Cybellum

acquired also known as Cybellum Ltd., Cybellum Technologies LTD

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2016
Funding $15M
Last updated 2026-08-18

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Cybellum sells carmakers, medical device firms and industrial manufacturers a platform for securing the products they ship. Its engine reads a product's compiled firmware without the source code, builds the software inventory and triages vulnerabilities against it. LG Electronics took a controlling stake in 2021, in a deal SecurityWeek put at roughly $240 million in total, and left the brand standing. LG was also a customer, on Bronfman's 2021 account. Other named manufacturers reach past the parent, from Jaguar Land Rover to ASUS. Its own public output has gone quiet. The newest blog post is dated May 2025 and the newest press item September 2024, so a buyer has no recent signal there that the platform is advancing.

Sourced Details

Description Cybellum sells a product security platform and managed services that device manufacturers in automotive, medical and industrial markets use to build software inventories, triage vulnerabilities and assemble regulatory evidence for the connected products they ship. [f1]
Acquisition LG Electronics, announced 2021-09-23 [f2]
Founded 2016 [f2]
HQ Tel Aviv, Israel [f3]
Funding $15M total [f4]

Products

Product What it does
Product Security Platform Builds and validates software inventories for a manufacturer's own products, triages the vulnerabilities against them, and generates regulatory evidence.
Product Security Professional Services Managed SBOM analysis, vulnerability management and product incident response delivered by Cybellum staff, plus deployment and integration work.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Cybellum Product Security Platform inventories the software inside a manufacturer's own devices, triages the vulnerabilities and coding weaknesses found in that software, and supports post-production investigations when a new threat lands. These capabilities are mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 4/5 The buyer is the product security team inside a manufacturer, and the pain is written into law rather than into marketing. UN Regulation No 155 directs approval authorities to refuse cybersecurity type approval to a vehicle maker that has not put management arrangements in place, and the FDA asks for cybersecurity documentation in medical device premarket submissions. THE ELEC quoted an LG spokesperson tying the Cybellum purchase to that vehicle requirement. The reviewed record documents the mandate rather than the size of the loss it prevents. [s30, s29, s21, s2]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Cybellum's pages describe the mechanism concretely: firmware binaries analyzed without source code into a replica carrying the software inventory, hardware bill of materials, licences, cryptography and operating system configuration, with extraction of embedded frameworks such as AUTOSAR. The independent artifacts of that craft are thin. NVD carries a command injection flaw in a Linksys router and a hard-coded key in Cybellum's own distribution, both recorded under Cybellum Technologies LTD, and the reviewed record carries no independent technical evaluation of the platform. [s4, s8, s27, s26, s14]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is regulatory and dated. UN Regulation No 155 gates vehicle type approval on cybersecurity arrangements, Cybellum's own newsroom puts the July 2024 deadline across 54 countries, and the FDA guidance covers the medical side. What the reviewed record does not carry is a buyer-side demand signal from the past year: the newest customer story in the reviewed record is dated February 2025 and no independent source dates the demand later than that. [s30, s32, s29, s4, s13]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Slava Bronfman and Michael Engstler founded the company in 2016 and still hold the chief executive and chief technology roles on the about page. Infosecurity Magazine and Calcalist both report that the two served in Unit 81 of Israeli military intelligence, and independent outlets covered the sale of the company they built. That sale is the exit on the record, and the reviewed sources describe no build either founder completed before it. [s2, s22, s20, s18, s19, s21]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Cybellum names manufacturers across all three of its industries, including Jaguar Land Rover, Audi, Nissan, Danaher, Siemens and Supermicro, and publishes customer stories on Hyundai, McLaren and ASUS. TechCrunch named the Jaguar Land Rover and Nissan work in 2021 and S&P Global covered an Indian distribution partnership in 2022. References dated after 2022 are published by Cybellum itself, and the record carries one revenue signal, Bronfman telling Calcalist in 2021 that the company was selling in the millions. [s32, s5, s4, s6, s12, s18, s20, s25]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 4/5 Calcalist put the total raise at $15 million and TechCrunch at just over $14 million, against the $140 million LG paid for a controlling stake. SecurityWeek put the whole transaction at roughly $240 million and TechCrunch called it a good return for investors. A third party reported the stake price, so the outcome on capital is confirmed rather than asserted. Disclosure holds it below the exceptional rung: no revenue, margin or growth figure appears beyond Bronfman's 2021 remark that the company was selling in the millions, and the larger multiple rests on the softer total. [s20, s19, s18, s24]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Independent outlets place Cybellum without help, but they place it narrowly. SecurityWeek, THE ELEC and S&P Global all file it as automotive cybersecurity, while the company sells a product security platform spanning automotive, medical and industrial manufacturing. Its own pages treat the broader label as one it has to teach, calling product security a relatively new and evolving field, and no analyst firm in the reviewed record positions it against named rivals in a market landscape. [s19, s21, s25, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Reading compiled firmware into a component-level replica is real engineering, and the platform sits inside the customer's product lifecycle and continuous integration tooling, which raises the cost of swapping it out. The compliance side is the exposed half: the regulatory templates map published standards that any funded rival can map as well, and the reviewed record names no non-public corpus behind the analysis. [s4, s3, s9, s16]
Business Risks LG Electronics could fold Cybellum into its Vehicle Solution division and retire the standalone brand, ending the independent-entity arrangement both companies described in 2021…
  • LG Electronics could fold Cybellum into its Vehicle Solution division and retire the standalone brand, ending the independent-entity arrangement both companies described in 2021.
  • The public record could stay dormant. With no press item since September 2024 and no blog post since May 2025, a buyer has no way to confirm the platform is still advancing.
  • Application security and SBOM vendors that already hold a manufacturer's budget could add binary firmware analysis and take the account.
  • Vehicle makers that have completed cybersecurity type approval could treat the evidence work as a finished project and cut the recurring spend to a maintenance line.
  • The medical line could stall. Cybellum's automotive page names BMW, Jaguar Land Rover, Audi, Nissan, Denso, Faurecia and Mobileye where its medical page names Dräger, Siemens, Danaher and Supermicro.
  • A rival that wins an analyst category placement could take the label, since no analyst firm in the reviewed record positions Cybellum against named rivals.
Problem & Market Cybellum sells to the people inside a manufacturer who have to answer for the security of what the company ships, not for the security of what it runs…

