Skip to content

Cymulate

Cloud-based breach and attack simulation (BAS) and exposure-validation platform that continuously tests security controls with simulated attack techniques.

Visit Website ↗
65/100Incremental Innovator

Overview

Cymulate, founded in 2016 by Eyal Wachsman, Avihai Bar Yosef, and Eyal Gruner, is headquartered in New York with core R&D based in Israel. The company built one of the earlier commercially available breach and attack simulation (BAS) platforms, letting security teams run continuous, automated attack simulations against their own environment rather than relying on periodic manual red-team engagements.

The platform runs a library of thousands of attack techniques mapped to frameworks like MITRE ATT&CK against network, email, endpoint, and cloud security controls, then reports which techniques succeeded, providing prioritized remediation guidance. This continuous-validation approach differs from point-in-time penetration tests by giving teams an ongoing signal as configurations, patches, and threat techniques change.

Cymulate has raised funding across several rounds, including a $45 million round led by One Peak with participation from Vertex Ventures Israel and Dell Technologies Capital, bringing disclosed funding to roughly $141 million as it has continued to expand from BAS into broader exposure-management and attack-surface-management capabilities.

Innovation Matrix Assessment

Innovation Velocity 7/10

Has expanded from core BAS into exposure management and attack-surface-management modules across successive product releases.

Operational Value 7/10

Continuous, automated control validation gives security teams an ongoing signal rather than a point-in-time snapshot from an annual pentest.

Market Momentum 6/10

Multiple funding rounds (Series A through C/D) from credible institutional investors indicate sustained market interest, per public press releases.

Category Disruption 6/10

BAS is a genuinely different validation model than scanning, though the category now has several well-funded competitors (SafeBreach, AttackIQ, Pentera) reducing its uniqueness.

Real-World Efficacy 6/10

MITRE ATT&CK-mapped simulation library provides a structured basis for testing, though independent named-incident validation was not found in this research.

Enduring Relevance 7/10

Continuous control validation remains important as attacker techniques and organizational configurations both change faster than annual assessment cycles can track.

Why CISOs Should Care

Cymulate lets security teams continuously verify that existing controls actually stop known attack techniques, rather than assuming a control works because it was configured correctly once during a point-in-time audit.

What Makes It Different

Runs an ongoing library of simulated attack techniques against live controls instead of relying on periodic manual penetration tests, giving a continuous rather than episodic validation signal.

The Matrix Verdict

65/100 — INCREMENTAL INNOVATOR

A well-established BAS vendor with real product breadth and credible funding, competing in an increasingly crowded exposure-validation category; solidly in the middle tier.

Editorial Note: Claims vs. Verified Findings

Funding figures are corroborated by independent press coverage (SecurityWeek, TechCrunch); specific simulation-accuracy and control-coverage claims are vendor-sourced.

Sources