Enterprise

Axio lands $23M to help companies quantify cyber risk

Comment

illustration of binary code brick wall
Image Credits: enot-poloskun / Getty Images

Axio, a platform for cybersecurity risk evaluation, today announced the closure of a $23 million Series B round led by Temasek’s ISTARI, with participation from investors Distributed Ventures, IA Capital Group and former BP CEO Bob Dudley. Axio CEO Scott Kannry tells TechCrunch that the proceeds — which bring New York–based Axio’s total capital raised to $30 million — will be put toward product and engineering team development and supporting go-to-market functions and expanding across “key geographies.”

Axio was co-founded in 2016 by Kannry and Dave White, who say they were inspired by the difficulty companies often have making decisions around cybersecurity investments. Kannry led the cyber insurance team for several years at Aon, while Dave came from Carnegie Mellon and spent the bulk of his career architecting cybersecurity frameworks, including a model — C2M2 (Cybersecurity Capability Maturity Model) — adopted by the U.S. Department of Energy.

“We saw how CEOs and boards of directors struggled with even approaching discussions around cyber risk. At that time, the common view was that cyber was fundamentally a technical problem, solved through investments in IT by the people who run IT,” Kannry said in an email interview with TechCrunch. “Now, given the wave of high-profile breaches affecting virtually every sector, industry and size of organization, boards and CEOs recognize that cybersecurity is fundamentally a business problem, which literally requires the discussion of it in financial terms.”

Axio aims to help businesses answer questions like whether they should invest in cyber controls (e.g., endpoint security) versus cyber insurance and how much of a budget a security team needs to reduce the likelihood of a loss, Kannry said. The product produces reports that quantify cyber risk in financial terms without resorting to scores and technical jargon, allowing departments to input information to generate metrics showing how a company is — or isn’t — improving over time.

Startups like BitSight offer similar products that assess the likelihood an organization will be breached. But Kannry says that Axio differentiates through a focus on modeling the impact of cyber scenarios. In other words, Axio worries less about probabilities when evaluating risk and more about their severest effects.

Axio recently introduced dynamic scenarios that let companies model “what if” scenarios to help them understand how to prioritize their security controls. It also inked strategic partnerships with several large cyber insurers, which Kannry says leverage Axio’s platform as part of their cyber insurance underwriting processes.

Axio
Image Credits: Axio

“Our platform allows security leaders to baseline their existing security controls, quantify their cyber exposure in dollars and stress-test their insurance coverage to understand if they are sufficiently covered. [It moves] beyond legacy and compliance-driven approaches to cybersecurity to more risk-based models that [look] at cybersecurity holistically and in the context of spending,” Kannry said. “Over the past two years, we’ve seen significant uptick in security leaders leveraging our platform to assess and quantify their cyber risk. Many of our core customers in energy and critical infrastructure, despite spending in some cases millions of dollars per year in cybersecurity controls, began to critically evaluate their cyber programs in the wake of high-profile attacks like SolarWinds and the ransomware-related shutdown of Colonial Pipeline. At the same time, cyber insurers and reinsurers have asked us to provide deeper, quantified risk visibility to support their underwriting teams.”

It’s certainly true that there’s pressure on businesses, particularly public ones, to better manage cyber risk. Earlier this year, the U.S. Securities and Exchange Commission proposed new reporting rules that pertain to cybersecurity postures and policies for all publicly traded companies. While they haven’t been formally adopted, the suggested requirements include periodic updates about previously revealed cybersecurity incidents and disclosures of management’s role in mitigating risk and implementing cybersecurity procedures.

Meanwhile, certain forms of cyberattack are becoming common. According to cybersecurity firm Sophos’s 2022 report, 66% of organizations were hit with ransomware attacks last year, up from just 37% in 2020.

Spurred by these pressures, Gartner predicts that 40% of all public boards will have dedicated cybersecurity committees by 2025.

“Despite significant increases in cybersecurity spending in recent years, cyber threats continue to pose significant challenges for companies across every sector, especially for critical infrastructure operators, who have historically been at the heart of our customer base,” Kannry added. “The rise of state-sponsored cyberattacks, geopolitical instability and ‘ransomware-as-a-service’ have all demonstrated the critical infrastructure sector’s susceptibility to attacks … The pandemic [also] changed the cyber risk landscape for our customers, especially in the critical infrastructure sector. Companies were going remote, enabling remote access for employees and systems and introducing a range of new technologies and collaboration tools that were introducing additional attack vectors.”

The cybersecurity industry, once the VC darling, has been hammered by layoffs recently as macroeconomic factors take their toll. But Kannry says Axio has had no trouble at all securing clients, with a customer base that now totals over 350 companies, including utilities, oil and gas providers and energy grid trade associations.

While he declined to reveal financials, Kannry said that he was “very happy” with the round size and deal terms, which he expects will allow Axio to double the size of its 35-person team by the end of the year. “We have an aggressive product roadmap into 2023,” he said. “[We’ll] be using funds partly to accelerate investments in our AI, machine learning and data science teams to add deeper automation capabilities.”

More TechCrunch

Bedrock Materials is developing a new type of sodium-ion battery, which promises to be dramatically cheaper than lithium-ion.