Cybellum sells to the people inside a manufacturer who have to answer for the security of what the company ships, not for the security of what it runs. Its own account of the founding says the team found dedicated tooling everywhere in the product lifecycle, from product lifecycle management to quality systems and continuous integration, and nothing purpose-built for cybersecurity, which was handled manually with general-purpose information security tools.

The demand behind that pitch is written into regulation, and the regulation is checkable. UN Regulation No 155 directs approval authorities to grant cybersecurity type approval only to vehicle types that satisfy it, and to refuse approval where a manufacturer has not put satisfactory arrangements in place. On the medical side the FDA asks manufacturers for cybersecurity design, labelling and documentation in premarket submissions. THE ELEC quoted an LG spokesperson saying the Cybellum purchase would prepare LG for the vehicle requirement.

The category is younger than the problem. Cybellum tells prospective partners that product security is a relatively new and evolving field in all three of its industries, which is the shape of a label a vendor still has to teach a buyer. Independent outlets reach for a narrower one and call the company an automotive cybersecurity firm. [s2, s16, s30, s29, s21, s19]

Product Capabilities The engine works on compiled software rather than source code…

The engine works on compiled software rather than source code. Cybellum calls the output a Cyber Digital Twin, a replica extracted from a product's binary files that carries the software inventory, version history, licences, hardware architecture and operating system configuration. It says the analysis surfaces embedded frameworks such as AUTOSAR, and that the resulting data is matched against its own product vulnerability database.

Around that engine sits the workflow a product security team runs. The platform merges inventories from binary scanners, source code and uploaded SPDX or CycloneDX files, then fixes, validates and routes them for approval across business units. Vulnerabilities are triaged in the context of a specific product version, weaknesses are handed to engineering, and compliance evidence is assembled from templates for the FDA premarket guidance, ISO 21434, UN Regulation No 155 and the EU Cyber Resilience Act.

