anthropic
Vitaly Gudanets
Episode 7
Coming 12/17
Rubrik CEO Bipul Sinha: Cyber Resilence in the Age of AI
Bipul Sinha
Listen and follow

CISO SURVEY

AI in Cybersecurity

The Lightspeed Cyber 60 CISO Survey reveals that the enterprise cybersecurity landscape is experiencing a fundamental transformation driven by artificial intelligence. Organizations are rapidly adapting their security strategies to address both the opportunities and threats presented by AI.

Our survey of 200 Chief Information Security Officers (CISOs) at companies with $500M+ annual revenue reveals a critical inflection point: 75% of organizations have experienced or suspect AI-related security incidents in the past 12 months, while simultaneously recognizing AI as essential to their defensive capabilities. AI is now the biggest threat in cybersecurity, and also our greatest hope for building a more secure future.

{{ $statistic['value'] }}%

of organizations have experienced or suspect AI-related security incidents in the past 12 months

{{ $statistic['value'] }}%

consider AI critical to their business and security strategy

{{ $statistic['value'] }}%

expect cybersecurity budgets to increase over next 12 months

{{ $statistic['value'] }}%

have conducted or plan to conduct AI threat surface assessments

CISO SURVEY

AI Threat Landscape

AI-Related Security Incidents (Past 12 Months)

Suspected incident (unconfirmed)

0%

Confirmed incident

0%

Detected attacks but no incidents

0%

No attacks detected

0%

Critical Finding

75% of organizations experienced either confirmed or suspected AI-related security incidents in the past year, with 91% at least detecting attempted attacks—underscoring the immediate and tangible nature of AI threats.

Perceived Threat Level of AI Attacks (Next 12 Months)

Moderate threat

0%

Minimal threat

0%

Severe threat

0%

No meaningful threat

0%

Top AI-Related Threat Vectors

AI-generated phishing/deepfakes

0%

Synthetic identity fraud

0%

LLM-powered malware or bots

0%

Prompt injection/jailbreaks

0%

Shadow AI/unsanctioned usage

0%

Data poisoning

0%

Adversarial prompt chaining

0%

Model exfiltration

0%

Expected Attacker AI Tools

Code-generation tools

0%

Offensive LLMs (e.g., WormGPT)

0%

Autonomous agents

0%

Deepfake audio/video

0%

Key Insight

Nearly two-thirds of CISOs expect attackers to leverage AI code-generation tools, with autonomous agents and offensive LLMs close behind—signaling an arms race in AI-powered attack capabilities.

AI Threat Surface Assessment Status

Already conducted

0%

Planned within 6 months

0%

Planned later

0%

No plans

0%

In our view, the best cybersecurity companies emerge when founders understand that threats aren’t theoretical. With 94% conducting threat assessments and 75% already experiencing incidents, the market is demanding solutions built for reality, not PowerPoints.

Tal Morgenstern Lightspeed partner. Enterprise.
CISO SURVEY

Organizational Context

Security team size

50 to 99 personnel
0%
25 to 49 personnel
0%
Less than 25 personnel
0%
100 or more personnel
0%

Key Insight

Security team sizes vary significantly, with 61% of organizations maintaining teams of 25-99 personnel, reflecting diverse approaches to security staffing at the enterprise level.

Company AI Strategy

AI is critical to business & security

0%

AI is being explored in initiatives

0%

AI is important but not foundational

0%

AI not currently part of strategy

0%
CISO SURVEY

AI in Security Operations

Current AI Tool Deployment in Security Stack

Vulnerability management

0%

SOC/SIEM (threat detection, log triage)

0%

Endpoint protection/XDR

0%

Application security

0%

Insider threat detection

0%

Identity and access management

0%

GenAI-specific tools

0%

DSPM/data security

0%

Key Insight

AI adoption is widespread across security stacks, with traditional security areas (vulnerability management, SOC/SIEM) leading deployment while GenAI-specific tools are gaining traction.

Planned AI Security Tool Evaluations (NEXt 12 Months)

AI model access governance

0%

Secure inference platforms

0%

AI-powered risk scoring/behavior analytics

0%

LLM red teaming/jailbreaking tools

0%

Model firewalls/API layer security

0%

Future Focus

Organizations are prioritizing governance and secure deployment of AI, with over half planning to evaluate model access governance and secure inference platforms in the coming year.

CISO SURVEY

Vendor Strategy and Procurement

Importance of Vendor AI Strategy

  • 59% Very important
  • 23% Critically important
  • 19% Somewhat important

Key Insight

100% of CISOs consider vendor AI strategy important, with 82% rating it as very or critically important—making AI capabilities a key differentiator in procurement decisions.

