Security Unicorns Snyk and Aqua Raise $435M Combined
Two cloud security unicorns, Snyk and Aqua Security, announced late-stage financing totaling $435 million today further signaling the growing importance of cloud-native and open source security.
Two cloud security unicorns, Snyk and Aqua Security, announced late-stage financing totaling $435 million today further signaling the growing importance of cloud-native and open source security.
Snyk closed a $300 million Series E funding round, which included both primary and secondary offerings and resulted in $175 million of new capital into the business. The company has now raised a total of $470 million with a valuation of $4.7 billion following the Series E, thus quadrupling its valuation since the beginning of 2020.
Snyk said it will use the new investment to advance its Cloud Native Application Security Platform, which provides security visibility and remediation across the application code, open source libraries, container infrastructure, and infrastructure as code.
The funding follows a banner year for the developer-focused security company, which ended 2020 with more than $350 million in new funding and 200% year-over-year revenue growth.
“The industry is realizing the need to transform security as part of digital transformation,” Snyk President and co-founder Guy Podjarny said in an interview with SDxCentral last month. “You need to re-think the scope of responsibility and developers have and the importance that developers embrace security. And so as the mass market starts accepting that, they seek out the philosophy and the pipeline that Snyk offers around more developer-focused, cloud native security.”
Meanwhile, cloud-native security company Aqua Security also joined the cybersecurity unicorn club with $135 million in Series E funding that pushed its valuation above $1 billion. Aqua’s funding since its founding in 2015 now totals $265 million.
Similar to Snyk, Aqua had a successful 2020. It doubled its paying customers, and now claims half a dozen with an annual recurring revenue of more than $1 million each. The company says it now protects “several” of the world’s largest Kubernetes and container production environments — some with more than 10,000 nodes in a single environment.
The adoption of Aqua’s open source tools more than doubled, with Trivy, Aqua’s open source vulnerability scanner, selected as the default scanner for the Harbor Registry, by GitLab, and for the CNCF’s Artifact Hub.
It also released a software-as-a-service cloud security product and an enterprise version of its platform that extends Aqua’s serverless and container-based workload protection tools to virtual machines (VMs).
And its threat research arm, Team Nautilus, published research on the rise in sophisticated, organized attacks that target the container supply chain, which served to further shape Aqua’s Dynamic Threat Analysis product, which is a container sandbox that identifies malware undetectable by static analysis tools.
“We’ve been growing at high double-digit rates and sometimes triple-digit rates, year on year, over the past five years,” Aqua VP of Strategy Rani Osnat said.
Aqua, which started as a container security company, has since expanded to support serverless and now VM environments, and it also provides cloud security posture management that it acquired from CloudSploit in 2019.
“We were growing with the market and with the need for security for this market,” Osnat added. “And what happened in the past 18 months or so, which is what drives this funding round and the size of it, is that the market has matured.”
This is happening on two tracks, he added. On one: more companies are moving to cloud-native technologies and practices such as continuous integration and continuous delivery (CI/CD) as well as Kubernetes and containers.
“But at the same time, companies — especially large enterprises that have been early adopters —are now moving into a phase where they’re deploying a lot more cloud-native workloads and they’re moving workloads on a much larger scale,” Osnat said. “And this is what drives the growth.”
In light of this growth, Aqua plans to use its new investment to add more capabilities to its platform and also expand geographically beyond North America and into Asia Pacific, Europe, the Middle East, Africa, and Latin America.
“One of the unfortunate but also pretty predictable outcomes of a market growing, is that bad actors, malicious actors, are also paying attention,” Osnat said. “When Kubernetes was in its infancy, and not many people were using it, it wasn’t a very attractive target to attack because it was not gonna deliver dividends.”
However, this has changed as more enterprises use Kubernetes, which makes it much more lucrative from a hacker’s point of view. Aqua’s Dynamic Threat Analysis product was its first step to detect malware hidden in container images and prevent supply chain attacks, Osnat added. “That is something that we need to extend further,” he said. “It could be going beyond containers and into additional capabilities around understanding different types of attacks. In general, the more we can do in the shift-left category, the better.”
By this, he’s referring to a DevSecOps approach, or preventing and fixing flaws earlier in the application development cycle.
“The other direction is expanding our capabilities around cloud posture security, and we already have a CSPM solution that’s great,” Osnat said, referring to the CloudSploit technology. “We’re going to expand the ability to tackle infrastructure as code, which is the shift left of cloud configuration,” he explained. “And lastly, we’re going to invest more around Kubernetes itself. Kubernetes itself is a lot more complicated than people think, and the attack vectors are very varied. We need to really address multiple vectors, and how you can, first of all, prevent things in advance, and then also detect and automatically respond when something happens.”