People are part of the delivery, not an afterthought. Cybellum sells managed SBOM analysis, vulnerability management and post-production incident response performed by its own staff, and its services page argues that software alone cannot make the judgement calls. Its partner programme describes the same combination of technology and professional services as what customers expect.

The most recent published release is version 3.7 of May 2025, which added a rebuilt vulnerability engine drawing on multiple public feeds, plus milestone tracking and penetration-test reporting. Custom performance metrics inside the milestone feature and the penetration-test reports each need their own licence, arranged through an account manager. [s4, s8, s9, s5, s10, s11, s16, s31, s34, s13]

Competitive Positioning The durable half of the product and the replicable half are easy to tell apart…

The durable half of the product and the replicable half are easy to tell apart. Reading a product's firmware into a component-level replica without its source code is slow engineering to build. Mapping published standards into report templates is not, because the standards are public and the mapping is a content exercise a funded rival can repeat.

Ownership changes the competitive picture in two directions. LG Electronics and Cybellum announced the CSMS Cockpit for automotive manufacturers at CES 2024, and Cybellum describes it as designed in a collaborative effort between the two companies. Two of the three testimonials the site rotates come from parties tied to Cybellum. One is from an LG cybersecurity team leader, and one is from Christopher Gates, a product security director who also sits on Cybellum's advisory board. The third is from Supermicro's software security team.

No third-party assessment in the reviewed record places the platform against its rivals. S&P Global covers Cybellum's partnerships as news, and no analyst firm in the reviewed record positions it against named rivals in a market landscape. The awards it displays are a Frost and Sullivan managed-services award, a 2023 Cybersecurity Excellence listing and a 2022 Global Infosec listing, all conferred by third parties and all republished on Cybellum's own pages. [s4, s9, s32, s1, s2, s5]

Go-to-Market & Traction The named-customer record has two grades…

The named-customer record has two grades. Cybellum states outright that Jaguar Land Rover, Audi, Faurecia, Supermicro, Danaher, Rolls Royce and Mobileye use the platform, it publishes customer stories on Hyundai, McLaren and ASUS, and TechCrunch independently reported Nissan using the technology. A second set, including BMW, Denso, Siemens, Dräger and the China Automotive Technology and Research Center, appears as logos with no accompanying statement of use.

Independent corroboration exists and is old. TechCrunch reported in 2021 that Jaguar Land Rover and Nissan were using the technology and that Harman, Toyota Tsusho and PTC were partners, and S&P Global's AutoTechInsight covered a 2022 tie-up under which Steelbird would take the platform to Indian manufacturers. Nothing after 2022 in the reviewed record corroborates traction from outside the company.

The motion runs through partners as well as direct sales. Cybellum operates a partner programme for solution providers and technology integrators, and its ecosystem covers product lifecycle, application lifecycle, threat analysis, continuous integration, testing and certification tooling. Buying starts with a demo request rather than a published price. [s12, s5, s4, s6, s32, s18, s25, s16]

Team & Credibility The founders are still running the company they sold…

The founders are still running the company they sold. Slava Bronfman and Michael Engstler are listed as chief executive and chief technology officer on the about page, ten years after founding, and Infosecurity Magazine and Calcalist both report that the pair served in Unit 81 of Israeli military intelligence. Independent outlets covered the LG deal, which is the exit on their record, and the reviewed sources describe no earlier build by either founder.

The board now reflects the ownership. Alongside the two founders it seats a senior vice president who is president of LG Electronics Vehicle Solution and the head of that division's research and development. The advisory board mixes buyers with the company's own side of the table. It seats a former head of car security at Daimler, a former automotive cybersecurity vice president at Harman and a medical device product security director, alongside the founder of a security vendor and a partner at Target Global, one of Cybellum's investors.

