Top 5 Cybersecurity Investors Behind a $14B Market in 2026
Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.
Last updated: September 2026
Cybersecurity founders raising capital in 2026 face a strange market: $14 billion poured into cyber startups in 2025 (up 47% from 2024), and cyber startups took in $10.6 billion across all stages in the first half of 2026 — while 30 rounds above $100 million made up just 8% of 2025 deal volume but took nearly half of all dollars. (SecurityWeek, Pinpoint Search Group, Crunchbase News) That means capital is concentrating in fewer, bigger bets. If you are raising from a cyber-specialist VC, you need to be sharper than ever on wedge, distribution, and proof.
I spent years on the investor side at Backed VC and Target Global before co-founding Peony, a data room company now used by 6,800+ customers. The cybersecurity founders who use Peony to share deal materials tend to target the same five specialist firms over and over — and our page-level analytics show which of those firms are actually reviewing decks. That pattern, combined with public fund data and conversations with founders, is what shaped this list. If you are still mapping your broader raise, start with our startup fundraising strategy guide and how to send your pitch deck to investors before narrowing to specialist cyber VCs.
TL;DR: Cybersecurity VC hit $14 billion in 2025 (47% YoY increase, up from $9.5B in 2024) (SecurityWeek, Jan 2026) and kept running through 2026: $4.62 billion in Q1 across 128 rounds (Pinpoint Search Group, Apr 2026), while Crunchbase's broader security-and-privacy universe put the first half of 2026 at $10.6 billion across all stages (Crunchbase News, Jul 2026). Capital is concentrating: 30 rounds exceeded $100M in 2025 — 8% of deal volume, nearly half of all dollars (Pinpoint, Apr 2026). Israeli cyber funding alone hit a record $4.4 billion in 2025 (SecurityWeek, Feb 2026), and Alphabet closed its $32 billion acquisition of Wiz on 11 March 2026 — a full year of global antitrust review after the March 2025 announcement, cleared unconditionally in the US, EU, Australia, Israel, Saudi Arabia, South Africa and Türkiye — turning Cyberstarts' original $6.4M seed into a realized 200x (Cybersecurity Dive, Mar 2026; Reuters, Mar 2025). The five specialist firms below have raised more than $4.8 billion in cyber-dedicated capital between them — Cyberstarts $1.4B+, Ten Eleven $1B+, YL Ventures $800M, Ballistic ~$660M, Forgepoint $1B+. If you are raising a seed, Series A, or Series B for a cybersecurity company, these are the investors to target — and having a secure data room ready before the first call is table stakes.
Quick Reference Table
| Investor | Website | Headquarters | Stage | Estimated Check | Key Focus | Latest Fund Signal |
|---|---|---|---|---|---|---|
| Cyberstarts | cyberstarts.com | Tel Aviv, New York | Seed to breakout | $2M-$25M+ | Cyber-native, wedge-to-platform | $1.4B total, Wiz 200x realized |
| Ten Eleven Ventures | 1011vc.com | San Francisco | Multi-stage | $5M-$50M+ | Full-stack cybersecurity | $1B+ raised, 60+ cyber investments |
| YL Ventures | ylventures.com | Tel Aviv, San Francisco | Seed to scale | $2M-$15M | Cyber-focused, Israel-origin | $800M AUM, largest cyber seed fund |
| Ballistic Ventures | ballisticventures.com | San Francisco | Pre-seed to Seed | $2M-$10M | Cyber-only, incubation | $360M Fund II, ~$660M AUM |
| Forgepoint Capital | forgepointcap.com | San Mateo, California | Early-stage | $5M-$20M | Cyber + infrastructure software | $1B+ AUM, 3 unicorns, Fund III active |
Before reaching out to any of these firms, organize your startup data room with Peony. Our AI auto-indexing structures your documents in under three minutes, and page-level analytics show you exactly which investor spent time on which page — so you know who to follow up with first.

How do I pick the right cybersecurity investor for my stage and category?
Start with your security category (identity, cloud, AppSec, data, SecOps, or AI security), then filter by go-to-market motion (developer-led, CISO-led, channel, or platform ecosystem), then by stage fit. Getting this filter right saves you months of misrouted pitches.
Start with your security category
Most cyber specialists mentally bucket startups into one of these areas. Know which one you belong to — it determines who takes your first meeting.
- Identity and access — IAM, ITDR, PAM, auth, secrets management
- Cloud and infrastructure security — CSPM/CNAPP, runtime, containers, API security
- AppSec and software supply chain — SAST/DAST, SBOM, code scanning, vulnerability management
- Data security and privacy — DSPM, encryption, governance, data loss prevention
- SecOps and automation — SIEM/SOAR evolution, detection engineering, agentic security workflows
- Security for AI — model risk, prompt injection, data exfiltration, AI governance
Your category story should fit in one sentence with a crisp buyer and budget line attached.
Match the investor to your go-to-market motion
Cyber is not one market. Distribution varies wildly:
- Bottom-up / developer-led — fast adoption, high product bar, PLG motion
- CISO-led enterprise — longer cycles, heavier proof requirements, bigger ACVs
- Channel / MSSP / MDR — partner strategy matters from day one
- Platform ecosystems — cloud marketplaces, SI integrations, co-sell motions
Pick investors who have scaled companies with your motion before. A firm that excels at developer-led products may not know how to help you navigate a 6-month CISO procurement cycle.
Stage-fit matters more than brand
A cyber fund that "does early" may still prefer Series A and up. Conversely, some seed specialists only lead early and will not follow on. Build your list around who can lead your current round and has reserves for the next one.
Pattern recognition is the real value
The best cyber investors have seen dozens of cycles — what sells, what does not, which problems are real, and which are analyst-driven hype. That pattern recognition is often more valuable than a generalist with a bigger brand and a larger check.
Who are the top 5 cybersecurity investors writing checks in 2026?
The five specialist firms writing the largest cyber-native checks in 2026 are Cyberstarts (Tel Aviv / New York, $1.4B total), Ten Eleven Ventures (San Francisco, $1B+ raised across 60+ cyber investments), YL Ventures (Tel Aviv / San Francisco, $800M AUM), Ballistic Ventures (San Francisco, ~$660M across two vehicles), and Forgepoint Capital (San Mateo, California, $1B+ AUM). Each has a distinct thesis, stage focus, and pitching hook below.
