Enterprise

Vdoo raises $25M more to develop its AI-based security for IoT and connected devices

Comment

Image Credits: your_photo / Getty Images under a Royalty free license.

It’s estimated that there were some 50 billion connected devices globally in 2020, and while that really says a lot about how far we’ve come in tech, for many it also speaks to a big issue: security vulnerabilities, with the devices themselves, plus all the components and services running on them, all potential targets for anything from malicious hackers to not-so-intentional data leaks.

Today, Israeli startup Vdoo — which has been developing AI-based services to detect and fix those kinds of vulnerabilities in IoT devices — is announcing $25 million in funding, money that it plans to use to help it better address the wider issue as it applies to all connected objects.

With its initial focus on large industrial deployments, medical systems, communications infrastructure and automotive, Vdoo also is looking more deeply now at the wider network of devices that use communications chips, providing quick (as in minutes) assessments to identify and remediate or directly fix various issues: it cites zero-day vulnerabilities, CVEs, configuration and hardening issues, and standard incompliances among them.

The funding — an extension to the $32 million round that Vdoo announced in April 2019 — is coming from two investors, Israel’s Qumra Capital and Verizon Ventures (the investing arm of Verizon, which — by way of its acquisition of Aol many years ago — also owns TechCrunch).

VDOO secures $32M for a platform that uses AI to detect and fix vulnerabilities on IoT devices

Verizon’s interest in Vdoo is strategic and speaks to the opportunity in the market.

As CEO Netanel Davidi (who co-founded the company with Uri Alter and Asaf Karas) describes it, operators like Verizon are interested because of their role as a distributer and reseller of hardware as part of their wider services play, be it for broadband access, or a telematics service or something for the connected home or connected office.

“They sell connected devices to enterprises and home users that are not made by them, yet the carriers are responsible for the security,” he said, “so the solution is to bake that into devices” to make it work more seamlessly, he said.

Verizon is not the startup’s only strategic backer. Others in the first tranche of this round included another carrier, Japan’s NTT Docomo, MS&AD Ventures (the venture arm of the global cyber insurance firm) and Dell Technology Capital, the VC arm of Dell.

The company has now raised around $70 million, and while it’s not disclosing valuation, Davidi confirmed that it has more than doubled this year.

(In April 2019, PitchBook estimated that it was just under $100 million, which would make it now at over $200 million if that figure is accurate.)

Davidi said that the decision to raise this money as an extension to the previous round rather than a new round was strategic: it gave the company the chance to raise funding more quickly, and to take more time to prepare for a bigger funding round in the near future.

And the reason for raising quickly was to address what was a quickly moving target: One of the by-products of the COVID-19 pandemic has been a dramatic shift to people working from home, buying new devices to enable that and in general using their communications networks much more heavily than before.

Connected-device security typically focuses on monitoring activity on the hardware, how data is moving in and out of it. Vdoo’s approach has been to build a platform that monitors the behavior of the devices themselves, using AI to compare that behavior to identify when something is not working as it should. 

“For any kind of vulnerability, using deep binary analysis capabilities, we try to understand the broader idea, to figure out how a similar vulnerability can emerge,” is how Davidi described the process when we talked about the first part of this round back in 2019.

Vdoo generates specific “tailor-made on-device micro-agents” to continue the detection and repair process, which Davidi likens to a modern approach to some cancer care: preventive measures such as periodic monitoring checks, followed by a “tailored immunotherapy” based on prior analysis of DNA.

As Davidi described it to me this week, the platform “analyzes the device software, uncovers all of its security flaws, weaknesses, and vulnerabilities, prioritizes them by their criticality, and offers ways to remediate them.” Vdoo’s analysis considers the complete device context and treats several other factors like configuration, OS, drivers, etc. to accurately reflect a holistic view of the device’s security posture. Then, based on the results of the analysis, “it can automatically generate an on-device agent that provides ongoing monitoring and protection.”

