XM Cyber
Attack path management pioneer that continuously maps how an attacker could realistically chain misconfigurations and vulnerabilities to reach critical assets.
Visit Website ↗Overview
XM Cyber was founded in 2016 in Israel by former Mossad director Tamir Pardo, along with Noam Erez, Boaz Gorodisky, and businessman Shaul Shani. Germany’s Schwarz Group acquired the company in 2021 for a reported $700 million after XM Cyber had raised roughly $48 million in venture funding, folding it into Schwarz’s cybersecurity division. Press reporting indicates its technology was subsequently acquired by CrowdStrike in a deal reported around 2025-2026, five years after the Schwarz Group sale.
XM Cyber’s core technical contribution to the category is continuous attack path modeling: rather than scoring individual vulnerabilities in isolation, it maps how an attacker could chain together misconfigurations, credential exposures, and unpatched vulnerabilities across a network to reach a defined critical asset. This graph-based approach highlights choke points — a small number of fixes that would break many possible attack paths at once — rather than presenting a long, undifferentiated list of individual findings.
This attack-path-graph model has since been widely emulated across the exposure-management category, making XM Cyber one of the more influential technical templates in this space even as its corporate ownership has changed hands twice.
Innovation Matrix Assessment
Continued extension of the attack-path model to external attack surface and cloud environments through its time under Schwarz Group ownership.
Graph-based choke-point identification lets remediation teams fix a small number of issues that break many possible attack paths, rather than working through an undifferentiated vulnerability backlog.
Two acquisitions — a $700M sale to Schwarz Group in 2021 and reported acquisition by CrowdStrike around 2025-2026 — indicate sustained strategic value, though this reflects M&A activity rather than independent growth metrics.
Attack path graph modeling was a genuinely different way of presenting exposure data when introduced, prioritizing chokepoints over isolated vulnerability counts, though the approach has since been adopted broadly across the category.
A $700M acquisition price implies substantial buyer confidence in the technology, though independent named-incident efficacy validation was not located in this research.
Attack path reasoning remains highly relevant as environments grow more interconnected across on-prem, cloud, and identity systems, increasing the number of possible attacker chains.
Why CISOs Should Care
XM Cyber's chokepoint identification lets remediation teams fix the small number of issues that would break the largest number of possible attack paths, rather than working through a long, undifferentiated vulnerability list.
What Makes It Different
It models exposure as a graph of chained attack paths toward critical assets, rather than scoring vulnerabilities individually and in isolation — pioneering an approach now widely copied across the exposure-management category.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A technically influential pioneer of attack path management whose repeated acquisition (twice, at rising strategic interest) reflects real underlying value, even as its independent corporate identity has been absorbed into larger platforms.
Editorial Note: Claims vs. Verified Findings
The Schwarz Group acquisition price and date are independently corroborated; the reported CrowdStrike acquisition is based on limited press coverage found in this research and should be treated as a reported deal pending fuller independent confirmation.
Sources
Alternatives to XM Cyber
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Pentera
Automated security validation platform that safely runs real attack techniques against production environments to prove which exposures are…
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…
CrowdStrike
Publicly traded endpoint and cloud security leader whose Falcon Exposure Management module extends its platform into AI-driven vulnerability…
Mandiant (Google Cloud)
Incident-response and threat-intelligence firm founded by Kevin Mandia, acquired by Google Cloud in 2022 for $5.4 billion.