There is a public research record behind the product, and it is thin. Cybellum publishes a disclosure policy covering both its own products and embedded products built by other vendors, commits to initiating a CVE reservation within 72 hours, and has published vulnerability research on a widely used ultrasound machine. NVD lists the company as the assigning source on a command injection flaw in a Linksys router and on a hard-coded private key in Cybellum's own air-gapped distribution, which Cybellum disclosed and fixed. [s2, s22, s20, s19, s21, s14, s6, s27, s26]

Trust Readiness Cybellum documents its vulnerability disclosure practice in detail…

Cybellum documents its vulnerability disclosure practice in detail. The company runs a published policy with committed response times, accepts reports about other vendors' embedded products as part of its research scope, and assigns CVE identifiers as a numbering authority. One of the identifiers NVD records under its name covers a flaw in its own distribution, which is what a working disclosure practice looks like from the outside. On the compliance side it publishes two credentials on its own pages, an ISO 27001 badge and a TISAX badge.

What the public record does not show is how much of the operation is still running. Cybellum's news index carries nothing after September 2024 and its blog nothing after May 2025, and the served careers page shows no listings under its Open Positions heading. [s1, s14, s26, s36, s13, s12]

Competitors Finite State…
Company Relationship Note Compare
Finite State competes with Finite State publishes a comparison datasheet against Cybellum for connected device security, so it treats Cybellum as an alternative for the same product security buyer. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Cybellum.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

The durable part is the firmware engine. Reading a shipped product's compiled binaries into a component-level replica, without the source code, is years of embedded engineering. That replica carries the software inventory, the hardware bill of materials, the cryptography and frameworks such as AUTOSAR. What a funded rival could rebuild is the compliance side: the templates map published standards, and the vulnerability engine correlates public feeds. Cybellum's own certifications are the ordinary enterprise kind. The mandates its buyers face are the buyers' own. The one dependency that is not software is the managed service, because Cybellum staff do the customer's SBOM, triage and incident work. The cited record does not size what replacing them would cost.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Cybellum sells the platform and, beside it, managed SBOM analysis, vulnerability management and post-production incident response performed by its own staff, on the stated argument that software cannot make the judgement calls alone. Code and expertise blend in what the customer buys, and the Frost and Sullivan award the company displays names automotive managed services as the recognised line.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Accumulated software inventories tracked across versions and business units, plus wiring into the customer's product lifecycle and continuous integration tooling, are the data history, integrations and learned workflows this rung names. The switching mechanism is documented and the cited record does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The product generates evidence for cybersecurity type approval and FDA premarket submissions, which serves the buyer's own mandate rather than blocking Cybellum's replacement. The credentials Cybellum publishes are ISO 27001 and TISAX, which a funded competitor can obtain through ordinary enterprise preparation.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Extracting a component-level replica from compiled firmware without source code, recovering hardware architecture, cryptography and embedded frameworks such as AUTOSAR, is years of specialised binary-analysis work. The disclosure policy puts that research scope in writing, covering embedded products built by other vendors, and one of the records NVD publishes under the company's name as the assigning authority covers a command injection flaw in a third-party router.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyers are regulated manufacturers: vehicle makers that need cybersecurity type approval before they can sell and medical device firms filing premarket submissions. Cybellum's own press boilerplate names Jaguar Land Rover, Audi, Faurecia, Supermicro, Danaher and Rolls Royce as manufacturers that use the platform.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The platform is the record a manufacturer's product security work runs against, and it plugs into product lifecycle, application lifecycle and continuous integration tooling. The reviewed pages show it consuming and feeding those systems rather than carrying applications the customer builds, which keeps it a platform with application features rather than infrastructure.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The vulnerability engine correlates public feeds the company lists as OSV, Red Hat, Debian, ExploitDB and others, and the reviewed record names no non-public corpus behind the analysis. The firmware replicas it accumulates describe each customer's own products, so no cross-customer asset appears in the record, and no patent or licensed content appears either. What is hard to copy here is engineering effort, which this rubric scores under problem complexity.
Strategic Market Segmentation Cybellum sells to one function across three industries…

Cybellum sells to one function across three industries. The buyer is the product security team inside a manufacturer, the group that answers for the software in what the company ships rather than for the software the company runs. Its own careers page puts the range plainly, naming Audi, Rolls Royce, Danaher and Mobileye as manufacturers whose teams use the platform.

