Enterprise

Eclypsium lands $25M to secure the device supply chain

Comment

Lock in the middle of a network of applications illustrating cloud security
Image Credits: Traitov / Getty Images

As the enterprise device supply chain grows increasingly global and fragmented, it’s becoming more challenging for organizations to secure their hardware and software from suppliers. According to the European Union Agency for Cybersecurity, the EU agency that contributes to the bloc’s cyber policy, 66% of cyberattacks focused on a supplier’s code as of 2021.

Combating these attacks is no easy feat — but Yuriy Bulygin is making a go of it. He’s the founder of Eclypsium, a cloud platform that provides protection against device hardware, firmware and software exploits in corporate environments and public sector environments.

In a reflection of investor confidence — or perhaps simply the demand for supply chain security solutions — Eclypsium today closed a $25 million Series B round led by Ten Eleven Ventures with participation from Global Brain’s KDDI Open Innovation Fund and J Ventures, bringing the company’s war chest to $50 million. Bulygin says that the capital will be put toward expanding Eclypsium’s product capabilities, supporting current sales efforts and expanding headcount from around 80 people to over 100 by the end of the year.

“A few macro-level trends are driving demand for Eclypsium’s solution, and therefore made this the right time to raise funding to enable accelerated growth,” Bulygin told TechCrunch in an email interview. “The global supply chain is increasingly complex, which means that finished devices may have hardware and firmware components sourced from vendors around the world — all of whom add to the risk and complexity of securing a device. Moreover, the White House’s continued focus on … creating resiliency in America’s supply chains has brought a new focus to the risks inherent in a global economy, and has also driven increased demand from government agencies in Eclypsium’s solutions.”

Prior to launching Eclypsium, Bulygin spent nearly a decade at Intel, where he led security threat analysis and directed research on software and hardware vulnerabilities and exploits. Bulygin went on to become the senior director of advanced threat research at McAfee before founding CHIPSEC, an open source platform security assessment framework.

In founding Eclypsium, Bulygin sought to build a service that — in his own words — helps companies avoid “falling into the trap” of relying on equipment manufacturers and more traditional endpoint security management tools. While some startups, like Finite State, provide firmware-based supply chain security for connected devices, Bulygin argues that this level of protection is an afterthought where it concerns most cybersecurity vendors.

Eclypsium
Eclypsium’s cloud management dashboard Image Credits: Eclypsium

The assertion has to be taken with a grain of salt — Bulygin has a product to sell, obviously. But all else being equal, it’s true that supply chain attacks are on the rise globally. According to a 2022 survey by Venafi, a machine identity management firm, 82% of chief information officers believe that their organizations are vulnerable to cyberattacks targeting supply chains. The report suggests the shift to cloud-native development, along with the increased speed brought by DevOps processes, made the challenges associated with securing supply chains significantly more complex.

“The sheer number and complexity of modern devices requires highly specialized understanding and expertise in equipment built by various manufacturers — with all firmware and software shipped with these devices — and requires a unique set of capabilities to detect compromised devices and protect from further compromise,” Bulygin said. “Because firmware plays such a critical role in enabling and defending our technology supply chains, many traditional security vendors have opportunistically added ‘firmware-specific features’ to their products. However, firmware security is not an add-on.”

Eclypsium supports hardware, including PCs and Macs, servers, “enterprise-grade” networking equipment and Internet of Things devices. Using the platform, organizations can see and control fleets of devices as well as networking infrastructure without having to install client software. Firmware orchestration capabilities allow security teams to go one step further, tapping Eclypsium to discover, analyze and deploy firmware updates published by device manufacturers to spot “unexpected” — and potentially malicious — software modules embedded in the hardware.

“Organizations are increasingly turning to zero trust principles to defend their device fleets and operations. As such, the default position is to avoid trusting systems and users until explicitly verified … [yet] each device represents a complex system of computers with their own embedded code and operating systems — each built by many suppliers,” Bulygin said. “Organizations need to understand all layers of hardware and software code for device verification to be truly successful, from all of the code embedded into devices and supplied by manufacturers to operating systems and applications. Software and firmware code embedded into devices is the most fundamental and privileged software running on each device.”

Bulygin was coy when asked about the size of Eclypsium’s customer base, and he declined to reveal any specific revenue figures. But Bulygin did volunteer that a third of the company’s customers are Fortune 2000 firms and that Eclypsium has a number of U.S. federal government contracts.

The pandemic shifted many organizations to a remote-first, work-from-anywhere, bring-your-own-device environment, accelerating the need to adopt defensive models and principles which don’t rely on perimeter defenses. The most notable shift is the move to zero trust principles, both at the application and the device level. This growing recognition of the need to provide multi-layered defense for devices, including at the operating system, embedded software and firmware, and hardware layers, has increased interest in supply chain … solutions for devices, like those from Eclypsium.

As funding rounds like Eclypsium’s shows, the cybersecurity bubble might be starting to deflate — but it hasn’t burst. Data from Momentum Cyber, a financial advisory firm, showed that cybersecurity startups raised a record-shattering $29.5 billion in venture capital in 2021, more than doubling the $12 billion raised in 2020, while a record number were minted as unicorns. And according to Crunchbase, venture dollars invested into cyber startups hit almost $6 billion in Q1 2022.

More TechCrunch

Snowflake is the latest company in a string of high-profile security incidents and sizable data breaches caused by the lack of MFA.

