

The fortress built by most large cybersecurity companies is crumbing. And the only people ready to man the frontlines are startups.
Why? They’re seeing a shift in the landscape that others have missed.
For decades, companies built fortifications around their operating systems—firewalls, antivirus software, endpoint detection tools—all designed to keep bad actors from breaching the OS perimeter. The assumption was simple: control the operating system, control security.
But today that assumption is broken. Today’s security battleground has migrated from the OS to the application layer.
It reflects a massive trend in software toward a constantly updating, fluid ecosystem. It’s been great for creativity, and we see more interesting ways of building software than ever before. But it also creates an entirely new security ecosystem that is largely uncharted or invisible.
This is an amazing area for startups to build meaningful solutions while incumbents struggle to catch up.
The space is dynamic and constantly reinventing itself.
Software has changed dramatically in the last few decades. In turn, cybersecurity has had to adapt even faster. With each new wave of software change, the “attack surface” for potential threats multiplies exponentially, and new companies are founded to take on the challenge.
This symbiotic relationship between software evolution and cybersecurity innovation demonstrates the pattern.


In the early 1980s, software was mostly on-premises and “single player.” The biggest threats were viruses that could copy themselves onto floppy disks, like the 1986 “Brain” virus. The attack surface was simple: the individual machine itself.
But as the internet proliferated in the late 80s and early 90s, hackers realized networks themselves were vulnerable. The 1988 “Morris Worm” was a huge wake-up call. Distributed via the internet and exploiting backdoors in mail systems, it spread from MIT to Berkeley within days, infecting thousands of computers. The pattern became clear: the more networked computers become, the greater the attack surface area. (It was such a big realization that the US created the first Computer Emergency Response Team after the attack.)
This spawned the first wave of major cybersecurity players like McAfee, Trend Micro and Symantec, which sold antivirus tools that could “bolt-on” security at the operating system level.
By the 1990s, email-borne viruses emerged, along with other viruses that could constantly change and evade detection. Companies responded by creating firewalls to protect networks. The pattern continued: more integration created more surface area for bad actors, spurring new protective technologies.
The internet boom of the 2000s accelerated this pattern. The biggest shift was toward cloud computing and app-level security. Cloud computing fundamentally changed how software is created and distributed. Teams developed applications quickly with DevOps and tweaked them on the fly. Data and workloads spread across virtual servers worldwide, exponentially increasing the attack surface.
Focusing on OS protection wasn’t enough anymore. We started baking security into the code itself (DevSecOps). This spawned companies like Palo Alto Networks (next-generation firewalls), CrowdStrike (cloud-managed endpoint security), Snyk (real-time code scanning), and Wiz.
In September 2025, the agentic application layer became the new security battleground. Applications are entire ecosystems of code packages, plugins, extensions, AI models, and updates. Enterprises have little visibility or control over what software enters their organization.
One of the first companies to recognize this shift was our company Koi Security (Acquired by Palo Alto Networks for $400M). Founder Amit Assaraf came to us with a key realization: legacy security systems haven’t recognized this change. They proved it by building a fake VSCode theme extension called “Darcula Official” that infected 300+ organizations worldwide, including a national court network, within a week.
We invested in them immediately because they fit the pattern we constantly see in cybersecurity: constant software evolution leads to inevitable new threats, creating practically endless opportunities for startups to act as software’s new guardians.
Today, in 2026, we’re seeing a great deal of coverage regarding the rise of agentic hacking – the idea that agents themselves can autonomously execute portions of the “attack chain.” Ultimately, this means that the speed and scale of attacks are likely to increase.
OpenAI puts it this way: “We have a limited window to strengthen cyber defenses.”
AI-powered defense is necessary to defend against AI-powered attacks. This is a new opportunity.
So what did this history lesson tell us? Think of it like an eternal arms race. Each time the “good guys” build software in a new way, the “bad guys” find new attack vectors. Then cybersecurity has to reinvent itself.


This cycle creates massive opportunities for startups with fresh perspectives. In just the last five years, dozens of new cybersecurity companies have grown into billion-dollar players.
But standing out isn’t easy. The key is developing a unique insight about a problem that only you can solve.
For the app-layer security problem, Koi demonstrated this thinking perfectly (we wrote about that here, if you’re interested). We expect many more companies are developing this POV today for AI-powered defense.
If you can spot these emerging vulnerabilities before the incumbents do, you’re halfway to product-market fit. The results speak for themselves: Koi hit $1M ARR faster than Wiz, Snyk, Vanta, Figma, and Loom.
The appetite for real solutions in this space is simply that great.
When the battleground shifts, incumbents’ advantages become liabilities. Their scale, established customer base, and existing architecture all anchor them to the old paradigm.
Startups, meanwhile, can:
In cybersecurity, being anchored to an old paradigm is toxic.
It’s great for startups, because incumbents in this space are more vulnerable than in other industries.
Of course, this raises important questions about defensibility. What happens once you become the incumbent? That is why we constantly argue that defensibility can’t be based on just one thing (unless you are a bio company with IP, for example).
Your “wedge” into the market – like spotting an early vulnerability – can provide a head start. But you need to build more sustainable forms of defensibility over time, like network effects, brand, and embedding.
We cover all of the above here.
Paradigm shifts create windows where startups can outrun incumbents—but only if you see the shift early and build specifically for the new reality.
The only constant in cybersecurity is change. And if you’re a startup, that only plays to your advantage.
As Founders ourselves, we respect your time. That’s why we built BriefLink, a new software tool that minimizes the upfront time of getting the VC meeting. Simply tell us about your company in 9 easy questions, and you’ll hear from us if it’s a fit.