Cymulate
Cloud-based breach and attack simulation (BAS) and exposure-validation platform that continuously tests security controls with simulated attack techniques.
Visit Website ↗Overview
Cymulate, founded in 2016 by Eyal Wachsman, Avihai Bar Yosef, and Eyal Gruner, is headquartered in New York with core R&D based in Israel. The company built one of the earlier commercially available breach and attack simulation (BAS) platforms, letting security teams run continuous, automated attack simulations against their own environment rather than relying on periodic manual red-team engagements.
The platform runs a library of thousands of attack techniques mapped to frameworks like MITRE ATT&CK against network, email, endpoint, and cloud security controls, then reports which techniques succeeded, providing prioritized remediation guidance. This continuous-validation approach differs from point-in-time penetration tests by giving teams an ongoing signal as configurations, patches, and threat techniques change.
Cymulate has raised funding across several rounds, including a $45 million round led by One Peak with participation from Vertex Ventures Israel and Dell Technologies Capital, bringing disclosed funding to roughly $141 million as it has continued to expand from BAS into broader exposure-management and attack-surface-management capabilities.
Innovation Matrix Assessment
Has expanded from core BAS into exposure management and attack-surface-management modules across successive product releases.
Continuous, automated control validation gives security teams an ongoing signal rather than a point-in-time snapshot from an annual pentest.
Multiple funding rounds (Series A through C/D) from credible institutional investors indicate sustained market interest, per public press releases.
BAS is a genuinely different validation model than scanning, though the category now has several well-funded competitors (SafeBreach, AttackIQ, Pentera) reducing its uniqueness.
MITRE ATT&CK-mapped simulation library provides a structured basis for testing, though independent named-incident validation was not found in this research.
Continuous control validation remains important as attacker techniques and organizational configurations both change faster than annual assessment cycles can track.
Why CISOs Should Care
Cymulate lets security teams continuously verify that existing controls actually stop known attack techniques, rather than assuming a control works because it was configured correctly once during a point-in-time audit.
What Makes It Different
Runs an ongoing library of simulated attack techniques against live controls instead of relying on periodic manual penetration tests, giving a continuous rather than episodic validation signal.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
A well-established BAS vendor with real product breadth and credible funding, competing in an increasingly crowded exposure-validation category; solidly in the middle tier.
Editorial Note: Claims vs. Verified Findings
Funding figures are corroborated by independent press coverage (SecurityWeek, TechCrunch); specific simulation-accuracy and control-coverage claims are vendor-sourced.
Sources
Alternatives to Cymulate
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Pentera
Automated security validation platform that safely runs real attack techniques against production environments to prove which exposures are…
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…
CrowdStrike
Publicly traded endpoint and cloud security leader whose Falcon Exposure Management module extends its platform into AI-driven vulnerability…
Recorded Future
Threat intelligence platform aggregating open, dark web, and technical sources into real-time risk scoring; acquired by Mastercard in…