Skip to content

XM Cyber

Attack path management pioneer that continuously maps how an attacker could realistically chain misconfigurations and vulnerabilities to reach critical assets.

Visit Website ↗
63/100Incremental Innovator

Overview

XM Cyber was founded in 2016 in Israel by former Mossad director Tamir Pardo, along with Noam Erez, Boaz Gorodisky, and businessman Shaul Shani. Germany’s Schwarz Group acquired the company in 2021 for a reported $700 million after XM Cyber had raised roughly $48 million in venture funding, folding it into Schwarz’s cybersecurity division. Press reporting indicates its technology was subsequently acquired by CrowdStrike in a deal reported around 2025-2026, five years after the Schwarz Group sale.

XM Cyber’s core technical contribution to the category is continuous attack path modeling: rather than scoring individual vulnerabilities in isolation, it maps how an attacker could chain together misconfigurations, credential exposures, and unpatched vulnerabilities across a network to reach a defined critical asset. This graph-based approach highlights choke points — a small number of fixes that would break many possible attack paths at once — rather than presenting a long, undifferentiated list of individual findings.

This attack-path-graph model has since been widely emulated across the exposure-management category, making XM Cyber one of the more influential technical templates in this space even as its corporate ownership has changed hands twice.

Innovation Matrix Assessment

Innovation Velocity 6/10

Continued extension of the attack-path model to external attack surface and cloud environments through its time under Schwarz Group ownership.

Operational Value 7/10

Graph-based choke-point identification lets remediation teams fix a small number of issues that break many possible attack paths, rather than working through an undifferentiated vulnerability backlog.

Market Momentum 6/10

Two acquisitions — a $700M sale to Schwarz Group in 2021 and reported acquisition by CrowdStrike around 2025-2026 — indicate sustained strategic value, though this reflects M&A activity rather than independent growth metrics.

Category Disruption 6/10

Attack path graph modeling was a genuinely different way of presenting exposure data when introduced, prioritizing chokepoints over isolated vulnerability counts, though the approach has since been adopted broadly across the category.

Real-World Efficacy 6/10

A $700M acquisition price implies substantial buyer confidence in the technology, though independent named-incident efficacy validation was not located in this research.

Enduring Relevance 7/10

Attack path reasoning remains highly relevant as environments grow more interconnected across on-prem, cloud, and identity systems, increasing the number of possible attacker chains.

Why CISOs Should Care

XM Cyber's chokepoint identification lets remediation teams fix the small number of issues that would break the largest number of possible attack paths, rather than working through a long, undifferentiated vulnerability list.

What Makes It Different

It models exposure as a graph of chained attack paths toward critical assets, rather than scoring vulnerabilities individually and in isolation — pioneering an approach now widely copied across the exposure-management category.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

A technically influential pioneer of attack path management whose repeated acquisition (twice, at rising strategic interest) reflects real underlying value, even as its independent corporate identity has been absorbed into larger platforms.

Editorial Note: Claims vs. Verified Findings

The Schwarz Group acquisition price and date are independently corroborated; the reported CrowdStrike acquisition is based on limited press coverage found in this research and should be treated as a reported deal pending fuller independent confirmation.

Sources