Founders build. We clear the path.
We support you across the entire lifecycle.
We built a full framework to back founders from seed to market leadership. One clear path with the right tools, people, and momentum.G-Seed starts it. G+ scales it. Mach5 accelerates it. G-Club surrounds it.Focused on Cybersecurity and AI, Glilot brings hands-on experience, flexible capital, and a global network that delivers results. We cover every stage with real, hands-on support.
G-Seed
Backs founders from first spark to scale. Early, deep, aligned.
G+
For founders ready to scale. Leads A/B rounds toward growth and dominance.
Exclusive wealth management for tech founders.
Value
We support founders with practical value, wrapping them with professional support from every possible type needed.
Five rounds of customer insight to hit product-market fit fast.
Fast access to top industry minds.
A VC that is deeply aligned with you - yep, that exists.
I love the Glilot team. They're incredibly professional.
Name:
Rotem Iram
Position:
CEO of At-Bay
Glilot helped us with every possible challenge, such as opening doors, hiring, and providing insights.
Name:
Daniel Krivelevich
Position:
CTO of Cider Security
Glilot is one of the most amazing VCs in cyber security.
Name:
Shay Morag
Position:
CEO of Ermetic
Glilot is founder-friendly and here to support founders and companies.
Name:
Yoav Levy
Position:
CEO of Upstream Security
Knowledge-Hub
Cybersecurity venture capital built around real market signals
Glilot Capital is an AI-first VC firm founded in Israel in 2011 as the world’s first VC dedicated to cybersecurity. Today, we invest in cybersecurity, AI and enterprise software at seed and early growth through Glilot Seed and Glilot+. The firm manages approximately $1.3 billion and has completed 27 exits.
Our cybersecurity strategy starts with a simple principle: strong technology becomes a company only when real buyers are ready to adopt it. We combine focused investing with direct access to CISOs and senior enterprise leaders, structured product-market fit work through Mach5, and ongoing support from our Value Creation team.
Why cybersecurity requires a specialized investment approach
Cybersecurity markets are shaped by both technology adoption and active adversaries. New infrastructure, cloud architectures and AI systems create new ways to build, but they also create new attack surfaces. This keeps security priorities closely tied to operational risk and makes practitioner insight essential to investment decisions.
Gartner forecast worldwide end-user spending on information security of $213 billion in 2025 and $240 billion in 2026, representing 12.5% growth. Security software was expected to account for approximately $105.9 billion in 2025, ahead of security services at $83.8 billion. Gartner linked continued growth to rising threats and the expanding use of AI by employees and attackers. [4]
The threat data points in the same direction. Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches began with software vulnerabilities, 48% involved ransomware, and 15 attack techniques were being augmented by generative AI. For investors, the implication is clear: cybersecurity is not a single, static category. It is a constantly evolving market made up of distinct subcategories, buyers and technology layers. Investment decisions must therefore begin with the problem, the team and real buyer signals rather than a fixed market map.
Israel’s role in global cybersecurity
Israeli cybersecurity companies raised $4.1 billion in 2025, according to Start-Up Nation Central. Cybersecurity ranked behind business software in total funding, but its median deal size reached $20 million, twice the median for business software.
The sector’s depth extends beyond a single year. Start-Up Nation Central reported that Israeli cybersecurity funding in 2024 was equal to 40% of the total raised by the U.S. cybersecurity market. The number of Israeli cybersecurity companies grew from 272 in 2014 to 505 in 2024, 60% of them remained at an early stage, and seven of the world’s ten largest cybersecurity companies maintained R&D centres in Israel.
That concentration of founders, technical expertise, buyers and global acquirers gives Israel an unusually strong cybersecurity ecosystem. It also creates a competitive seed market in which access to capital is only one part of what founders need from an investor.
Where Glilot Capital invests
Glilot Capital invests from the first institutional round through early growth. Glilot Seed leads seed investments. Glilot+ invests in companies after Series A that have established early traction and are ready to scale. In September 2025, Glilot Capital announced $500 million across new Seed and Glilot+ funds. Reuters reported that approximately half of each fund was reserved for follow-on investments. [1][2][3]
Cybersecurity, AI and enterprise software increasingly overlap. AI systems create new identity, governance and data-security requirements. Security products must integrate into cloud and developer workflows. Enterprise infrastructure becomes more valuable when it can be deployed with trust. We therefore evaluate companies across these intersections instead of treating them as separate markets.
