top of page

Cyera Series G Funding Reaches $1 Billion as Goldman Sachs Backs Its AI Security Bet

2 days ago
11 min read

Cyera added $400 million to its Series G funding from Goldman Sachs, extending a remarkable capital run built around enterprise anxiety over AI security. The investment lifts the round to $1 billion and keeps Cyera valued above $12 billion, according to the company. It also brings the startup's fundraising since June 2025 to $1.94 billion.

The Cyera Series G funding is more than another large cybersecurity round. Goldman Sachs is backing a specific thesis: companies will need one control layer for sensitive data, human identities, software services, and autonomous AI agents.

That thesis now faces a demanding test. Cyera must convert corporate concern about agent access into durable revenue while integrating acquisitions and competing with established security platforms. Its valuation assumes that this emerging problem becomes a major software category, rather than another feature inside broader cloud and data products.

Cyera Series G Funding Turns a Large Round Into a $1 Billion Bet

Goldman Sachs has transformed Cyera's Series G from a major financing into a concentrated wager on the security architecture surrounding enterprise AI.

Cyera announced the extension on September 22, 2026. Growth Equity at Goldman Sachs Alternatives supplied the entire $400 million investment, according to the company's funding announcement.

The extension follows the $600 million Series G that Cyera announced on June 10. Evolution Equity Partners led that original financing, with participation from Temasek, Cyberstarts, and existing investors.

Cyera said the original round valued it at $12 billion. Reporting about the extension placed its post-money valuation near or above that level, indicating that Goldman Sachs did not reset the company's valuation downward.

That distinction matters because an extension usually adds capital under terms connected to an earlier financing. It does not necessarily represent a fresh, independent repricing of the entire company.

The combined Series G now totals $1 billion. Since June 2025, Cyera has raised four large amounts:

  • A $540 million Series E in June 2025

  • A $400 million Series F in January 2026

  • A $600 million Series G in June 2026

  • The new $400 million Series G extension

Those financings total $1.94 billion over roughly 15 months. That figure describes capital raised since June 2025, not Cyera's lifetime funding.

The pace is unusual even within the heavily financed cybersecurity market. Cyera's June 2025 round valued it at $6 billion, while the January 2026 financing lifted that figure to $9 billion. The June Series G then raised it again to $12 billion.

Cyera said the new money will support its AI security roadmap, federal-market expansion, and international growth across Europe, the Middle East, Africa, and Asia-Pacific. These plans require both product investment and a much larger sales operation.

The extension also introduces a prominent Wall Street investor after several venture and private-equity firms already backed the company. Goldman Sachs Alternatives said it sees AI security becoming a defining enterprise software category during the next decade.

Goldman Sachs is not buying public shares with transparent daily pricing. It is making a growth-equity investment whose eventual return depends on a private sale, an initial public offering, or another liquidity event.

Cyera co-founder and CEO Yotam Segev has said the company has an eventual public listing in its sights. However, the company has not announced an IPO timetable, and its recent fundraising reduces any immediate need to enter public markets.

That flexibility is strategically useful. It also delays the moment when investors can examine standardized disclosures covering revenue quality, customer concentration, expenses, retention, and cash flow.

Why AI Agents Are Creating a New Data Security Budget

Cyera is attracting capital because AI agents turn data access from a permissions problem into a continuous operational risk.

Traditional enterprise software usually acts within known workflows and assigned permissions. An AI agent can interpret a request, select tools, query databases, generate code, and initiate actions without human review at every step.

The resulting risk is not limited to malicious prompts. A properly authenticated agent can still expose confidential information if its permissions are broader than the user's business need.

It can also combine several harmless data sources into a sensitive result. That behavior makes access governance more complicated than scanning files for predefined labels.

Cyera describes its target as the gap between what agents are trusted to do and what they can actually reach. The company wants to connect data classification, identity, agent activity, and access decisions within one platform.

Data security posture management, commonly shortened to DSPM, is the foundation of that approach. DSPM products find sensitive information, classify it, map access, and identify risky exposure across cloud and software environments.