Consolidation vs. Point Solution Strategy

0% 0%
  • Consolidate into fewer platforms
  • Adopt AI-native point solutions

Split Strategy

The market is nearly evenly divided between those adopting specialized AI-native solutions (53%) and those preferring platform consolidation (47%), reflecting different organizational philosophies on managing AI security.

Organizations are split almost evenly on whether to consolidate or adopt point solutions. That uncertainty creates opportunity for founders who can solve a specific, painful problem exceptionally well.

Arif Janmohamed Lightspeed partner. Enterprise.
CISO SURVEY

Budget and Investment Outlook

Cybersecurity Budget Changes (NEXt 12 Months)

Increase moderately

0%

Increase significantly

0%

Stay flat

0%

Decrease moderately

0%

Budget Momentum

88% of CISOs anticipate budget increases, with one in five expecting significant growth—signaling strong organizational commitment to cybersecurity investment despite economic uncertainties.

AI Budget allocation (% Of Security Budget)

6%-10% of budget

0%

11%-25% of budget

0%

1%-5% of budget

0%

More than 25%

0%

Key Insight

100% of organizations are allocating budget to AI initiatives, with 86% dedicating more than 5% of their security budget—a significant commitment reflecting AI's strategic importance.

Organizations are committing real dollars—88% increasing budgets, 86% allocating over 5% to AI security. This isn’t exploratory spending. Companies invest like this when the pain is acute and the stakes are existential.

Tal Morgenstern Lightspeed partner. Enterprise.
CISO SURVEY

Skills and Talent Management

Confidence in In-House AI Security Skills

Mostly confident

0%

Somewhat confident

0%

Fully confident

0%

Not confident

0%

Confidence Gap

Only 16% of CISOs are fully confident in their team's AI security skills, with 85% expressing some level of doubt—highlighting a critical capability gap that organizations must urgently address.

In-House vs. Vendor Reliance for AI Security

About an equal mix

0%

Mostly in-house, some vendors

0%

Mostly vendors, some in-house

0%

Entirely in-house

0%

Entirely vendors

0%

Hiring and Reskilling Plans for AI Security

Planning within 6 months

0%

Already hired/reskilled

0%

Planning within 12 months

0%

No plans

0%

Talent Urgency

88% of organizations have already hired AI security talent or plan to within 6 months—demonstrating urgent action to close the skills gap and build AI security capabilities.

This isn’t just a skills gap—it’s a fundamental mismatch between the speed of AI adoption and our ability to secure it. We believe the companies that win will help security teams do more with what they have, not require rare expertise to operate.

Guru Chahal Lightspeed partner. Enterprise.
CISO SURVEY

Governance and Operational Challenges

Top AI Security Governance Challenges

Third-party model risk/trust boundaries

0%

Shadow use of GenAI tools

0%

Legal and regulatory uncertainty

0%

Unclear accountability for AI risk

0%

Lack of internal audit/model explainability

0%

Governance Complexity

CISOs face multiple simultaneous challenges, with third-party risk and shadow AI usage topping concerns—reflecting the difficulty of securing AI in complex enterprise environments where control and visibility are limited.

Every security company claims to be AI-driven, but our job is to separate signal from noise. With 50% of CISOs citing third-party model risk as their top challenge, the problems are real and immediate.

Guru Chahal Lightspeed partner. Enterprise.
CISO SURVEY

The AI Security
Opportunity Map

Where CISO Pain Points Signal Market Needs

The gap between threat reality and organizational readiness creates significant opportunities for innovation across the security stack. Based on our survey findings, we've identified five high-priority areas where CISO challenges align with emerging solution categories.

5 High-Priority Opportunity Areas

  • 1
    AI Governance & Policy Automation
  • 2
    Security Workforce Augmentation
  • 3
    ITDR for Non-Human Identities
  • 4
    AI Discovery & Shadow AI Management
  • 5
    AI Supply Chain Security
AI Governance & Policy Automation
AI Governance & Policy Automation
THE GAP

of organizations have cybersecurity driving AI governance processes, while 87% involve security as “one voice among many.” This distributed ownership model creates accountability gaps and inconsistent risk management.

Market Opportunity:
  • AI governance platforms that centralize policy creation and enforcement
  • Automated compliance frameworks for AI usage and deployment
  • Risk assessment tools specific to AI/ML model deployment
  • Cross-functional governance workflows integrating security, legal, and data teams
VALIDATION

82% of CISOs rate vendor AI strategy as very or critically important in procurement decisions, indicating demand for solutions that address governance systematically.