What gets our attention
We look for founders who understand a problem from the inside and can turn that insight into a category-defining company. Five signals consistently matter in our investment process:
- A founding team with first-hand technical, operational or industry knowledge of the problem.
- A problem large and urgent enough to support a category, with a buyer who has both responsibility and budget.
- Technical depth that remains valuable as models, platforms and competitors evolve.
- Evidence that enterprise buyers will change an existing process or priority to adopt the product.
- The ambition and adaptability to build a durable global company.
Our due diligence combines technical and market analysis with direct practitioner feedback. Glilot Capital’s network of CISOs and enterprise leaders helps us test whether a problem is urgent, how buying decisions are made, and what would need to be true for adoption. That input brings real market signals into the investment process and makes the evidence more concrete.
From investment to product market fit
The first institutional round starts the work. Early cybersecurity companies must refine the product, identify the right buyer, navigate enterprise procurement and convert interest into repeatable adoption. Many strong technologies stall because these pieces do not align at the same time.
Mach5 is Glilot Capital’s structured product-market fit program. It brings portfolio founders into direct conversations with senior operators and prospective customers from our advisory network. The goal is to generate real feedback on the problem, product, positioning and buying process early enough to act on it.
Our Value Creation team continues to work across go-to-market strategy, customer access, executive hiring and the next stages of growth. The model is designed to create a faster loop between assumptions and market signals, helping founders make decisions with more clarity.
A track record built in cybersecurity
Glilot has completed 27 exits since 2011, including all eight investments from its first fund. Selected publicly reported cybersecurity exits include:
| Company | Acquirer | Reported value | Date |
| Aorato | Microsoft | Approx. $200M | November 2014 [10] |
| IntSights | Rapid7 | $335M | July 2021 [11] |
| Cider Security | Palo Alto Networks | Not disclosed | December 2022 [12] |
| Ermetic | Tenable | $265M | September 2023 [13] |
| Entitle | BeyondTrust | $100M-$150M reported | April 2024 [14] |
| LayerX | Akamai | $205M | May 2026 [15] |
| CardinalOps | Cribl | Approx. $100M | July 2026 [16] |
These outcomes reflect several paths to value creation, from products acquired by major platforms to companies that helped define new security categories. The current portfolio continues that focus across identity, cloud, application security, data security and AI-native security.
Building for category leadership
Cybersecurity has an active global acquirer market. In 2025, Israeli technology M&A reached $74.3 billion across 150 transactions, led by Alphabet’s $32 billion acquisition of Wiz and Palo Alto Networks’ approximately $25 billion acquisition of CyberArk.
At the same time, founders need to build around customer value rather than a presumed exit path. Category leadership begins with a significant problem, a differentiated product and a repeatable reason for enterprises to adopt it. Pricing, hiring and go-to-market choices should support that ambition from the first year.
Working with a specialist cybersecurity investor
A specialist investor should contribute more than pattern recognition. It should understand which security problems have real urgency, how CISOs evaluate new products, where integrations create friction, and what evidence can move a company from an initial pilot to broad enterprise adoption.
Glilot brings that context into both investment decisions and the work that follows. The combination of sector focus, partner involvement, the CISO advisory network, Mach5 and the Value Creation team is built to turn strong ideas into real market traction, and real traction into category leadership.
Frequently asked questions
What stages does Glilot Capital invest in
Glilot invests from seed through early growth. Glilot Seed leads first institutional rounds, while Glilot+ invests after Series A & B in companies with early traction.
Which sectors does Glilot Capital focus on
Cybersecurity, AI and enterprise software, with particular interest in the infrastructure and control layers where these markets converge.
How does Glilot Capital support product market fit
Mach5 connects portfolio founders with CISOs, senior operators and prospective buyers for structured feedback on the problem, product and buying process. The Value Creation team supports go-to-market execution, customer access, hiring and growth.
