TrapX, which makes tools to thwart cyberattacks in real time via decoy databases and workstations, raises $18M Series C, bringing its total raised to ~$50M
Kyle Wiggers / VentureBeat :
Context & Ripple Effects
TrapX's $18M Series C lands mid-way through a funding cluster around a specific thesis: that attackers get caught by what they touch, not by signatures at the perimeter. Its decoy databases and workstations bait intruders into revealing themselves in real time, and the round brings the company to roughly $50M raised.
The nearest comparable is Illusive Networks, which raised its own $24M Series B1 over a year later on the same deception-on-endpoints idea, edging past TrapX's cumulative total. Adjacent behavioral approaches drew parallel checks — Cyberhaven's data behavior analytics for trade-secret protection and SpyCloud's account-takeover tooling — signaling investors were underwriting detection-after-intrusion as a distinct budget line.
First-order effects
- TrapX gains multi-year runway to push decoy-based detection into enterprise deals, where it now competes head-to-head with Illusive Networks for the same 'assume breach' security budgets.
- Security teams evaluating deception technology get a second well-funded vendor, turning what was a niche purchase into a competitive procurement.
Second-order effects
- Rivalry between TrapX and Illusive Networks pressures both to broaden beyond pure deception — bundling analytics, endpoint coverage, or response workflows — since the decoy layer alone is easy to commoditize once two funded players offer it.
- The round validates the category for follow-on investors, as seen in the adjacent raises from Cyberhaven and SpyCloud, pulling more capital into behavioral and post-intrusion detection startups.
Third-order effects
- If the pattern holds, enterprise security spending structurally shifts a share of budget from perimeter prevention to in-network detection, making deception vendors candidates for consolidation by larger platform security companies seeking that capability.
- A funded deception duopoly sets up the classic endpoint-security pattern: category creation by startups, then absorption or price competition once the approach proves out in production networks.
The trend: Venture capital is steadily funding post-intrusion detection — deception, behavior analytics, account-takeover defense — as enterprises plan for breaches rather than only blocking them.