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware

The buy will benefit ChromeOS, Google’s lightweight Linux-based operating system, by giving ChromeOS users greater access to Windows apps “without the hassle of complex installations or updates.”

Google acquires Cameyo to bring Windows apps to ChromeOS

Mistral is no doubt looking to grow revenue as it faces considerable — and growing — competition in the generative AI space.

Mistral launches new services and SDK to let customers fine-tune its models

The warning for the Ai Pin was issued “out of an abundance of caution,” according to Humane.

Humane urges customers to stop using charging case, citing battery fire concerns

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Welcome to Elon Musk’s X. The social network formerly known as Twitter where the rules are made up and the check marks don’t matter. Or do they? The Tesla and…

Elon Musk’s X: A complete timeline of what Twitter has become

TechCrunch has kept readers informed regarding Fearless Fund’s courtroom battle to provide business grants to Black women. Today, we are happy to announce that Fearless Fund CEO and co-founder Arian…

Fearless Fund’s Arian Simone coming to Disrupt 2024

Bridgy Fed is one of the efforts aimed at connecting the fediverse with the web, Bluesky and, perhaps later, other networks like Nostr.

Bluesky and Mastodon users can now talk to each other with Bridgy Fed

Zoox, Amazon’s self-driving unit, is bringing its autonomous vehicles to more cities.  The self-driving technology company announced Wednesday plans to begin testing in Austin and Miami this summer. The two…

Zoox to test self-driving cars in Austin and Miami 

Called Stable Audio Open, the generative model takes a text description and outputs a recording up to 47 seconds in length.

Stability AI releases a sound generator

It’s not just instant-delivery startups that are struggling. Oda, the Norway-based online supermarket delivery startup, has confirmed layoffs of 150 jobs as it drastically scales back its expansion ambitions to…

SoftBank-backed grocery startup Oda lays off 150, resets focus on Norway and Sweden

Newsletter platform Substack is introducing the ability for writers to send videos to their subscribers via Chat, its private community feature, the company announced on Wednesday. The rollout of video…

Substack brings video to its Chat feature

Hiya, folks, and welcome to TechCrunch’s inaugural AI newsletter. It’s truly a thrill to type those words — this one’s been long in the making, and we’re excited to finally…

This Week in AI: Ex-OpenAI staff call for safety and transparency

Ms. Rachel isn’t a household name, but if you spend a lot of time with toddlers, she might as well be a rockstar. She’s like Steve from Blues Clues for…

Cameo fumbles on Ms. Rachel fundraiser as fans receive credits instead of videos  

Cartwheel helps animators go from zero to basic movement, so creating a scene or character with elementary motions like taking a step, swatting a fly or sitting down is easier.

Cartwheel generates 3D animations from scratch to power up creators

The new tool, which is set to arrive in Wix’s app builder tool this week, guides users through a chatbot-like interface to understand the goals, intent and aesthetic of their…

Wix’s new tool taps AI to generate smartphone apps

ClickUp Knowledge Management combines a new wiki-like editor and with a new AI system that can also bring in data from Google Drive, Dropbox, Confluence, Figma and other sources.

ClickUp wants to take on Notion and Confluence with its new AI-based Knowledge Base

New York City, home to over 60,000 gig delivery workers, has been cracking down on cheap, uncertified e-bikes that have resulted in battery fires across the city.  Some e-bike providers…

Whizz wants to own the delivery e-bike subscription space, starting with NYC

This is the last major step before Starliner can be certified as an operational crew system, and the first Starliner mission is expected to launch in 2025. 

Boeing’s Starliner astronaut capsule is en route to the ISS 

TechCrunch Disrupt 2024 in San Francisco is the must-attend event for startup founders aiming to make their mark in the tech world. This year, founders have three exciting ways to…

Three ways founders can shine at TechCrunch Disrupt 2024

Google’s newest startup program, announced on Wednesday, aims to bring AI technology to the public sector. The newly launched “Google for Startups AI Academy: American Infrastructure” will offer participants hands-on…

Google’s new startup program focuses on bringing AI to public infrastructure

eBay’s newest AI feature allows sellers to replace image backgrounds with AI-generated backdrops. The tool is now available for iOS users in the U.S., U.K., and Germany. It’ll gradually roll…

eBay debuts AI-powered background tool to enhance product images

If you’re anything like me, you’ve tried every to-do list app and productivity system, only to find yourself giving up sooner rather than later because managing your productivity system becomes…

Hoop uses AI to automatically manage your to-do list

Asana is using its work graph to train LLMs with the goal of creating AI assistants that work alongside human employees in company workflows.

Asana introduces ‘AI teammates’ designed to work alongside human employees

Taloflow, an early stage startup changing the way companies evaluate and select software, has raised $1.3M in a seed round.

Taloflow puts AI to work on software vendor selection to reduce costs and save time

The startup is hoping its durable filters can make metals refining and battery recycling more efficient, too.

SiTration uses silicon wafers to reclaim critical minerals from mining waste

Spun out of Bosch, Dive wants to change how manufacturers use computer simulations by both using modern mathematical approaches and cloud computing.

Dive goes cloud-native for its computational fluid dynamics simulation service

The tension between incumbents and fintechs has existed for decades. But every once in a while, the two groups decide to put their competition aside and work together. In an…

When foes become friends: Capital One partners with fintech giants Stripe, Adyen to prevent fraud

After growing 500% year-over-year in the past year, Understory is now launching a product focused on the renewable energy sector.

Insurance provider Understory gets into renewable energy following $15M Series A