
Work Here?
Work Here?
Work Here?
Filigran builds an extended threat management (XTM) cybersecurity platform based on open-source principles, combining threat intelligence, breach-and-attack simulation, and risk management. Its core products include OpenCTI for consolidating and visualizing threat knowledge, OpenAEV for testing security controls against real-world attack scenarios, and OpenGRC for threat-informed risk management. The company operates a dual model with free open-source community editions and enterprise editions that add advanced features, managed hosting, and professional services such as support and training. Its goal is to help organizations anticipate and reduce cyber risk with a scalable, proactive security platform and agentic AI to automate threat analysis.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
201-500
Company Stage
Series C
Total Funding
$115.8M
Headquarters
Asnières-sur-Seine, France
Founded
2022
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$115.8M
Above
Industry Average
Funded Over
5 Rounds
Industry standards
Health Insurance
Remote Work Options
Flexible Work Hours
401(k) Retirement Plan
401(k) Company Match
Stock Options
Equity
Intelligence Approval Workflows: ensure data quality and streamline processes. Organizations collect intelligence from many different sources, but not all data arrives in a consistent format or through automated feeds. Manual submissions, file imports, and form-based contributions often require review before becoming part of a trusted intelligence repository. Previously, draft content in OpenCTI could typically move between two simple states: Open or Validated. While effective for basic use cases, organizations often need greater visibility into the review status of a draft and who's responsible for the next action. This is precisely the gap that Filigran is addressing with its new draft intelligence workflows. Tl;dr. * Configurable multi-step approval workflows: OpenCTI now lets organizations build custom review chains for draft intelligence with fine-grained RBAC, keeping quality control and governance transparent and easy to set up. * Workflows can be applied to any draft intelligence: Unstructured, human-sourced intelligence (analyst notes, tips, customer reports) via manual creation, file import, form intake, or the browser extension. * Granular RBAC at status and transition level: Control who can view, edit, manage, or advance a draft, including dynamic roles and cross-organization sharing, for full accountability at every stage. * Built for scale and governance: ISACs, MSSPs, large enterprises, government bodies, and teams handling external intelligence all benefit from consistent, auditable review before data is published. Organizations can now configure multi-step approval workflows with fine grained role-based user access (RBAC) to ensure quality control and data governance, while keeping the process transparent and easy to implement. Whether it's an ISAC collecting member-submitted observations, an MSSP fielding incident reports from customers, or internal teams contributing their own intelligence, draft workflows ensure ingestion processes are consistent and scalable. Watch the video for an introduction to draft approval workflows in OpenCTI: Manual vs automated intelligence. Automated and manual threat intelligence serve very different purposes, and organizations need both. Whereas automated feeds are built for scale, continuously ingesting structured, pre-vetted data like indicators and reports from trusted sources, manual intelligence is built for context, capturing what only a person can observe. For instance an analyst's investigation notes, a partner's tip-off, or a customer's description of an incident, arriving unstructured and unvetted. That difference is exactly why manual submissions can't simply flow into the same pipeline as automated feeds: they require a review step that automated sources have often already earned. Submitting manual intelligence in OpenCTI. In OpenCTI manual submissions are saved in 'Draft' mode, so they can first be reviewed before entering the knowledge base. There are a few ways manual intelligence can be submitted in OpenCTI: * Manual draft creation: Analysts can create a draft directly in OpenCTI and populate it from scratch, building out entities and relationships within the isolated workspace before review. * File import: When importing a file, users can select draft validation mode so the system automatically generates a draft and routes the extracted results into it for review, instead of writing directly to the main knowledge base. * Form intake: Contributors can submit structured input via form toggles on entity list pages (Reports, Incidents, Threat Actors, Indicators, and more), the 'Import using a Form' option in the standard import dialog, or a shared form link distributed to external or non-expert contributors (e.g., ISAC members, MSSP customers) who need to submit incidents or observations without direct platform access. * XTM browser extension: With the Filigran browser plugin, analysts can capture intelligence while browsing, flagging web pages, articles, or indicators encountered in the field, and send them straight into a draft for review, streamlining collection at the source without leaving