
Work Here?
Claroty protects cyber-physical systems such as OT, IoT, BMS and IoMT by providing a centralized security platform that gives visibility, threat detection and risk management for assets in industries like healthcare, real estate, defense, utilities and public sector. Its solution combines continuous monitoring with risk assessment and proactive threat intelligence, and it includes Team82 for vulnerability and threat research to support rapid incident response. This focus on CPS across multiple sectors differentiates Claroty from rivals by addressing the security needs of systems where physical devices and digital networks intertwine. The goal is to help organizations achieve full visibility, protection and resilience for their CPS, thereby reducing cyber risk across critical assets.
Industries
Data & Analytics
Industrial & Manufacturing
Government & Public Sector
Cybersecurity
Company Size
501-1,000
Company Stage
Series F
Total Funding
$909.4M
Headquarters
New York City, New York
Founded
2015
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$909.4M
Above
Industry Average
Funded Over
8 Rounds
Claroty has established Claroty Public Sector LLC as an independent subsidiary to handle US Federal, State and local government work. The cyber-physical systems protection company has achieved FedRAMP High "In Process" designation for its Claroty xDome for Government platform, which is now listed on the FedRAMP Marketplace. The company has also secured an Authority to Operate from the Defense Logistics Agency. Jen Sovada will serve as General Manager of the new subsidiary, whilst Lynn Norris has been appointed Regional Vice President of Federal Sales. Norris brings over 40 years of experience, including military service and positions at Lockheed Martin, PTC, Illumio and Orca Security. The Arlington, Virginia-based subsidiary will focus on protecting critical infrastructure across government agencies.
Ascenty strengthens cybersecurity with Claroty. Project brought 50% evolution in maturity level in security and cyber risk management. July 29, 2026 - 16:25 Font size: -A+A Photo: Disclosure Ascenty, one of the largest data center players in Brazil, adopted xDome, a modular industrial cybersecurity platform in the Software as a Service (SaaS) model from Claroty, an Israeli industrial cybersecurity company. According to Rui Mella Junior, manager of information security and IT infrastructure at Ascenty, the project was born from the need to gain more visibility of critical assets, strengthen risk management, and improve monitoring of environments related to the company's data center operations. This includes power systems, cooling, access control, Closed Circuit Television, and Building Management Systems (BMS). The search was for a more mature approach to identifying, prioritizing, and mitigating operational and cyber risks. "In operational environments, it is not possible to treat security the same way as in traditional IT. Often we are talking about critical and legacy equipment that cannot simply be updated. We need to understand the risk, the criticality, and what compensatory controls can be applied without compromising operation," explains Mella Junior. The solution allowed Ascenty to create automated inventories of its assets, monitor traffic in real time, detect anomalous behavior, and obtain contextualized analyses of vulnerabilities and risk exposure. Furthermore, the tool began to support strategic decisions related to prioritizing vulnerability mitigation, network segmentation, and implementing compensatory controls. The first visibility gains were achieved about six weeks after the start of implementation, a period that included infrastructure preparation, installation of edges, port mirroring, and environment integration. Within six months, the company achieved expanded operational visibility of the monitored data centers, in addition to integration with security information and event management, security operations center, and internal vulnerability and risk management processes. "The great gain of the solution is bringing context. It is not enough to just identify a vulnerability. We need to understand the severity, the operational impact, the exploitability, and what the impact is for the business," continues Mella Junior. The project also contributed to the evolution of the company's corporate cybersecurity program, which covers different fronts, including IT, OT, identity management, and supply chain. As a result, Ascenty recorded an estimated evolution of approximately 50% in its level of maturity in security and cyber risk management. "Today, security is no longer just a support area and has become a strategic part of the business. Our customers expect availability, reliability, and operational resilience. Without maturity in security, certifications, and practical proof of controls, it is impossible to compete in this market," concludes Mella Junior. Founded in Brazil in 2010 by investment fund Great Hill, Ascenty is a joint venture between Digital Realty and Brookfield Infrastructure. Today, the company has 40 data centers, 26 in operation and 14 under construction, in Brazil, Chile, and Mexico. Of the operational ones, 21 are in Brazil, three in Chile, and two in Mexico. The units are interconnected by 4,000 km of proprietary fiber optic network. Among its clients are names such as Sky, CI&T, CPQD, DPaschoal, Kyndryl, GPA, Magalu, Nubank, Stone, Riachuelo, Vigor, Unimed, Claro, and Vivo. Founded in 2015 and headquartered in New York, Claroty is one of the leading cybersecurity companies for industrial, healthcare, and corporate environments in the market. Among its technology partners are AWS, Cisco, FortiNet, and ServiceNow. In Latin America, the company claims to have more than 1,000 protected plants, but does not disclose client names, which is common in this area. Reporter at Baguete Diário. Want to place your ad only in news with the most important keywords for your company? Ask me how.