Security Workforce Augmentation
Security Workforce Augmentation
THE GAP

of CISOs are fully confident in their teams’ AI security capabilities, yet 88% plan to hire or reskill within six months—a clear supply-demand imbalance in AI security talent.

Market Opportunity:
  • AI-native SOC co-pilots that augment analyst capabilities
  • Automated threat detection and triage systems
  • Security workflow automation reducing manual investigation time
  • Training and simulation platforms for AI security scenarios
  • Decision support systems that codify expert knowledge
VALIDATION

With 100% of organizations investing in AI security and widespread skills gaps, solutions that multiply the effectiveness of existing teams address a universal need.

ITDR for Non-Human Identities
ITDR for Non-Human Identities
THE GAP

The identity explosion extends beyond human users to AI agents, service accounts, and automated systems. Traditional identity solutions weren’t designed for this reality.

Market Opportunity:
  • ITDR platforms purpose-built for AI agents and autonomous systems
  • Identity graph solutions that map relationships between human and non-human identities
  • Dynamic access controls that adjust permissions based on AI agent behavior
  • Anomaly detection for machine-to-machine authentication patterns
  • Agent runtime security and policy enforcement
VALIDATION

58% of CISOs expect attackers to use autonomous agents and Identity was consistently cited among top concerns—highlighting both defensive and offensive dimensions of this challenge.

AI Discovery & Shadow AI Management
AI Discovery & Shadow AI Management
THE GAP

of CISOs identify shadow AI/unsanctioned GenAI usage as a top governance challenge, while 41% cite it as a primary threat vector. Organizations lack visibility into what AI tools employees are using.

Market Opportunity:
  • AI discovery and inventory platforms (similar to CSPM for AI)
  • SaaS security posture management with AI-specific controls
  • Data exfiltration prevention for AI interactions
  • Usage monitoring and policy enforcement for approved AI tools
  • Browser and endpoint controls for AI service access
VALIDATION

This challenge sits at the intersection of governance (49%), threat prevention (41%), and third-party risk (50%), making it a multi-dimensional market opportunity.

AI Supply Chain Security
AI Supply Chain Security
THE GAP

of CISOs cite third-party AI model risk and trust boundaries as their top governance challenge. Organizations are consuming AI models without adequate security validation mechanisms.

Market Opportunity:
  • AI supply chain security platforms
  • Model provenance and attestation systems
  • Third-party AI risk assessment frameworks
  • Model integrity verification and monitoring
  • Secure inference platforms with confidentiality guarantees
  • ML-specific vulnerability scanning and testing
VALIDATION

With 54% planning to evaluate secure inference platforms and 49% considering LLM red teaming tools in the next 12 months, organizations recognize this gap and are actively seeking solutions.

100%

investing in AI security

88%

increasing security budgets

75%

experienced AI incidents

Cross-Cutting Themes

Several patterns emerge across these opportunity areas:

  • Platform vs. Point Solution Tension

    The market remains split (53% prefer point solutions, 47% prefer consolidation), suggesting room for both specialized best-of-breed tools and integrated platforms. Success may depend on solving a specific pain point exceptionally well or providing genuine integration value across multiple problems.

  • AI-Native vs. AI-Augmented

    Solutions built from the ground up for AI security (GenAI-specific tools) are gaining traction (39% already deployed), but traditional categories enhanced with AI capabilities (vulnerability management at 49%, SOC/SIEM at 45%) show strong adoption. Both approaches have merit depending on the problem domain.

  • Immediate vs. Strategic Needs

    Budget increases (88%) and urgent hiring plans (60% within 6 months) indicate organizations will invest in solutions that address immediate pain points. However, 94% conducting threat surface assessments suggests longer-term strategic thinking as well.

Implications for Innovation

These opportunity areas share several characteristics that define successful AI security solutions:

  1. Solve a confirmed pain point: 

    Each area maps directly to challenges cited by 40%+ of surveyed CISOs

  2. Address the skills gap: 

    Solutions that multiply team effectiveness matter more than those requiring rare expertise

  3. Integrate with existing workflows: 

    48% prefer balanced in-house/vendor approaches, suggesting solutions must complement rather than replace

  4. Demonstrate ROI quickly: 

    With 75% already experiencing incidents, organizations need solutions that show value fast

  5. Scale with AI adoption:

    As 71% view AI as critical or important to strategy, security solutions must enable rather than block innovation

AI security has to both create and protect value—enabling organizations to harness AI’s potential while defending against real threats. We believe the best companies will view security as an enabler of innovation, not a blocker.