the browser. Flexible workflows to meet any organization's needs. Every organization has its own intelligence processes. Some may require only a few straightforward review steps, while others need detailed approval chains involving analysts, managers, and specialized teams. The new Draft Workflows can easily be adapted to your organization's needs. Administrators can create custom statuses, connect them through transitions, and define how drafts move from one stage to the next. Workflows can be kept simple, or expanded to support complex operational processes. With intelligence approval workflows, organizations can: * Define custom review and approval stages * Control which users or roles can move a draft forward * Restrict editing rights at specific stages * Maintain visibility into the status of intelligence submissions * Ensure only properly reviewed intelligence enters the platform Applying role-based access control to workflows. For organizations that require additional governance, workflows can incorporate role-based controls that determine who can perform specific actions or approvals. This provides a structured way to manage collaboration while preserving accountability throughout the review process. RBAC within a workflow can be controlled at two different levels: * 1/ Status: This setting controls who can view, edit or manage the draft content. Access control can be applied when the user enters or exits the draft. * 2/ Transition: This setting controls which user(s) can transition to the next step: * Who can trigger the transition (who can move the draft to the next status, regardless of editing rights on the draft). * Who can view, edit or manage the draft content. * Provide other organizations access to the draft content in the context of cross organization work. Built-in validation checks help ensure workflows remain coherent before publication, providing administrators with guidance during configuration. Playbooks can also be configured to run automatically when the new intelligence has completed the approval process. Key use cases. Organizations that manage high volumes of intelligence submissions or operate in highly regulated environments can particularly benefit from intelligence approval workflows, including: * Information Sharing and Analysis Centers (ISACs): Information-sharing communities that need controlled submission and approval processes. With members submitting intelligence from varied sources and skill levels, a formal review step ensures only vetted, actionable data reaches the wider community. * Managed security service providers (MSSPs): Coordinating intelligence between teams and customers. Approval workflows give MSSPs a consistent way to validate findings before they're passed to clients, protecting both accuracy and client trust. * Large enterprises: With multiple teams and review layers. Draft workflows let intelligence move through the right chain of stakeholders, from analysts to leadership, without bottlenecking day-to-day operations. * Government and public-sector organizations: These environments often require auditable, multi-stage sign-off before intelligence can inform decisions, especially when countering foreign information manipulation and interference (FIMI) campaigns. * Teams collecting intelligence from external sources: External submissions can vary widely in reliability, so a review layer helps confirm credibility and context before intelligence is acted upon or shared further. Community versus Enterprise Edition. Basic workflow management is included in the Community Edition, including the ability to define multiple steps in the approval workflow and perform the review process without having to leave the platform. The following advanced features are included in the Enterprise Edition: * Enforce RBAC at each step: Define who can view, edit, or manage a draft at every stage. Authorized members can be specific users, groups, or organizations, or dynamic roles like "the draft creator" or "the draft's author organization," ensuring only the right people can act on it at each point. * Control who can advance each step: Independent of edit rights, you can specify exactly which user, group, or organization can push a draft to its next step. For example, you can specify that only managers can move the draft forward. * Enable cross-organization collaboration: When platform segregation applies, drafts can be shared with other organizations before specific edit rights are assigned. You can pre-define which organizations automatically receive the draft at a given step, or leave it open so the user chooses who to share with when that step is reached. Conclusion. At its core, Draft Approval Workflows help organizations improve the quality of their intelligence. By introducing structured review gates before intelligence is published, teams can validate submissions, verify context, and ensure data meets internal standards before it enters the platform. The result: higher-quality intelligence, stronger governance, and a more consistent process for collecting, reviewing, and approving data before it enters your platform. Would you like to see Draft Approval Workflows in action? Book a demo with one of its threat intelligence experts, or start a free 30-day trial of OpenCTI Enterprise Edition.
