Breach and attack simulation startup SafeBreach raises a $53.5M Series D led by Sonae IM and Israel Growth Partners, bringing its total raised to over $106M
Duncan Riley / SiliconANGLE :
Context & Ripple Effects
SafeBreach has been building breach and attack simulation since its $15M Series A in 2016, when Sequoia Capital, Deutsche Telekom Capital Partners, and HP Pathfinder backed the idea of continuously testing enterprise defenses instead of relying on annual penetration tests. Five years later, the company is more than doubling its cumulative funding to over $106M with a $53.5M Series D led by Sonae IM and Israel Growth Partners.
The raise lands four months after direct rival AttackIQ pulled in a $44M Series C to expand internationally, making this the second large check into the same validation category within one quarter — capital is now racing to own the 'prove your defenses work' layer of security.
First-order effects
- SafeBreach gets the war chest to scale sales and product against AttackIQ, turning what was an emerging category into a two-horse contest for enterprise security-validation budgets.
- New backers Sonae IM and Israel Growth Partners take board-level stakes in a company whose disclosed vulnerability research (Avast, AVG, Avira) doubles as marketing for the simulation platform.
Second-order effects
- AttackIQ, fresh off its own international-expansion round, now faces a better-capitalized competitor and will be pushed to differentiate on coverage of attack techniques rather than price.
- Enterprises evaluating simulation tools gain negotiating leverage as two funded vendors compete for the same CISO spend that might otherwise have gone to traditional penetration-testing engagements.
Third-order effects
- If validation keeps attracting capital — SafeBreach here, AttackIQ in July, and cyber risk quantification's $50M Series B for Safe Security the following year — security budgets are structurally shifting from buying more controls toward continuously measuring whether existing ones actually work.
- The pattern points toward boards and insurers demanding quantified, continuously tested proof of resilience, making simulation output a standard input to cyber risk pricing rather than a niche red-team exercise.
The trend: Enterprise cybersecurity is moving from accumulating defensive tools to continuously validating them, with breach-and-attack simulation vendors competing to become the measurement layer.