Arif Janmohamed Lightspeed partner. Enterprise.

Key Conclusions and Implications

  • AI Security Has Reached a Tipping Point

    With 75% of organizations experiencing AI-related incidents and 91% detecting attacks, AI security is no longer theoretical. The threat is real, immediate, and affecting the majority of enterprises today.

  • The Skills Gap is the Primary Bottleneck

    Only 16% of CISOs are fully confident in their teams’ AI security capabilities. This skills shortage is driving aggressive hiring (88% hiring within 6 months) and increased reliance on vendor partnerships (65% use vendors for AI security).

  • Governance Remains Fragmented and Risky

    While 87% involve security in AI governance, only 33% have security leading these efforts. Combined with challenges around shadow AI (49%) and third-party risks (50%), this creates significant vulnerabilities.

  • Investment is Universal but Measured

    Every organization is investing in AI security, with most allocating 6-10% of their security budget. The near-even split between point solutions (53%) and platform consolidation (47%) reflects market uncertainty about the optimal approach.

  • The Attack Surface is Expanding Rapidly

    CISOs expect sophisticated AI-powered attacks across multiple vectors—from code generation tools (65%) to deepfakes (41%). Organizations are responding with comprehensive threat assessments (94% completed or planned) and diverse security tool deployments.

Strategic Imperatives for 2026

  • Accelerate talent acquisition

    The skills gap won’t close itself—aggressive hiring and reskilling are essential.

  • Strengthen governance

    Security must move from participant to leader in AI governance.

  • Balance innovation with control

    Managing shadow AI while enabling business innovation.

  • Prepare for AI-vs-AI warfare

    As attackers adopt AI tools, defenders must match their sophistication.

  • Vendor AI capabilities are now table stakes

    82% consider vendor AI strategy critical in procurement

The data is clear: AI security is not a future concern but a present imperative. Organizations that act decisively on these findings—investing in talent, technology, and governance—will be best positioned to harness AI’s transformative potential while defending against its risks. The question is no longer whether to prioritize AI security, but how quickly you can mobilize your organization to meet this moment.

METHODOLOGY

The Fortune Cyber 60 is a listing of the most important venture-backed startups that have not had an IPO, acquisition, or other significant exit event.

The list is alphabetized into groups of 20 by stage: early-stage companies, early growth stage companies, and growth stage companies.

To construct the 2025-26 Cyber 60 list, Lightspeed requested data from over 500 cybersecurity startups and performed an initial sort by ARR and current and prior year growth rate.

Lightspeed then validated the accuracy of the self-reported data and reviewed the business operations of each company for inclusion. Lightspeed partners also nominated companies for consideration based on proprietary research including consultation with our CISO network, and analysis of the cybersecurity market landscape. No company was added or removed from the list for any reason except those listed above, and the final list was reviewed and validated by Fortune. When Lightspeed is an investor in a Cyber 60 company, it is noted on their listing.

The Lightspeed CISO Survey was conducted by Wakefield Research among 200 US CISOs at companies with a minimum of $500M in annual revenue, between July 29th and August 6th, 2025, using an email invitation and an online survey.

Results of any sample are subject to sampling variation. The magnitude of the variation is measurable and is affected by the number of interviews and the level of the percentages expressing the results. For the interviews conducted in this study, the chances are 95 in 100 that a survey result does not vary, plus or minus, by more than 6.9 percentage points from the result that would be obtained if interviews had been conducted with all persons in the universe represented by the sample.

ABOUT LIGHTSPEED

SERVING THE BOLD BUILDERS OF THE FUTURE.

For over twenty years Lightspeed has been the first investor and an early backer of some of the most innovative companies in the world, dedicated to serving bold Founders with big ideas.

We stand behind our Founders with high conviction, from Seed to Series F and beyond. We pursue opportunities based on their merits, regardless of where the Founder resides, because the future is global and so are we, with offices in 8 locations across 6 countries, comprising one Lightspeed community.

Visit us at LSVP.COM to learn more.

 

Fortune is a registered trademark, and Fortune Cyber 60 is a trademark, of Fortune Media IP Limited, used under license.

The content here should not be viewed as investment advice, nor does it constitute an offer to sell, or a solicitation of an offer to buy, any securities. Certain statements herein are the opinions and beliefs of Lightspeed; other market participants could take different views.