Richard Stiennon’s Post

View profile for Richard Stiennon, graphic

Research Analyst, Author of Security Yearbook 2023 stiennon.substack.com

The numbers are in for the first half of 2022. Of 2,868 cybersecurity vendors 163 received funding of $10.5 billion. API Security is a new category we have pulled out from underneath Application Security. It is the fastest growing category with 29% growth in six months. Security Operations grew 16.4% followed by IoT Security with 13%. Like last year, GRC is receiving the highest number of new funding rounds, but they are smaller investments than the other categories. dashboard.it-harvest.com #DataDriven #Insights #cybersecurity

  • No alternative text description for this image
Todd Neilson

Entrepreneur, Board member, CISO, Cyber Security Expert

1y

Wow, what a giant waste of money. 5% funded and 60%+ will fail. $6B gone. https://spdload.com/blog/startup-success-rate/ But the lawyers will get rich.

Mikhael Felker

Head of Security & Privacy Engineering @ Verily Life Sciences | Privacy, Security, and Compliance Leader

1y

This is both the challenge and glory of cybersecurity. Go with the traditional known vendor in a category or take a chance on something new but not fully proven. Ideally it’s a mix of both, not all blue chips but not all new chips. Both “all in” strategies have downsides. I wouldn’t for example, bet all my marbles on a new unproven IdP unless I was looking for immense amount of stress and asking to be questioned 10x. Other categories like GRC/Training/etc that doesn’t impact production is easier to stomach.

What are the use cases (capabilities) driving api security? Is it WAF, DLP, or least privileges? Appsec is shift left (dev) and api security runtime (ops)?

Shelley Ruddock

EMEA & APAC Sales Development Mgr & Trusted Advisor @ Venafi to clients securing their machine identities

1y

Thanks Richard this is very interesting, where would you place #machineidentitymanagement ?

Jeffrey Caruso (né Carr)

Writing the Third edition of Inside Cyber Warfare

1y

I’m stunned by the number of cybersecurity vendors. Unbelievable.

Amitpal Singh Dhillon ✪ M.S. EngMgmt 🔐 CCSP 🌁 AWS, OCI 🚀 MITRE ✅ ESG

MultiCloud SME | Cybersecurity Leadership | Web3 GenAI | Client Engineering | Design Thinking | Internet Safety for Kids | Environment Social Governance | Startup Mentorship

1y

Thanks Richard Stiennon for sharing this, I recently learned of this category WAAP (web app and api protection), would that map to API Sec, AppSec and some part of IAM above taking it to almost 50% of new investments in 2022

Thats interesting. I do find that api secuirty is getting a lot of buzz, but I disagree that cloud security isn’t its own category. People are looking for fewer tools, not more. So I think cloud security or CNAPP should be it’s own catagory.

Saul Garcia

CEO of Mass Data, Principal Architect and Advisor | Serving US Private Sector, US Public Sector, Canada & LATAM

1y

Thanks for the share!

Where is cspm/cwpp/cnapp? Is operations siem/soar/xdr? Cloud or on prem?

Great info, thanks for sharing. The rise of API security to the top of the list is consistent with what we're hearing from large enterprises.

See more comments

To view or add a comment, sign in

Explore topics