Cybersecurity market intelligence · Transaction diligence · Verified AI

Decision-grade intelligence for the cybersecurity market.

RiskOne is a standing intelligence system for investors and operators — every material claim source-tagged, confidence-banded, and re-verified on a clock. Built for the few engagements where being right matters more than being fast, and delivered fast anyway.

Opinions do not keep score. RiskOne does.

Coverage

How we segment the cybersecurity universe.

Every entity that matters sits in a standing census — watched daily for material change. The ones that matter most carry full structural profiles: ownership, capital stack, technology position, trajectory. Explore the segments:

13
segments
3,100+
entities under standing census
550+
full structural profiles
Continuous
re-verification — never stale
Segment · census → profiledAs of 2026-10-07

MDR, MXDR, SOAR, IR and DFIR — and the shift to agentic security operations.

733 under census → 186 structurally profiled · re-verified continuously

Tracking an entity we have not profiled yet? Request coverage →

+ 540 entities under census in emerging domains, not yet broken out

Abstract rendering — entities are never identified · as of 2026-10-07

The connected universe

Coverage is a graph, not a list — every profile is wired to the people, owners, products, and transactions around it.

  • executives mapped352
  • investors tracked192
  • products mapped142
  • ecosystem links74
  • transactions comped210
··

Signals & intelligence

What the system surfaced recently.

Publicly-reported market events on tracked entities, from the daily news sweep. External sources only — analyst findings, deliverables, and client material never appear here.

2026-09-21
m&a

Accenture — Accenture Completes $4.18B OT Cybersecurity Platform Build: Dragos (majority stake) + NetRise + runZero

Accenture's $4.18B bet on industrial cybersecurity closes: $3.25B majority stake in Dragos + outright acquisition of NetRise and runZero. Combined platform serves critical infrastructure (power, pipelines, manufacturing). OT…

Source →
2026-10-02
funding

Armadin — Armadin -- $255.5M Series B at >$2.5B (AI-native offensive security, US)

Armadin -- $255.5M Series B at >$2.5B (AI-native offensive security, US)

Source →
2026-10-06
cyber-breach

Accenture — FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

ShinyHunters exploited CVE-2026-35273 bypass in Oracle PeopleSoft to breach FBI job portal, stealing employee personal data. Accenture contractor failed to apply required patch. FBI removed the contractor. Mandiant investigated attack…

Source →
2026-10-07
platform-move

Anthropic — Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

<p>Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.</p> <p>The post <a href="">Anthropic Introduces 3-Tier Cyber

Source →
2026-10-02
m&a

Quarkslab — Airbus Defence and Space to Acquire Quarkslab

Airbus / Quarkslab -- sovereign cyber acquisition completes (France)

Source →
2026-10-02
m&a

Fentron — TRG to Acquire Fentron

TRG / Fentron -- PE-backed MSP cybersecurity bolt-on (Ohio)

Source →
2026-10-01
funding

Armadin — Kevin Mandia's Armadin Raises $255 Million at $2.5 Billion Valuation

Series B funding brings the AI-powered offensive security startup's total capital to roughly $445 million only seven months after its public launch. Andreessen Horowitz and Accel co-led; new investors Bain Capital Ventures and Redpoint…

Source →
2026-10-06
cyber-breach

Accenture — FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

<p>The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.</p> <p>The post <a href="">FBI Blames Contractor&#8217;s Missed Patch for Shi

Source →
2026-10-01
funding

Armadin — Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation

Kevin Mandia, best known as the founder of Mandiant, has a new startup that is using agent swarms to test and protect enterprises.

Source →
2026-09-26
cyber-attack

xAI — New x47.c Windows Botnet Weaponizes xAI Grok for AI-Driven Persistence

A new Windows botnet (x47.c) weaponizes xAI Grok API to choose from predefined persistence actions, using AI to maintain stealth. Represents first known botnet using xAI's model for autonomous decision-making in malicious…

Source →

Updated with each census sweep · as of 2026-10-07

01

Market intelligence

A standing system — not a subscription to someone else's thesis.

Traditional coverage is a $1M-a-year stack of analysts and subscriptions that applies someone else's framework on someone else's schedule. RiskOne replaces it with a system that runs continuously against your thesis: a daily census across the cybersecurity universe, structural profiles of every entity that matters, and ranked screens you can put in front of a board or an investment committee — with the evidence chain visible on every line.