How can founders contact Glilot Capital
Founders building ambitious companies in cybersecurity, AI or enterprise software can contact Glilot Capital through glilotcapital.com/contact-us. Bring the problem, the insight and the evidence. Let’s make it real.
Sources
[1] Reuters, Israel’s Glilot Capital raises $500 million for new AI and cybersecurity investments, 17 September 2025.
[2] Globes, Glilot Capital raises $500m for VC funds, 17 September 2025.
[3] Calcalist and CTech, Glilot Capital raises $500 million, topping $1 billion in assets, 17 September 2025.
[4] Gartner, Gartner Forecasts Worldwide End User Spending on Information Security to Total $213 Billion in 2025, 29 July 2025.
[5] Verizon, 2026 Data Breach Investigations Report.
[6] Start-Up Nation Central, Israeli Tech Annual Report 2025, 22 December 2025.
[7] Calcalist and CTech, Israeli startups raised $15.6 billion in 2025 as AI drove bigger, more concentrated bets, 22 December 2025.
[8] Start-Up Nation Central, Israel’s Cybersecurity Sector Surges, Secures 40% of U.S. Funding Total, 13 July 2025, updated 5 November 2025.
[9] Reuters, reporting on the Wiz and CyberArk acquisitions, 17 September 2025.
[10] TechCrunch, Microsoft Buys Israeli Hybrid Cloud Security Startup Aorato In $200M Deal, 13 November 2014.
[11] SecurityWeek, Rapid7 to Acquire Threat Intelligence Firm IntSights for $335 Million, 20 July 2021.
[12] Palo Alto Networks, Palo Alto Networks Completes Acquisition of Cider Security, 20 December 2022.
[13] Globes, Tenable confirms acquisition of Israeli cloud security company Ermetic, 7 September 2023.
[14] Globes, BeyondTrust buys Israeli access security company Entitle, April 2024.
[15] Calcalist and CTech, Akamai acquires Israeli AI browser security startup LayerX for $205 million in cash, 14 May 2026.
[16] Calcalist and CTech, Cribl acquires Israeli cyber startup CardinalOps for around $100 million, 14 July 2026.
[17] Glilot Capital, About and Portfolio pages, current firm data for assets under management and exits.
Knowledge-Hub
AI is driving an extraordinary rise in opportunities right now. Our deal flow has never been richer. In the last quarter alone, we closed 4 new investments. We are very picky about new investments, so for us, that is a very high number. Given that, I thought I would share more clarity on what we look for in a new investment.
Since we founded Glilot Capital in 2011, one thing has become very clear: the founders are in the center of everything we do, it doesn’t matter how much work we put into helping portfolio companies, we are not the ones to determine if a company will succeed or not, it’s all about the founders. This is why the identity of the founders is the most important part of any investment. We can talk about markets, technologies and returns, but in the end, every successful company we’ve backed was built by people who combined vision, discipline and persistence. Our job as investors is to be great partners to those people, focused, committed and hands‑on, from the first check to the last major decision.
We invest in cybersecurity and enterprise software from seed through growth, but our filter always starts with the entrepreneurs. When I look at a new cyber deal, I do not run through a mechanical checklist. I ask a few simple questions: who are these founders, why are they building this, and do we see a path to build something truly meaningful.
What We Look For
When evaluating a cybersecurity deal, the first thing we look for is a founding team that can build a huge business fast. The best founders we’ve backed lead from the front, stay close to the details, and are ready to do the hard work themselves, not just delegate. They usually bring a deep understanding of the problem space, often from intelligence units, security roles or building products at leading vendors, and they know how to translate that experience into a clear product and business.
We care a lot about persistence. Markets change, funding cycles come and go, and nothing moves in a straight line. Founders who stick it out through challenges, keep their heads, and continue to think creatively are the ones who ultimately build lasting companies. When we see that combination of character, experience and clarity, it matters more than any single feature in the product.
Of course, we also look at the market and technology. We focus on problems that represent large categories, not just nice features, and we pay attention to timing, whether a problem is becoming urgent for customers, not just interesting. On the technology side, we prefer depth over wrappers: architectures, detection methods or data advantages that are difficult to copy and can support real scale. These are the same fundamentals we apply across every cybersecurity deal we evaluate.
