Frequently Asked Questions

Company Growth, Funding & Leadership

What recent funding has Cymulate secured?

In September 2022, Cymulate announced a million Series D investment led by existing investors, including One Peak, Susquehanna Growth Equity (SGE), Vertex Ventures Israel, Vertex Growth, and Dell Technologies Capital. This round doubled Cymulate's total funding to 1 million to date. (Source)

How will Cymulate use its Series D funding?

The Series D funding will be used to extend Cymulate’s technological capabilities, accelerate global growth, and expand staff by 75% to support go-to-market efforts. (Source)

Who are the new executive leaders at Cymulate?

Maria Mastakas joined as Chief Operating Officer and Carolyn Crandall as Chief Marketing Officer and Chief Security Advocate. Both bring extensive leadership experience in cybersecurity and technology. (Source)

How many customers does Cymulate serve?

Cymulate serves more than 500 customers globally, including Fortune 500 companies and strategic partners such as Optiv and Wipro. (Source)

What is Cymulate’s mission and vision?

Cymulate’s mission is to transform cybersecurity practices by providing tools for continuous threat validation and exposure management. The vision is to create a collaborative environment where organizations can achieve lasting improvements in their cybersecurity strategies. (Source)

What industry recognition has Cymulate received?

Cymulate has been named a Market Leader for Automated Security Validation by Frost & Sullivan and a Customers' Choice in the 2025 Gartner Peer Insights. (Source, Source)

How fast is Cymulate growing?

Cymulate more than doubled its annual recurring revenue (ARR) in 2021 and grew over 200% in North America alone. (Source)

Where can I find Cymulate’s latest news and press releases?

You can find all of Cymulate's latest company announcements, press releases, and media coverage in our newsroom. This includes information on partnerships, product updates, industry awards, and expert research featured in leading publications.

What is Cymulate’s relationship with its investors?

Cymulate’s Series D round was led by existing investors, demonstrating their confidence in the company’s current and future performance. Key investors include One Peak, SGE, Vertex Ventures Israel, Vertex Growth, and Dell Technologies Capital. (Source)

Who are some of Cymulate’s strategic partners?

Cymulate’s strategic partners include Optiv and Wipro, among others. (Source)

Platform Features & Capabilities

What is Cymulate’s Extended Security Posture Management (XSPM) platform?

Cymulate’s XSPM platform is a SaaS-based solution that enables organizations to continuously challenge, validate, and optimize their on-premises and cloud cybersecurity posture. It provides end-to-end visualization across the MITRE ATT&CK® framework and automates risk assessments for all cybersecurity maturity levels. (Source)

What are the four pillars of Cymulate’s XSPM platform?

The four pillars are Attack Surface Management, Continuous Automated Red Teaming, Breach & Attack Simulation, and Advanced Purple Teaming. These are tied together with analytics to provide actionable security posture insights. (Source)

How does Cymulate help reduce cyber risk?

Cymulate’s customers see their cyber risk reduced by nearly 50% during the first three months of use. Running daily risk assessments, the cyber risk continues to decrease in the first year without any security drift. (Source)

What types of risk assessments does Cymulate provide?

Cymulate provides automated, expert, and threat intelligence-led risk assessments that are simple to deploy and use for organizations of all cybersecurity maturity levels. (Source)

How does Cymulate support red and purple teaming?

The platform provides an open framework to create and automate red and purple teaming by generating penetration scenarios and advanced attack campaigns tailored to unique environments and security policies. (Source)

What is Cymulate’s approach to continuous security validation?

Cymulate sets the industry standard for using automation to continuously validate threat exposure and cyber posture by testing cloud and on-premise networks against the latest threats in the wild. (Source)

How does Cymulate address the cybersecurity workforce shortage?

Cymulate’s real-world solutions help close security gaps quickly and efficiently, rationalize technology, upskill staff, and improve processes, addressing the global shortage of cybersecurity professionals. (Source)

What is Cymulate’s relationship with the MITRE ATT&CK® framework?

Cymulate’s platform provides end-to-end visualization across the MITRE ATT&CK® framework, helping organizations map and understand their security posture against known attack techniques. (Source)

What types of organizations use Cymulate?

Cymulate is used by organizations of all sizes and industries, including Fortune 500 companies, financial institutions, healthcare, retail, and more. (Source)

Pricing & Plans

What is Cymulate’s pricing model?

Cymulate operates on a subscription-based pricing model tailored to each organization's requirements. Pricing is determined by the chosen package, number of assets, and scenarios selected for testing and validation. For a detailed quote, you can schedule a demo with the Cymulate team. (Source: knowledge base)

Security, Compliance & Integrations

What security and compliance certifications does Cymulate hold?

Cymulate holds several key certifications, including SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1. These certifications demonstrate Cymulate’s commitment to industry-leading security and compliance standards. (Source)

How does Cymulate ensure data security?

Cymulate ensures data security through encryption for data in transit (TLS 1.2+) and at rest (AES-256), secure AWS-hosted data centers, and a tested disaster recovery plan. (Source)

What integrations does Cymulate offer?

