Investors

Cybersecurity investors: who actually funds security startups

In security the buyer decides the investor. A company selling to a Fortune 500 CISO needs a fund with design partners inside those teams. A company selling to government needs one that understands clearances and procurement timelines measured in years. A developer-led security tool is really a devtools company with a security label. The technology matters less to this choice than most founders expect.

Reviewed Full-year 2025

The state of cybersecurity investment

$13.97bnraised by security vendors across 392 funding rounds in 2025, up 47% on 2024Pinpoint Search Group, 2025
63%of funding volume was early stage, at seed and Series APinpoint Search Group, 2025
49%of all capital went into just 30 rounds above $100m, which were 8% of dealsPinpoint Search Group, 2025

This is a barbell and it is worth reading carefully before you calibrate an ask. 2025 was the strongest year for security funding since the 2021 peak, with dollars up 47% and round count up 29% to 392. Early-stage deals dominated by volume at 63%, while 30 very large rounds took almost half the capital. In other words there is plenty of seed activity and a small number of enormous cheques, with the middle thinner than the headline suggests.

The four kinds of cybersecurity investor

A fund tagged "security" sits in one of four columns, and the columns are defined by who signs the cheque at the customer end. That determines sales cycle, capital need and which investors can actually help.

Enterprise & CISOGovernment & defenceDeveloper-led & open sourceIdentity & data protection
Typical entry stageSeed to Series ASeed, often with non-dilutive money alongsidePre-seed to seedSeed to Series A
Cheque shapeOrdinary ventureVenture plus grants and programme fundingOrdinary venture, often smallerOrdinary venture
Wants to seeDesign partners who are real CISOs, not advisersClearances, past performance and a contract vehicleAdoption, stars and a conversion path to paidA compliance driver forcing purchase
Time to revenue12-18 months2-4 years12-24 months, longer to monetise12-18 months
Biggest risk they underwriteA platform vendor bundling the featureBudget cycles and political changeAdoption that never converts to revenueRegulation shifting the requirement
Who else must be in the roundOperator angels who have been CISOsA fund with government experienceDeveloper-reach angelsNobody in particular

Cybersecurity investors, grouped by the cheque they write

Cybersecurity investors we hold in the Causo catalogue, grouped by the cheque they actually write. Open any of them to see the partners, the stage and the recent deals. This is not every cybersecurity investor in the market, and no catalogue is.

Corporate and strategic

Balance-sheet investors whose parent is a plausible customer, carrier or channel.

What cybersecurity investors need to see

The gates that are specific to this sector, and that a generalist fundraising guide will not tell you about.

  • Bring design partners who actually hold the budgetSecurity investors discount advisers heavily. A named CISO who has agreed to pilot, and ideally to pay, is the single strongest signal at seed. An advisory board of former CISOs is not the same thing and everyone in the room knows it.
  • Say what happens when the platform vendor ships thisThe dominant risk in security is that Microsoft, CrowdStrike or a cloud provider bundles your feature. You will be asked. Answer with depth, data or a buyer who will not consolidate, not with a roadmap.
  • Be precise about compliance driversSecurity budgets move when a regulation or an auditor forces them. If a specific framework, mandate or insurance requirement compels your purchase, name it. If nothing does, expect a much harder conversation about why this is bought rather than admired.
  • If you sell to government, show the contract vehicleClearances, past performance and a route onto an existing vehicle matter more than product maturity in that column. Investors who fund government security know the timelines; investors who do not will misprice your runway.
  • Do not overstate your detection claimsSecurity buyers and their investors test claims. Overstating efficacy, coverage or independence of testing is the one thing that ends a diligence process permanently in this sector.

Where a cybersecurity investor’s real track record is published

  • CVE and vulnerability disclosure records
  • MITRE ATT&CK evaluation results
  • FedRAMP marketplace listings and authorisation status
  • SOC 2 and ISO 27001 attestation records
  • Government contract award notices
  • GitHub repositories and contribution history
  • Funding announcements
  • Fund portfolio pages and partner talks
  • Why evaluation results matter more here than elsewhereSecurity is one of the few sectors with published, independent product testing. MITRE evaluations and FedRAMP authorisation status are dated, public and hard to spin, which makes them a far better read on a company’s real maturity than its own marketing.

Reading one cybersecurity investor’s actual record

One worked example of what reading those sources produces, from the Causo catalogue with the identity removed.

Your matches
Name withheld
Cybersecurity-only fund · seed and Series A · US and Israel
Verified
Match reasoning86 / 100

A single-sector security fund whose stated model is bringing a CISO network to portfolio companies as design partners and first customers. Entry is at seed and Series A, and the record shows consistent security-only activity rather than opportunistic participation.

Single-sector mandate Security is the only category on the record. The fit test is unusually clean, and a company that is only adjacent to security should not expect a stretch.
The network is the differentiator The value proposition is buyer access rather than capital, so an approach that does not engage with design partners misses what this fund is selling to its own founders.
Geography is split Activity spans the US and Israel, which is characteristic of this sector and worth reflecting in how and where an approach is made.

Questions founders ask about cybersecurity investors

Who are the main cybersecurity investors?

Security-dedicated firms include YL Ventures, Ten Eleven Ventures, Ballistic Ventures, AllegisCyber Capital, Paladin Capital Group, Glasswing Ventures and .406 Ventures. In Israel, JVP, Hetz Ventures, Vertex Ventures Israel and Pitango are highly active. Corporate arms including Dell Technologies Capital and Capital One Ventures invest strategically.

How much venture funding does cybersecurity get?

Security vendors raised $13.97bn across 392 rounds in 2025, a 47% increase on the $9.50bn raised in 2024, with round count up 29%. That made 2025 the strongest year for the sector since the 2021 peak.

Is it a good time to raise for a security startup?

At seed, yes: early-stage deals were 63% of funding volume in 2025. The caveat is concentration, because 30 rounds above $100m took 49% of all capital while being 8% of deals. Seed is active and the very top of the market is active, and the middle is where the squeeze is.

Do cybersecurity investors require design partners?

Effectively yes at seed, and this is the sector where it is least negotiable. A named CISO piloting the product carries more weight than any amount of technical validation, because security buying is relationship-driven and the investor is assessing whether you can reach that buyer at all.

What do cybersecurity investors look for at seed?

Founders who have lived the problem, ideally from inside a security team. Design partners with budget. A clear compliance or regulatory driver that forces the purchase. And a credible answer to what happens when a platform vendor bundles the capability, which is the risk that ends most security companies.

Do I need to be in Israel or Silicon Valley to raise for security?

No, but you should understand that a large share of specialist capital and operating talent sits in those two places, and several leading funds run explicitly across both. Founders elsewhere raise successfully by bringing the buyer relationships that make geography less relevant.

Find the investors who back companies like yours

Browse investors