AI agents increase the urgency because they can traverse these environments faster than people. They can also reuse service accounts, application credentials, and nonhuman identities that security teams already struggle to inventory.

Cyera says Agent Guardian and Cyera Endpoint observe prompts, responses, tool calls, database queries, and related actions. That broader activity trail is meant to show what an agent attempted, not simply which model produced its response.

The company also offers controls spanning data at rest, data moving between systems, and information used during active workflows. Cyera says this coverage lets customers apply policy based on the meaning and sensitivity of data.

These descriptions remain company claims. Customers still need to test classification accuracy, connector coverage, policy enforcement, and the volume of false alerts within their own environments.

The funding nevertheless reflects a real procurement tension. Companies want productivity gains from copilots and agents, but security teams cannot approve broad access without understanding the underlying data.

Blocking every connection weakens the value of enterprise AI. Allowing unrestricted access creates unacceptable exposure. Cyera is selling a system intended to operate between those extremes.

The problem becomes particularly acute in financial services, healthcare, government, and other regulated industries. An agent's technically valid action can still violate policy, confidentiality requirements, or separation-of-duties rules.

Enterprise adoption therefore depends on context. Security software must identify the data, the requesting identity, the action, and the reason for access before it can make a useful decision.

This explains why Cyera frames data and identity as one problem. An inventory of sensitive files has limited value when a company cannot determine which human, service, or agent can retrieve them.

It also explains Goldman's interest beyond the current funding cycle. If agents become a standard interface for enterprise systems, governing their access could become recurring infrastructure rather than temporary compliance work.

The Core Bet Is Data Security Versus Platform Consolidation

Cyera must prove that AI creates a distinct data security platform, while larger vendors argue that enterprises need fewer security products.

Cyera competes within a crowded field that includes specialists such as BigID, Sentra, Securiti, and Varonis. It also encounters broader platforms from Microsoft, Palo Alto Networks, Rubrik, and cloud-security vendors.

These companies do not offer identical products. However, they increasingly compete for overlapping budgets covering discovery, classification, access governance, data loss prevention, privacy, and AI risk.

Cyera began with visibility into sensitive enterprise data. It has since expanded into data loss prevention, identity, remediation, privacy, and agent security.

That expansion reflects customer demand, but it is also defensive. A narrow discovery tool risks becoming a feature inside a larger security suite once the underlying market matures.

Broader vendors enter the contest with established customer relationships and integrated product bundles. Microsoft, for example, can connect data governance with identity, productivity software, and cloud infrastructure.

Specialists answer that argument by promising deeper classification and faster adaptation. They contend that general-purpose platforms cannot consistently understand data across competing clouds, applications, databases, and local systems.

Cyera's January 2026 Series F disclosure said its platform protected data and AI for 20% of Fortune 500 companies. The company also reported operations across 15 countries and more than 1,100 employees.

Those figures indicate substantial commercial reach, but Cyera reported them itself. It did not disclose customer spending, contract duration, retention, or the share of deployments using multiple products.

That missing detail matters because platform value depends on adoption depth. A customer running a limited data assessment creates different economics from one using the software for continuous enforcement.

Cyera's strategy increasingly relies on acquisitions to broaden that adoption. It acquired Trail Security to support its Omni DLP offering, moving beyond data discovery into controls governing information in motion.

The company later acquired Ryft and Genie Security. Those deals extended its technical scope and accelerated product development, but each acquisition also added integration demands.

Its most consequential move came with the reported $1 billion cash-and-stock acquisition of Oasis Security. Oasis focuses on nonhuman identities, including service accounts, automated tools, and AI agents.

The combination gives Cyera a clearer response to platform consolidation. It can argue that sensitive-data context and machine-identity controls must work together because neither side fully describes agent risk.

This argument has technical merit, but integration will determine its commercial value. A shared sales presentation does not guarantee unified policy, consistent data models, or manageable administration.

