Dune Security
New York-based platform that continuously scores and remediates human risk, using adaptive, real-time interventions instead of static training.
Visit Website ↗ + Add to CompareOverview
Dune Security builds a User Adaptive Risk Management platform aimed at the human layer of the breach chain: social engineering, phishing, and insider risk. Rather than relying on periodic, generic security-awareness training, the platform continuously monitors behavioral and contextual signals, scores individual user risk in real time, and adapts interventions, alerts, and access controls to each person’s current risk level, integrating with identity and endpoint tools like Entra ID, Okta, CrowdStrike, and Microsoft Defender.
Founded in 2023 by David DellaPelle and Michael Waite, both early team members at Abnormal AI, Dune Security is headquartered in New York and reports around 67 employees. The platform simulates omni-channel attacks — email, SMS, voice, video, and encrypted messaging apps like Telegram and WhatsApp — reflecting how real social-engineering campaigns actually reach employees today, and serves Fortune 1,000 customers.
The company’s own reported figures claim more than 85% reduction in phishing clicks and 60% reduction in PII exposures for customers, though these are vendor-stated outcomes rather than independently audited results. As an early-stage company competing against established security-awareness players like KnowBe4 and Proofpoint, Dune’s differentiation is real-time behavioral adaptation rather than scale, and its long-term traction is still being proven.
Innovation Matrix Assessment
Founding team's Abnormal AI background shows in rapid iteration on real-time, multi-channel behavioral risk scoring.
Shifts security-awareness programs from static annual training to continuous, individualized risk-based intervention.
Fortune 1,000 customer traction and a credible founding pedigree, but funding scale and customer count are not fully disclosed.
Real-time, adaptive human-risk scoring is a genuine step beyond static phishing-simulation training, in a category ripe for disruption.
85% phishing-click reduction and 60% PII-exposure reduction figures are vendor-reported, not independently audited.
Human error remains the leading breach vector, and social-engineering attacks are growing more sophisticated with AI.
Why CISOs Should Care
Replaces generic annual training with continuous, individualized risk scoring and real-time behavioral interventions.
What Makes It Different
Real-time, omni-channel attack simulation (email, SMS, voice, encrypted apps) tied to adaptive, per-user controls rather than static training modules.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A promising early-stage entrant in human-risk management with a credible team; a Meaningful Innovator worth tracking as it scales.
Editorial Note: Claims vs. Verified Findings
Reduction percentages (85% phishing clicks, 60% PII exposure) are vendor-published customer outcomes, not independently verified.
Sources
Alternatives to Dune Security
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…