Automotive is where the evidence concentrates. The automotive page names BMW, Jaguar Land Rover, Audi, Nissan, Denso, Faurecia, Mobileye and a national automotive research centre, the medical page names Dräger, Siemens, Danaher and Supermicro, and the customer stories the company publishes are led by vehicle makers. That skew matches the regulatory pressure: vehicle makers must hold cybersecurity type approval before they can sell a vehicle, while the FDA asks medical device makers for cybersecurity documentation in their premarket submissions.

The industrial line reads as the extension of the same engine to a third buyer rather than a separate business. Its page repeats the automotive and medical capability set, framed around downtime and safety risks where the medical page names costly recalls and delays.

Product Capabilities & AI Advantages The differentiating work is binary analysis…

The differentiating work is binary analysis. Cybellum extracts what it calls a Cyber Digital Twin from a product's firmware files without needing the source code, and says that replica carries the software inventory, version history, licences, hardware architecture, cryptographic characteristics and operating system configuration. It also says the analysis recovers embedded frameworks such as AUTOSAR and gives a system-of-systems view across components.

The matching layer is built on public feeds. The May 2025 release notes say the rebuilt vulnerability engine detects 33% more issues by correlating multiple sources the company lists as OSV, Red Hat, Debian, ExploitDB and others, and by combining CPE and PURL identifiers. Cybellum presents that multi-source design as resilience against a single point of truth, written against the funding lapse in the MITRE CVE programme.

AI appears as an assistant rather than as the product. The platform pages describe AI insights that auto-fix and validate inventories and a triage assistant the company calls VM CoPilot, and the professional services page argues that software alone cannot make the judgement calls a product security programme needs.

Sales Engagement & Go-to-Market Buying starts with a demo request…

Buying starts with a demo request. There is no self-service entry point, no trial and no published price on any page in the reviewed record, so every path into the product runs through a sales conversation.

Partners carry part of the motion. Cybellum runs a programme for solution providers and for technology partners, and describes an ecosystem spanning product lifecycle, application lifecycle, threat analysis, continuous integration, testing and certification tooling. S&P Global's AutoTechInsight covered a 2022 arrangement under which Steelbird would take the platform to Indian manufacturers.

Ownership produced a joint product aimed at the same buyers. LG Electronics and Cybellum announced the CSMS Cockpit for automotive manufacturers at CES 2024, describing it as designed in a collaborative effort, and the reviewed record documents the collaboration but not what the product has sold. One of the three testimonials the site rotates is from the parent.

Pricing Model No price reaches the public record…

No price reaches the public record. Every path through the site ends at a demo request, and the reviewed pages carry no plan tiers, no unit of pricing and no published rate for the services.

Licensing is modular underneath. The May 2025 release notes gate custom performance metrics behind a Custom Metrics licence and penetration-test reporting behind a Penetration Testing licence, and tell the reader to contact a customer success manager to enable either. Features arriving behind their own named licences is a buyer-visible fact, and the reviewed record does not say what any of them cost.

The services are presented as their own offerings rather than as part of the platform. Managed SBOM analysis, vulnerability management and incident response each have their own page, and deployment and customisation work is a fourth engagement, but no source states how any of them is charged.

Product Delivery & Operations The platform is software the customer's team operates, and the customer chooses where it runs: the platform page offers it on public clouds or in the customer's own datacentre…

The platform is software the customer's team operates, and the customer chooses where it runs: the platform page offers it on public clouds or in the customer's own datacentre. Cybellum staff then operate parts of it for customers who want that, and the services page describes managed SBOM analysis, managed vulnerability management and managed post-production incident response, all performed by Cybellum's own experts.

Deployment is a structured engagement rather than a download. The company describes a four-stage method of discovery, concept plan, implementation and monitoring, tailored to each customer's product lifecycle, application lifecycle, continuous integration, ticketing and threat-feed tooling. It also publishes a measurement framework it calls the ProdSec KPI Model for tracking a team's performance over time.