1. Cyberstarts — Cybersecurity-First, Seed Through Breakout
Website: cyberstarts.com
Headquarters: Tel Aviv, New York
Latest fund activity: Cyberstarts closed Opportunity Fund II ($380M) in 2025 and raised $700M or more in 2025 alone, bringing total commitments to over $1.4 billion across funds. They also launched a $300M employee liquidity fund to help portfolio companies retain talent through hypergrowth stages. (Business Wire, Reuters)
Stage and motion: Seed through breakout follow-on. The core fund invests early, and the Opportunity Fund provides growth capital for winners — a structure that lets them stay with portfolio companies from first check through scaled exit.
Key categories: Identity, cloud security, data security, AI security. Cyberstarts backs companies that start with a sharp wedge and expand into platforms.
Why founders pick them: Track record. Cyberstarts' original $6.4M seed investment in Wiz turned into approximately $1.3 billion when Alphabet's $32 billion acquisition of Wiz closed on 11 March 2026 — a 200x return, and now a realized one rather than a mark on paper. It is the single best cybersecurity VC outcome in history and the largest acquisition Google has ever made, ahead of the $12.5 billion it paid for Motorola Mobility in 2012. (Cybersecurity Dive, TechCrunch) Portfolio also includes Island, Fireblocks, and Cyera, which raised a $600M Series G at a $12 billion valuation on 10 June 2026 — a doubling in twelve months — $6 billion in June 2025, $9 billion in January 2026, $12 billion in June 2026, led by Evolution Equity Partners with Cyberstarts and Temasek joining, taking Cyera past $2 billion raised in total. (Cyberstarts, Business Wire) Founding partner Gili Raanan's CISO network is one of the deepest in the industry.
Lead or follow? Cyberstarts' recent activity is mostly follow-on into its own winners rather than headline leads, which matters if you need someone to price and lead your round. It re-upped in Upwind Security's $250M Series B (26 January 2026, led by Bessemer Venture Partners at a $1.5B valuation, on the back of 900% year-over-year revenue growth), in Zafran Security's $60M Series C (2 December 2025, led by Menlo Ventures), and in Cyera's $600M Series G (June 2026). It also co-led Glow's $180M Series A at a $1.2B valuation in July 2026 alongside Sequoia, Greenoaks and Redpoint. (Business Wire, SecurityWeek)
What they scrutinize: Why now (what changed in the threat landscape), wedge sharpness (can you explain the entry point in one sentence), and early buyer signal (design partners, pipeline, pilots).
How to pitch Cyberstarts: Bring a concrete "why now" threat shift combined with a wedge that expands into a platform. Show early evidence that CISOs actually care — not just interest, but pilots, design partnerships, or technical validation from security teams. If you are pitching a category that overlaps with an existing portfolio company, address that head-on.
2. Ten Eleven Ventures — Cyber-Only, Multi-Stage Specialist
Website: 1011vc.com
Headquarters: San Francisco
Latest fund activity: Ten Eleven has raised over $1 billion and, on its own boilerplate, made more than 60 cybersecurity investments across stages; Crunchbase counts 21 portfolio exits to date (Barracuda and Ping Identity among them). Recent activity includes leading IQM Quantum Computers' $320M Series B (September 2025) — a notable expansion into quantum security — and Hypernative's $40M Series B. In January 2026 they led Furl's $10M Seed round, with participation from Rapid7 CEO Corey Thomas and the Open Opportunity Fund, and in February 2026 they backed VulnCheck's Series B. In January 2026 the firm also appointed Grace Cassy — co-founder of the CyLon cyber accelerator — as a Partner, deepening its European bench. (Ten Eleven, Ten Eleven, Business Wire, Business Wire)
Stage and motion: Multi-stage — one of the few cyber-only firms that can lead a seed round and still participate meaningfully in a Series C. This flexibility means they do not need to hand off portfolio companies to generalists at growth stage.
Key categories: Full-stack cybersecurity — cloud, identity, runtime, application security, detection, and compliance. Ten Eleven explicitly positions itself as "dedicated to igniting the next generation of innovative cybersecurity companies." (Ten Eleven)
Why founders pick them: Two decades of cybersecurity-only investing creates pattern recognition that generalists simply do not have. They understand enterprise security sales cycles, platform consolidation dynamics, and how security categories evolve.
Portfolio: A public portfolio spanning the full cybersecurity stack. (Ten Eleven)
What they scrutinize: ICP clarity (who buys, what budget, what trigger), defensibility (data moat, workflow lock-in, switching costs), and adoption realism (deployment model, time-to-value, integration requirements).
How to pitch Ten Eleven: Treat your pitch like a buyer-led business case. Lead with the security pain point, the budget that exists for it, and your adoption plan. Then show your wedge and what makes you defensible over a 5-year horizon. Use your data room to organize customer case studies, pipeline data, and competitive analysis so the Ten Eleven team can self-serve during diligence.
3. YL Ventures — Cyber-Focused, Seed to Scale
Website: ylventures.com
Headquarters: Tel Aviv, San Francisco
Latest fund activity: YL's Fund V ($400M, closed 2022) is the largest seed fund ever raised for cybersecurity, bringing total AUM to $800M across five funds. The fund is in active deployment with 3-5 years of runway remaining. (YL Ventures) YL's 10th annual "State of the Cyber Nation" report showed Israeli cyber funding hit a record $4.4 billion in 2025 across 130 rounds — up 9% on $4.03 billion from 89 rounds in 2024, and the first year in which global VC outpaced domestic Israeli capital at every stage, including seed. (SecurityWeek, PR Newswire) Recent 2026 investment: Novee, the AI offensive-security company that came out of stealth on 14 January 2026 with $51.5 million disclosed in aggregate — an $8.5M seed in May 2025, a $33M Series A in September 2025 and $10M of venture debt in December — co-led by YL Ventures with Canaan Partners and Oren Zeev. Novee raised its Series A within four months of being founded. (SecurityWeek) Recent exits include Aim (acquired by Cato Networks), Vulcan (acquired by Tenable), and Satori (acquired by Commvault) — all in 2025. The firm was named to TIME's list of top VC firms for 2025. (Reuters, YL Ventures)
Stage and motion: Seed to scale, with a clear thesis of championing cyber founders through the entire early journey. YL provides hands-on support from product-market fit through growth, not just capital. With 17 portfolio exits, they have a track record of actually returning capital — not just deploying it.