But even in these dimensions, we look at them through the lens of the founders. We ask whether this particular team is the right one to build in this specific market with this kind of technology, and whether they can attract the people and customers they will need along the way.
Why We Sometimes Say No
Saying no is as important as saying yes. Over the years, we’ve learned that when something feels fundamentally misaligned, it is better for both sides to pass early. Usually, that misalignment shows up around the founders and the story they are building.
Sometimes we meet teams targeting crowded spaces without a clear, sharp reason for why their company should lead the category. Sometimes the vision and the market size do not match, or the team is incomplete for the kind of company they want to build. For example, strong technology without a true business leader, or the opposite. And sometimes the difficulty is simply that the founder cannot explain the problem and solution in a way that is clear and convincing.
These are not theoretical criteria; they come from many years of working with entrepreneurs through good and bad cycles. When we decide to say no, we try to be direct and transparent, because honest feedback can still be useful for the founder’s next step, whether with us or with another investor.
What Happens When We Say Yes
When we decide to invest, we do not think in portfolio terms; we think in terms of this specific company and this specific partnership. We built Glilot to be a focused, value‑added fund, not a factory that jumps from one trend to another. That means deep involvement: helping with strategy, opening doors through our network of CISOs and executives, supporting hiring and go‑to‑market, and staying close through every major inflection point.
One of the things I am most proud of today is seeing founders come back to work with us on their second or third company. For us, that is the clearest sign that the way we choose deals, and the way we show up after we invest is working. In the end, our investment criteria in cyber deals can be summarized very simply: we look for great founders with real problems to solve, and we commit to being the kind of partner those founders deserve.
If you’re building in cybersecurity or enterprise software and think Glilot Capital could be the right seed partner, we’d love to hear from you, reach out to our team.
Knowledge-Hub
Since joining Glilot, the question I hear most often has nothing to do with AI itself – it has to do with time. LPs ask whether exits will happen sooner. GPs debate whether holding periods will compress. Founders wonder whether AI lets companies scale and get acquired years earlier than before.
It’s a fair question. Diligence that once took months can now take weeks, and capital moves faster than it used to. But I’d frame the real question differently: has the speed of investing changed our expectations more than it’s changed the underlying work of building great companies? Sitting between LPs who fund our conviction and GPs who act on it, my answer, after many of these conversations, is yes.
What AI Has Actually Changed
AI has genuinely upgraded venture’s operating model. Founders build with remarkable efficiency; small teams now do what once required entire engineering organizations. Investors synthesize market research in minutes and evaluate competitive landscapes at a scale that would have been impossible a few years ago. Fundraising has shifted too – companies often arrive at first meetings with more polished products and clearer data, though this varies by sector and stage. On the LP side, reporting is faster, and questions that once took a week of pulling data can often get answered in an afternoon.
That’s really good. But it carries a risk. In our enthusiasm for faster ways of working, we can start assuming the outcomes themselves should arrive faster too. AI has compressed many of the activities surrounding venture investing without rewriting the mechanics of building businesses that endure. Confusing operational speed with value creation is one of the more subtle risks facing our industry right now.
What It Hasn’t
Venture has always run on asymmetry – a handful of exceptional investments can define a fund, and finding them has always required technical insight, conviction, and patience. AI strengthens those capabilities, but the qualities that separate extraordinary companies from merely good ones are still resistant to automation.
Enduring companies are built through thousands of decisions about product, hiring, customers, pricing, and execution that compound quietly, long before the market notices. AI changes how quickly founders reach each decision. It doesn’t change how long it takes good decisions to add up to an obviously great company.
Cybersecurity makes this vivid. It’s one of the fastest-moving sectors in tech, yet the process by which great cybersecurity companies become trusted partners to enterprises hasn’t sped up nearly as much. Large organizations still evaluate vendors carefully, and mission-critical infrastructure still depends on confidence that takes time to earn.
The same pattern holds more broadly: many companies now reach product-market fit faster than a decade ago, but becoming genuinely indispensable to customers tends to stay a long game. The companies that define categories rarely do so because they moved fastest in year one – more often it’s because they kept making better decisions than competitors, year after year.
