Skip to content
    Security Operations (SecOps)Startup$141M raised

    Cymulate

    Israeli continuous security validation platform: breach and attack simulation, exposure management and agentic AI (Vero AI) to test and optimize controls against real-world threats

    Mkt Cap / ValPrivate
    RevenueEst. $42M ARR
    Jun 2026: Launched Vero AI agentic platform with Mitigation Hub and Detection Studio
    Full CTEM suite pairing BAS with agentic Vero AI so teams prove, prioritize and adapt defenses continuously
    Analyst take · Competitive edge

    SWOT Analysis

    Strengths
    • Broad validation suite: BAS, exposure management and CTEM in one platform
    • Vero AI agentic layer automates prove, prioritize and adapt workflows
    • Wiz partnership (Jan 2026) extends validation into cloud security
    • Established since 2016 with $141M raised and a global customer base
    • SaaS delivery gives faster time to value than consultant-led red teaming
    Opportunities
    • CTEM adoption wave as Gartner pushes continuous exposure programs
    • Demand for AI-driven attack simulation as adversaries automate
    • Cloud security validation through Wiz and CSP integrations
    • Channel and MSSP expansion across APAC and EMEA
    Weaknesses
    • No new funding round since the 2022 Series D amid better-funded rivals
    • Crowded BAS/CTEM market blurs differentiation vs Picus, Pentera, SafeBreach
    • Undisclosed ARR limits buyer visibility into commercial traction
    • Platform breadth can add complexity for lean security teams
    Threats
    • Platform giants adding native validation features
    • Rival BAS vendors with fresher capital and aggressive pricing
    • Budget scrutiny lumping BAS into discretionary testing spend
    • Open-source attack emulation tools eroding entry-level deals

    User Sentiment

    Synthesized from G2, Gartner Peer Insights, and analyst review data.

    What users love
    • Easy to launch safe attack simulations without red team skills
    • Clear scoring that tracks security control drift over time
    • Wide attack scenario library updated with fresh threats
    • Actionable mitigation guidance mapped to specific controls
    Common complaints
    • Pricing can climb quickly as modules are added
    • Occasional false positives require manual tuning
    • Report customization is limited for executive audiences

    Customer Profile

    Who buys this

    Typical segments

    Mid-market and enterprise SOC teamsRegulated industries

    Typical buyer

    CISO or security operations lead

    Top use cases
    1. 1Continuous validation of EDR, SIEM and email controls
    2. 2Exposure prioritization and CTEM program automation
    3. 3Board-ready security posture reporting

    Future Focus Areas

    1

    Agentic AI defense automation via Vero AI

    2

    Cloud exposure validation with the Wiz ecosystem

    3

    Detection engineering via Detection Studio

    4

    Autonomous mitigation workflows