At least one deployment form is built to run disconnected. The NVD record for CVE-2023-42419 names a QCOW air-gapped distribution and a China Edition of it, which is a packaging choice the reviewed record documents without saying who runs it.

Earning Customers' Trust Cybellum documents its vulnerability disclosure practice in detail…

Cybellum documents its vulnerability disclosure practice in detail. It publishes a policy with committed response times, accepts reports about embedded products built by other vendors as part of its research scope, and commits to initiating a CVE reservation within 72 hours. It is a CVE numbering authority, and NVD names it as the assigning source on the records it has published. On the compliance side it publishes two credentials on its own pages, an ISO 27001 badge and a TISAX badge.

One of those records is a flaw in Cybellum's own air-gapped distribution, a hard-coded private cryptographic key that the company disclosed and fixed in a later version. Publishing a defect in the product a customer buys is a costly kind of honesty.

Platform Strategy & Ecosystem Positioning The integration story is the platform claim…

The integration story is the platform claim. Cybellum argues the product is more useful the more it connects, and lists integrations across product lifecycle management, application lifecycle management, threat analysis, continuous integration, testing and certification, digital twin and safety tooling. The platform page names PTC, Polarion, GitLab and Jenkins among them.

Compliance content is the second ecosystem asset. The company says it maps pre-built requirement templates for more than 50 standards and regulations, naming ISO 21434, UN Regulation No 155, the Chinese ICV standard system, the FDA premarket guidance, IMDRF, EU MDR and IVDR, and the EU Cyber Resilience Act. Customers can also load their own frameworks.

The joint work with LG is where the ecosystem reaches beyond Cybellum's own product. The CSMS Cockpit was designed by both companies and announced for CES 2024, and the announcement describes it analysing vehicle components across a lifespan of roughly twenty years.

Team & Execution Capability The founders sold the company and stayed…

The founders sold the company and stayed. Slava Bronfman and Michael Engstler are listed as chief executive and chief technology officer a decade after founding, and Infosecurity Magazine and Calcalist both report that the pair served in Unit 81 of Israeli military intelligence. Calcalist put the company at 50 people with 35 in the Tel Aviv research and development centre at the time of the deal, and LG's own release gave the same headcount alongside operations in Japan, Germany and North America.

The board carries the ownership. Beside the two founders it seats a senior vice president who is president of LG Electronics Vehicle Solution and that division's head of research and development. The advisory board mixes buyers with the company's own side of the table. It seats a former head of car security at Daimler, a former automotive cybersecurity vice president at Harman and a medical device product security director, alongside the founder of a security vendor and a partner at Target Global, one of Cybellum's investors.