Key categories: Cyber-native companies across identity, cloud, data, and detection — with a strong preference for founders building from first principles rather than incremental improvements.
Why founders pick them: True cyber-native guidance. YL helps with category framing, go-to-market sequencing, and the "how buyers buy" nuance that makes the difference between a pilot that converts and one that stalls. If you are an Israeli founder, YL's dual Tel Aviv-San Francisco presence bridges the US enterprise market.
What they scrutinize: Problem urgency (what breaks without your product), technical differentiation (why incumbents cannot patch it), and commercial realism (security buyers are skeptical by default — show that your approach wins both technically and commercially).
How to pitch YL: Show a crisp problem statement with proof of urgency. Demonstrate early buyer pull — not just interest, but evidence that security teams are actively searching for what you build. If you have Israeli R&D with US GTM ambitions, make the cross-border plan explicit. Track engagement with your pitch materials using Peony's analytics to time your follow-ups.
4. Ballistic Ventures — Cyber-Only, Early-Stage With Incubation DNA
Website: ballisticventures.com
Headquarters: San Francisco
Latest fund activity: Ballistic closed an oversubscribed Fund II of $360M in March 2024 and has invested in over 25 companies since launch. The firm filed with the SEC in April 2025 to raise a new $100M vehicle; as of September 2026 no close has been announced, so treat Fund II as the money actually available today. Across its two vehicles Ballistic manages roughly $660 million. Its most recent lead is Native's $31M Series A in March 2026. (Ballistic Ventures, TechCrunch, PitchBook)
Stage and motion: Pre-seed and seed, with a strong incubation orientation. Ballistic explicitly positions itself as "dedicated exclusively to early-stage funding and incubation in cybersecurity." (Ballistic Ventures)
Key categories: Broad cyber — identity, cloud, data, SecOps, AI security. The unifying thread is category-creating companies, not feature additions to existing platforms.
Why founders pick them: The founding partner bench is extraordinary. Kevin Mandia (founder of Mandiant, acquired by Google Cloud, and now a General Partner at the firm), Ted Schlein (former KPCB cyber lead), and Barmak Meftah (former AT&T Cybersecurity president) bring operational depth that few investors can match. In 2025, Phil Venables (former Google Cloud CISO) joined as Venture Partner, adding board-level governance expertise. (PR Newswire) One caveat worth knowing before you pitch: since March 2026 Mandia has also been CEO of Armadin, the AI red-teaming company that launched with $189.9 million in combined seed and Series A funding — the largest such round in cybersecurity history — led by Accel with GV, Kleiner Perkins, Menlo Ventures, In-Q-Tel, 8VC and Ballistic follow-on. He remains a GP, but his operating attention now has a second home. Ask directly who your day-to-day partner would be. (SecurityWeek)
Portfolio signals: Ballistic's portfolio already has notable exits with real prices attached — Veza sold to ServiceNow for $1.3 billion, closing 2 March 2026; CrowdStrike announced a definitive agreement in September 2025 to acquire Pangea for roughly $260 million; and Talon was acquired by Palo Alto Networks. Active companies include Above, Aembit, Alethea, Armadin, ArmorCode, AuthMind, BreachRx, Codezero, Concentric AI, GetReal, Gomboc AI, Hypernative, Magnitude, Mimic, Native, Noma, Nudge Security, Oligo, OverAI, Reach, Reveal, Root Evidence, SpecterOps, UForce, WitnessAI, and Zip. (Axios, ServiceNow)
What they scrutinize: Category creation potential (not a feature, but a new market), founder-market fit (deep domain expertise), and distribution realism (how you get to your first 50 customers).
How to pitch Ballistic: Show why you are a category creator, not a feature bolt-on. Bring a working demo plus a threat story: what fails today, why incumbents cannot patch it, and why you will win distribution. Ballistic likes founders who have lived the problem — former practitioners building the tool they wished existed.
5. Forgepoint Capital — Cybersecurity Plus Infrastructure Software
Website: forgepointcap.com
Headquarters: San Mateo, California
Latest fund activity: Forgepoint manages over $1 billion in AUM across funds, with Cybersecurity Fund III closed and in active deployment. Third-party data providers now count 79 portfolio companies, and the firm has produced 3 unicorns — Cyberhaven, Huntress, and Interos — plus 2 IPOs. Recent investments include RapidFort (February 2026) and Nudge Security Series A (November 2025), and Forgepoint led Tadaweb's $20M raise in 2025. Its newest activity is participating as an existing investor in DataBahn's $40M Series B, led by Insight Partners and announced in summer 2026. (Forgepoint Capital, Forgepoint Capital, PR Newswire)
Stage and motion: Early-stage, with explicit focus on cybersecurity, AI, and infrastructure software. Forgepoint bridges the gap between pure-play cyber and the infrastructure layer that security products depend on. (Forgepoint Capital)
Key categories: Cloud security, identity, security data platforms, security engineering tooling, and infrastructure software. If your product lives at the intersection of security and infrastructure, Forgepoint is a natural fit.
Why founders pick them: Forgepoint connects product strategy to infrastructure realities. If you are building a security product that depends on cloud primitives, identity planes, or data pipeline architecture, Forgepoint's team can help you navigate platform partnerships and technical go-to-market.
Portfolio: Active portfolio including recognizable names like Huntress and companies spanning cloud, identity, and security engineering categories. (Forgepoint Capital)
What they scrutinize: Technical architecture clarity (does it scale?), infrastructure fit (where does your product sit in modern cloud stacks?), and land-and-expand potential (what do you sell next, and to whom?).
How to pitch Forgepoint: Bring a clear technical architecture diagram plus a scaling story. Show how your product fits into the modern stack — cloud, identity plane, data plane — and articulate your land-and-expand motion. Share your technical documentation alongside your deck in a Peony data room so the Forgepoint team can evaluate your architecture depth during diligence.
What has each of these five firms actually done in the last 12 months?
