Illumio, which takes a zero trust approach to protect data centers and cloud networks, raises $225M Series F led by Thoma Bravo at a $2.75B valuation
Carly Page / TechCrunch :
Context & Ripple Effects
Illumio's raise closes a four-year gap since its Series D at a $1B+ valuation in 2017 — the new $2.75B figure more than doubles that mark and lands the company firmly in late-stage territory. The lead investor is the telling part: Thoma Bravo, a buyout firm, is writing a growth check into a startup rather than taking control of it.
That fits a pattern in Thoma Bravo's security portfolio: it already holds a majority stake in Venafi, the machine identity management provider bought at a $1.15B valuation, and later led AppOmni's $70M Series C in SaaS security. Illumio adds network-layer zero trust to a stack that now spans machine identities and SaaS posture.
First-order effects
- Illumio gains $225M to scale its zero trust segmentation across data center and cloud networks, with its valuation stepping up from $1B+ in 2017 to $2.75B.
- Thoma Bravo now has growth-stage exposure to network security on top of its Venafi control stake, giving it two positions in the zero trust infrastructure layer.
Second-order effects
- Zero trust rivals feel the bar rise: Cyolo's $60M Series B for employee-access zero trust and JupiterOne's $70M cyber-asset round show competitors raising against a market where the category leader just priced at $2.75B.
- With Venafi, AppOmni, and Illumio in one orbit, Thoma Bravo can position cross-sell bundles across machine identity, SaaS posture, and network segmentation — pressuring point-solution vendors on enterprise procurement.
Third-order effects
- The raise blurs the VC/PE boundary in cybersecurity: buyout firms leading growth rounds lets them build security platforms through minority stakes first, with buyout as the follow-on move rather than the entry.
- If zero trust keeps attracting capital at every layer — network (Illumio), identity (Venafi), SaaS (AppOmni), access (Cyolo) — segmentation-by-default hardens from architecture trend into procurement requirement, squeezing vendors still selling perimeter-based tooling.
The trend: Cybersecurity is consolidating around zero trust as the default enterprise architecture, with private equity firms like Thoma Bravo assembling multi-layer security platforms through a mix of control stakes and growth rounds.