Vdoo is a play on the Hebrew word that sounds like “vee-doo” and means “making sure”, and points to the basic idea of how it approaches the verification around its device monitoring. It also feels somewhat like the next step in endpoint security, which was the focus of Davidi and Alter’s previous startup, Cyvera, which was eventually acquired by Palo Alto Networks.

The focus on devices, in some ways, is a significantly more complex approach, given that it’s not just about the device, but the many components that go into them. As we have seen with Meltdown and Spectre, vulnerabilities might exist at the processor level.

And as Davidi pointed out to me this week, at times those issues aren’t even intentional but still mean data can leak out, and at worst that can be exploitable by bad actors.

“Backdoors are being built into many devices, and some are not even intentional,” he said. “It may be that the developer wanted to create a shortcut to make something else easier in the future. Some will see that as a back door, and some will not.”

The fractal-like nature of the issue is what Vdoo is digging into with its widening approach.

“Initially we wanted to serve the ecosystem of manufacturers, since they are the cause of the problem and the origin of the security issues,” he said. “We started there with Fortune 500 customers in areas like automotive and industrial and medical and telco and aviation. The idea was to make a platform that could serve and protect security stakeholders. But then we saw that this was a big unserved market.”

Indeed, Vdoo quotes figures from research firm MarketsandMarkets that forecast that the global device security market will grow to $36.6 billion by 2025 from $12.5 billion in 2020.

“The number of connected IoT devices is rapidly growing, creating greater opportunities for security breaches,” said Boaz Dinte, managing partner of Qumra Capital, in a statement. “Vdoo’s unique device-centric, deep technology automated approach has already brought immediate value to vendors in a very short period of time. We believe the market opportunity is huge, and with newly infused growth capital, Vdoo is well-positioned to become the leading global player for securing connected devices.”

“With the expansion of 5G networks and mobile edge compute, there’s a need for an end-to-end, device-centric security approach to IoT,” added Verizon Ventures MD Tammy Mahn in a statement. “As the venture arm of a leading telco, Verizon Ventures is proud to invest in Vdoo and its world-class team on their journey to solve this global need, while ushering in a new era of security by design in our increasingly connected world.”

More TechCrunch

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Well,…

Startups Weekly: Drama at Techstars. Drama in AI. Drama everywhere.

Last year’s investor dreams of a strong 2024 IPO pipeline have faded, if not fully disappeared, as we approach the halfway point of the year. 2024 delivered four venture-backed tech…

From Plaid to Figma, here are the startups that are likely — or definitely — not having IPOs this year

Federal safety regulators have discovered nine more incidents that raise questions about the safety of Waymo’s self-driving vehicles operating in Phoenix and San Francisco.  The National Highway Traffic Safety Administration…

Feds add nine more incidents to Waymo robotaxi investigation

Terra One’s pitch deck has a few wins, but also a few misses. Here’s how to fix that.

Pitch Deck Teardown: Terra One’s $7.5M Seed deck

Chinasa T. Okolo researches AI policy and governance in the Global South.

Women in AI: Chinasa T. Okolo researches AI’s impact on the Global South

TechCrunch Disrupt takes place on October 28–30 in San Francisco. While the event is a few months away, the deadline to secure your early-bird tickets and save up to $800…

Disrupt 2024 early-bird tickets fly away next Friday

Another week, and another round of crazy cash injections and valuations emerged from the AI realm. DeepL, an AI language translation startup, raised $300 million on a $2 billion valuation;…

Big tech companies are plowing money into AI startups, which could help them dodge antitrust concerns

If raised, this new fund, the firm’s third, would be its largest to date.

Harlem Capital is raising a $150 million fund

About half a million patients have been notified so far, but the number of affected individuals is likely far higher.

US pharma giant Cencora says Americans’ health information stolen in data breach

Attention, tech enthusiasts and startup supporters! The final countdown is here: Today is the last day to cast your vote for the TechCrunch Disrupt 2024 Audience Choice program. Voting closes…

Last day to vote for TC Disrupt 2024 Audience Choice program

Featured Article

Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Among other things, Whittaker is concerned about the concentration of power in the five main social media platforms.

