ThreatAware
London-based cyber asset management platform that continuously verifies device inventory and security control coverage, reaching profitability and 100+ clients before raising outside funding.
Visit Website ↗ + Add to CompareOverview
ThreatAware is a London-based cyber asset management and cyber hygiene platform founded in 2018. Its core function is closing the gap between what security teams believe is deployed across their environment and what is actually running: the platform continuously discovers and cross-references devices, endpoints, and cloud assets against the security tools (EDR, patching, MFA, backup) that are supposed to be covering them, then flags gaps where a control is missing, misconfigured, or has silently stopped reporting. The company cites internal data suggesting roughly 10% of devices accessing corporate networks go undetected by existing tools, and that 30% of security controls are missing, misconfigured, or failing silently.
What distinguishes ThreatAware from a general CMDB or vulnerability scanner is the control-verification angle: rather than just inventorying assets, it checks whether the security stack a company believes it has deployed is actually functioning on each asset, which is a common blind spot in environments that rely on point-in-time audits or self-reported compliance dashboards. The company reached profitability and signed over 100 clients organically before taking any outside investment, which it raised for the first time in February 2026 with a $25 million round led by One Peak.
For CISOs, ThreatAware’s pitch is straightforward assurance: confirming that the controls already purchased are actually deployed and working, rather than adding another detection layer on top of an unverified base. The funding is earmarked for expanding into North America and building out an AI-powered security workspace, so its roadmap and competitive position outside the UK/European market are still developing.
Innovation Matrix Assessment
ThreatAware built and iterated its core product for years pre-funding to reach profitability, and is now using its Series A to accelerate an AI-powered security workspace roadmap, though independent evidence of release cadence is limited to company announcements.
The platform cross-references asset inventory against actual control coverage (EDR, patching, MFA, backup) rather than just cataloging devices, and the company reached profitability with 100+ paying clients before taking outside capital, a strong real-world operational signal.
A $25M Series A in February 2026 from One Peak, following years of self-funded profitable growth, and an active North American expansion plan are independently reported by multiple funding trackers (Crunchbase, PitchBook, FinSMES) and press coverage.
Continuous control-verification against a live asset inventory addresses a real blind spot (tools that silently stop working or were never deployed), but the underlying approach extends established asset-management and CAASM concepts rather than introducing a fundamentally new detection method.
The company's own statistics (10% of devices undetected, 30% of controls missing or failing silently) are vendor-published and not independently benchmarked; the strongest independent-ish evidence of efficacy is that the company reached profitability and 100+ clients without outside sales-driven funding, suggesting genuine customer-perceived value.
Asset visibility and control-coverage verification is a persistent, well-documented gap for security teams, and ThreatAware's continuous rather than point-in-time approach is directly relevant to attack surface management priorities as environments grow more distributed.
Why CISOs Should Care
Gives CISOs a way to confirm that security controls they already pay for are actually deployed and functioning on every device, rather than relying on point-in-time audits or self-reported compliance dashboards.
What Makes It Different
Focuses on verifying control coverage against a live asset inventory (is EDR/MFA/patching actually running here) rather than just discovering and cataloging assets like a typical CAASM tool.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A credible, customer-validated asset visibility and control-assurance platform whose organic path to profitability is a stronger evidence signal than most early-stage vendors can show; its next test is whether the North American expansion and new AI workspace features can be verified independently rather than through company-reported statistics alone.
Editorial Note: Claims vs. Verified Findings
The device-undetected and control-failure percentages are ThreatAware's own published statistics and are not independently verified; the funding amount, investor, and pre-funding profitability/100+ client claims are corroborated across multiple independent outlets (Crunchbase, PitchBook, FinSMES, Tech Show London), so those are treated as independently confirmed.
Sources
Alternatives to ThreatAware
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…