What the reviewed record cannot show is the shape of the team now. The careers page runs from its Open Positions heading straight to an invitation to reach out, and no source in the record gives a current headcount.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Cybellum platform page: what the Product Security Platform does official 2026-08-18
f2 LG Corp newsroom: LG to acquire Cybellum official 2026-08-18
f3 TechCrunch: LG is acquiring automotive cybersecurity startup Cybellum in a $240M deal press 2026-08-18
f4 CTech: LG acquiring Israeli vehicle cybersecurity startup Cybellum for at least $140 million press 2026-08-18
Profile Analysis Sources (33)
Id Source Tier Accessed
s1 Cybellum home page: platform framing, manufacturer logos and awards
“Cybellum brings the entire product security workflow into one dedicated platform, allowing device manufacturers to keep the connected products they build cyber-secure and cyber-compliant.”
official 2026-08-18
s2 Cybellum about page: origin story, management team and board composition
“OUR MISSION SINCE 2016”
official 2026-08-18
s3 Cybellum platform page: use cases, integrations and the AI-driven framing
“Create, merge and validate complete SBOMs & assets, detect and triage risks & vulnerabilities, integrate with threat models and security tests, and automate evidence creation for regulatory submissions. All from one AI-driven product security platform.”
official 2026-08-18
s4 Cybellum Cyber Digital Twins page: how the binary analysis works
“Sitting at the core of the Product Security Platform, CDTs are digital replicas of your products’ firmware that allow for unprecedented visibility and control.”
official 2026-08-18
s5 Cybellum automotive page: manufacturer names, CSMS framing and award listing
“Track and manage all CSMS activities with the CSMS Cockpit, allowing you to comply with WP. 29. much more efficiently.”
official 2026-08-18
s6 Cybellum medical page: FDA framing and named medical manufacturers
“Use pre-mapped requirements of medical device regulations such as the FDA Premarket Guidance to automatically identify compliance gaps and produce audit-ready reports in a click of a button”
official 2026-08-18
s7 Cybellum industrial page: the third industry line
“Detect and mitigate vulnerabilities, coding weaknesses and malware from design to post market, manage SBOMs, and analyze Threat Models, all from one place”
official 2026-08-18
s8 Cybellum SBOM management page: formats and merge sources
“Create reliable and complete assets & SBOMs by combining data from binary scanners, source code and external SBOM sources in SPDX, CycloneDX or CPEs CSV formats.”
official 2026-08-18
s9 Cybellum compliance page: regulatory templates and evidence generation
“Use regulatory templates for common regulations such as FDA PMA, ISO 21434, EU CRA and others, or upload your own custom framework”
official 2026-08-18
s10 Cybellum red-team automation page: weakness detection workflow
“The red-team’s job is complex, time consuming and expensive. Teams need to scale their analysis, understand the relevancy and priority of risks, hand over findings to R&D and meet strict deadlines, all at the same time. This is why automation is key.”
official 2026-08-18
s11 Cybellum services page: the managed and deployment service lines
“Managed services for SBOM analysis, vulnerability management and incident response, as well as customization services for Product Security Platform enterprise deployments. All services are performed by a team of experts, and amplified by automation and AI.”
official 2026-08-18
s12 Cybellum careers page, fetched 2026-08-18: named manufacturers and the openings list
“That's right -- software. We are a cybersecurity company specializing in keeping physical devices like cars and medical devices cyber secure. Companies like Audi, Rolls Royce, Danaher and Mobileye use our Product Security Platform every day to keep their products' software safe from cyber risks.”
official 2026-08-18
s13 Cybellum blog index, fetched 2026-08-18: newest post and its date
“Introducing Cybellum v3.7”
official 2026-08-18
s14 Cybellum disclosure policy: vulnerability research scope and CVE handling
“Reserve the CVE number: Cybellum will also initiate the reservation of a CVE number within 72 hours after having sufficient information on the vulnerability unless the vulnerability is meant to remain private.”
official 2026-08-18
s15 Cybellum automotive regulations page: the standards it maps to
“The ISO/SAE 21434 cybersecurity standard requires OEMs maintain cyber resilience throughout the lifecycle of each vehicle.”
official 2026-08-18
s16 Cybellum partners page: partner program and integration ecosystem
“The Cybellum partner program combines the industry’s most knowledgeable professionals with our award-winning Product Security Platform to help you design and deliver the product cybersecurity risk management solution your customers need.”
official 2026-08-18
s17 LG Corp newsroom: LG to acquire Cybellum