Customers will expect Cyera's acquired products to share identity context, classification results, alerts, and remediation workflows. Separate consoles or conflicting risk scores would weaken the platform claim.

Competitors also have room to respond. They can build comparable features, purchase specialists, or include AI governance within existing enterprise agreements.

Cyera therefore faces two races. It must develop agent-specific security faster than other specialists while proving that its broader platform is more useful than an incumbent's bundle.

The Cyera Series G funding supplies resources for both races. It does not settle which distribution model enterprises will ultimately prefer.

A $12 Billion Valuation Raises the Standard of Proof

Cyera's financing signals confidence, but its valuation requires exceptional growth, durable margins, and evidence that customers will expand their deployments.

Private valuations are negotiated prices from individual financing events. They are not continuous market verdicts, and they provide limited information about investor protections or share preferences.

Cyera's reported trajectory has been striking. Its valuation moved from $6 billion in June 2025 to $9 billion in January 2026, then to $12 billion five months later.

The company said its June 2025 Series E round followed a doubling of its customer base. It also reported 353% year-over-year growth among Fortune 500 customers.

In January, Cyera said revenue had grown more than 3.4 times. These are meaningful indicators, but they do not disclose the base values needed to assess scale and efficiency.

A June 2026 valuation analysis reported that Cyera had surpassed $150 million in annual recurring revenue. The report placed the proposed valuation near 80 times that amount.

The company disputed the financial figures as inaccurate. It did not provide replacement numbers, leaving outside observers unable to calculate a verified revenue multiple.

That disagreement should remain central to any assessment. Neither a private valuation nor a reported revenue estimate establishes the company's operating performance by itself.

Cyera is also investing heavily in sales, product development, international expansion, and acquisitions. Those expenditures can support future growth, but they can obscure how efficiently the core business wins and retains customers.

The $400 million extension offers more time to pursue that strategy without prioritizing near-term profitability. Goldman Sachs gains exposure to the upside if Cyera becomes a central control point for enterprise AI.

Cyera gains capital and an investor with extensive financial-services relationships. Those relationships could prove valuable in a sector that handles sensitive data and faces demanding regulatory obligations.

Still, a prominent investor cannot validate every product claim. Goldman evaluated an investment opportunity, while enterprise buyers must evaluate security outcomes within their own infrastructure.

Security teams should look beyond financing totals. Useful measures include deployment time, classification precision, unsupported data stores, remediation rates, and the number of alerts requiring manual review.

They should also examine how Cyera handles autonomous actions. Visibility after an agent retrieves data is different from preventing unauthorized access before the retrieval occurs.

The platform must distinguish legitimate automation from risky behavior without stopping normal operations. Excessive blocking reduces productivity, while permissive policies undermine the reason for purchasing the system.

Another uncertainty concerns market boundaries. Agent security overlaps with identity governance, cloud security, data loss prevention, model monitoring, and application security.

If enterprises consolidate those responsibilities under existing vendors, specialist growth could slow. If agent access demands a separate control layer, Cyera's addressable market expands significantly.

The valuation assumes something close to the second outcome. The next phase must provide operating evidence rather than another increase in private capital.

Goldman Sachs Is Backing a Strategic Position, Not Just Growth

The investor's arrival suggests financial institutions see data control as a prerequisite for scaling AI, not merely an insurance expense.

Goldman Sachs Alternatives joined the Series G after Cyera had already secured substantial funding from Accel, Blackstone, Coatue, Cyberstarts, Lightspeed, Sequoia, and other investors.

Irit Kahan, a managing director within Goldman's Growth Equity business, connected the investment to the rapid multiplication of AI agents. She argued that the difference between intended access and reachable data is becoming increasingly dangerous.

That statement points toward a specific enterprise concern. AI agents often depend on connectors, delegated credentials, and service identities that were created before autonomous software became common.

Financial institutions face an especially difficult version of this problem. Their AI systems can touch client records, trading information, internal research, communications, and regulated workflows.

These organizations already maintain extensive identity and data controls. Agentic systems can still expose gaps because a single task may cross several applications and permission domains.

