Nikesh Arora.

Nikesh Arora sees 40 companies racing to secure AI agents. At least 20 are Israeli

Palo Alto Networks is deliberately watching the emerging market before deciding which companies to back or buy, as Israeli-founded startups have already raised roughly $900 million to secure autonomous software. 

At least 20 Israeli-founded cybersecurity startups are now competing to secure AI agents, as companies increasingly give autonomous software access to corporate applications, data and identities.
Seventeen of the startups have disclosed funding, with their combined total now reaching roughly $900 million. The majority of the companies were founded only in the past few years, making AI-agent security one of the fastest-emerging areas in Israel's cybersecurity industry.
The market is attracting the attention of the world's largest cybersecurity companies. Palo Alto Networks CEO Nikesh Arora said recently that about 40 companies are currently being funded in the agentic security market, including a significant number of Israeli startups.
“We're not smart enough to figure out how the world's going to evolve and how this stuff is going to all line up,” Arora said during an ICONIQ Frontier fireside chat.
“And suddenly what you'll find is that about 40 companies get funded in the space of agentic security. You'll fund some and a bunch of Israeli companies get funded, a bunch of your peers in the industry will fund them.”
2 View gallery
נשיא פאלו אלטו ניקש ארורה
נשיא פאלו אלטו ניקש ארורה
Nikesh Arora.
(Photo: Yuval Chen)
Arora described the crowded market as an advantage for Palo Alto Networks. Rather than trying to predict immediately which approach will win, the company can watch the startups develop and see which teams demonstrate the right technology, execution and strategy.
“You guys just afford us a very large resource lab. So I get to see all 40 companies within reason and see who's got the right idea and I can wait for six months or 12 months or 18 months or 24 months to see a good team, good execution. Have they got a cohesive end-to-end thesis and how this gets figured out.”
Palo Alto Networks is also developing its own capabilities in the area. But Arora acknowledged that the company may not get the problem right.
“I still have internal efforts but remember I'm one of 41 efforts,” he said. “You have to have humility to believe that I will not get it right. More than likely I won't get it right nine out of 10 times, but somebody will.”
The difference, he said, is that Palo Alto Networks has the resources to acquire the companies that emerge as leaders.
“But I have something they don't. I have cash. I have market cap. So I can go buy them and bring them, make them my team. That's how we do it, right?”
His comments capture both the opportunity and the uncertainty facing the Israeli startups entering the market. They are competing not only to win customers, but to determine what could become a new layer of enterprise cybersecurity.
2 View gallery
מייסדי זניטי, בן קליגר (מימין) ומיכאל ברגורי
מייסדי זניטי, בן קליגר (מימין) ומיכאל ברגורי
Zenity founders.
(Photo: Eyal Toueg)
A new security problem
AI agents are fundamentally different from the software that companies have traditionally secured.
An employee using an AI assistant may simply ask it to summarize documents or draft an email. An autonomous agent can go further. It can access applications, retrieve information, use other tools and take actions on behalf of a user or organization.
That creates a new set of questions for security teams. Which agents are operating inside the company? What identities are they using? What permissions do they have? Which applications and data can they reach? And how can a company determine whether an action was taken by a human or by an AI system operating through that person's identity?
The problem is becoming more urgent as companies move from experimenting with AI to deploying agents inside business processes.
Reco, which has now raised $140 million, said its platform maps agents, applications, users and the connections between them. Its Reco Graph tracks the identities and permissions used by agents, as well as the systems and data they can access and the workflows they can initiate. The platform also maps access through OAuth grants, API connections, service accounts, browser sessions and MCP tools.
Reco's $55 million round last week included strategic backing from AT&T Ventures, which had previously been a customer. Forestay and Quadrille Capital also participated.
One of the largest Israeli companies in the category is Zenity, founded in 2021 by Unit 8200 veterans Ben Kliger and Michael Bargury.
Zenity raised $125 million in a Series C in August, bringing its total funding to approximately $185 million. The company is building a platform for securing AI agents as enterprises increasingly deploy autonomous systems.
Onyx Security has raised $148 million. The company raised $35 million in March before securing a $113 million Series B in July at a $640 million valuation. Its platform is designed to discover, control and monitor AI agents operating inside organizations.
Noma Security has raised $132 million. Founded in 2023 by Niv Braun and Alon Tron, the company focuses on identifying and mitigating risks created by AI applications and agents, including vulnerability discovery, security profiling and attack simulation.
Neo, founded by veterans of SentinelOne, emerged from stealth in July with $100 million in funding. The company argues that traditional cybersecurity systems were designed for predictable software and human users, rather than autonomous systems capable of reasoning, making decisions and acting inside enterprise environments.
AIR Security raised $50 million in September, only six months after being founded. Its focus is the supply chain surrounding AI agents, including the plugins, skills, MCP servers and other external tools and content that agents can encounter while operating.
Lasso Security is another company that has moved quickly. Founded in 2023, it announced a $30 million funding round in September. The round was led by ClearSky, with participation from Entrée Capital, iAngels, Singtel Innov8, Mindset and Swish Data. Alongside the financing, Lasso launched LEAP, a CPU-based guardrail designed to inspect AI requests and actions without requiring GPU infrastructure.
Other funded companies include Cymphony, which has raised $30 million, Bloom Security with $20 million, Pillar with $9 million, Pluto and Arrakis with $8 million each, Capsule and Willow with $7 million each, and Tenet with $6 million.
Rig Security and Rein Security bring the disclosed funding total even higher. Rig has raised $12 million, while Rein has raised $8 million to date.
The funding reflects how quickly investors have moved into a market that barely existed as a distinct category a few years ago. The companies are pursuing different approaches, but they share a basic premise: giving autonomous software access to corporate systems creates security problems that existing tools were not necessarily designed to solve.
The rapid expansion of the market is creating several competing theories about where AI-agent security will ultimately sit.
Some startups are trying to build broad platforms that cover the entire agent security lifecycle. Others are concentrating on identity, endpoint activity, permissions, runtime behavior or the tools and data that agents consume.
The identity side of the market is expanding particularly quickly. In August, Israeli companies including NewCore, Oak and others were betting that AI agents would turn identity into a new cybersecurity battleground. NewCore emerged from stealth with $66 million and aims to rebuild identity security for a world in which autonomous software, rather than only employees, accesses corporate systems.
The boundaries of the category remain fluid. Some companies are focused specifically on AI agents, while others are expanding existing products in endpoint, identity, application and data security to deal with the rise of autonomous software.
That makes Arora's estimate of roughly 40 funded companies particularly notable. The number does not necessarily represent 40 companies pursuing exactly the same product. Instead, it reflects how many different approaches are now being funded around the broader question of how enterprises will secure autonomous software.