Skip to content

Dune Security

New York-based platform that continuously scores and remediates human risk, using adaptive, real-time interventions instead of static training.

Visit Website ↗ + Add to Compare
57/100Incremental Innovator

Overview

Dune Security builds a User Adaptive Risk Management platform aimed at the human layer of the breach chain: social engineering, phishing, and insider risk. Rather than relying on periodic, generic security-awareness training, the platform continuously monitors behavioral and contextual signals, scores individual user risk in real time, and adapts interventions, alerts, and access controls to each person’s current risk level, integrating with identity and endpoint tools like Entra ID, Okta, CrowdStrike, and Microsoft Defender.

Founded in 2023 by David DellaPelle and Michael Waite, both early team members at Abnormal AI, Dune Security is headquartered in New York and reports around 67 employees. The platform simulates omni-channel attacks — email, SMS, voice, video, and encrypted messaging apps like Telegram and WhatsApp — reflecting how real social-engineering campaigns actually reach employees today, and serves Fortune 1,000 customers.

The company’s own reported figures claim more than 85% reduction in phishing clicks and 60% reduction in PII exposures for customers, though these are vendor-stated outcomes rather than independently audited results. As an early-stage company competing against established security-awareness players like KnowBe4 and Proofpoint, Dune’s differentiation is real-time behavioral adaptation rather than scale, and its long-term traction is still being proven.

Innovation Matrix Assessment

Innovation Velocity 7/10

Founding team's Abnormal AI background shows in rapid iteration on real-time, multi-channel behavioral risk scoring.

Operational Value 6/10

Shifts security-awareness programs from static annual training to continuous, individualized risk-based intervention.

Market Momentum 5/10

Fortune 1,000 customer traction and a credible founding pedigree, but funding scale and customer count are not fully disclosed.

Category Disruption 5/10

Real-time, adaptive human-risk scoring is a genuine step beyond static phishing-simulation training, in a category ripe for disruption.

Real-World Efficacy 4/10

85% phishing-click reduction and 60% PII-exposure reduction figures are vendor-reported, not independently audited.

Enduring Relevance 7/10

Human error remains the leading breach vector, and social-engineering attacks are growing more sophisticated with AI.

Why CISOs Should Care

Replaces generic annual training with continuous, individualized risk scoring and real-time behavioral interventions.

What Makes It Different

Real-time, omni-channel attack simulation (email, SMS, voice, encrypted apps) tied to adaptive, per-user controls rather than static training modules.

The Matrix Verdict

57/100 — INCREMENTAL INNOVATOR

A promising early-stage entrant in human-risk management with a credible team; a Meaningful Innovator worth tracking as it scales.

Editorial Note: Claims vs. Verified Findings

Reduction percentages (85% phishing clicks, 60% PII exposure) are vendor-published customer outcomes, not independently verified.

Sources