Endpoint security firm Glow launches with $180M in funding at $1.2B valuation. Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. | July 22, 2026 (6:00 AM ET) AI-powered endpoint security startup Glow today announced it has emerged from stealth mode with $180 million in Series A funding at a $1.2 billion valuation. The investment round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with additional support from Index Ventures, Swish Ventures, Lux Capital, and Holly Ventures. Based in Tel Aviv, Glow was founded in 2025 by CEO Roi Tiger, former VP of engineering at Meta, CTO Omer Singer, former head of cybersecurity strategy at Snowflake, and VP of R&D Ophir Arie, former VP of R&D at Claroty. The company also employs Arnon Joseph as Chief Product Officer, who previously served as senior director of product at Meta, and Emily Heath as chief strategy officer, who previously was CISO at United Airlines and DocuSign, a board of directors member at Wiz, and a partner at Cyberstarts. Glow aims to reduce risk in modern environments, which are dominated by employees' use of AI and exposed to attacks that leverage Mythos-class capabilities and exploit weaknesses at machine speed. For that, it provides security teams with control over what runs on the endpoint through specialized AI agents that map the environment and analyze risks in real time, and automatically enforce policies. Glow leverages context and a reasoning engine to proactively allow or remove software, adapting to the environment to reduce the endpoint attack surface and allow employees to securely adopt and use AI. While operating in stealth mode, Glow has signed enterprise customers across industries such as financial services, healthcare, and retail. The startup will use the new investment to accelerate its go-to-market efforts in the US and to expand its research arm Glow Labs. "I sat in the CISO seat for a long time, and I can tell you the tools available to us were never built for what enterprises face today. Every enterprise wants to move faster with AI. The question isn't whether they'll adopt it - it's whether security can keep up. That's the challenge Glow is solving," Heath said. Ionut Arghire is an international correspondent for SecurityWeek.
How to evaluate the CMMC Phase 2 compliance pause. The Claroty Team The U.S. Department of Defense (DoD) slammed the brakes on the Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements on Monday, citing a need to lower barriers to entry for smaller innovative technology contractors, reduce bureaucracy - and compliance costs - and speed up the introduction of new capabilities to the defense industrial base (DIB). Phase 2, set to begin in November, would have required that accredited third-party auditors known as third-party assessment organizations (C3PAO) would determine whether DIB contractors were up to snuff on their compliance with NIST 800-171 and other related cybersecurity standards. While Phase 2 is on pause, this does not spell the end of CMMC, nor does it relieve contractors and subcontractors from ensuring the security of controlled unclassified information (CUI) and federal contract information (FCI). These third parties, key to the functioning and continuity of the DIB, must continue to self-attest the implementation and enforcement of basic security hygiene controls in their environment. DoD Chief Information Officer Kirsten A. Davies made this clear in her announcement of the pause, which also included the announcement of a 60-day review of CMMC, putting its future up in the air as the department aims to reduce or eliminate CMMC's high compliance costs and administrative burdens on small businesses looking to do business with the DoD. The evaluation also puts a pause on future CMMC milestones, Davies said. Davies, meanwhile, stressed that operational resilience through cybersecurity remains a priority for the DIB, but that it can be achieved with less red tape. In this blog, Claroty'll provide an overview of: * CMMC compliance mandates on the DIB supply chain * How NIST SP 800-171 impacts CPS protection * Why Claroty's compliance capabilities can help ongoing CMMC compliance What is CMMC compliance? CMMC was designed to protect FCI and CUI as it is handled and stored by the DIB supply chain. All DoD contractors and subcontractors are subject to CMMC compliance; CMMC formalizes compliance with standards such as NIST SP 800-171, which outlines controls meant to protect sensitive unclassified information from adversaries. CMMC certification is a mandate for businesses bidding on DoD contracts. There are three phases of maturity based on the sensitivity of data being handled. * Phase 1: Requires annual self assessments that ensure foundational cyber hygiene controls are implemented and enforced. * Phase 2: Mandates strict protocols that align with NIST standards; third-party assessments are typically required to ensure compliance * Phase 3: Government-led assessments are required at this level; here, companies handling extremely sensitive data must implement high levels of cybersecurity controls. Phases 2 and 3 have been suspended as of this week; Phase 2 requirements would have begun in November and Phase 3 in November 2027. How the Phase 2 suspension impacts CPS. In short, Phase 2 suspension means that third-party certification requirements in new DoD contracts are no longer required. CMMC, for the time being, is not going away, and organizations must self-attest to Phase 1 compliance to standards