Cymulate integrates with a wide range of security technologies, including Akamai Guardicore, AWS GuardDuty, BlackBerry Cylance OPTICS, Carbon Black EDR, Check Point CloudGuard, Cisco Secure Endpoint, CrowdStrike Falcon, Wiz, SentinelOne, and more. For a complete list, visit our Partnerships and Integrations page. (Source: knowledge base)

Is Cymulate GDPR compliant?

Yes, Cymulate incorporates data protection by design and has a dedicated privacy and security team, including a Data Protection Officer (DPO) and Chief Information Security Officer (CISO), ensuring GDPR compliance. (Source)

What application security measures does Cymulate use?

The platform is developed using a strict Secure Development Lifecycle (SDLC), including secure code training, continuous vulnerability scanning, and annual third-party penetration tests. (Source)

What HR security policies does Cymulate have?

Employees undergo ongoing security awareness training, phishing tests, and adhere to comprehensive security policies. (Source)

Use Cases, Benefits & Customer Success

What core problems does Cymulate solve?

Cymulate addresses overwhelming threat volume, lack of visibility, unclear risk prioritization, and resource constraints by providing continuous threat validation, exposure prioritization, improved resilience, operational efficiency, and collaboration across teams. (Source: knowledge base)

What are the key benefits of using Cymulate?

Key benefits include up to a 52% reduction in critical exposures, a 20-point improvement in threat prevention, a 60% increase in team efficiency, 40X faster threat validation, and an 81% reduction in cyber risk within four months. (Source: knowledge base)

Who can benefit from Cymulate?

Cymulate is designed for CISOs, security leaders, SecOps teams, red teams, and vulnerability management teams in organizations of all sizes and industries, including finance, healthcare, retail, media, transportation, and manufacturing. (Source: knowledge base)

How easy is Cymulate to implement and use?

Cymulate is designed for quick, agentless deployment with no need for additional hardware or complex configurations. Customers can start running simulations almost immediately, and the platform is praised for its intuitive, user-friendly interface. (Source: knowledge base)

What feedback have customers given about Cymulate’s ease of use?

Customers consistently praise Cymulate for its ease of use, intuitive dashboard, and actionable insights. Testimonials highlight the platform’s user-friendliness and the accessibility of support. (Source: knowledge base)

What are some real-world results achieved with Cymulate?

Hertz Israel reduced cyber risk by 81% in four months, a sustainable energy company scaled penetration testing cost-effectively, and a credit union optimized SecOps with live-data exercises. See more case studies on the Cymulate Customers page. (Source: knowledge base)

How does Cymulate address different pain points for different personas?

Cymulate tailors solutions for CISOs (communication barriers, risk prioritization), SecOps (resource constraints), red teams (threat simulation), and vulnerability management teams (operational inefficiencies), delivering measurable improvements for each role. (Source: knowledge base)

What are some common pain points Cymulate solves?

Cymulate addresses fragmented security tools, resource constraints, unclear risk prioritization, cloud complexity, communication barriers, inadequate threat simulation, operational inefficiencies, and post-breach recovery challenges. (Source: knowledge base)

Where can I find Cymulate’s customer reviews and case studies?

You can read customer reviews on the Cymulate Reviews page and explore case studies by industry on the Cymulate Customers page.

Competition & Differentiation

How does Cymulate differ from similar products in the market?

Cymulate stands out with its unified platform combining Breach and Attack Simulation, Continuous Automated Red Teaming, and Exposure Analytics. It offers continuous threat validation, AI-powered optimization, complete kill chain coverage, ease of use, and proven results such as a 52% reduction in critical exposures and an 81% reduction in cyber risk within four months. (Source: knowledge base)

What advantages does Cymulate offer for different user segments?

CISOs benefit from quantifiable metrics, SecOps teams from automation and efficiency, red teams from advanced offensive testing, and vulnerability management teams from automated validation and prioritization. (Source: knowledge base)

Technical Requirements & Support

How long does it take to implement Cymulate?

Cymulate is designed for rapid, agentless deployment. Customers can start running simulations almost immediately after deployment, with minimal resources required. (Source: knowledge base)

What support options are available for Cymulate customers?

Cymulate offers email support, real-time chat support, a knowledge base with technical articles and videos, webinars, e-books, and an AI chatbot for quick answers and best practices. (Source: knowledge base)

Where can I access Cymulate’s educational resources?

Educational resources such as webinars, e-books, and technical articles are available on the Cymulate website. Visit the Resource Hub for more information. (Source: knowledge base)

Cymulate named a Customers' Choice in 2025 Gartner® Peer Insights™
Learn More
New Case Study: Credit Union Boosts Threat Prevention & Detection with Cymulate
Learn More
New Research: Cymulate Research Labs Discovers Token Validation Flaw
Learn More
An Inside Look at the Technology Behind Cymulate
Learn More

Cymulate Raises $70M Series D Funding for Continuous Security Posture Testing

September 6, 2022

Investor participation from prior round demonstrates confidence in the company’s current and future performance 

Company announces new Chief Operating Officer and Chief Marketing Officer

New York, and Tel Aviv, (September 6th, 2022) - Cymulate, the market leader in Extended Security Posture Management (XSPM), today announced a $70 million Series D investment led by existing investors One Peak, together with Susquehanna Growth Equity (SGE), Vertex Ventures Israel, Vertex Growth and Dell Technologies Capital.  Cymulate has raised $141M to date.

