档案库 · 开发与企业工具 · 产品决策 · 2025–2026
Fig Security的SecOps赌注:3800万美元捕捉静默故障
Fig的赌注:安全工具变更时,安全堆栈会默默失效,因此它端到端追踪检测流程;融资3800万美元,数月内获财富100强客户。
Fig Security
做的是什么生意
Sells SecOps 'resilience' software that maps an enterprise's detection and response flows across the whole security stack, traces data lineage from sources through SIEMs and data lakes to SOAR platforms and SOC agents, and alerts teams when a change would silently break detection or response.
启动资金:$38M announced March 2026, across seed and Series A rounds, with Team8 and Ten Eleven Ventures among the investors, plus security leaders including former Splunk CEO Doug Merritt and former Palo Alto Networks CMO Rene Bonvanie.
起因
Gal Shafir led Google Cloud Security's global architecture team before founding Fig Security in 2025 with CTO Roy Haimof and CPO Nir Loya Dahan, veterans of Israel's Unit 8200 and Mamram. While pitching Google's AI products to CISOs, Shafir kept hearing the same doubt: 'I don't know if I trust my detections right now' — meaning AI that promises safety tomorrow is worthless if the data feeding existing detections is already broken. The founders concluded that constant tool and environment change silently skews security operations, and that no vendor was solving that trust problem, so they left to build Fig.
经过
Fig's platform autonomously discovers and maps an organization's complete detection and response flows, samples data as it moves through pipelines, and builds a data lineage that shows how an upstream change could break downstream detection in real time. It connects to data links and SIEM systems, alerts security teams to inconsistencies, and lets them simulate fixes before deployment. The company ran in stealth with offices in New York and Tel Aviv, and by March 2026 had raised $38M across seed and Series A rounds from Team8, Ten Eleven Ventures and a group of security-industry angels, with plans to triple headcount and expand in North America.
还没有结局,它还在跑。
背景
Fig Security由Gal Shafir、Roy Haimof和Nir Loya Dahan于2025年创立,均为以色列8200部队和Mamram老兵,Shafir曾领导谷歌云安全全球架构团队。公司于2026年3月3日摆脱隐身,获3800万美元种子轮和A轮融资。其前提:企业安全堆栈过于密集且变化频繁,检测会静默失效,数月的警报或许只是坏掉而非证实一切无虞。
该产品是一个SecOps韧性平台,将每条检测作为真相之源并逆向工作。它自主映射组织的检测与响应流程,端到端追踪数据血统——从源通过管道、数据湖和SIEM到SOAR平台和SOC代理——并在上游变更威胁检测或响应时实时向团队警报。团队还可模拟修复、补丁或配置变更在部署到生产前如何影响堆栈。
创意来自Shafir在谷歌云安全期间的客户谈话:CISO告诉他,当今日检测下数据流动不确定时,他们无法信任AI对明日安全态势的建议。最初赌注是市场需要的是对现有安全运维的信心,而非另一个点工具。Team8和Ten Eleven Ventures支持了这些轮次,前Splunk CEO Doug Merritt和前Palo Alto Networks CMO Rene Bonvanie等安全领袖也参与其中。
公司推出约八个月后,已有大型企业客户,包括财富100强在内,数量达两位数低段,计划到2026年底扩展至50至100家,同时将员工人数增加两倍并扩大北美业务。截至公告时,公司未披露收入或定价,其影响取决于CISO是否将“安全堆栈本身的韧性”作为独立于检测工具的预算线。
这件事要成立,得有什么
- 数月不触发的检测与坏掉的检测难以区分,因此随着工具变化,对安全堆栈的信任会静默下降。
- CISO表示,当不确定当前检测数据是否正常流动时,他们无法信任AI对明日态势的建议。
- 从每条检测为源头逆向追溯,把难以管理的工具蔓生转化为单一可审计的数据血统。
- 部署前用模拟销售企业已渴望的工作流程——SOC中的安全创新——而非新的警报源。
- 拥有谷歌云安全、8200部队和Mamram背景的创始人让企业买家有理由信任全新品类。
可借鉴之处
最危险的故障是无人看见的:销售对现有检测的确定信心——追溯流程,对静默故障发出警报,部署前模拟。
后续进展
截至2026年3月3日公告,Fig Security在纽约和特拉维夫运营,平台已在两位低段数的的大型企业客户上线,包括财富100强。3800万美元种子和A轮资金用于将工程和市场人员增加两倍并扩大北美业务,目标2026年底达到50至100家客户;投资者Team8和Ten Eleven Ventures另有如Splunk前CEO Doug Merritt等安全天使,而定价、收入和留存数据尚未公布。
资料来源
- Fig Security emerges from stealth with $38M to help security teams deal with change
- Fig Security emerges from stealth with $38m
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