Friction vs. Judgment
This is where the conversation inside venture is starting to shift. We increasingly celebrate speed as if it were the objective itself: how quickly diligence finishes, how fast capital deploys, how soon companies scale. These are useful questions, but not the most important ones.
Venture has generally rewarded firms not for the fastest decisions, but for the right ones. Faster diligence is valuable because it can lead to a better decision, not because it finishes sooner. AI-assisted sourcing matters when it surfaces founders who’d otherwise be missed, not just more of them.
What This Means for Founders, GPs, and LPs
For founders, there’s never been a better time to build – but the same tools are available to everyone, so speed alone is becoming less of a differentiator. The edge is shifting to what AI can’t replicate: customer understanding, technical originality, resilience, and the ability to earn trust over time.
For GPs, the logic is similar internally. AI should free up time for the work that actually compounds returns: understanding founders, evaluating technical differentiation, and helping portfolio companies through inflection points. The best investors have never been distinguished by how fast they gather information, but by how well they interpret it.
For LPs, this argues for a different set of diligence questions. Rather than asking how much AI has sped up a manager’s process, it’s more useful to ask how AI has improved the quality of their decisions, and whether the firm has a repeatable way of identifying exceptional founders. Speed alone can reward the wrong behavior – it’s possible to move fast and still make worse decisions. In my own conversations with LPs, the ones I particularly value don’t ask only about our impressive speed; they also ask about our conviction, and whether we can defend it years later.
The Discipline of “Not Yet”
The best firms should use every tool that makes them genuinely faster: admin, research, internal process, portfolio support. But that efficiency shouldn’t reduce the rigor applied to investment decisions, or rush an exit before a business has reached its potential. Some of the most successful venture-backed companies got there not by pursuing the earliest possible liquidity, but by continuing to build and pivot long after they had the option to stop.
The View from the IR Desk
Working in investor relations puts me between institutional investors and venture managers – one side focused on distributions, the other on building extraordinary companies. Both are right. The job isn’t choosing one perspective over the other; it’s resisting the temptation to assume that because everything moves faster, value creation does too.
My conversations with LPs are rarely just about performance. More often they’re about conviction and repeatability, and about how technology is changing not just the companies we invest in, but how we invest. I’ve come to think that’s what IR is really for – translating the realities of company-building to investors, and bringing the priorities of institutional capital back into the venture ecosystem.
AI will keep reshaping venture capital in ways we can’t fully predict. Some of those changes will make us faster; the best will make us smarter. The firms that define the next decade will likely be the ones that understand the difference – using technology to remove friction, not judgment, while holding onto what has always produced exceptional outcomes: intellectual honesty, disciplined decision-making, and real partnership with LPs and founders alike.
Frequently Asked Questions
Is AI making venture capital exits happen faster?
Diligence that once took months can now take weeks, and capital moves faster than it used to. But AI has compressed many of the activities surrounding venture investing without rewriting the mechanics of building businesses that endure. Confusing operational speed with value creation is one of the more subtle risks facing the industry right now.
What has AI actually changed in venture capital?
AI has genuinely upgraded venture’s operating model. Founders build with remarkable efficiency; small teams now do what once required entire engineering organizations. Investors synthesize market research in minutes and evaluate competitive landscapes at a scale that would have been impossible a few years ago. On the LP side, reporting is faster, and questions that once took a week of pulling data can often get answered in an afternoon.
What has AI not changed in venture capital?
Trust isn’t generated by a language model. Culture isn’t automated, and judgment isn’t outsourced. Enduring companies are built through thousands of decisions about product, hiring, customers, pricing, and execution that compound quietly, long before the market notices. AI changes how quickly founders reach each decision. It doesn’t change how long it takes good decisions to add up to an obviously great company.
What should LPs ask GPs about AI?
Rather than asking how much AI has sped up a manager’s process, it’s more useful to ask how AI has improved the quality of their decisions, and whether the firm has a repeatable way of identifying exceptional founders. Speed alone can reward the wrong behavior – it’s possible to move fast and still make worse decisions.
Why does cybersecurity illustrate the gap between speed and progress?
Cybersecurity is one of the fastest-moving sectors in tech, yet the process by which great cybersecurity companies become trusted partners to enterprises hasn’t sped up nearly as much. Large organizations still evaluate vendors carefully, and mission-critical infrastructure still depends on confidence that takes time to earn.