Cyberstarts has been almost entirely a follow-on investor in this window apart from co-leading Glow's Series A, Ten Eleven and Ballistic have each led two rounds, YL has led one, and Forgepoint has led three while joining a fourth. The distinction between leading and participating is the one founders most often lose money on: a fund that participates in your round is not a fund that will price it, set terms, or take the board seat. Every firm below publishes participation as "investment," so read the column headers carefully.
| Firm | Capital raised | Last fund close | 2025–26 rounds led | 2025–26 rounds joined | Realized exits in window |
|---|---|---|---|---|---|
| Cyberstarts | $1.4B+ across 7 funds | Opportunity Fund II, $380M, Sep 2025 (plus a $300M employee liquidity fund, Jul 2025) | Glow $180M A (co-led with Sequoia, Jul 2026) — otherwise a follow-on posture | Upwind $250M B (Bessemer led), Zafran $60M C (Menlo led), Cyera $600M G (Evolution led) | Wiz → Alphabet, $32B, closed 11 Mar 2026 — $6.4M seed to ~$1.3B, a realized 200x |
| Ten Eleven Ventures | $1B+ raised; 60+ cyber investments on the firm's own boilerplate; 21 portfolio exits per Crunchbase | Not disclosed | IQM Quantum $320M B (Sep 2025); Furl $10M seed (Jan 2026) | Hypernative $40M B; VulnCheck Series B (Feb 2026) | Historic: Barracuda, Ping Identity |
| YL Ventures | $800M across 5 funds; Fund V at $400M is the largest cyber seed fund ever raised | Fund V, 2022 | Novee, $51.5M disclosed in aggregate at its Jan 2026 launch | — | Aim → Cato Networks; Vulcan → Tenable; Satori → Commvault (all 2025). 17 portfolio exits to date |
| Ballistic Ventures | ~$660M across two vehicles; Fund II $360M (Mar 2024); $100M Fund III filed Apr 2025, still unclosed | Fund II, Mar 2024 | Native $31M A (Mar 2026) | Armadin $189.9M seed + A (Accel led, Mar 2026) | Veza → ServiceNow, $1.3B, closed 2 Mar 2026; Pangea → CrowdStrike, ~$260M, definitive agreement Sep 2025; Talon → Palo Alto Networks |
| Forgepoint Capital | $1B+ AUM; 79 portfolio companies; 3 unicorns (Cyberhaven, Huntress, Interos); 2 IPOs | Cybersecurity Fund III, in deployment | Tadaweb $20M (2025); Nudge Security Series A (Nov 2025); RapidFort (Feb 2026) | DataBahn $40M Series B (Insight Partners led, summer 2026) | — |
Read that table as a routing tool, not a scoreboard. If you need a lead for a priced seed today, Ten Eleven, Ballistic and YL have each done exactly that inside the last twelve months. If you want a partner who will re-up at growth without a new syndicate, Cyberstarts' Opportunity Fund is built precisely for that and its recent behaviour proves it. Whichever way you route, the documents each of these firms will ask for are broadly the same — and how investors actually read a data room is the part founders underestimate.
What changed among these investors since this list was first published?
Seven things changed materially between the April 2026 publication of this list and September 2026, and four of them change who you should pitch.
- Cyberstarts' Wiz return became real money. Google's $32 billion acquisition closed on 11 March 2026 after twelve months of global antitrust review, cleared unconditionally in the US, EU, Australia, Israel, Saudi Arabia, South Africa and Türkiye. It is the largest acquisition in Google's history. Cyberstarts' $6.4M seed returned roughly $1.3 billion. (Cybersecurity Dive, Mar 2026)
- Kevin Mandia is now a General Partner at Ballistic — and simultaneously CEO of a portfolio company. Armadin launched on 10 March 2026 with $189.9 million (Accel-led, Ballistic following on), the largest combined seed and Series A in cybersecurity history, with Mandia as CEO alongside co-founders Travis Lanham as CTO, Evan Peña as chief offensive security officer and David Slater as chief architect. If Mandia's involvement is the reason Ballistic is on your list, ask on the first call who the day-to-day partner would be. (SecurityWeek, Mar 2026)
- Ballistic booked its biggest exit. Veza sold to ServiceNow for $1.3 billion, announced in December 2025 and closed on 2 March 2026. CrowdStrike announced a definitive agreement in September 2025 to acquire Pangea for roughly $260 million.
- Ten Eleven built a European bench. Grace Cassy, co-founder of the CyLon cyber accelerator, joined as Partner on 28 January 2026 — the most concrete change for the EU and UK founders this list has historically under-served. (Business Wire, Jan 2026)
- Cyera went from Cyberstarts portfolio company to acquirer. A $600M Series G at $12 billion in June 2026, then a roughly $1 billion letter of intent for Oasis Security in July 2026 — its third acquisition of the year. The Oasis deal has not closed.
- Ballistic's Fund III has not closed. The $100M vehicle filed with the SEC in April 2025 has produced no close announcement in the seventeen months since. Fund II, at $360 million from March 2024, remains the operative capital.
- Israeli cyber kept its lead. $2.57 billion in H1 2026, about 34% of all capital raised by Israeli tech in the half — up from $2.2 billion in H1 2025, per YL Ventures and Startup Nation Central — against a full-year 2025 record of $4.4 billion across 130 rounds. (Globes, 2026)
Which cybersecurity categories are attracting the most VC funding in 2026?
AI security is the runaway category of 2026, identity has led deal flow all year and is now absorbing data security, and offensive security has turned from a service line into a fundable product category. The segment map below cross-references the 5 specialist-firm portfolios profiled above plus NightDragon and Evolution Equity against H1 2026 deal data — $10.6 billion across all stages, per Crunchbase News in July 2026 — rather than the Q1 snapshot this section originally ran on.