AI-Powered attacks become top concern for security professionals, new Filigran survey reveals. A survey of cybersecurity professionals at Infosecurity Europe finds organisations struggling to prioritise risks, validate threats and prepare for AI-driven attacks LONDON, UK - 17th June 2026 - AI-powered attacks have emerged as the biggest cybersecurity concern among security professionals, according to new research conducted by Filigran during Infosecurity Europe 2026. The survey of 168 cybersecurity professionals across various industry sectors found that 41% identified AI-powered attacks at scale as their biggest security concern, nearly double the number citing supply chain risk (21%) or unknown threats (21%). AI-driven threats and what security professionals are doing about them is also the top concern for nearly one in three boards (32%). The findings suggest that organisations are entering a new phase of threat-informed defence, where security teams are focused on being armed with the intelligence and context to figure out which threats pose genuine business risk in order to make informed and accurate decisions quickly... "Organisations have access to more security data than ever before, but turning that information into action remains difficult," said Julien Richard, CTO at Filigran. "The challenge is determining which exposures actually matter, which can be exploited in their environment, and whether their existing controls will stop them. That's where many organisations are still struggling." Security teams continue to lose time to operational inefficiencies. When asked what wastes the most time in their security team, the most common response was chasing false positives and low-priority alerts (26%). A further 25% cited validating whether risks are real, while 17% said manually stitching together data from multiple security tools and 13% pointed to delays waiting for other teams to act on findings. The results suggest that security teams are spending a significant proportion of their time validating findings, correlating information and coordinating remediation efforts. As organisations face growing volumes of threat intelligence, vulnerabilities and security alerts, the challenge lies not in collecting more data, but in reducing complexity and accelerating decision-making across the security workflow. Boardrooms increasingly focused on AI-driven risk. When questioned on what boards ask about most, respondents selected AI-driven threats and organisational preparedness as the top issue, cited by 32% of security professionals. This placed AI ahead of more established boardroom cyber priorities, including regulatory compliance such as NIS2 and DORA (19%), supply chain and third-party risk (16%), and cloud and infrastructure exposure (15%). The findings indicate that boards are increasingly looking for reassurance that their organisations understand how AI could change the threat landscape, whether existing controls are fit for purpose, and how prepared security teams are to respond. For security leaders, this creates a growing need to translate AI risk into clear business terms, moving beyond technical discussion to explain exposure, readiness and resilience. Organisations struggle to turn threat intelligence into action. The survey found that while threat intelligence plays an increasingly important role in security operations, many organisations still struggle to translate intelligence into clear actionable priorities. Only 19% of respondents said they completely trust threat intelligence to tell them what to fix first. More than half (52%) said it helps inform decisions but still requires significant human judgement, while 21% said the volume of information often creates more noise than clarity. This challenge is reflected in automation priorities. When asked what they would automate tomorrow, the most common response was turning threat intelligence into actionable priorities, selected by 27% of respondents. Security pros remain cautious about autonomous AI. While AI-powered attacks topped the list of concerns, respondents showed significant caution when it came to using AI for security decision-making. Only 8% said they would trust AI to make security decisions without human approval. By comparison: * 44% said a human should always remain in the loop * 38% would trust AI only for low-risk, routine decisions * 11% said they are still experimenting with AI-driven decision-making This suggests that, for now, the most credible role for AI in cybersecurity is as an analyst accelerator rather than an independent decision-maker: helping teams move faster while keeping accountability and final judgement with human experts. CTEM adoption remains in its early stages. The survey also examined adoption of Continuous Threat Exposure Management (CTEM), a growing framework for prioritising and validating cyber risk. Only 28% of respondents described their organisation as having a continuous, proactive exposure management programme in place. The remainder reported either operating reactive security programmes, running disconnected initiatives, or being unfamiliar with CTEM altogether. "The findings from this research tell a consistent story: security professionals know they need to be more proactive, but the tools and processes around them create constraints and siloes," said Neena Sharma, Head of Customer and Product Marketing at Filigran. "The volume of findings is high but with no clear way to determine what matters, what's exploitable, and whether their defenses are working as expected to do so. That's the promise of Continuous Threat Exposure Management. It's not a single product; it's a discipline that allows security teams to unify threat signals, take faster, better-informed remediation decisions and show that the actions they're taking are actually reducing risk." About the research. The research was conducted by Filigran at Infosecurity Europe 2026. A total of 168 cybersecurity professionals participated in the survey, representing organisations of varying sizes across technology, financial services, government, healthcare, energy, manufacturing, communications, legal and other sectors. About Filigran Filigran, a cybersecurity company, offers an open-source, AI-powered, threat-informed approach to Continuous Threat Exposure Management (CTEM). Its eXtended Threat Management (XTM) platform delivers threat intelligence, exposure validation, and cyber risk reduction. Learn more: Website - Blog - LinkedIn - X
Filigran, a European open-source threat management company, has launched XTM One, an AI-native platform that automates Continuous Threat Exposure Management workflows. The company announced a $120 million Series C round led by Ribbit Capital, valuing it at $1.45 billion. XTM One introduces an AI orchestration layer connecting Filigran's OpenCTI and OpenAEV products, automating workflows from threat intelligence to validated defensive action. The platform deploys AI agents to handle intelligence ingestion, threat summarisation, attack scenario generation and remediation guidance. Early benchmarks show organisations achieving up to 70% faster threat detection cycles and 80% less preparation time for security testing. The platform supports on-premises deployment and allows organisations to use their own large language models. XTM One is available now across three pricing tiers.
