Censys, an IoT search engine aimed at helping organizations find poorly protected assets, raises a $35M Series B, hires former OneLogin CEO to be its new CEO
https://techcrunch.com/...
Context & Ripple Effects
This round is the middle beat of a three-step funding arc: Censys raised a $15.5M Series A led by GV and Decibel in 2020 to build out its internet-connected-device search engine, and the $35M Series B reported here pairs that capital with a leadership change — the former OneLogin CEO, who previously took OneLogin through a $100M Series D, takes over as Censys' chief executive.
The bet paid forward: by late 2023 Censys had raised a $50M Series C plus $25M in debt, lifting total funding to $128.1M, which makes this Series B the point where the company shifted from research-grade asset discovery toward an enterprise security business.
First-order effects
- Censys gains both growth capital and an operator with enterprise go-to-market experience, accelerating its push to sell exposure monitoring to organizations that cannot find their own poorly protected assets.
- OneLogin — a sign-on and identity access management vendor competing with Okta and Ping — loses its chief executive to a company whose product sits on the other side of the security stack.
Second-order effects
- Attack-surface rivals like CyCognito, which scans companies' full spectrum of internet-connected devices for vulnerabilities, now face a better-funded competitor with search-engine roots and enterprise sales leadership.
- Identity and asset-discovery vendors begin converging on the same buyer budget, forcing category lines between 'know your exposed assets' and 'control access to them' to blur.
Third-order effects
- If the pattern holds, external attack surface management consolidates around internet-wide scanning platforms, and discovering unmanaged IoT and host assets becomes baseline security infrastructure rather than a niche tool.
- Security spending structurally shifts from defending known perimeters toward continuously mapping everything an organization has accidentally exposed to the public internet.
The trend: Enterprise security is being rebuilt around continuous discovery of exposed internet-facing assets, with escalating venture rounds funding the shift.