BitSight, which assesses the likelihood that orgs will be breached, raises $250M from Moody's at a $2.4B valuation and acquires cyber risk startup VisibleRisk
Carly Page / TechCrunch :
Context & Ripple Effects
BitSight has been compounding quietly: a $60M Series D in 2018 priced it around $600M while it rated the security practices of 1,200+ firms, and today's $250M round from Moody's takes that to a $2.4B valuation — roughly a 4x markup in three years. The strategic twist is who's writing the check: Moody's already led VisibleRisk's May 2021 Series A, so the agency is now simultaneously funding BitSight and handing it the startup it backed four months ago.
That makes this less a funding round than a consolidation of the cyber-risk-scoring category under a ratings-agency banner, with BitSight's later Cybersixgill acquisition showing the same playbook continued — bolt on data sources, keep the score at the center.
First-order effects
- Moody's converts its minority bet on VisibleRisk into an anchor stake in the category leader, moving from passive investor to owner of both the scoring platform and the vulnerability-assessment tooling.
- VisibleRisk's team and technology fold into BitSight within months of its Series A, giving BitSight enterprise-facing attack-campaign assessment to pair with its third-party security ratings.
Second-order effects
- BlueVoyant — which raised at a $430M+ valuation in 2019 and over $1B by early 2022 on managed security and threat intelligence for SMBs — now faces a rival that can bundle ratings, vulnerability data, and eventually threat intelligence behind a Moody's-branded score.
- Cyber insurers like Coalition, whose real-time risk tooling underpins its $5B-valued insurance business, depend on exactly this kind of external risk data — ownership of the score shifts pricing leverage toward BitSight and away from the insurers' own models.
Third-order effects
- If rating agencies keep acquiring rather than building, breach-risk scoring becomes an extension of the credit-rating franchise — a standardized, agency-issued number feeding insurance underwriting, vendor selection, and potentially borrowing costs, with the usual questions about conflicts when one scorer holds equity across the ecosystem.
The trend: Credit-rating agencies are absorbing the cyber-risk quantification stack through investment and M&A, turning organizational security posture into a scored, sellable asset class.