Israeli-founded EDR/XDR pioneer. Lior Div, Yonatan Striem-Amit, Yossi Naar (all Unit 8200), 2012. Boston HQ, Tel Aviv R&D. SoftBank $200M 2019 Series E. $700M+ raised total. 2022 IPO withdrawn; 2023 CEO transition to SoftBank's Eric Gan.
Cybereason is an Israeli-founded cybersecurity company operating in the endpoint detection and response category, the software layer that monitors laptops, servers, and other computing devices for indicators of compromise, contains active attacks, and produces the forensic record enterprise security teams use to understand what happened after an incident. The company was one of the earlier commercial entrants in what became the modern EDR (endpoint detection and response) and XDR (extended detection and response) categories, and remains one of the most recognizable Israeli-founded names in the endpoint-security stack.
Cybereason was founded in 2012 by Lior Div, Yonatan Striem-Amit, and Yossi Naar, three veterans of the Israel Defense Forces' Unit 8200 cyber intelligence group. The company is dual-anchored between Boston headquarters and Tel Aviv engineering, with meaningful operations in Tokyo through a long-standing SoftBank commercial partnership. Cybereason reached unicorn valuation in the 2019 funding cycle following a $200 million SoftBank-led Series E.
What does Cybereason's product actually do?
The endpoint-detection category exists because traditional antivirus software, the signature-matching pattern-recognition tools that dominated enterprise security through the 2000s, proved inadequate against attackers whose techniques were designed specifically to evade signatures. EDR software instead watches process behavior on every endpoint, correlates activity across the network, and applies detection logic that looks for patterns of activity rather than known-bad signatures.
Cybereason's product line covers this workflow end to end: agents deployed to every endpoint, a cloud-hosted detection engine that ingests the telemetry, an analyst-facing console that surfaces incidents in priority order, and response tools that let a security team contain a threat from that console. The company's XDR extension covers adjacent data sources beyond endpoints, primarily identity systems, cloud workloads, and email.
Who founded Cybereason?
Lior Div co-founded Cybereason and served as long-time CEO, following an earlier career in Israeli intelligence and commercial technology roles. Div became the public face of the company through most of its first decade and continues in a senior operating capacity.
Yonatan Striem-Amit co-founded the company and served as Chief Technology Officer through its first decade, leading the underlying detection-engine architecture and remaining a recurring reference figure in Israeli cybersecurity technical press.
Yossi Naar co-founded the company and served as Chief Visionary Officer, driving Cybereason's early research culture and the malicious-activity classification framework that became the marketable difference between Cybereason and generic EDR.
All three founders spent formative professional years in Unit 8200, and Cybereason is one of the most-cited examples of the 8200-to-commercial-cyber pipeline that produced most of the Israeli-founded cybersecurity cohort of the 2010s.
What technology sits behind Cybereason's detection engine?
Cybereason's technical positioning historically centered on what the company called the "MalOp" (malicious operation) framework, the argument that security teams should be presented with correlated incidents rather than raw alerts. That framing anticipated the direction the broader endpoint-detection category moved in the subsequent decade, as competitors converged on similar correlation-first models.
The detection stack combines behavioral analytics, machine-learning models trained on threat-intelligence corpora, and traditional signature-matching for known-bad artifacts. The response layer runs across a cross-platform agent that operates on Windows, Linux, macOS, and mobile.
Who does Cybereason compete against?
Cybereason competes primarily with CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, and Palo Alto Networks Cortex XDR. It competes indirectly with the broader consolidated security-platform vendors moving into endpoint from adjacent categories.
The market has been structurally difficult through the mid-2020s. CrowdStrike's public listing and rapid growth compressed the venture-scale independent EDR competitive field. SentinelOne's public listing added a second scaled independent. Microsoft's aggressive bundling of Defender for Endpoint into enterprise-agreement pricing changed the buyer economics in the mid-market. Cybereason's competitive position through this window has been described publicly by its own leadership as a rebuild-and-focus period.
How much funding has Cybereason raised?
Cybereason's funding history runs long. Early rounds through 2014 to 2016 established the company's initial commercial position. The 2019 SoftBank-led $200 million Series E produced the unicorn valuation. A subsequent $275 million Series F in July 2021 was led by Liberty Strategic Capital (former U.S. Treasury Secretary Steve Mnuchin's fund) and pushed the valuation reported publicly to approximately $2.7 billion. A $100 million infusion in June 2023 was led by SoftBank alongside Liberty Strategic Capital, at what press reporting characterized as a substantially reduced valuation reflective of the broader growth-software repricing.
Total capital raised sits above $700 million, one of the higher totals among Israeli-founded cybersecurity companies still operating privately.
Did Cybereason ever go public?
Cybereason filed confidentially for a U.S. IPO in 2022 during the initial window when large private cybersecurity companies were preparing public listings. The filing was withdrawn as public-market conditions deteriorated through the second half of that year. The company subsequently announced multiple workforce reductions across 2022 and 2023, restructuring the operating model to fit the changed capital and competitive environment.
Who runs Cybereason today?
Lior Div stepped down as CEO in October 2023. Eric Gan, previously a SoftBank operating executive with prior Cybereason board involvement, took the CEO role. Div remained associated with the company in a senior advisory capacity. The leadership transition was framed publicly as part of the broader operational reset.
Where does Cybereason sit in Israel's cybersecurity cohort?
Cybereason sits in the largest and most-cited Israeli category, the cyber cohort, alongside Palo Alto Networks (Israeli-founded, U.S.-headquartered), Check Point Software, CyberArk, Armis, SentinelOne, Wiz, Snyk, and the broader constellation of Unit 8200-derived commercial companies. Within that cohort, Cybereason holds one of the earlier positions on the endpoint-detection timeline and one of the more direct pipelines from military-intelligence origin to commercial security product.
The founder pattern is characteristic: three Unit 8200 veterans, a dual-anchored operating model across Israel and the U.S., and a strategic-investor relationship with a major non-U.S. capital source in SoftBank.
What is Cybereason's standing today?
Cybereason operates as a mid-scale independent player in a category that has consolidated aggressively around a small number of scaled public leaders. Its brand recognition, particularly in Japan through the long SoftBank commercial partnership, and its installed base across specific enterprise segments remain meaningful. The company's post-2022 restructuring produced a smaller, more focused operating footprint. Its long-term category position is contested, and its next commercial cycle will run against the same public-market EDR leaders that have shaped the category since 2020. The founding team's roots in Unit 8200 and the company's early influence on the endpoint-detection product architecture remain among the most-cited case studies in Israeli cybersecurity history regardless of how the current cycle resolves.