Cyber VC deployment by segment (Peony 2026 framework)
| Category | 2026 VC momentum | Which firms lead here | What it looks like |
|---|---|---|---|
| AI security (model risk, prompt injection, agent security) | Very high | Ballistic (GetReal, Noma, Armadin), YL Ventures (Novee), Evolution Equity (Noma) | $855M across 150+ seed rounds in 2026 YTD — every CISO now carries an AI security budget line |
| Identity & ITDR | Very high | Cyberstarts (Island, Cyera), Ballistic (AuthMind), Forgepoint | Led deal flow all year; identity breaches still dominate incident data (~$4.5M average, IBM 2026) |
| Data security / DSPM | Very high | Cyberstarts and Evolution Equity (Cyera, $600M Series G at $12B, June 2026) | Consolidating into identity — Cyera has agreed to buy Oasis Security for ~$1B |
| Offensive security / AI red teaming | Very high | Ballistic (Armadin), YL Ventures (Novee) | Three plays in seven months: Novee $51.5M, Armadin $189.9M, Cathedral $160M |
| Cloud / CNAPP (runtime, container, API sec) | High | Cyberstarts (Upwind $250M Series B Jan 2026, Bessemer-led), Forgepoint | Consolidating, not expanding — the category's defining exit, Wiz, closed into Google in March |
| Endpoint | High | Cyberstarts (Glow $180M Series A, co-led with Sequoia) | Reloaded in July 2026: ThreatLocker $190M and Glow $180M in the same month |
| SecOps / detection engineering | Medium | Ten Eleven, Ballistic (SpecterOps), Forgepoint (DataBahn) | Agentic-security workflows emerging; SIEM/SOAR evolution |
| AppSec / software supply chain | Medium | Forgepoint (RapidFort Feb 2026), Ballistic (ArmorCode) | SBOM and code scanning still commoditizing |
| OT / IoT / industrial | Lower-momentum | NightDragon, specialized growth funds | Cyclical; strong bets but thinner deal flow |
| Quantum security | Emerging | Ten Eleven (IQM $320M Series B Sept 2025) | Still the marquee datapoint a year on — capital is arriving, deal flow is not |
Three of those rows deserve their evidence spelled out, because they are where the 2026 market genuinely diverged from the 2025 one.
AI security's surge is happening at seed, not at growth. AI-focused cybersecurity startups raised $855 million across more than 150 reported seed-stage rounds in 2026 year to date, on track for an all-time high, according to Crunchbase News in July 2026. The largest of those seeds were Oak at $60M in July (identity intelligence for the AI era), Cylake at $45M in March, founded by Palo Alto Networks founder Nir Zuk, and JetStream Security at $34M in March for AI governance. Above the seed line, Armadin's $189.9M combined seed and Series A in March 2026 is the largest such round in cybersecurity history, and Neo Security took $100M in July.
Identity is absorbing data security rather than sitting beside it. Pinpoint Search Group's July 2026 brief has identity leading deal flow all year. The structural move is Cyera: a $600M Series G at a $12 billion valuation in June, then a letter of intent announced on 28 July 2026 to acquire Oasis Security for roughly $1 billion, specifically to cover non-human identity — the credentials AI agents use to act. That deal has not closed. If you are building in DSPM, you are now building into an identity roadmap whether you meant to or not.
Offensive security became a category. Novee ($51.5M disclosed, January), Armadin ($189.9M, March) and Cathedral ($160M, July) are three AI red-team plays funded inside seven months. Two years ago this was a consulting line item.
Hands-on observation from the cyber fundraises I've watched pass through Peony in 2025-2026: the median diligence data room contains 340+ documents — SOC 2 Type II, ISO 27001, pentest reports, threat models, customer deployment references, and a security roadmap for the next 4 quarters. Peony's page-level analytics let cyber founders see which VCs actually read the security section versus just the financials. And per Peony's 2026 VDR pricing research, 47% of Western VDRs hide pricing entirely — a real tax on early-stage cyber founders who need predictable cost structures when running concurrent fundraising and enterprise sales processes.
More firms to watch
The five firms above represent the deepest cyber-only specialists, but two other $1B-plus platforms deserve attention:
NightDragon (nightdragon.com) — Led by Dave DeWalt (former CEO of McAfee and FireEye), NightDragon manages roughly $1.5 billion, per SC Media's 2026 award profile, and invests at growth stage across cybersecurity, defense, and national security. The firm publishes no AUM figure of its own, so treat that number as reported rather than confirmed. It won the 2026 SC Award for Investor of the Year, and about half of its current portfolio is cybersecurity, with all advisory clients in security. If your product bridges commercial cyber and government/defense, NightDragon occupies a unique lane. (SC Media)
Evolution Equity Partners (evolutionequity.com) — Closed a $1.1 billion Fund III in 2024, the largest dedicated cybersecurity fund ever raised at the time. Led by Richard Seewald, Evolution has a strong EU/UK presence alongside US investments. Portfolio includes Arctic Wolf, Snyk, and SecurityScorecard, and the firm led Noma Security's $100M Series B in AI security. Its biggest 2026 act was leading Cyera's $600M Series G at a $12 billion valuation on 10 June 2026, alongside Cyberstarts and Temasek — which puts Evolution on the cap table of the year's most aggressive acquirer in data and identity security. (PR Newswire, Business Wire)

How do I actually pitch a cybersecurity VC in 2026? (5 tactical tips)
Lead with a concrete threat-shift story and evidence of buyer pull, not "AI-powered" category claims. Cyber specialists have seen a thousand security pitches — the five tips below are what separates a funded round from a polite pass.
1. Sell urgency, not fear
Show a concrete failure mode: what breaks, how often, how expensive, and who owns the budget. "Breaches are increasing" is not a pitch — "stolen credentials cost an average of $4.50 million per breach, and mean time to identify and contain rose to 247 days in 2026, the first increase after five straight years of improvement" is (IBM, Cost of a Data Breach 2026). The same report puts the global average breach at $4.99 million, up 12% year over year, and the US average at $11.5 million. Numbers like those give a CISO the budget argument they have to make internally on your behalf.
2. Prove the buyer path early
Even pre-revenue: design partners, pilots, lighthouse prospects, pipeline quality, security leader references. Cyber VCs know that the biggest risk is not technology — it is distribution.
3. Make adoption realistic
Security teams hate friction. Be explicit about your deployment model, time-to-value, and how you avoid becoming "another dashboard." If you can show 15-minute time-to-value in a POC, say so.
4. Be crisp about wedge-to-platform
Top cyber investors back "one sharp entry point that expands." Spell out the expansion path: what you sell next and to whom. The initial wedge gets you in the door — the platform story gets you funded.
5. Bring receipts for differentiation
In cyber, "AI-powered" is table stakes. Differentiation is data moats, workflow lock-in, integration depth, detection quality, or cost curves — show something that is hard to copy and gets harder to replicate over time.
Why does a data room matter more for cybersecurity founders than other startups?
Because you are pitching investors on your ability to protect sensitive data while sharing your most sensitive documents — financial models, zero-day research, customer lists, GTM playbooks — and the delivery mechanism is part of your credibility story. There is a specific irony in cybersecurity fundraising: founders who pitch data protection through unprotected Google Drive links. Investors notice.