Key Takeaways
- LPs ask whether exits will happen sooner, GPs debate whether holding periods will compress, and founders wonder whether AI lets companies get acquired years earlier.
- AI has genuinely upgraded venture’s operating model: leaner teams, faster research, faster LP reporting.
- It has compressed the activities surrounding venture investing without rewriting the mechanics of building businesses that endure.
- Trust, culture and judgment remain resistant to automation, and cybersecurity makes that especially vivid.
- AI should compress friction, not judgment – and the discipline to say “not yet” can be as valuable as the conviction to say “yes.”
Knowledge-Hub
For years, a proof of concept was exactly what its name suggested: an opportunity to prove the concept. If your technology solved the customer’s problem better than the alternatives, there was a good chance you would win the deal. The evaluation was largely technical, and technical superiority usually translated into commercial success.
Enterprise buying has changed.
Over the last few months, I’ve spoken with dozens of founders, CISOs and enterprise security leaders about why technically brilliant startups struggle to convert successful POCs into long-term customers. Some conversations focused on AI security, others on identity, browser security, endpoint protection or cloud infrastructure. The technologies were different, but the pattern was remarkably consistent.
That’s an important distinction. It changes how founders should think about enterprise sales, and how enterprise security teams should think about evaluating innovation.
Why Founders Think a POC Means the Deal Is Won
From the founder’s perspective, the buying journey feels logical:
- Problem identified
- Product built
- Capital raised
- Introductions secured
- Security architect aligned
- Platform engineering engaged
- IAM lead focused on integrations

Eventually, you hear the sentence every founder wants to hear.
“Let’s run a POC.”
At that point, it feels as though the hardest part is behind you.
The assumption is simple: if technology performs, the deal should naturally follow.
For a long time, that wasn’t an unreasonable assumption. Enterprise cybersecurity rewarded technical superiority. If your solution delivered stronger detection, lower operational overhead, richer telemetry or integrated more cleanly into an existing security stack, there was a reasonable expectation that the better product would win.
Increasingly, that’s only half the story.
What the CISO Is Actually Evaluating
While the founder leaves the meeting thinking about technical differentiation, the CISO walks into another meeting thinking: “Great guys, good technology, but does my organization have the capacity to deal with that?”
The Seven Questions Behind Every POC Decision
The conversation inside the enterprise rarely begins with the product itself. Instead, it begins with a different set of questions:
- Is this one of the most important problems we need to solve this year?
- Are we already halfway through implementing something similar?
- Will one of our strategic platform vendors add enough functionality over the next twelve months that introducing another vendor no longer makes sense?
- Do we have platform engineers available to deploy another sensor, connector or integration?
- Will our security architects have time to review another architecture, another data flow and another privileged access model?
- If this POC succeeds, do we actually have the operational capacity to deploy it across the organization?
- Do we have the processes, tooling and internal support to operate yet another solution?

Notice how few of those questions are really about technology.
They’re about everything surrounding the technology.
One security leader described a startup whose product genuinely impressed the evaluation team. The technology was stronger, the deployment model was cleaner and the roadmap was compelling. The POC still stalled.
Not because the technology failed, but because the organization had already committed itself to another strategic initiative. Engineers had spent months implementing it. Architects had signed off on it. Procurement was already well underway. Internal champions had invested political capital getting it approved. Even if the new product was objectively better, changing direction carried a cost the organization wasn’t prepared to absorb.
Another security leader described pausing an entirely different category of products. Again, technology wasn’t the issue. Engineering resources were already committed elsewhere, architecture teams were stretched, and there simply wasn’t a credible path from a successful POC to a successful production deployment.
You’re Not Competing Against Another Startup
Across these conversations, one theme kept emerging. Founders believed they were competing against another startup.
In reality, they were often competing against engineering bandwidth, implementation timelines, governance, procurement, projects already underway and, increasingly, the expectation that an incumbent platform would eventually deliver a “good enough” version of the capability.
What Founders Should Do Differently: Qualify Readiness, Not Just the Problem
The findings point to a different challenge than most sales methodologies acknowledge.