  • —Ranked investment screens, board-ready
  • —Sector pre-reads with consolidation vectors and trading comps
  • —Capital-stack monitoring — maturities, covenant posture, distress signals
  • —Continuous currency: findings expire, claims re-verify on a clock
02

Transaction diligence

Three weeks becomes three hours — and the output stays current after it ships.

For private-equity sponsors and acquirers in the cybersecurity market: a deal-cycle suite built on the same living dossiers — triage one-pagers for Monday pipeline calls, deep-dive competitive dossiers, IC memos with every claim linked to falsifiable assertions, CFO packs with the valuation multiple implied by technology ownership, and a simulated pressure-test from the five people who will actually challenge the deal.

  • —One-pager triage → deep-dive dossier → IC memo
  • —CFO pack: revenue quality, margin levers, implied multiples, deal comps
  • —Capital-stack posture before strategic logic — distress is structural
  • —Q&A simulation: IC skeptic, operator, LP, GC, management
03

Verified AI

Trust is earned by architecture — and verified continuously.

Most AI programs ask for trust up front and never check it again. Published red-team results say adaptive prompt injection wins more often than not — so we don't negotiate with the model, and we don't grant trust by policy. We architect so trust is earned: sensitive data physically cannot reach a frontier model — local redaction before anything leaves, a deterministic egress gate that classifies every call, and a tamper-evident audit chain of exactly what left and why. Then the trust is re-verified on every call, because sensitive work fails closed to local models instead of leaking.

This is a reference architecture we run in production — not a slide. We bring the same rigor to your AI estate, and we audit vendor AI claims the way an underwriter would: demonstrated, claimed-only, or theater.

The topology
workspace
│
redaction · PII never leaves
│
egress gate · deterministic, fail-closed
│
audit chain · hash-linked, append-only
│
frontier model · public-class data only
04

Detection & response advisory

Advice from an operator who has built what the market buys.

RiskOne's principal has built detection and response products adopted by two of the largest banks in the United States, by government, and across the Fortune 500 — each time as an operator inside those environments first, learning the biggest unmet needs firsthand and building the products that defined what came next.

That operator-builder base, paired with the standing intelligence engine, is what we bring to clients: where the market is moving, what buyers will actually pay for, and how to aim a development effort so it lands — grounded in public detection-efficacy evidence rather than analyst quadrants.

  • —Product strategy and roadmap guidance, steered by the intelligence engine
  • —Program strategy and vendor selection from the buyer's chair
  • —Evaluation against detection-efficacy evidence, not quadrant position
  • —Operator-to-operator counsel, delivered with builder's candor

Methodology

A chain of custody on every material claim.

Most diligence arrives as a finished document — conclusions detached from their evidence, current as of the day it was written, stale by the time it is read. RiskOne deliverables keep the chain attached. Three links, visible on every assertion:

i

Source-tagged

Every claim carries its source class — public, triangulated, expert judgment, or privileged — and privileged material never crosses into a client-facing deliverable. The MNPI firewall is structural, not procedural.

ii

Confidence-banded

High, medium, or low — earned, visible, and auditable. No false-precision scores, no decimal-point theater. If the evidence doesn't support a band, the claim says so.

iii

Re-verified

Findings expire. Every claim re-verifies on a standing cadence — material events trigger immediate re-verification, and nothing is allowed to go stale. Predictions are scored after the fact; the system's calibration is itself a tracked metric.

Who this serves

Built for the few decisions where being wrong is expensive.

i

Investors & acquirers

Sponsors, growth investors, and corporate development teams putting capital to work in the cybersecurity market.

What to expect
Ranked screens, living dossiers, and IC memos delivered in deal time — every claim sourced and confidence-banded.
Why it is worth it
Replaces a seven-figure stack of analysts and subscriptions with conviction that holds up in front of an investment committee.
ii

Operating executives

CEOs and product leaders of security companies deciding what to build, buy, or exit next.

What to expect
Market structure, competitive position, and roadmap guidance from an operator who has built category-defining products.
Why it is worth it
Product and portfolio bets de-risked before the capital is committed — not post-mortemed after.
iii

Boards & risk owners

Directors, CISOs, and the committees who must stand behind security and AI decisions.

What to expect
Vendor claims graded as demonstrated, claimed-only, or theater. AI adoption architected to earn trust and verify it continuously.
Why it is worth it
Confidence you can defend under questioning — not assurances you inherited from a vendor's deck.

Engage

Engagements are focused by design.

RiskOne works with a focused slate of marquee clients each quarter — investors, acquirers, and operating executives in the cybersecurity market. Outline the decision you need to make and the timeline it is on.