The Cyber Defense Innovation Matrix
A way to evaluate cybersecurity companies on more than marketing, market size, or analyst-category placement. It asks one question: is this company truly changing cybersecurity, and does that innovation translate into measurable value for a CISO?
Every year, the security industry produces another wave of quadrants, radars, and wave reports. Vendors brief analysts for months to move a single dot. Budgets get built around placement in a box. And CISOs are left asking the same quiet question none of those reports actually answer:
Is this company truly changing cybersecurity — or did they just have a good year in sales?
The Cyber Defense Innovation Matrix exists because that question deserves a real answer, built from evidence rather than briefing decks.
Why We Built a Matrix Instead of a Quadrant
A quadrant asks two questions: how big are you, and how complete is your feature list? Both are proxies for market success, not innovation. They reward incumbents for staying incumbent and often miss the ten-person team that just changed how a problem gets solved, because that team hasn’t sold enough seats yet to show up as a dot worth plotting.
The Matrix asks a different, harder question of every company we evaluate: does this technology represent genuine forward motion for the industry, and can a CISO point to real value because of it? That question can’t be answered with a market-share chart. It has to be answered dimension by dimension, with evidence, in public, so you can check our work.
Six Dimensions, Not One Score
A single “innovation score” hides more than it reveals. A company can be moving fast (high velocity) while building something that doesn’t actually hold up against real attackers (low efficacy). Another can have a technically brilliant approach with almost no market traction to prove anyone wants it yet. Collapsing that into one number erases exactly the nuance a CISO needs.
So we score six dimensions independently, each 1–10, and only then sum them — to a total of 60, normalized to a score out of 100. The tier a company lands in (Emerging, Incremental, Meaningful, or Transformational Innovator) is a direct function of that evidence, not a subjective label applied after the fact.
Reading the Evidence Like a Skeptic, Not a Sponsor
Sponsored placement exists elsewhere in this industry, and we think it belongs nowhere near a score. Every company profile on Cyber Defense Genius carries an explicit split between two kinds of claims:
- Vendor claims — a detection percentage from a datasheet, a “zero false positives” line in a press release, a competitor comparison the company wrote about itself. We record these, but they don’t move a score on their own.
- Independently verified findings — a named customer case study, an analyst evaluation, a MITRE ATT&CK result, government or independent research funding, a documented incident response. These are what Real-World Efficacy and Market Momentum are actually built on.
When a company’s evidence is thin, its score says so honestly — that’s not a penalty for being young, it’s the Matrix doing its job. A well-funded incumbent making unproven claims should not outscore a smaller company with real, cited evidence behind a smaller set of claims.
A Worked Example: Unknown Cyber
The clearest way to explain a scoring model is to show it working on a real company. Unknown Cyber positions its technology around malware genomics — automated deep static analysis and function-level code comparison, rather than the two questions most tools still ask: “what did this file do when I ran it?” (sandboxing) or “have I seen something like this before?” (signatures). Unknown Cyber’s genomic approach asks a third, deeper question: what functions make up this code, where has that code appeared before, and what else shares its functional DNA?
That distinction is exactly what the Matrix is built to expose. Run through the six dimensions:
- Innovation Velocity — 9/10. The underlying genomic analysis has been extended into a real product line: Malware Lab, the JUCY genomic sandbox, Software Scan, automated YARA rule generation, and DFIR workflows.
- Operational Value — 9/10. Work that normally requires an expert reverse engineer — triage, attribution, indicator extraction, rule generation — is described as compressed into an automated workflow measured in minutes.
- Market Momentum — 7/10. An In-Q-Tel portfolio company with DARPA-related government R&D funding and 100+ clients worldwide — real signals, scored a point below the top because customer retention and revenue weren’t independently verifiable in this pass.
- Category Disruption — 10/10. Not a better sandbox — a different question entirely. That’s what earns a perfect score on this dimension specifically.
- Real-World Efficacy — 9/10. Published examples span supply-chain analysis and a Salt Typhoon/Snappybee-related case where the analysis reportedly isolated malicious code inserted into an otherwise near-identical binary — strong, though still a claim awaiting further independent validation before it earns a 10.
- Enduring Relevance — 10/10. Polymorphic malware, AI-generated variants, and supply-chain compromise all make code-lineage analysis more important with time, not less.
Total: 54/60, normalized to 90/100 — Transformational Innovator. Not because Unknown Cyber is large. Because the evidence, dimension by dimension, says it changed the underlying model for how the problem gets solved. See the full profile, sources, and radar chart →
What “Transformational” Actually Costs
We treat the top tier as something to be earned rarely, not handed out generously. Most capable, well-run companies land as Meaningful or Incremental Innovators — genuinely useful, genuinely competent, just not reinventing how the underlying problem is solved. That’s not a insult; most real progress in security is incremental, and we say so plainly rather than inflating scores to make every profile sound exciting.
This Is a Living Assessment
Companies ship new capability, raise funding, get acquired, and sometimes get breached. Scores here are dated, sourced, and revisited — not carved in stone the way a single annual report is. If you’re a vendor and believe a score is missing evidence, tell us what we’re missing. If you’re a CISO and a claim looks thin, that’s the point of the claims note — go check it yourself.
The Six Dimensions
Each dimension is scored 1–10 and summed to a total out of 60, normalized to a score out of 100.
| Dimension | What it measures |
|---|---|
| Innovation Velocity | How quickly the company turns new ideas into meaningful, repeatable security advances. |
| Operational Value | Whether the technology makes the CISO and security organization more effective, resilient, efficient, or informed. |
| Market Momentum | Evidence of adoption, customer demand, ecosystem traction, partnerships, and durable market pull. |
| Category Disruption | Whether the company is merely improving an existing tool or fundamentally changing how the problem is solved. |
| Real-World Efficacy | Whether the technology demonstrably works against genuine enterprise threats outside a controlled lab. |
| Enduring Relevance | Whether the innovation remains strategically important as attackers, architectures, AI, cloud, and infrastructure evolve. |
Innovation Tiers
| Score | Tier | What it means |
|---|---|---|
| 85–100 | Transformational Innovator | Changes the underlying model for how the industry can solve the problem. |
| 70–84 | Meaningful Innovator | A materially better way to solve the problem than the incumbent approach. |
| 50–69 | Incremental Innovator | Makes an existing approach faster, cheaper, or easier — without changing the model. |
| Below 50 | Emerging / Unranked | Not yet enough independent evidence for a confident score. |
Editorial Safeguard
Cyber Defense Genius distinguishes vendor-provided claims from independently verified Matrix findings. Claims such as detection percentages, specific competitor comparisons, or "zero false positives" receive full points only after supporting evidence, customer validation, or independent testing. Every profile lists its sources.
This produces something more useful than another analyst quadrant: an evidence-driven measurement of who is actually moving cybersecurity forward — where a highly innovative emerging vendor can outrank a multibillion-dollar incumbent if its technology meaningfully changes the state of the art.