Sysdig was founded by the co-creator of Wireshark — the network analysis tool that basically every security engineer on earth has used. That pedigree mattered. Loris Degioanni brought genuine technical credibility when he founded Sysdig in 2013, and the company turned it into a $2.5 billion valuation by 2022. They also created Falco, the open-source cloud runtime threat detection tool that became an industry standard and a CNCF project. Not bad for a company most people outside security have never heard of.
Founded
2013
HQ
San Francisco, USA
Total Raised
$749 million
Founder
Loris Degioanni
Status
Private
Website
sysdig.comTHE ORIGIN STORY
Loris Degioanni had already built something important before Sysdig. He co-created Wireshark in 1998 — the open-source network packet analyzer that security engineers and network administrators use worldwide to understand what is moving through their networks.
By 2013, he saw that the monitoring and visibility problem was moving from traditional networks to containers. The existing tools weren't built for it.
Container processes appeared and disappeared too fast, the system call visibility was missing, and the debugging experience for containerized applications was painful. He founded Sysdig in San Francisco to build container-native visibility and security tooling.
The name — from system diagnostic — signals the engineering-first philosophy.
WHAT THEY ACTUALLY DO
Sysdig sells to enterprises that need to monitor, troubleshoot, and secure containerized and cloud-native workloads. The commercial platform has two main products.
Sysdig Secure handles cloud security posture management, vulnerability scanning, and runtime threat detection. Sysdig Monitor handles infrastructure metrics and performance monitoring for Kubernetes and cloud workloads.
Both integrate with AWS, GCP, and Azure as well as CI/CD pipelines. Customers pay subscription fees based on the scale of their infrastructure.
Falco — the runtime threat detection engine — is open source and free, building community and serving as the top of the commercial funnel.
THE PRODUCTS
Sysdig Secure — the CNAPP platform covering vulnerability management, cloud security posture management, compliance, runtime security, and threat detection. Sysdig Monitor — infrastructure monitoring for Kubernetes clusters and cloud workloads, with dashboards and alerting.
Falco — the open-source cloud-native runtime threat detection engine donated to CNCF in 2018. Falco detects unexpected or malicious behavior in containers and cloud environments using kernel-level event monitoring, and is one of the most widely deployed security tools in Kubernetes production environments.
HOW THEY GREW
Like the best infrastructure security companies, Sysdig used open source as the primary growth engine. Falco became a CNCF (Cloud Native Computing Foundation) adopted project in 2018, giving it the neutral, trusted status that accelerates adoption in large enterprises.
Thousands of companies running Kubernetes use Falco in production today. When they need enterprise support, compliance coverage, or a full CNAPP platform, Sysdig is the natural call.
The CNCF imprimatur means enterprise buyers feel less like they're being sold a product and more like they're adopting a community standard — a much easier sales conversation. That dynamic took years to build and is genuinely hard to replicate.
THE HARD PART
The cloud security market is brutal at scale. Palo Alto Networks, CrowdStrike, and Wiz have all pushed aggressively into cloud-native security with enormous distribution advantages.
Sysdig is technically strong in runtime security and deep system-level observability — areas where it genuinely leads — but it is hard to win budget against platform vendors that come pre-integrated with security tools an enterprise already uses. The 2022 Series G raised $350 million at a $2.5 billion valuation.
Delivering growth that justifies that valuation, in a market with those competitive dynamics, is the central challenge. They need to be both technically excellent and commercially aggressive at the same time.
MONEY TRAIL
Series A
2015 · Led by Bain Capital Ventures
$11M raised
Series B
2016 · Led by Bain Capital Ventures
$15M raised
Series C
2018 · Led by Accel
$69M raised
Series D
2019 · Led by Insight Partners
$68M raised
Series E
2021 · Led by Accel
$188M raised
$1.2B valuation
Series G
2022 · Led by Vista Equity Partners
$350M raised
$2.5B valuation
WHO BACKED THEM
Sysdig has attracted serious institutional capital across many rounds. Bain Capital Ventures led the early Series A and B.
Accel participated in multiple rounds and led the Series C. Insight Partners, Goldman Sachs, Battery Ventures, and Permira have also invested.
Vista Equity Partners led the landmark $350 million Series G in 2022 at a $2.5 billion valuation. The investor lineup — spanning specialist tech VCs, growth equity, and private equity — reflects how a cloud security company matures from seed-stage technical bet to institutional-scale growth story.
Related Profiles
Companies
CrowdStrike
Both are cloud security platforms competing for enterprise security budgets. CrowdStrike leads with endpoint and identity, expanding into cloud. Sysdig leads with container and Kubernetes runtime, expanding into CNAPP. They increasingly compete for the same platform consolidation deals.
Datadog
Both monitor cloud-native infrastructure at scale. Datadog owns the observability market and has added security features. Sysdig owns container runtime security and has added monitoring. They overlap significantly in the Kubernetes observability and security space, competing for the same engineering and security teams.
Head-to-Head
Compare Sysdig vs another company.