Filigran launches XTM One to automate threat exposure management with AI agents. French cybersecurity company Filigran SAS today launched XTM One, an artificial intelligence orchestration layer that automates continuous threat exposure management workflows across its platform. XTM One connects the company's OpenCTI extended threat intelligence platform and its OpenAEV exposure validation tool into a single continuous workflow. Security teams today move manually between systems, ingesting threat intelligence in one tool, building attack scenarios in another and tracking remediation in separate dashboards. XTM One automates those handoffs by coordinating AI agents across the lifecycle, taking raw intelligence through to validated defensive action. The XTM platform already includes AI-powered automation within OpenCTI and OpenAEV. Filigran said XTM One differs by adding a dedicated layer where agents coordinate across products rather than assisting within a single one. "The volume of CVEs, threat actors and attack campaigns has reached a scale no human team can process manually," said co-founder Julien Richard. "XTM One is not AI as a feature. It is AI as the operating system for threat management. Security teams deserve automation that works the way they work." The platform ships with prepackaged AI agents that handle some of the most time-intensive security tasks. These include intelligence ingestion and enrichment, threat summarization and reporting, attack scenario generation and validation and remediation guidance. The agents interact to form a continuous loop, letting teams identify priority threats, test their exploitability and validate defenses from one interface. Filigran said that early platform benchmarks show organizations using XTM achieving up to 70% faster threat detection and response cycles and up to 80% less preparation time for offensive security testing. Customers can build and deploy their own agents, workflows and integrations on top of XTM One. The platform's Bring Your Own LLM support means they can run Filigran's models or plug in their own and it can be deployed on-premises. Filigran is pitching that last point at regulated industries and government agencies that cannot send sensitive data off their own systems. "The biggest barrier to threat intelligence adoption has always been complexity," Jean-Philippe Salles, vice president of product management at Filigran, said in the announcement. The natural-language interface lets junior analysts become productive faster while removing repetitive work for experienced practitioners, he added. XTM One will be available in three tiers. Existing Enterprise Edition customers of OpenCTI or OpenAEV receive a built-in set of prepackaged agents, a usage quota and BYOLLM support at no additional cost, while organizations needing custom agent creation, workflow orchestration and premium model packages can license XTM One separately. A free, open-source Model Context Protocol server is also available for integrating Filigran products into other AI architectures regardless of tier. The product will be generally available this month. Founded in 2022, Filigran raised $58 million in a Series C round in October backed by Eurazeo SE, Insight Partners LP, Accel Partners LP and Deutsche Telekom AG's T.Capital. Image: siliconangle/ideogram. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
Filigran announces strategic expansion into Japan to accelerate proactive cyber defense. Leveraging Global CTEM Research to Address Critical Visibility and Prioritization Gaps in the Japanese Market TOKYO, JAPAN - April 9 2026 - Filigran (Headquarters: Paris, France;), an innovator in open-source and AI-driven cybersecurity, today announced the official launch of its Japanese organization and the commencement of its strategic expansion to accelerate business operations in the Japanese market. The expansion underscores the strategic importance of cybersecurity collaboration between France and Japan. Addressing unmet needs: the strategic significance of Filigran's entry into Japan. According to Filigran's latest global CTEM (Continuous Threat Exposure Management) report, Japanese organizations face unique challenges compared to their global counterparts. Filigran's entry into the Japan market aims to build resilience through a proactive, threat-informed defense within an intelligence-driven ecosystem. * From Limited Visibility to Proactive Awareness: 54% of Japanese