Goldman's investment should not be read as a claim that Cyera has solved every issue. It indicates that the investor expects demand for solutions connecting data context with machine identity.

The investment also provides Cyera with strategic credibility in financial services. Large banks typically run lengthy evaluations involving security, compliance, legal, architecture, and procurement teams.

A relationship with Goldman does not bypass those reviews. However, it can improve Cyera's access to decision-makers and strengthen its position in competitive evaluations.

The company says the funding will also support its expansion into the U.S. federal market. Government deployments can require specialized certifications, procurement processes, hosting arrangements, and support commitments.

Federal expansion therefore consumes capital before it produces predictable revenue. International growth creates similar demands across data residency, regulation, localization, and channel partnerships.

Cyera's June 2026 Series G announcement described a platform covering DSPM, privacy, identity, data loss prevention, and agentic security. The company said it had released more than 100 capabilities during the preceding year.

Product velocity helps Cyera address a fast-changing threat model. It can also create operational complexity for customers and the company itself.

A platform with many capabilities needs consistent policy, reliable integrations, clear ownership, and usable reporting. Otherwise, customers receive more features without gaining better control.

Goldman's participation effectively backs Cyera's ability to manage that complexity. The investment thesis depends on the company becoming infrastructure, not simply selling another dashboard.

That transition changes Cyera's obligations. Infrastructure vendors must demonstrate availability, predictable behavior, governance, auditability, and support across years of changing customer systems.

They must also survive incidents without losing trust. A serious security failure involving the control layer itself would carry consequences beyond a typical software outage.

The opportunity is equally significant. A platform that consistently identifies sensitive data and governs agent access could become embedded in every AI deployment decision.

This is the promise behind the financing. Goldman Sachs is betting that AI security spending will follow AI adoption, and that Cyera will capture a central portion of that budget.

What the Next Three Signals Will Reveal

Customer expansion, product integration, and IPO readiness will show whether Cyera's funding reflects durable demand or private-market momentum.

The first signal is adoption beyond initial discovery projects. Cyera needs to show that customers move from identifying sensitive data to governing access and enforcing policy across daily workflows.

Deployment breadth will matter more than a headline customer count. Evidence that organizations use DSPM, identity, data loss prevention, and agent controls together would strengthen Cyera's platform argument.

The opposite result would weaken it. If customers purchase isolated modules or limited assessments, broader vendors could absorb those functions into existing security agreements.

The second signal is the integration of Oasis Security and Cyera's other acquisitions. Cyera must connect nonhuman identity management with data classification and agent activity in a coherent operating model.

Buyers should watch whether the combined platform can answer four questions within one workflow: what data exists, who can reach it, what an agent did, and how policy responded.

Independent customer evidence will be important. Demonstrations can show an ideal workflow, while production environments expose connector gaps, identity conflicts, false positives, and remediation delays.

Competitor responses belong within this signal. New identity-data integrations from Microsoft, Varonis, BigID, Sentra, or cloud-security platforms would pressure Cyera to defend its technical depth.

The third signal is financial discipline ahead of a possible public offering. Cyera has enough capital to delay an IPO, but each private round raises expectations for its eventual public-market performance.

Investors will want verified revenue, retention, gross margin, customer concentration, sales efficiency, and cash consumption. Enterprise buyers will also care because these measures affect long-term vendor stability.

A public filing would replace selective growth statistics with standardized disclosures. It would reveal whether Cyera's rapid expansion is producing durable economics or requiring sustained external funding.

The Cyera Series G funding already establishes the company as one of the best-capitalized private cybersecurity vendors. Its next milestone should not be another financing headline.

The more consequential test is whether enterprises treat agent access as a separate security layer with a dedicated budget. Cyera must then prove that its data-and-identity approach deserves that position.

For security leaders, the immediate action is practical: inventory which agents can access sensitive systems, then test whether existing controls explain and restrict those actions. If they cannot, Cyera's core thesis is already relevant, regardless of which vendor supplies the answer.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page