Forget EVs: Why Bedrock Materials is targeting gas-powered cars for its first sodium-ion batteries

Private equity giant Thoma Bravo has announced that its security information and event management (SIEM) company LogRhythm will be merging with Exabeam, a rival cybersecurity company backed by the likes…

Thoma Bravo’s LogRhythm merges with Exabeam in more cybersecurity consolidation

Consumer protection groups around the European Union have filed coordinated complaints against Temu, accusing the Chinese-owned ultra low-cost e-commerce platform of a raft of breaches related to the bloc’s Digital…

Temu accused of breaching EU’s DSA in bundle of consumer complaints

Here are quick hits of the biggest news from the keynote as they are announced.

Google I/O 2024: Here’s everything Google just announced

The AI industry moves faster than the rest of the technology sector, which means it outpaces the federal government by several orders of magnitude.

Senate study proposes ‘at least’ $32B yearly for AI programs

The FBI along with a coalition of international law enforcement agencies seized the notorious cybercrime forum BreachForums on Wednesday.  For years, BreachForums has been a popular English-language forum for hackers…

FBI seizes hacking forum BreachForums — again

The announcement signifies a significant shake-up in the streaming giant’s advertising approach.

Netflix to take on Google and Amazon by building its own ad server

It’s tough to say that a $100 billion business finds itself at a critical juncture, but that’s the case with Amazon Web Services, the cloud arm of Amazon, and the…

Matt Garman taking over as CEO with AWS at crossroads

Back in February, Google paused its AI-powered chatbot Gemini’s ability to generate images of people after users complained of historical inaccuracies. Told to depict “a Roman legion,” for example, Gemini would show…

Google still hasn’t fixed Gemini’s biased image generator

A feature Google demoed at its I/O confab yesterday, using its generative AI technology to scan voice calls in real time for conversational patterns associated with financial scams, has sent…

Google’s call-scanning AI could dial up censorship by default, privacy experts warn

Google’s going all in on AI — and it wants you to know it. During the company’s keynote at its I/O developer conference on Tuesday, Google mentioned “AI” more than…

The top AI announcements from Google I/O

Uber is taking a shuttle product it developed for commuters in India and Egypt and converting it for an American audience. The ride-hail and delivery giant announced Wednesday at its…

Uber has a new way to solve the concert traffic problem

Google is preparing to launch a new system to help address the problem of malware on Android. Its new live threat detection service leverages Google Play Protect’s on-device AI to…

Google takes aim at Android malware with an AI-powered live threat detection service

Users will be able to access the AR content by first searching for a location in Google Maps.

Google Maps is getting geospatial AR content later this year

The heat pump startup unveiled its first products and revealed details about performance, pricing and availability.

Quilt heat pump sports sleek design from veterans of Apple, Tesla and Nest

The space is available from the launcher and can be locked as a second layer of authentication.

Google’s new Private Space feature is like Incognito Mode for Android

Gemini, the company’s family of generative AI models, will enhance the smart TV operating system so it can generate descriptions for movies and TV shows.

Google TV to launch AI-generated movie descriptions

When triggered, the AI-powered feature will automatically lock the device down.

Android’s new Theft Detection Lock helps deter smartphone snatch and grabs

The company said it is increasing the on-device capability of its Google Play Protect system to detect fraudulent apps trying to breach sensitive permissions.

Google adds live threat detection and screen-sharing protection to Android

This latest release, one of many announcements from the Google I/O 2024 developer conference, focuses on improved battery life and other performance improvements, like more efficient workout tracking.

Wear OS 5 hits developer preview, offering better battery life

For years, Sammy Faycurry has been hearing from his registered dietitian (RD) mom and sister about how poorly many Americans eat and their struggles with delivering nutritional counseling. Although nearly…

Dietitian startup Fay has been booming from Ozempic patients and emerges from stealth with $25M from General Catalyst, Forerunner

Apple is bringing new accessibility features to iPads and iPhones, designed to cater to a diverse range of user needs.

Apple announces new accessibility features for iPhone and iPad users

TechCrunch Disrupt, our flagship startup event held annually in San Francisco, is back on October 28-30 — and you can expect a bustling crowd of thousands of startup enthusiasts. Exciting…

Startup Blueprint: TC Disrupt 2024 Builders Stage agenda sneak peek!

Mike Krieger, one of the co-founders of Instagram and, more recently, the co-founder of personalized news app Artifact (which TechCrunch corporate parent Yahoo recently acquired), is joining Anthropic as the…

Anthropic hires Instagram co-founder as head of product

Seven orgs so far have signed on to standardize the way data is collected and shared.

Venture orgs form alliance to standardize data collection

Alkira has raised $100M for its “network infrastructure as a service,” which lets users virtualize and orchestrate hybrid cloud assets, and manage them. 

Alkira connects with $100M for a solution that connects your clouds

Charging has long been the Achilles’ heel of electric vehicles. One startup thinks it has a better way for apartment dwelling EV drivers to charge overnight.

Orange Charger thinks a $750 outlet will solve EV charging for apartment dwellers

So did investors laugh them out of the room when they explained how they wanted to replace Quickbooks? Kind of.

Embedded accounting startup Layer secures $2.3M toward goal of replacing QuickBooks

While an increasing number of companies are investing in AI, many are struggling to get AI-powered projects into production — much less delivering meaningful ROI. The challenges are many. But…

Weka raises $140M as the AI boom bolsters data platforms

PayHOA, a previously bootstrapped Kentucky-based startup that offers software for self-managed homeowner associations (HOAs), is an example of how real-world problems can translate into opportunity. It just raised a $27.5…

Meet PayHOA, a profitable and once-bootstrapped SaaS startup that just landed a $27.5M Series A