respondents - significantly higher than the global average of 41% - report limited visibility across assets as their primary challenge. Filigran's OpenCTI addresses this by centralizing disparate threat intelligence data into a unified platform, giving security teams the structured visibility needed to continuously identify, prioritize, and respond to the threats most relevant to their environment. * Alleviating Prioritization Fatigue: 86% of Japanese organizations struggle to clarify which issues need immediate attention, with security teams spending 43% of their time investigating risks that prove to be low priority or non-exploitable. Filigran elevates Cyber Threat Intelligence (CTI) from a technical tool to a strategic function, empowering CISOs to make decisions faster and with confidence, including validation of their attack exposure. The Filigran advantage: A positive shift for Japan's cybersecurity. Filigran's presence will help Japanese organizations to shift from reactive, siloed tools to a unified, intelligence-driven, proactive security posture. * Transparency through Open Source: Unlike traditional "black-box" proprietary tools, Filigran's open-source-first philosophy ensures transparency and openness. This allows Japanese organizations to avoid vendor lock-in and build sustainable defense infrastructures. Filigran has an active community of over 6,500 users globally. * Automation via Agentic AI: With 84% of Japanese respondents stating that automation is essential to keep up with risk assessments, Filigran's Agentic AI connects every product in the XTM Suite and powers them with role-based cybersecurity expert AI Agents - from threat analysis to report generation - allowing limited human resources to focus on high-impact strategic initiatives. * The Evolution of GRC: OpenGRC* will transform static compliance into dynamic, threat-informed risk management, facilitating data-driven investment decisions at the board level. *Additional information regarding OpenGRC will be provided at a later date. Local Leadership and growth strategy. Filigran's operations in Japan will be led by industry veteran Maya Toda, who joins as Country Manager for Japan. * Leadership: Maya Toda brings a proven track record of scaling global cybersecurity initiatives in the Japanese market, having previously served as Sales Director at CrowdStrike and Country Manager at Sysdig. In her new role, she will oversee Filigran's Go-To-Market (GTM) strategy and execution nationwide. * Solutions & Engagement: Filigran will introduce its full XTM Platform, including OpenCTI and OpenAEV, to the Japanese market. To mark its launch, the company will host exclusive executive briefings in April 2026 to provide strategic insights to Japanese business leaders. * Local Ecosystem: Filigran plans to double its local headcount by the end of 2026, building a robust ecosystem of technology partners, system integrators, and government agencies to provide localized support. * Target Sectors: The initial focus will be on government agencies, critical infrastructure (power, telecommunications, transport), financial services, and high-tech manufacturing. "Japan is a top strategic priority for Filigran. Our research reveals that while Japanese organizations possess high technical capabilities, they are currently overwhelmed by the volume of data and manual processes," said Julien Richard, co-founder of Filigran. "By introducing our open-source platform, we are committed to helping Japan become a global leader in proactive cyber defense." About Filigran Filigran, a cybersecurity company founded in 2022, offers open-source, AI-powered solutions covering end-to-end threat intelligence management, attack simulation, and security posture validation. Its platforms are trusted by over 6,000 organizations worldwide: * OpenCTI: structures and operationalizes holistic threat intelligence across technical, operational, and strategic levels, enabling security teams to contextualize attacks and act proactively. * OpenAEV: helps identify critical vulnerabilities and strengthen organizational security posture through advanced attack simulations, resilience testing, and crisis management exercises. Media Contact Filigran PR Email: [email protected]
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
201-500
Company Stage
Series C
Total Funding
$115.8M
Headquarters
Asnières-sur-Seine, France
Founded
2022
Find jobs on Simplify and start your career today