9 hours ago
Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Lucid Motors is laying off about 400 employees, or roughly 6% of its workforce, as part of a restructuring ahead of the launch of its first electric SUV later this…

Lucid Motors slashes 400 jobs ahead of crucial SUV launch

Google is investing nearly $350 million in Flipkart, becoming the latest high-profile name to back the Walmart-owned Indian e-commerce startup. The Android-maker will also provide Flipkart with cloud offerings as…

Google invests $350 million in Indian e-commerce giant Flipkart

A Jio Financial unit plans to purchase customer premises equipment and telecom gear worth $4.32 billion from Reliance Retail.

Jio Financial unit to buy $4.32B of telecom gear from Reliance Retail

Foursquare, the location-focused outfit that in 2020 merged with Factual, another location-focused outfit, is joining the parade of companies to make cuts to one of its biggest cost centers –…

Foursquare just laid off 105 employees

“Running with scissors is a cardio exercise that can increase your heart rate and require concentration and focus,” says Google’s new AI search feature. “Some say it can also improve…

Using memes, social media users have become red teams for half-baked AI features

The European Space Agency selected two companies on Wednesday to advance designs of a cargo spacecraft that could establish the continent’s first sovereign access to space.  The two awardees, major…

ESA prepares for the post-ISS era, selects The Exploration Company, Thales Alenia to develop cargo spacecraft

Expressable is a platform that offers one-on-one virtual sessions with speech language pathologists.

Expressable brings speech therapy into the home

The French Secretary of State for the Digital Economy as of this year, Marina Ferrari, revealed this year’s laureates during VivaTech week in Paris. According to its promoters, this fifth…

The biggest French startups in 2024 according to the French government

Spotify is notifying customers who purchased its Car Thing product that the devices will stop working after December 9, 2024. The company discontinued the device back in July 2022, but…

Spotify to shut off Car Thing for good, leading users to demand refunds

Elon Musk’s X is preparing to make “likes” private on the social network, in a change that could potentially confuse users over the difference between something they’ve favorited and something…

X should bring back stars, not hide ‘likes’

The FCC has proposed a $6 million fine for the scammer who used voice-cloning tech to impersonate President Biden in a series of illegal robocalls during a New Hampshire primary…

$6M fine for robocaller who used AI to clone Biden’s voice

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Is it…

Tesla lobbies for Elon and Kia taps into the GenAI hype

Crowdaa is an app that allows non-developers to easily create and release apps on the mobile store. 

App developer Crowdaa raises €1.2M and plans a US expansion

Back in 2019, Canva, the wildly successful design tool, introduced what the company was calling an enterprise product, but in reality it was more geared toward teams than fulfilling true…

Canva launches a proper enterprise product — and they mean it this time

TechCrunch Disrupt 2024 isn’t just an event for innovation; it’s a platform where your voice matters. With the Disrupt 2024 Audience Choice Program, you have the power to shape the…

2 days left to vote for Disrupt Audience Choice

The United States Department of Justice and 30 state attorneys general filed a lawsuit against Live Nation Entertainment, the parent company of Ticketmaster, for alleged monopolistic practices. Live Nation and…

Ticketmaster antitrust lawsuit could give new hope to ticketing startups

The U.K. will shortly get its own rulebook for Big Tech, after peers in the House of Lords agreed Thursday afternoon to pass the Digital Markets, Competition and Consumer bill…

‘Pro-competition’ rules for Big Tech make it through UK’s pre-election wash-up

Spotify’s addition of its AI DJ feature, which introduces personalized song selections to users, was the company’s first step into an AI future. Now, Spotify is developing an alternative version…

Spotify experiments with an AI DJ that speaks Spanish

Call Arc can help answer immediate and small questions, according to the company. 

Arc Search’s new Call Arc feature lets you ask questions by ‘making a phone call’