Cybereason logo
Cybersecuritycybersecurityendpoint-securityedr

CYBEREASON

Netfigo Verdict
on Cybereason

Founded by Israeli intelligence veterans who built an endpoint security platform to hunt hackers in real time. Cybereason raised $850 million including a massive check from SoftBank. Then the market shifted, competition from CrowdStrike and SentinelOne intensified, and the company had to restructure. The technology — which visualizes entire cyberattacks as connected stories rather than isolated alerts — is genuinely innovative. The business execution hasn't matched the tech. A classic case of great product, tough market.

Founded

2012

HQ

Boston, USA

Total Raised

$850 million

Founder

Lior Div, Yossi Naar, Yonatan Striem-Amit

Status

Private

THE ORIGIN STORY

Three former members of Unit 8200 — Israel's elite intelligence unit, the equivalent of the NSA — founded Cybereason in 2012. Lior Div, Yossi Naar, and Yonatan Striem-Amit brought military-grade cyber offense knowledge and flipped it to defense.

Their insight: most security tools show individual alerts in isolation. Cybereason connects the dots across an entire attack — from initial phishing email to lateral movement to data exfiltration — and presents it as a single visual story.

They called this the "Malop" (malicious operation). The military background was genuine — these guys hunted state-sponsored hackers before starting a company.

WHAT THEY ACTUALLY DO

Cybereason sells endpoint detection and response (EDR) software to enterprises. The platform monitors every device in a company's network for signs of cyberattack.

When threats are detected, the system maps the entire attack chain and enables automated response. Revenue comes from annual subscriptions based on the number of endpoints (computers, servers, devices) being protected.

THE PRODUCTS

Cybereason Defense Platform — endpoint detection and response (EDR). MalOp Detection — the signature feature that visualizes entire attack chains.

Extended Detection and Response (XDR) — expanding beyond endpoints to cloud, identity, and network. Managed Detection and Response (MDR) — 24/7 security monitoring service.

HOW THEY GREW

Military pedigree marketing. The Unit 8200 background gave Cybereason instant credibility with CISOs and enterprise security teams.

SoftBank's massive investment ($300M+ across rounds) funded aggressive global expansion, particularly in Japan and Asia-Pacific markets where SoftBank has deep relationships.

THE HARD PART

CrowdStrike dominated the market. While Cybereason was building, CrowdStrike went public and became the default enterprise endpoint security platform.

The market largely became a two-horse race between CrowdStrike and SentinelOne, leaving Cybereason fighting for third place. SoftBank's investment came with growth expectations that were hard to meet in such a competitive market.

MONEY TRAIL

Series B

2014 · Led by CRV

$25M raised

Series C

2017 · Led by SoftBank

$100M raised

Series D

2019 · Led by SoftBank

$200M raised

Series E

2021 · Led by Liberty Strategic Capital

$275M raised

WHO BACKED THEM

SoftBank Vision Fund was the largest investor ($300M+). Other investors include Lockheed Martin, CRV, Spark Capital, and Liberty Strategic Capital (Stephen Feinberg's fund).

The SoftBank relationship opened doors in Japan but came with intense growth pressure.

Head-to-Head

Compare Cybereason vs another company.