Peony was built for exactly this tension. A cybersecurity founder sharing IP through a Peony data room gets:
- Screenshot protection that deters and logs capture attempts on Business, with Screenshield on Data Room actively blocking screen capture and recording
- Dynamic watermarks tied to each viewer's identity, embedded in every page view
- Page-level analytics showing exactly which documents each investor reviewed, how long they spent per page, and how many times they returned
- NDA gates that require identity verification before access — investors self-serve, you do not grant permissions manually
- AI auto-indexing that organizes uploaded documents into deal-ready folder structures in under 3 minutes
You set it up in under five minutes, not weeks. Pricing is transparent: Business at $30/admin/month covers the core security stack — screenshot protection, Simple NDA, and analytics — while Data Room at $52/admin/month adds Screenshield, dynamic watermarks, AI auto-indexing, custom domain, and unlimited rooms — versus legacy platforms like Datasite and Intralinks, which quote custom and commonly run $50,000 or more per deal once per-page upload fees of $0.40 to $0.85 a page land on top. For a 3-person founding team running a seed round, that is $90-$156/month versus tens of thousands. Across 6,800+ customers, that ladder is the one most founders climb: Free for the first deck, Business when the deck starts going to funds, Data Room when diligence opens.
Where Peony is not the right answer: if you are running a cross-border megadeal where institutional counsel insists on a legacy brand name in the diligence log, or you need FedRAMP or ITAR certification, buy Datasite or Intralinks and do not argue. That is a real constraint, not a marketing one — and it almost never applies to a Series A cyber round.
For cybersecurity founders specifically, how you handle sensitive materials is part of your credibility story. A secure data room is not just a convenience — it is a signal.

How much capital actually flowed into cybersecurity startups in 2025-2026?
| Metric | Value | Source |
|---|---|---|
| Total cybersecurity VC in 2025 | $14 billion across 392 rounds | SecurityWeek, Pinpoint |
| Year-over-year increase from 2024 | 47% (up from $9.5B) | SecurityWeek |
| Q1 2026 cybersecurity funding | $4.62 billion across 128 rounds | Pinpoint Search Group |
| H1 2026 cybersecurity funding | $10.6 billion across all stages | Crunchbase News |
| AI-security seed funding, 2026 YTD | $855 million across 150+ reported seed rounds | Crunchbase News |
| Total cybersecurity M&A in 2025 | 426 deals announced; $92.5 billion disclosed across the 74 that reported terms | SecurityWeek |
| Rounds exceeding $100M in 2025 | 30 — 8% of volume, nearly half of all dollars | Pinpoint Search Group |
| Wiz acquisition by Alphabet | $32 billion, closed 11 Mar 2026 (200x realized for seed investor) | Cybersecurity Dive, TechCrunch |
| Cyberstarts total commitments | $1.4 billion+ across 7 funds | Business Wire |
| YL Ventures total AUM | $800 million (Fund V is largest cyber seed fund ever) | YL Ventures |
| Israeli cyber funding in 2025 | $4.4 billion record high across 130 rounds | SecurityWeek |
| Forgepoint total AUM | $1 billion+ with 3 unicorns in portfolio | Forgepoint Capital |
The takeaway: more capital is going into fewer companies with stronger proof points. If you are in the running, the opportunity is enormous. If you are not, the bar to get in is higher than it has ever been.
On the M&A side, the 2025 headline needs its footnote read: 426 deals were announced, but only 74 of them disclosed terms, and the $92.5 billion figure covers just those 74. Deal count rose 5% year over year after two years of decline, disclosed value rose 82% largely because of the Wiz deal, 11 deals cleared $1 billion, and the United States was a party to 288 of the 426. (SecurityWeek)
Which cybersecurity funding rounds actually closed in 2026?
Cybersecurity startups closed $4.62 billion across 128 rounds in Q1 2026 on Pinpoint Search Group's count, while Crunchbase's broader security-and-privacy universe put the first half at $10.6 billion across all stages. Pinpoint's monthly briefs put April at $418 million, May at $694 million, June at $1.68 billion and July at $1.56 billion. Read each series against its own baseline rather than chaining them, because the two houses count different universes. The month-by-month view matters because the aggregate hides the shape: 2026 ran cold in the spring and reheated over the summer, and July was the first time in the year that two consecutive months each cleared $1.5 billion.
2026 cybersecurity funding by period
| Period | Disclosed funding | Source |
|---|---|---|
| FY 2025 | $13.97B across 392 rounds; +47% over $9.5B and 300 rounds in 2024; 30 rounds above $100M were 8% of volume and ~50% of dollars | SecurityWeek, Jan 2026 (data: Pinpoint Search Group) |
| Q1 2026 | $4.62B across 128 funding rounds; 159 total vendor transactions (128 funding + 31 M&A); more than double Q1 2025's $2.22B; $100M-plus rounds took a significant share of total investment, unquantified in the release | Pinpoint Search Group, Q1 2026 report |
| April 2026 | $418M disclosed | Pinpoint Search Group monthly brief |
| May 2026 | $694M disclosed | Pinpoint Search Group monthly brief |
| June 2026 | $1.68B disclosed | Pinpoint Search Group, June 2026 brief |
| Q2 2026 | $4.4B (Crunchbase security & privacy universe, seed through growth) — down ~30% against Crunchbase's own Q1 basis, which is not the Pinpoint Q1 row above | Crunchbase News, Jul 2026 |
| H1 2026 | $10.6B across all stages | Crunchbase News, Jul 2026 |
| July 2026 | $1.56B across 38 funding rounds plus 9 M&A deals — 47 transactions; first month-pair of 2026 to each clear $1.5B | Pinpoint Search Group, July 2026 brief |
The named 2026 rounds worth knowing
| Date | Company | Round | Amount | Lead and notes |
|---|---|---|---|---|
| 14 Jan 2026 | Novee | Out of stealth (seed + A + venture debt) | $51.5M | YL Ventures co-led with Canaan Partners and Oren Zeev. AI offensive security. |
| 26 Jan 2026 | Upwind Security | Series B | $250M | Bessemer led; Salesforce Ventures and Picture Capital joined, Greylock and Cyberstarts existing. $1.5B valuation, $430M raised to date, 900% YoY revenue growth. |
| Jan 2026 | Furl | Seed | $10M | Ten Eleven led; Rapid7 CEO Corey Thomas and the Open Opportunity Fund joined. Security remediation. |
| 17 Feb 2026 | VulnCheck | Series B | — | Ten Eleven participated. |
| Mar 2026 | Cylake | Seed | $45M | Founded by Nir Zuk, founder of Palo Alto Networks. AI-native security without public-cloud dependency. |
