The archive · Developer & Business Tools · Strategic decision · 2018–2026
Exein: EU cyber rules make firmware security a must-buy — €170M raised in 2025
Exein embeds AI runtime security in device firmware, betting EU cyber rules (CRA, RED 3.3) make it a must-buy: €170M in 2025, 1.5B+ devices protected.
Exein
What the business is
Exein builds AI-powered runtime security that lives inside device firmware, giving connected products real-time threat detection, containment and response while keeping them compliant with EU and US device-security rules.
How it started
Rome-based Exein, founded by Gianni Cuozzo, bet that connected devices need a digital immune system living inside the device itself: an AI runtime in firmware that detects, contains and responds to threats in real time, even without connectivity. For years that was a security sale; the EU's device-security rulemaking turned it into a compliance sale for every manufacturer shipping connected products into Europe.
What happened
The regulatory bet started paying off as EU rules phased in: in July 2025 Exein raised a €70M Series C led by Balderton with Supernova and Lakestar, reporting year-over-year growth above 450% and chipset and OEM partnerships with MediaTek, Supermicro, Kontron, SECO and AAEON. In December 2025 it raised another €100M led by Blue Cloud Ventures with HV Capital, Intrepid Growth Partners, Geodesic Capital and J.P. Morgan — €170M in one year — after revenue grew 5x during 2025 and its valuation nearly doubled in the five months between the two rounds. It reported protecting more than 1.5 billion devices, expecting over 2 billion by Q1 2026.
How it ended up
Scaling: by April 2026 Exein had opened its Asia-Pacific headquarters in Taipei, integrated with MediaTek Genio and server-chip maker ASPEED, and was running a 2026 M&A programme in Europe and the US while readying next-generation runtime security, including protection for on-device AI and LLMs, for RSAC 2026.
Background
Exein is a Rome-based cybersecurity company founded by Gianni Cuozzo. Its product is a digital immune system for connected devices: an AI-powered runtime embedded in firmware that detects, contains and responds to threats in real time, even on devices without continuous connectivity. The company bet that security belongs inside the device rather than at the network perimeter.
That bet gained a second engine when the EU began enforcing device-level cybersecurity. Radio Equipment Directive rules (RED 3.3) and the Cyber Resilience Act, whose obligations phase in from 2026, made embedded security a compliance requirement for manufacturers selling connected products in Europe. Investors followed the regulatory curve: a €70M Series C led by Balderton in July 2025, then a €100M round led by Blue Cloud Ventures in December 2025, bringing the year's total to €170M as revenue grew 5x.
By the end of 2025 Exein said its platform protected more than 1.5 billion devices across energy, healthcare, automotive, semiconductors and industrial automation, with over 2 billion expected in Q1 2026. In April 2026 it opened an Asia-Pacific headquarters in Taipei and deepened chip-level integrations with MediaTek and ASPEED. The open question is whether its growth reflects durable demand or the one-time pull of regulatory deadlines, and how much of the market it can hold once every security vendor claims CRA compliance.
What has to be true
- EU rules land on every connected product: RED 3.3 and the Cyber Resilience Act gave Exein a compliance sale on top of a security sale.
- Firmware-level placement is sticky: once security is embedded at build time, replacing the vendor means redesigning the device.
- Chipset and OEM partnerships (MediaTek, ASPEED, Supermicro, Kontron) let Exein ride the bill of materials instead of selling to each manufacturer one by one.
- The numbers backed the bet: >450% YoY growth in mid-2025, revenue up 5x during 2025, 1.5B+ devices protected, and a valuation that nearly doubled in five months.
What can be applied
When a law hits an industry, the winners are vendors already embedded at the point of compliance: Exein's firmware runtime turned an EU directive into a purchasing default.
Aftermath
As of April 2026 Exein was scaling internationally: it had opened its APAC headquarters and Taipei office, integrated its runtime into MediaTek Genio and ASPEED server BMC chips, and was executing a 2026 M&A programme in Europe and the US while preparing the first wave of next-generation runtime security, including on-device AI and LLM protection, for RSAC 2026. Media coverage through December 2025 put protected devices above 1.5 billion, with more than 2 billion expected in Q1 2026.
Sources
- Exein raises €70M to protect critical infrastructure from back door attacks
- Exein, new €100 million round of equity and debt financing
- Exein boucle une levée de 100 M€
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card