What the business is
IBM Security, the world's second-largest cybersecurity vendor behind Microsoft, selling security software and services to enterprises.
Starting capital
Deal terms undisclosed; Randori had raised almost $30M across two rounds.
How it started
Randori was founded in Boston in 2018 by a former Carbon Black executive and a former red team consultant 'to ensure every organization has access to the attacker's perspective', in CEO Brian Hazzard's words. Its Recon product continuously maps internet-facing assets; its Attack platform automates real-world attacks to show where security programs break down.
What happened
IBM announced the acquisition on 6 June 2022 and planned to fold Randori's attack surface management into the extended detection and response capabilities of its QRadar suite, use its red-teaming technology to bolster the X-Force Red offensive team, and feed its insights into Managed Security Services for thousands of clients. IBM had recently bought endpoint security platform ReaQta as the same push continued.
What has to be true
ESG data cited by IBM put 67% of organisations as having seen their external attack surface expand over two years of cloud, third-party and IoT growth.
The same data showed 69% of organisations had been compromised via unknown, unmanaged or poorly managed internet-facing assets in the past year.
Randori prioritises vulnerabilities by how attractive an asset is to real attackers, based on live attack techniques — not just abstract risk scores.
Offensive capability was scarce: automated red teaming let IBM's elite hacker team scale beyond what consultants alone could cover.
What can be applied
When exposures multiply faster than defences, the fastest fix can be buying the people who think like the other side.
Aftermath
As of 6 June 2022 the deal had been announced but not closed; IBM expected completion within months, subject to regulatory approval. Integration plans put Randori Recon's continuous attack surface assessment inside QRadar's XDR stack, Randori Attack's automated attacks inside X-Force Red stress-testing, and Randori insights inside Managed Security Services threat detection. No post-close results were reported in the coverage.
FOLLOW THE EVIDENCE