Tidal Cyber
A Virginia-based threat-informed defense platform, co-founded by three former MITRE ATT&CK leaders (Rick Gordon, Richard Struse, and Frank Duff), that maps adversary tactics and techniques to an organization's actual defensive coverage to prioritize where security investment matters most.
Visit Website ↗ + Add to CompareOverview
Tidal Cyber was founded in 2022 by Rick Gordon (CEO), Richard Struse (CTO), and Frank Duff (Chief Innovation Officer) — all three previously senior leaders at MITRE who helped build and advance the widely-used ATT&CK framework and MITRE’s Threat-Informed Defense research. The company’s platform maps known adversary tactics, techniques, and procedures (TTPs) against an organization’s actual deployed defensive controls, helping security teams identify where real coverage gaps exist relative to threats most likely to target them.
Tidal Cyber raised a $5M seed round in November 2023 led by Squadra Ventures, followed by a $10M Series A in September 2025, bringing total funding to $15M, with investment participation from USAA and Capital One Ventures reflecting interest from large enterprise security buyers in the threat-informed defense approach the founders pioneered at MITRE.
Innovation Matrix Assessment
Two funding rounds within two years of founding and continued product development indicate active, sustained iteration for a young company.
Mapping adversary TTPs against actual defensive coverage gives security teams a genuinely practical way to prioritize investment against realistic threats rather than generic best practices.
Strategic investment from USAA and Capital One Ventures, plus a 2025 Series A, are solid signals of enterprise-buyer confidence for a young company.
Operationalizing the ATT&CK framework directly into gap-analysis software is a meaningful practical extension of the threat-informed defense concept its founders pioneered.
Founded in 2022 with a small team and limited operating history; no independent efficacy data was found.
Threat-informed, adversary-technique-based defense prioritization is an increasingly central and durable approach to modern security investment decisions.
Why CISOs Should Care
CISOs wanting to know which specific adversary techniques their current security stack actually defends against — versus which ones would succeed despite existing investment — get a platform built by the people who created the ATT&CK framework most defenders already use to think about adversary behavior.
What Makes It Different
Tidal Cyber is directly founded and led by the creators of MITRE ATT&CK and MITRE's Threat-Informed Defense initiative, giving it arguably unmatched pedigree in translating adversary-technique frameworks into practical, prioritized defensive-gap analysis.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A credibly differentiated, founder-pedigree-driven threat-informed defense platform with strong strategic investor interest (USAA, Capital One Ventures); still early-stage in revenue scale, moderating momentum and efficacy relative to more established exposure-management vendors.
Editorial Note: Claims vs. Verified Findings
Funding rounds and founder backgrounds (former MITRE leaders) are independently corroborated by PRNewswire, SecurityWeek, and LinkedIn profiles; specific gap-analysis accuracy claims are vendor-stated and were not independently benchmarked.
Sources
Alternatives to Tidal Cyber
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…