📊 Key Data
  • $290 million in total funding secured by Cylake in just seven months.
  • Over 10 organizations from critical sectors have joined Cylake’s Design Partners program.
  • By 2029, over half of multinational organizations are projected to adopt digital sovereignty strategies.
🎯 Expert Consensus

Experts would likely conclude that the shift away from cloud security reflects growing regulatory pressures and operational vulnerabilities, necessitating a return to sovereign, on-premises solutions for mission-critical infrastructure.

about 7 hours ago
The Sovereign Backlash: Why Global Enterprises Are Abandoning Cloud Security

The Sovereign Backlash: Why Global Enterprises Are Abandoning Cloud Security

SUNNYVALE, Calif. – September 16, 2026 – For the better part of a decade, the governing doctrine of enterprise technology has been unilaterally clear: migrate to the public cloud. Driven by the promise of infinite scalability and frictionless updates, the world’s largest organizations steadily offloaded their most critical infrastructure to hyperscale data centers. But for the engines that power the global economy—power grids, defense manufacturers, and tier-one financial institutions—the cloud is no longer a sanctuary. It has become a profound regulatory and operational liability.

This morning, Cylake, a Sunnyvale-based cybersecurity startup, announced that well over ten organizations have joined its Design Partners program. The cohort, which includes massive operators across critical infrastructure, healthcare, financial services, and manufacturing, is actively shaping the development of Cylake’s operational sovereignty platform ahead of its first beta release later this year.

On the surface, it is a standard pre-launch milestone. But beneath the surface, Cylake’s announcement signals a systemic fracture in the cybersecurity market. The company is building an AI-native platform designed entirely for on-premises and private data center environments, effectively betting that the future of mission-critical defense requires tearing down the cloud-first paradigm.

“The closer you are to your customer, the better you can understand the problems they’re facing. Our Design Partners are providing invaluable input as we build our product, helping to shape the future of enterprise cybersecurity,” said Nick Campagna, Vice President of Product Management at Cylake. “From all the conversations we’ve had already, it’s clear that Cylake will solve a real pain point for organizations that cannot rely on the public cloud for security. Often, they’re managing a patchwork of dozens of tools, yet still not getting the complete protection and visibility they need. We don’t have to explain the value proposition of Cylake to them; they understand it immediately.”

The Architect of the Rebellion

To understand the gravity of this shift, one must look at who is leading the charge. Cylake was co-founded by Nir Zuk, a man whose fingerprints are all over the modern security stack. After pioneering stateful inspection at Check Point and founding Palo Alto Networks—where he served as CTO for two decades—Zuk stepped down in 2025. He quietly assembled a formidable technical brain trust, including Wilson Xu, former VP of Engineering at Palo Alto Networks, and Ehud (Udi) Shamir, the co-founder of endpoint detection pioneer SentinelOne.

The industry has taken notice. Cylake is not a scrappy underdog; it is one of the best-capitalized early-stage enterprise security infrastructure ventures in history. Within seven months of its launch, the company secured $290 million in total funding. A $45 million seed round was led by Greylock Partners alongside In-Q-Tel, the strategic investment arm of the U.S. intelligence community. Just days ago, a $245 million growth round was finalized, led by Lightspeed Venture Partners, Picture Capital, and Redpoint Ventures.

This massive war chest is deployed against a singular, contrarian thesis: the platformization of security into multi-tenant public clouds has fundamentally failed the world’s most regulated institutions.

The Data Puddle Dilemma

Over the past several years, dominant vendors have shifted their innovation engines almost exclusively to multi-tenant public cloud environments. The pitch was simple: aggregate all corporate telemetry into a centralized cloud data lake, apply massive computing power, and hunt threats at scale.

However, this model is fundamentally incompatible with the geopolitical and regulatory realities of the 2020s. Defense contractors bound by International Traffic in Arms Regulations (ITAR) and CMMC 2.0 mandates cannot stream telemetry from air-gapped manufacturing plants into shared commercial clouds. European financial institutions, now operating under the punitive oversight of the Digital Operational Resilience Act (DORA), face strict caps on third-party cloud concentration and cross-border data routing. Similarly, power utilities and healthcare networks are bound by NERC CIP and HIPAA localization mandates that forbid external cloud dependencies for command-and-control defenses.