Founders don’t just need to qualify the technical problem. They need to qualify the organization’s readiness to change. And qualify it hard and early.
That means understanding what strategic initiatives are already underway, where engineering capacity is already being consumed, whether the customer is waiting for an incumbent platform to close the gap, and what would actually need to happen for a successful POC to become a production deployment.
These aren’t objections to overcome.
They’re realities to understand.
If your internal champion has already invested months backing another initiative, pretending it doesn’t exist won’t make it disappear. Help them build the business case for changing direction. Help them quantify the operational value. Help them explain why changing course creates more long-term value than continuing with yesterday’s decision.
Because if you’re asking an enterprise to replace an existing initiative, you’re not simply asking them to buy different software. You’re asking them to revisit architecture decisions, engineering effort, procurement work and months of organizational momentum.
The founders who consistently succeed aren’t just better at selling technology.
They’re better at helping organizations navigate change.
What CISOs Should Do Differently: Evaluate Without Overcommitting
The same conversations point to a challenge inside the enterprise.
Innovation is moving faster than enterprise evaluation processes were designed to handle. Security teams are now being asked to assess AI-native startups, new identity models, browser security, runtime protection and entirely new categories of technology, often using governance processes built for a market that moved much more slowly.
Maintaining high standards is essential, but every lengthy evaluation has an opportunity cost. Every six-month POC consumes engineering capacity, architecture reviews, operational attention and executive sponsorship. The longer those resources remain tied up, the harder it becomes to evaluate the next wave of innovation.
The challenge isn’t to lower the bar.
It’s to build an organization that can evaluate innovation rigorously without making every evaluation a major organizational commitment.
The Real Constraint: Change Capacity, Not Innovation
The conversations behind this all pointed to the same conclusion.
Enterprise buying hasn’t become harder because founders are building worse products or because CISOs have become more risk averse. It’s become harder because innovation has accelerated while an organization’s ability to absorb change hasn’t kept pace.
For founders, success now depends as much on understanding the organization as it does on understanding the technical problem. The best founders don’t just prove their product works. They help customers understand how to act on the outcome.
For CISOs, the challenge is different. As innovation continues to accelerate, the organizations that consistently identify the next generation of category-defining companies won’t necessarily have larger budgets or bigger security teams. They’ll be the organizations that become better at evaluating new technology without overwhelming the people responsible for deploying it.
That raises an interesting question.
If the ability to evaluate innovation is becoming a competitive advantage in itself, what should a modern enterprise evaluation process actually look like?
Frequently Asked Questions
Why do enterprise POCs fail in 2026?
Most POCs don’t fail because the technology isn’t good enough. They fail because the organization was never in a position to act on the outcome — engineering capacity is committed elsewhere, another strategic initiative is already underway, or there is no credible path from a successful POC to a successful production deployment.
Who is the real competition in an enterprise security deal?
Usually not another startup. Founders are more often competing against engineering bandwidth, implementation timelines, governance, procurement, projects already underway and the expectation that an incumbent platform will eventually deliver a “good enough” version of the capability.
What should founders qualify before running a POC?
What strategic initiatives are already underway, where engineering capacity is already being consumed, whether the customer is waiting for an incumbent platform to close the gap, and what would actually need to happen for a successful POC to become a production deployment.
What does a long evaluation process cost the enterprise?
Every six-month POC consumes engineering capacity, architecture reviews, operational attention and executive sponsorship. The longer those resources remain tied up, the harder it becomes to evaluate the next wave of innovation.
What should CISOs change about how they evaluate innovation?
The challenge isn’t to lower the bar. It’s to build an organization that can evaluate innovation rigorously without making every evaluation a major organizational commitment.
Key Takeaways
- Most enterprise POCs in 2026 fail on organizational readiness, not on technical merit.
- Founders believe they are competing against another startup. More often they are competing against engineering bandwidth, initiatives already underway, and the expectation that an incumbent platform will close the gap.
- Founders need to qualify the organization’s readiness to change as hard, and as early, as they qualify the technical problem.
- CISOs need evaluation processes that assess innovation rigorously without turning every POC into a major organizational commitment.












