JupiterOne scores $70M sequence C funding, achieves unicorn standing


    The worldwide annual price of cyber crime is estimated to be $6 trillion per 12 months, or 1% of the World GDP. On the identical time, cloud computing is quickly changing into the dominant mannequin utilized by enterprise each to develop new providers and to host information and purposes. Cloud computing dominates, however safety is a problem.

    “As organizations proceed to extend their reliance on the cloud to centralize their operations, cloud safety options are seeing large development and adoption,” Erkang Zheng, founder and CEO of JupiterOne, stated. 

    “As well as, the necessity to strengthen defenses — upfront of macroeconomic adjustments that would lead to a rise in financially-motivated assaults — boosts the demand for cybersecurity software program, particularly for cloud environments that hackers could discover extra handy to penetrate.”

    That is how Zheng justifies JupiterOne’s estimated valuation of over $1 billion, which comes after in the present day’s announcement of a $70 million Collection C funding spherical. Though unicorns should not what they was once, with the cybersecurity area alone itemizing over 50 of them, this market gives loads of room.

    The cybersecurity market was valued at $217.87 billion in 2021, and it is projected to develop from $240.27 billion in 2022 to $345.38 billion by 2026, exhibiting a CAGR of 9.5% in the course of the years 2022-2026 in accordance with Markets and Markets. In accordance with Gartner, cloud safety is the quickest rising phase of the safety market, with spending leaping from $595 million within the US in 2020 to $841 million final 12 months.

    The necessity for JupiterOne is there. What’s price wanting into is how the corporate defines and approaches its mission.

    A graph-powered cybersecurity platform

    Zheng touts JupiterOne as “the primary cloud-native cyber asset assault floor administration (CAASM) platform constructed on a graph information mannequin… uniquely positioned to steer this rising market.”

    The corporate guarantees to assist purchasers simply determine, map, analyze, and safe cyber belongings. Its checklist of purchasers contains cloud-native enterprises like Cisco, Databricks, Certainly, and Robinhood. 

    Step one to doing that is to hook up with as many techniques as potential. As Zheng shared, JupiterOne presently helps over 180 integrations out of the field, with new integrations launched regularly. Some examples embody cloud suppliers, vulnerability scanners, authentication and authorization techniques, and identification administration instruments.

    JupiterOne connects to all of a corporation’s infrastructure, cloud, and safety tooling and techniques in an effort to accumulate, combine, and mannequin all of its cyber asset information. It is an agentless know-how that makes use of API-based connectivity to gather the information, Zheng stated.

    The corporate has been growing the breadth and depth of its integrations for over 4 years. At the moment, JupiterOne gives open supply options — corresponding to Starbase — that assist its integrations. It additionally permits third events to create their very own integrations by way of JupiterOne’s public integrations examples and SDK.

    JupiterOne’s CAASM platform is constructed on a graph information mannequin to reveal the intricate relationships between cyber belongings, one thing which Zheng recognized as key to the platform’s operation:

    “Visibility is of little worth with out context. The flexibility to attract connections between your cyber belongings enriches your safety investigations with a whole understanding of the incident, so you possibly can assess its impression, see what was affected, and optimize your incident response workflows.

    “It additionally permits you to acquire structural context about your enterprise to know not simply what is happening, however the place. We use a graph-based back-end system to mannequin the nodes (belongings) and connections (relationships) in an effort to present sensible and actionable insights and evaluation of your setting.”

    JupiterOne graphs piled together

    JupiterOne’s platform and capabilities are constructed on a graph information mannequin.


    Certainly, cybersecurity is among the domains during which graph shines. It comes down to 2 issues: the flexibleness of the information mannequin, which allows integration of information from disparate sources, and the effectivity of the queries, which allows exploration of complicated paths and relationships.

    Starbase, JupiterOne’s open supply framework aiming to “democratize graph-based safety evaluation,” collects belongings and relationships from providers and techniques together with cloud infrastructure, SaaS purposes, safety controls, and extra right into a graph view backed by Neo4j.

    JupiterOne’s core product contains a custom-built question language (J1QL), prebuilt queries, and a pure language-based search to reply any query. 

    Elaborating on how cyber asset information is monitored and up to date to serve totally different use instances and necessities, Zheng stated, “JupiterOne helps over 500 ‘out of the field’ English-language questions that customers can ask of their environments with a single click on. If these questions do not clear up your considerations, you should utilize our visible question builder or our direct search question language to ask any query of your selection.”

    Zheng added, “Ask any query and get any reply. Questions may be changed into constantly monitored queries which might be linked to alerts, and all information is out there by way of customizable dashboards”.

    One platform, many use instances, robust development

    Moreover CAASM, JupiterOne addresses cloud safety posture administration; safety operations and engineering; and governance and compliance. However how can one thing like GDPR compliance for information generated by way of software X and saved in cloud supplier Y be assessed and monitored?

    As Zheng defined, the entire cyber asset information from software X and cloud supplier Y are normalized and saved throughout the JupiterOne graph system. This permits customers to ask questions of that information in extraordinarily complicated methods.

    “Compliance comes from figuring out what inquiries to ask after which asking them with the suitable frequency to seek out dangers. As soon as you discover the dangers, you repair them, thus rising your safety alongside your compliance degree,” Zheng stated.

    What in regards to the monitoring vulnerabilities state of affairs? For instance, how can one thing just like the potential impression of Log4j to a shopper’s purposes be assessed and corrective motion be advised?

    First, JupiterOne connects to software scanning options to find out the place a code vulnerability, corresponding to Log4j, would exist in a consumer’s setting. From there, customers can ask complicated questions like: Who wrote the code that comprises the problem? What’s their safety coaching degree? Is that this code operating in manufacturing? Whether it is operating in manufacturing, who’s the applying proprietor?

    “JupiterOne connects vulnerabilities to the context surrounding them in your setting that can assist you unravel points and remediate them sooner than ever earlier than,” Zheng stated.

    JupiterOne’s $70 million Collection C funding spherical brings the corporate’s whole raised to greater than $119 million and its estimated valuation to over $1 billion. The spherical was led by Tribe Capital with participation from new buyers, together with Intel Capital and Alpha Sq. Group, and present buyers, together with Sapphire, Bain Capital Ventures, Cisco Investments, and Splunk Ventures.

    Commenting on the corporate’s valuation, Zheng stated that monetary metrics and development 12 months over 12 months have been robust. He added that the subscription mannequin promotes buyer retention and renewal, which helps challenge continued development for years to return.

    The funds will likely be used to develop go-to-market capabilities, broaden engineering investments, and enhance product growth. That is all to deal with market wants throughout assault floor administration, together with unified asset stock, vulnerability administration, and safety posture automation. 

    Moreover, the funds will likely be used to increase the attain of the corporate’s in depth partnership and integration groups, additional increasing the capabilities of the CAASM platform. JupiterOne will look to scale the corporate’s direct and channel gross sales efforts for enterprise clients whereas increasing self-service capability for small and midsize companies. 


    Please enter your comment!
    Please enter your name here