Because these organizations cannot legally or operationally rely on the public cloud, they have been left behind by modern security advancements. They are forced to maintain disjointed, on-premises toolsets—legacy syslog servers, disconnected firewalls, and standalone endpoint tools. Cylake refers to these fragmented databases as "data puddles."

Without a unified view of the threat landscape, these disconnected puddles make it impossible to correlate indicators of compromise across network, identity, and endpoint planes in real time. Furthermore, this fragmentation makes it technologically impossible for modern AI agents to provide meaningful benefits. Generative AI and autonomous threat hunters require massive, centralized context to function. If the data is siloed in dozens of legacy puddles, the AI is starved of the very telemetry it needs to reason.

“We’ve seen this gap in the cybersecurity market for several years, and our conversations with Design Partners are reinforcing why now is the time to fundamentally reimagine the technical stack,” said Nir Zuk, CEO and Founder of Cylake. “We’re thankful for the feedback our partners have provided already, and look forward to continuing to work with them ahead of our beta release.”

Rebuilding From the Hardware Up

Cylake’s solution is a radical departure from the SaaS margin arbitrage that defines modern enterprise software. The company is rebuilding security from the hardware up, engineering proprietary supercomputer appliances designed to sit physically within a customer’s private data center or colocation facility.

Instead of relying on multiple pipeline collectors that truncate and filter logs to save on exorbitant cloud egress fees, Cylake utilizes a single, high-throughput ingestion pipeline. This feeds into a unified local data lake optimized for "hot storage," allowing enterprises to retain massive volumes of raw telemetry locally for extended periods with sub-second query capabilities.

Crucially, this architecture solves the AI compute bottleneck. Modern autonomous security agents demand massive GPU acceleration. Hyperscalers typically fulfill this by routing enterprise prompts through central cloud APIs. Cylake circumvents this entirely by embedding dedicated AI compute silicon directly into its on-premises appliances. Large-scale threat detection and agentic reasoning models run locally against full-fidelity enterprise data, eliminating data leakage risks, unauthorized model training, and API latency.

As the company noted in a recently released episode of its Inside Cybersecurity podcast, this approach is not just more secure; it fundamentally alters the economics of enterprise defense. By consolidating data ingestion, storage, and AI inference into fixed-cost on-premises infrastructure, Cylake offers a drastically lower total cost of ownership at massive scales, challenging the entrenched assumption that cloud software is inherently more cost-effective.

The Geopolitics of Telemetry

The momentum behind Cylake’s Design Partners program—which is still accepting a limited number of qualified participants—is indicative of a broader macroeconomic trend. The era of blind faith in cloud centralization is over.

Industry analysts project that by 2029, over half of all multinational organizations will maintain explicit digital sovereignty strategies. True sovereignty is no longer just about where data is stored; it requires operational autonomy over who runs the systems and technological ownership over the underlying hardware and AI execution. The extraterritorial reach of legislation like the U.S. CLOUD Act has accelerated this "geopatriation," driving European and Asian enterprises to pull critical workloads back behind their own physical perimeters.

Furthermore, recent global IT outages have laid bare the strategic vulnerability of single-vendor cloud architectures, where a single flawed update can paralyze worldwide operations in minutes. Regulated giants are realizing that resilience requires isolation.

As the digital and physical worlds continue to merge, the engines that power our society require defenses that cannot be compromised by foreign subpoenas, multi-tenant data leaks, or upstream cloud outages. The shift back to sovereign, hardware-accelerated infrastructure is not a regression to the past. It is a necessary evolution for a global economy that has realized the cloud is simply someone else's computer, and some secrets are too critical to share.

Topics & Related

Event:
Partnership
Growth Equity
Theme:
Cloud Security
Agentic AI
Sector:
Cybersecurity

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 50339