| Mar 2026 | JetStream Security | Seed | $34M | AI governance and security; reported as heavily oversubscribed; CrowdStrike and SentinelOne alumni. |
| Mar 2026 | Native | Series A | $31M | Ballistic led. Multi-cloud security policy enforcement. |
| 10 Mar 2026 | Armadin | Seed + Series A combined | $189.9M | Accel led; GV, Kleiner Perkins, Menlo, In-Q-Tel, 8VC and Ballistic followed. Largest combined seed and A in cyber history. Kevin Mandia is CEO. |
| 10 Jun 2026 | Cyera | Series G | $600M | Evolution Equity led; Cyberstarts and Temasek joined. $12B valuation, double its June 2025 valuation, over $2B raised. |
| H1 2026 | NinjaOne | Series C extension | $400M+ | $12.3B valuation. |
| H1 2026 | Dream | — | $260M | $3B valuation. Israeli. |
| Jul 2026 | Spur | — | $200M | Threat intelligence. |
| Jul 2026 | ThreatLocker | — | $190M | Endpoint. |
| Jul 2026 | Glow | Series A | $180M | Co-led by Sequoia and Cyberstarts, with Greenoaks and Redpoint in the lead group. $1.2B valuation. Endpoint. |
| Jul 2026 | Cathedral | — | $160M | Offensive cyber. |
| Jul 2026 | Onyx Security | Series B | $113M | GRC. |
| Jul 2026 | Neo Security | — | $100M | AI and LLM security. |
| Jul 2026 | Oak | Seed | $60M | Identity intelligence for the AI era. Largest AI-security seed of 2026 to date. |
The M&A side of 2026 has been just as active: Google closed Wiz on 11 March at $32 billion, ServiceNow closed Veza on 2 March at $1.3 billion and also completed its Armis acquisition during the year, and Motorola Solutions agreed on 1 June 2026 to buy D-Fend Solutions for $1.5 billion, completing the deal on 20 August 2026. Cyera's roughly $1 billion agreement to acquire Oasis Security is a letter of intent announced on 28 July 2026, not a closed deal — about $700 million in cash with the balance in Cyera shares, for a company that had raised around $195 million from Accel, Craft and Cyberstarts. If you are building a comparable, do not model it as done.
Frequently Asked Questions
I'm raising a $5M seed for an AI security startup with 2 co-founders and a working prototype. Which of these 5 firms should I prioritize?
Start with Cyberstarts and Ballistic Ventures. Cyberstarts backs sharp wedge-to-platform plays and has the deepest CISO network for early commercial traction — they helped build Wiz from seed to a $32 billion exit. Ballistic is built for pre-seed and seed with hands-on incubation from operators like Kevin Mandia, who founded Mandiant and became a General Partner at the firm. YL Ventures is a strong third option if your founding team has Israel ties. At the seed stage, a structured data room signals professionalism to firms that evaluate dozens of pitches monthly. Peony's AI auto-indexing organizes your pitch deck, financials, and product architecture into a clean folder structure in under 3 minutes.
Our cybersecurity startup has $3M ARR and we're raising a $25M Series B. Should I target cyber-specialist VCs or switch to generalists?
At $3M ARR, cyber specialists are your strongest lead candidates. Ten Eleven and Forgepoint both invest at Series B and bring CISO networks, channel partnerships, and security-specific go-to-market advice that generalists cannot. A generalist growth fund works better as a co-investor than a lead for a cyber company at this stage. Your data room should demonstrate net revenue retention, pipeline by segment, and competitive positioning. Peony's page-level analytics show which investors spent time on your financial model versus your product roadmap, so you know exactly what to emphasize in follow-up conversations.
I'm raising a seed for a cloud security startup — what check size do cyber-specialist VCs like Cyberstarts and Ballistic actually write?
Estimated bands, based on what these firms have actually done: Cyberstarts writes roughly $2M to $25M+ from seed through breakout follow-on, Ten Eleven $5M to $50M+ across stages, YL Ventures $2M to $15M from seed to scale, Ballistic $2M to $10M at pre-seed and seed, and Forgepoint $5M to $20M early-stage. Treat those as bands, not price lists, because the 2026 evidence shows how wide the spread runs. Ten Eleven led Furl's $10M seed in January 2026. Ballistic led Native's $31M Series A in March 2026. YL's Novee reached $51.5 million in aggregate across a seed, a Series A and venture debt within eight months of being founded. There is no defensible published median for a 2026 cyber seed check, so discount any number presented as one and ask each partner directly what they need to own in order to lead.
We're pre-revenue with a DSPM prototype — what round size and ownership should I plan for from a cyber-specialist seed?
Plan from ownership mechanics, not from a market average. A specialist fund decides what percentage it needs to own for its fund math to work, then sizes the check to that target — so your round size falls out of the ownership your lead requires and the runway you need to reach the next milestone, not out of a benchmark. The 2026 data makes the point: AI-focused cybersecurity startups raised $855 million across more than 150 reported seed-stage rounds in 2026 year to date, with outliers such as Oak at $60M and Cylake at $45M, according to Crunchbase News in July 2026. When seed rounds span an order of magnitude, the stage label tells a partner nothing. Ask each firm on the first call what ownership they need to lead and what milestone they expect the round to buy, then build the number backwards from there.
I'm an Israeli cybersecurity founder raising a seed round. Do these US-listed firms actually invest in Israel-based companies?
Cyberstarts and YL Ventures have deep Israel roots and actively invest in Israeli-founded companies. YL Ventures is explicitly Israel-focused in its early-stage thesis and publishes the annual State of the Cyber Nation report tracking the Israeli ecosystem. Cyberstarts' founding partner Gili Raanan is based in Israel. Ten Eleven, Ballistic, and Forgepoint primarily back US-headquartered or US-GTM companies but have portfolio companies with Israeli R&D centers. The geography question matters less than it did: Israeli cyber startups raised a record $4.4 billion across 130 rounds in 2025, up 9% on $4.03 billion from 89 rounds in 2024, and for the first time global VC outpaced domestic Israeli capital at every stage including seed, per YL Ventures' State of the Cyber Nation report. Israeli cyber then took $2.57 billion in the first half of 2026 alone, roughly 34% of all capital raised by Israeli tech in the half, according to Globes. If you are fundraising across time zones, Peony's NDA gates let investors self-serve access with email authentication so you are not manually granting permissions at 3 AM.
