In security the buyer decides the investor. A company selling to a Fortune 500 CISO needs a fund with design partners inside those teams. A company selling to government needs one that understands clearances and procurement timelines measured in years. A developer-led security tool is really a devtools company with a security label. The technology matters less to this choice than most founders expect.
Reviewed Full-year 2025
This is a barbell and it is worth reading carefully before you calibrate an ask. 2025 was the strongest year for security funding since the 2021 peak, with dollars up 47% and round count up 29% to 392. Early-stage deals dominated by volume at 63%, while 30 very large rounds took almost half the capital. In other words there is plenty of seed activity and a small number of enormous cheques, with the middle thinner than the headline suggests.
A fund tagged "security" sits in one of four columns, and the columns are defined by who signs the cheque at the customer end. That determines sales cycle, capital need and which investors can actually help.
| Enterprise & CISO | Government & defence | Developer-led & open source | Identity & data protection | |
|---|---|---|---|---|
| Typical entry stage | Seed to Series A | Seed, often with non-dilutive money alongside | Pre-seed to seed | Seed to Series A |
| Cheque shape | Ordinary venture | Venture plus grants and programme funding | Ordinary venture, often smaller | Ordinary venture |
| Wants to see | Design partners who are real CISOs, not advisers | Clearances, past performance and a contract vehicle | Adoption, stars and a conversion path to paid | A compliance driver forcing purchase |
| Time to revenue | 12-18 months | 2-4 years | 12-24 months, longer to monetise | 12-18 months |
| Biggest risk they underwrite | A platform vendor bundling the feature | Budget cycles and political change | Adoption that never converts to revenue | Regulation shifting the requirement |
| Who else must be in the round | Operator angels who have been CISOs | A fund with government experience | Developer-reach angels | Nobody in particular |
Cybersecurity investors we hold in the Causo catalogue, grouped by the cheque they actually write. Open any of them to see the partners, the stage and the recent deals. This is not every cybersecurity investor in the market, and no catalogue is.
Firms whose entire mandate is security, several with CISO networks as their core asset.
Firms writing the first institutional cheque, with a strong Israeli contingent.
Firms that lead once there are enterprise contracts and a repeatable motion.
Balance-sheet investors whose parent is a plausible customer, carrier or channel.
The gates that are specific to this sector, and that a generalist fundraising guide will not tell you about.
One worked example of what reading those sources produces, from the Causo catalogue with the identity removed.
A single-sector security fund whose stated model is bringing a CISO network to portfolio companies as design partners and first customers. Entry is at seed and Series A, and the record shows consistent security-only activity rather than opportunistic participation.
Security-dedicated firms include YL Ventures, Ten Eleven Ventures, Ballistic Ventures, AllegisCyber Capital, Paladin Capital Group, Glasswing Ventures and .406 Ventures. In Israel, JVP, Hetz Ventures, Vertex Ventures Israel and Pitango are highly active. Corporate arms including Dell Technologies Capital and Capital One Ventures invest strategically.
Security vendors raised $13.97bn across 392 rounds in 2025, a 47% increase on the $9.50bn raised in 2024, with round count up 29%. That made 2025 the strongest year for the sector since the 2021 peak.
At seed, yes: early-stage deals were 63% of funding volume in 2025. The caveat is concentration, because 30 rounds above $100m took 49% of all capital while being 8% of deals. Seed is active and the very top of the market is active, and the middle is where the squeeze is.
Effectively yes at seed, and this is the sector where it is least negotiable. A named CISO piloting the product carries more weight than any amount of technical validation, because security buying is relationship-driven and the investor is assessing whether you can reach that buyer at all.
Founders who have lived the problem, ideally from inside a security team. Design partners with budget. A clear compliance or regulatory driver that forces the purchase. And a credible answer to what happens when a platform vendor bundles the capability, which is the risk that ends most security companies.
No, but you should understand that a large share of specialist capital and operating talent sits in those two places, and several leading funds run explicitly across both. Founders elsewhere raise successfully by bringing the buyer relationships that make geography less relevant.