such as NIST 800-171, a framework designed to protect CUI confidentiality. NIST 800-171 also extends to FCI and CUI within operational technology (OT) and cyber-physical systems (CPS). A number of OT and CPS security practices are called out in the NIST standard, including limiting access to OT and CPS through segmentation. It spells out that critical process networks must be isolated from corporate networks. Other controls such as multifactor authentication are required for human-machine interfaces (HMIs) and for engineering workstations that upload and download process data and commands from programmable logic controllers (PLCs). Secure remote access to OT assets is also a mandate under NIST 800-171, through the use of purpose-built solutions or restriction of unauthenticated traffic via the firewall. Real-time threat detection and network monitoring are also in the standard as a means of identifying asset behavior anomalies, or the introduction of malicious commands. Compensating controls are also outlined for legacy technologies that remain core to OT in several critical industries such as manufacturing. A Federal News Network article published on Monday said that this is not the first challenge to the high costs of CMMC compliance. The phased-in implementation was introduced by the Biden administration, which conducted its own CMMC review that ultimately imposed the third-party assessment requirements on fewer contractors. The phases also would give contractors more time to prepare for the respective requirements. How Claroty can help. The Phase 2 suspension does not mean that CUI protection is a thing of the past, nor that NIST 800-171 compliance is optional for contractors and subcontractors who handle and store unclassified information. Phase 1 self-assessments remain intact and third parties must sign and affirm their implementation and enforcement of foundational controls. Claroty can help support your organization's CMMC compliance efforts. Claroty xDome as well as its on-premises Claroty Continuous Threat Detection (CTD), and Claroty Secure Access are a complete solution to meet the aforementioned NIST 800-171 domains with the following capabilities: * Access Controls: Claroty controls network access to regulate and monitor internal and third party remote activities across the network. This includes tiered user access, multi-factor authentication, strict password rules, virtual network segmentation, and network traffic monitoring, and secure-by-design remote network access. * Asset Management: Claroty has the industry's broadest protocol coverage to support its active and passive collection capabilities. Claroty provide a full inventory of all CPS assets and their accompanying risks and vulnerabilities. With these methods Claroty is capable of providing the most comprehensive CPS visibility and asset management controls. * Zero Trust Segmentation and Secure Access: Network segmentation and secure remote access are zero trust controls that distinguish legitimate communication across business processes and applications. Claroty jumpstarts network segmentation programs by automatically creating and simulating policies that can be enforced through existing infrastructure. * Auditing and Accountability: Claroty has introduced CPS Compliance Mapping into its xDome platform hoping to ease some of the complexity around compliance alignment and reporting. The new feature consumes asset telemetry collected by the platform to provide a current state of compliance related to CPS assets and enabled frameworks. NIST 800.53 has a direct "push button" report for its clients. xDome continuously applies logical rules across your environment. It utilizes live, native platform telemetry, such as device attributes, threat alerts, MDS2 documents, and vulnerabilities, to automatically calculate compliance statuses across all enabled frameworks. The pause on CMMC Phase 2 aims to cut down on red tape potentially hindering protection of critical data handled by contractors and subcontractors. While the pause has its merits, it's important to recall that cybersecurity is not on the backburner for organizations that must be compliant. Basic hygiene requirements are still in place, and organizations must still self-attest to their compliance.
Claroty, a cyber-physical systems protection company, has partnered with Frenos to help industrial organisations reduce downtime risk. The partnership integrates Claroty's asset visibility platform with Frenos's AI-native operational technology penetration testing system. The combined solution enables security teams to continuously validate their defensive posture, measure vulnerability exploitability, and prioritise remediation based on demonstrated risk. Frenos creates environment-specific digital twins from Claroty's asset intelligence, allowing its AI adversary agent to identify which vulnerabilities are reachable and exploitable. The partnership addresses the challenge of AI-enabled threats that have accelerated the threat lifecycle. By combining deep asset visibility with simulated penetration testing, organisations can shift from reactive defence to proactive risk reduction whilst minimising operational impact.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Industrial & Manufacturing
Government & Public Sector
Cybersecurity
Company Size
501-1,000
Company Stage
Series F
Total Funding
$909.4M
Headquarters
New York City, New York
Founded
2015
Find jobs on Simplify and start your career today