The latest investment, which is among the largest for continuous security testing vendors, doubles Cymulate’s funding raised to date and accelerates the Company’s global expansion and pace of innovation.

In a recent report on Continuous Threat Exposure Management (CTEM) GartnerⓇ analysts observed, “Previous approaches to managing the attack surface are no longer keeping up with digital velocity — in an age where organizations can’t fix everything, nor can they be completely sure what vulnerability remediation can be safely postponed. CTEM is a pragmatic and effective systemic approach to continuously refine priorities, walking the tightrope between those two impossible extremes.”* The global shortage of 2.72 million cybersecurity professionals, and overstretched in-house security resources further exacerbates the need for Cymulate’s real-world solutions which closes security gaps quickly and efficiently, rationalizes technology, helps upskill staff and improves processes.

“We are thrilled to lead this round of investment in Cymulate,” said David Klein, Managing Partner of One Peak. “Cyber posture management and continuous security validation have dramatically increased in popularity in response to the onslaught of ransomware and cyber warfare for businesses across all size ranges. Cymulate is the clear leader in the sector, and we look forward to continuing to support the Company in further accelerating its already strong growth trajectory.”

Cymulate sets the industry standard for organizations to use automation to continuously validate their threat exposure and cyber posture, by testing their cloud and on-premise networks against the latest threats in the wild. The Company’s Extended Security Posture Management platform leverages its native offensive security technology and capabilities to widely support customers’ security and business needs. XSPM incorporates four fundamental pillars tied together with analytics to provide actionable security posture insights: Attack Surface Management, Continuous Automated Red Teaming, Breach & Attack Simulation, and Advanced Purple Teaming. Cymulate’s customers see their cyber risk reduced by nearly 50% during the first three months of use. Running daily risk assessments, the cyber risk of Cymulate’s customers continues to decrease in the first year without any security drift.

The Series D funding will be used to extend Cymulate’s technological capabilities and further accelerate its global growth. The Company more than doubled its ARR in 2021 and grew more than 200% in North America alone. Cymulate has more than 500 customers globally, including Fortune 500 companies and strategic partners such as Optiv and Wipro. By the end of this year, Cymulate plans to further expand its staff by 75% to continue supporting its go-to-market efforts.

“In a market where every business must be prepared to fight advanced threats, I am proud of our team’s ability to innovate and respond quickly to the constant turbulence of cybersecurity,” said Eyal Wachsman, CEO and Co-Founder of Cymulate. “Our funding from existing investors is a further testament to their confidence in our company, direction, and continued vision. We look forward to reaching our next innovation milestones and expanding into new markets across the globe.”

Alongside their Series D funding, Cymulate announces two C-level executive appointments to bolster the company’s leadership, namely the appointment of Maria Mastakas as Chief Operating Officer and Carolyn Crandall as Chief Marketing Officer and Chief Security Advocate of Cymulate.

Maria Mastakas, named one of Utah Business Magazine’s 30 Women to Watch, was CRO of threat intelligence provider Digital Shadows (acquired by Reliaquest) prior to joining Cymulate. Previously, she held executive leadership positions at Datashield, Integrated Business Solutions (IBS), and Metro Commercial Finance. Mastakas is a cyber security leader, specializing in sales and team building, with a proven track record of increasing sales efficiency and customer retention.

Carolyn Crandall, one of the Top 25 Women in Cybersecurity by Cyber Defense Magazine (2020 & 2019) and recognized as a global thought leader in technology trends, joins Cymulate from Attivo Networks (acquired by SentinelOne) where she also served as CMO and Chief Security Advocate. She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies, with a demonstrated track record of effectively taking companies from pre-IPO through to multi-billion-dollar sales. Crandall has held prior leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate.

*Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program, July 2022.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

About Cymulate

Cymulate’s SaaS-based Extended Security Posture Management (XSPM) provides security professionals with the ability to continuously challenge, validate and optimize their on-premises and cloud cyber-security posture with visualization end-to-end across the MITRE ATT&CK® framework. The platform provides automated, expert and threat intelligence led risk assessments that are simple to deploy and use for organizations of all cybersecurity maturity levels. It also provides an open framework to create and automate red and purple teaming by generating penetration scenarios and advanced attack campaigns tailored to their unique environments and security policies.

For more information, visit www.cymulate.com

About One Peak

One Peak is a leading growth equity firm investing in technology companies in the scale-up phase. One Peak provides growth capital, operating expertise and access to its extensive network to exceptional entrepreneurs, with a view to help transform innovative and rapidly growing businesses into lasting, category-defining leaders. In addition to Cymulate, One Peak’s investments include Neo4j, DocPlanner, Spryker Systems, PandaDoc, Keepit, Paysend, Ardoq, Quentic, HighQ, Coople, DataGuard, Brightflag and many more.

To learn more, visit www.onepeak.tech