I have no Israeli network and no VC intros — how do I actually get a warm intro to Cyberstarts or Ten Eleven?
Route through the CISO network, not through LinkedIn. Cyberstarts' entire model runs on founding partner Gili Raanan's relationships with security buyers, which means a design partner or a security leader willing to vouch for your product is worth more than a mutual connection who can only forward an email. Ten Eleven's partner bench is now transatlantic — Grace Cassy, co-founder of the CyLon cyber accelerator, joined as a Partner in January 2026, per Business Wire — so European founders have a real front door that did not exist eighteen months ago. Portfolio-founder intros beat everything else: each of these firms publishes its portfolio, so pick the two companies closest to your category and ask their founders directly. Cold inbound does get read at cyber specialists, but it converts at a fraction of the rate of a buyer-side referral.
We have sensitive zero-day research in our fundraise materials. How do I share that with cybersecurity VCs without it leaking?
This is where most cybersecurity founders trip up — you are pitching data protection while sharing your own IP through unprotected Google Drive links. Use a data room with screenshot protection and per-viewer watermarking. Peony's screenshot protection deters and logs capture attempts on the Business plan, while the Data Room plan adds Screenshield, which actively blocks screen capture and recording, plus dynamic watermarks that stamp each viewer's identity on every page; link expiry, which is on every plan including Free, auto-revokes access after your diligence window closes — unlike DocSend, which cannot detect screenshot attempts on any plan, or Google Drive, which has no watermarking or viewer-level expiry at all. For a cybersecurity startup specifically, investors notice whether you practice what you preach.
I'm building a seed pitch for a cloud security startup — how much venture capital actually went into cybersecurity in 2025?
Cybersecurity companies raised approximately $14 billion in 2025 across 392 funding rounds, a 47% increase from $9.5 billion in 2024, according to Pinpoint Search Group and SecurityWeek. Crunchbase reported $18 billion including broader security and privacy categories. The market kept running through 2026: $4.62 billion across 128 rounds in Q1 2026 on Pinpoint Search Group's count, while Crunchbase News in July 2026 put its broader security-and-privacy universe at $10.6 billion across all stages for the first half. Concentration is the real story — 30 rounds above $100 million were only 8% of 2025 deal volume but took nearly half of all dollars. The 5 specialist firms profiled here collectively deployed billions of this capital. To compete for their attention, organize your fundraise materials in a Peony data room on the Data Room plan with AI auto-indexing that structures 340+ documents in under 3 minutes — compared to Intralinks, which charges per-page upload fees and takes days to configure, or Google Drive, which cannot generate an indexed table of contents at all.
I'm pre-revenue with a working DSPM prototype and no data room yet. Is it too early to set one up for cybersecurity investor meetings?
No. Specialist cyber VCs expect professionalism from day one because they evaluate dozens of pitches monthly and use your preparation as a signal. Even pre-revenue, a clean data room with your deck, technical architecture, threat model, and founding team bios shows you understand enterprise rigor. Start on Peony Free ($0) for your first deck — page-by-page analytics and password protection, up to 50 documents, no card. Business ($30/admin/month) adds screenshot protection, email authentication and Simple NDA gates when you start sending to funds. The Data Room plan ($52/admin/month) adds Screenshield, dynamic watermarks, Advanced NDA with a countersigned PDF, auto-indexing, custom domain and unlimited rooms — the full stack a Series A-ready room needs. That is the ladder 6,800+ customers run on, and against a $5M seed the whole line item is a rounding error next to legacy platforms like Datasite, which are custom-quoted and commonly land at $50,000 or more per deal.
Five cyber VCs are reviewing my data room simultaneously during a competitive seed round. How do I tell which ones are actually serious?
Look at engagement depth, not just opens. An investor who spent 20 minutes on your financial model and returned twice is doing real diligence. One who glanced at the pitch deck for 90 seconds and never came back is likely a pass. Peony's page-level analytics show exactly which documents each investor reviewed, how long they spent per page, and how many times they returned — so you can prioritize follow-ups and stop wasting time on polite passes.
Our go-to-market is CISO-led enterprise with 6-month sales cycles. Will specialist cyber VCs see that as a red flag?
Cyber-specialist VCs understand CISO-led sales better than anyone. Firms like Ten Eleven and Forgepoint have backed dozens of enterprise security companies and know that longer cycles come with higher ACVs, stickier contracts, and lower churn. Frame your pipeline by stage — POC, pilot, procurement, close — and show progression velocity rather than just closed deals. The red flag is not long cycles but having no pipeline metrics at all. Organize your customer proof points and pipeline data in a Peony data room on the Business plan so investors can review deal details independently between calls, with AI document Q&A and Simple NDA gates they acknowledge before access — step up to the Data Room plan at $52/admin/month when you need Advanced NDA with a countersigned PDF — unlike DocSend, which has no per-deal room structure and forces you to manage NDAs through a separate tool, or Dropbox, which has no NDA workflow at all.
Three cyber VCs passed after first meetings — what are they actually screening for?
Each firm screens on a different axis, and a pass usually means you missed one of them rather than that the technology is weak. Cyberstarts screens on why-now, wedge sharpness and early buyer signal. Ten Eleven screens on ICP clarity, defensibility and adoption realism. YL Ventures screens on problem urgency and commercial realism. Ballistic screens on category-creation potential and founder-market fit. Forgepoint screens on technical architecture and land-and-expand potential. The most common reason a technically strong cyber team gets passed on is not the product — it is being unable to name the budget line the product gets bought out of and the person who owns it. If three firms passed after first meetings, rewrite the buyer slide before you rewrite the demo.
Related Resources
You might also like
Sep 7, 2026
Best Data Rooms for Investor Analytics (Who Read Which Page) in 2026
Aug 21, 2026
Top 8 Brazil Investors in 2026: Complete Guide to Raising from Brazil's Best VCs
Aug 21, 2026
Top 9 Active Investors in the Philippines (2026): Complete Guide to Philippine VC & Angel Funding

