📊 Key Data
  • $60M in funding raised across two rounds
  • 97% of cloud access sits dormant and unused (per Act Security)
  • AI agents can exploit vulnerabilities in minutes vs. months
🎯 Expert Consensus

Experts would likely conclude that Act Security's proactive, structural approach to cloud defense represents a necessary evolution in cybersecurity, particularly as AI-driven threats accelerate.

3 days ago

Act Security Launches With $60M to Remodel Cloud Defense for the AI Era

TEL AVIV, Israel – July 28, 2026 – In a move that signals a significant strategic shift in the cybersecurity landscape, Act Security has emerged from stealth with $60 million in funding and a platform designed not just to monitor cloud threats, but to eliminate them. Founded by the proven entrepreneurial team behind Medigate, which was acquired by Claroty for $400 million, the new venture is tackling what it calls the primary vulnerability of the modern enterprise: 'access sprawl.' As artificial intelligence reshapes both business operations and cyber warfare, Act Security is betting that the old model of finding and patching is no longer tenable, arguing instead for a proactive approach that structurally hardens cloud infrastructure against attacks before they can even begin.

The New Urgency: From Human-Speed to Machine-Speed Threats

The fundamental premise behind Act Security’s launch is that the nature of cyber risk has irrevocably changed. For years, organizations have accumulated a vast and tangled web of permissions across their cloud environments. Much of this access is a byproduct of rapid development and migration, resulting in a landscape where the vast majority of granted permissions are unneeded and unused. According to CEO and co-founder Jonathan Langer, this figure is alarmingly high. "Based on what we are seeing from our customers, close to 97% of cloud access sits dormant and unused," he stated.

For a time, this latent risk was manageable. Attackers, operating at human speed, had to manually discover and exploit these pathways. That era is over. The rise of sophisticated AI, including frontier models capable of autonomous exploitation, means that vulnerabilities can be found and weaponized in minutes, not months. "With AI now operating on every access path and exploiting it at machine speed, this problem has become urgent," the company noted in its launch. When AI agents inherit the same excessive permissions granted to humans—but operate around the clock with machine efficiency and none of the contextual judgment—dormant risks become active, imminent threats.

This reality is corroborated by broader industry trends. Cybersecurity research firms have documented a dramatic reduction in 'breakout time'—the period between an initial compromise and an attacker’s lateral movement through a network. This acceleration forces a strategic rethink. The game is no longer about staying one step ahead; it's about re-architecting the playing field entirely.

Beyond Visibility: A Structural Shift in Cloud Security

For the past decade, the dominant cloud security paradigm has been focused on visibility. A sprawling market of Cloud Security Posture Management (CSPM) and Cloud Infrastructure Entitlement Management (CIEM) tools has emerged to provide security teams with exhaustive lists of misconfigurations, vulnerabilities, and excessive permissions. While valuable, this approach has a critical flaw: it often results in 'alert fatigue,' overwhelming teams with thousands of findings while leaving the root cause unaddressed.

"Visibility tools surface thousands of findings and leave teams triaging symptoms one by one, while the root cause, the access architecture, goes unaddressed," Langer explained. Act Security’s platform is designed to break this reactive cycle. It is 'action-centric,' meaning its primary function is to enforce preventative controls rather than simply report problems.

The technology works by reasoning across identity, network, and AI access simultaneously to map the potential pathways an attacker could take. It then systematically eliminates unnecessary and unused access paths by enforcing deterministic boundaries that limit what humans, workloads, and AI agents can reach. By removing the exposed pathways, the platform ensures that even if an attacker gains an initial foothold, they have nowhere to go. This proactive hardening is designed to make the cloud structurally secure, transforming the principle of least privilege from a theoretical ideal into an operational reality.

The Pedigree and the Capital: A $60 Million Vote of Confidence

The ambition to reshape a multi-billion dollar market requires significant capital and credibility, both of which Act Security has in abundance. The company’s $60 million in funding was raised across two rounds: a $20 million seed round led by Team8 and Bessemer Venture Partners, and a $40 million Series A led by Notable Capital. The investor syndicate also includes Hetz Ventures, Claltech, Startpoint Capital, and the Silicon Valley CISO Investments (SVCI) group, signifying broad confidence from both financial and strategic backers.

Much of this confidence stems from the founding team’s track record. Their previous company, Medigate, pioneered security for connected medical devices and became a market leader before its $400 million acquisition. Investors are betting that this team can replicate their success by identifying and solving the next great challenge in cybersecurity.

Liran Grinberg, co-founder and Managing Partner at investor Team8, highlighted the strategic importance of the company's approach. "We backed Act because of the caliber of the founding team who saw the access problem before the rest of the market did," Grinberg stated. "Cloud security has spent a decade telling organizations where their risk is. Act is the first platform that actually removes it, and in an era where AI exploits exposure in minutes rather than months, that's the new baseline. We believe this is one of the largest opportunities in cybersecurity today."

Enabling the Future: Securing AI to Unleash Innovation

Perhaps the most critical strategic dimension of Act Security's mission is its role as an enabler of AI adoption. Enterprises are rushing to integrate AI agents into their core operations to drive efficiency and innovation. However, this rush creates immense security risks if not managed properly. The prospect of an AI agent, armed with excessive permissions, causing a catastrophic data breach or operational disruption is a primary concern for CISOs and boards everywhere.

Act Security directly addresses this by providing a mechanism to deploy AI agents safely. By enforcing tightly defined access boundaries around every AI workload, the platform ensures these agents can access precisely what they need to perform their function and nothing more. This allows organizations to embrace the transformative potential of AI without accepting an untenable level of risk.

Furthermore, the platform is built to prevent the creation of new access sprawl. By integrating into the CI/CD pipeline, it ensures that new access violations are blocked before they ever reach a production environment. This focus on prevention, combined with its ability to enforce boundaries that map directly to compliance frameworks like NIST 800-53, PCI DSS, and HIPAA, positions the platform not just as a security tool, but as a core component of modern business and technology governance.

Topics & Related

Sector:
Cybersecurity
Theme:
Cloud Security
Zero Trust
Artificial Intelligence
Agentic AI
Event:
Seed Round
Series A
Product Launch

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 44827