Security-as-a-service startup StackPath nabs $180M, 4 acquisitions including MaxCDN
A mass migration of IT services to the cloud, coupled with a huge growth of connected devices, has created a perfect storm for security breaches with some 400 million malware attacks identified last year alone according to IDC.
Context & Ripple Effects
StackPath is executing a roll-up rather than a product launch: $180M raised and four acquisitions at once, with MaxCDN the marquee name, to assemble a security-as-a-service platform on top of existing infrastructure. The stated backdrop is IDC's count of roughly 400 million malware attacks last year, driven by cloud migration and connected-device growth.
The bet landed in a funding lane that kept widening: cloud security broker Netskope followed within a year with a $100M Series E from Lightspeed and Accel, and by 2021 adjacent layers of the same stack — governance tools like CoreStack and Stacklet, and cloud-services selector Upstack — were each pulling in eight-figure rounds of their own.
First-order effects
- MaxCDN's customer base changes hands overnight, with its CDN traffic becoming the distribution channel for StackPath's security services rather than a standalone delivery product.
- StackPath enters the market as an assembled platform instead of a single-product startup, compressing what would have been years of organic build into one funded step.
Second-order effects
- Rival security and infrastructure vendors face a bundled competitor whose price floor spans multiple products, pressuring point-solution players to bundle or raise — the path Netskope took with its Series E months later.
- Capital allocators read the round as validation, steering follow-on money toward neighboring stack layers such as cloud governance and services selection, where CoreStack, Stacklet, and Upstack subsequently raised.
Third-order effects
- If bundling keeps beating point products, security consolidates into full-stack platforms that own the customer relationship across delivery, protection, and governance — a classic case of stack capture risk for vendors left selling single layers.
- The pattern points toward an industry structured around vertically integrated cloud stacks, where each layer's vendor competes less on features than on how much of the stack it controls.
The trend: Cloud security is consolidating from point products into venture-funded full-stack platforms, with each acquisition wave pulling adjacent layers — delivery, governance, procurement — under fewer owners.