“The deal allows LG to assume an approximate 64 percent stake in the tech company valued at USD 140 million, a strategic move that will enhance LG’s cybersecurity capabilities and accelerate its efforts to become an Innovation Partner for Future Mobility.”
official 2026-08-18
s18 TechCrunch: LG is acquiring automotive cybersecurity startup Cybellum in a $240M deal
“As it stands now, if the valuation remains consistent, the deal in total will be worth some $240 million (market forces or the company’s own business funnel could impact this).”
press 2026-08-18
s19 SecurityWeek: LG to acquire vehicle cybersecurity firm Cybellum
“South Korean electronics giant LG Electronics on Thursday announced plans to acquire Israel-based automotive cybersecurity company Cybellum for roughly $240 million.”
press 2026-08-18
s20 CTech: LG acquiring Israeli vehicle cybersecurity startup Cybellum for at least $140 million
“Cybellum, founded in 2016, had raised just $15 million in total to date from investors including RSBG Ventures, Blumberg Capital, and Target Global.”
press 2026-08-18
s21 THE ELEC: LG Electronics acquires automotive cybersecurity firm Cybellum
“LG Electronics said on Thursday that it has acquired Israel-based cybersecurity startup Cybellum.”
press 2026-08-18
s22 Infosecurity Magazine: LG to acquire Cybellum
“Cybellum was founded in 2016 in Tel Aviv by CEO Slava Bronfman and CTO Michael Engstler, both of whom served in the elite Israeli military intelligence group, Unit 81.”
press 2026-08-18
s24 Geektime (Hebrew): LG acquires Cybellum in a $240 million exit
“. לשאלתי איך סייבלום הצליחה לפעול עם מצבור מזומנים יחסית נמוך, כשבשאר השוק חוגגים עם גיוסי ענק, ענה לי סלבה בורנפמן, מנכ"ל ומייסד החברה, שהעובדה שהחברה יצאה עם המוצר שלה בשלב יחסית מוקדם (מה שהוביל להכנסות ממכירות) ושימוש במתודולוגיית פיתוח Lean איפשרו לה לפעול בלי גיוסים גדולים.”
press 2026-08-18
s25 S&P Global AutoTechInsight: Steelbird partners with automotive cybersecurity company Cybellum
“Steelbird International has tied up with Israel-based cybersecurity company Cybellum Technologies under which it will introduce Cybellum’s advanced product security platform to Indian OEMs and component manufacturers, the Financial Express reported on 1 March.”
press 2026-08-18
s26 NVD: CVE-2023-42419, a hard-coded key in a Cybellum distribution, assigned by Cybellum
“Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.”
regulatory 2026-08-18
s27 NVD: CVE-2022-38132, a Linksys router flaw assigned by Cybellum
“Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands.”
regulatory 2026-08-18
s29 FDA guidance: cybersecurity in medical devices, premarket submission content
“This document provides FDA’s recommendations to industry regarding cybersecurity device design, labeling, and the documentation that FDA recommends be included in premarket submissions for devices with cybersecurity risk.”
regulatory 2026-08-18
s30 UN Regulation No 155 as published in the EU Official Journal: cybersecurity type approval
“Approval Authorities shall grant, as appropriate, type approval with regard to cybersecurity, only to such vehicle types that satisfy the requirements of this Regulation.”
regulatory 2026-08-18
s31 Cybellum product risk management page: the centralized dashboard for product security managers and supplier risk
“Uncover the reality of your product security posture with a centralized dashboard purposely built for product security managers.”
official 2026-08-18
s32 Cybellum newsroom: LG and Cybellum debut the CSMS Cockpit at CES 2024
“, the automotive cybersecurity company acquired by LG in 2021, the CSMS Cockpit platform monitors and maintains vehicle cybersecurity.”
official 2026-08-18
s34 Cybellum newsroom: the v3.7 release notes of May 2025
“We’re excited to launch”
official 2026-08-18
s35 Finite State resource page: a competitor-published comparison datasheet against Cybellum
“Finite State vs Cybellum”
official 2026-08-18
s36 Cybellum news index, fetched 2026-08-18: the newest press item and its date
“Cybellum Receives Frost & Sullivan’s Competitive Strategy Award for its Innovative Product Security Solutions”
official 2026-08-18
Deep-Dive Sources (33)
Id Source Tier Accessed
s1 Cybellum home page: platform framing, manufacturer logos and awards
“Cybellum brings the entire product security workflow into one dedicated platform, allowing device manufacturers to keep the connected products they build cyber-secure and cyber-compliant.”
official 2026-08-18
s2 Cybellum about page: origin story, management team and board composition
“OUR MISSION SINCE 2016”
official 2026-08-18
s3 Cybellum platform page: use cases, integrations and the AI-driven framing
“Create, merge and validate complete SBOMs & assets, detect and triage risks & vulnerabilities, integrate with threat models and security tests, and automate evidence creation for regulatory submissions. All from one AI-driven product security platform.”
official 2026-08-18
s4 Cybellum Cyber Digital Twins page: how the binary analysis works
“Sitting at the core of the Product Security Platform, CDTs are digital replicas of your products’ firmware that allow for unprecedented visibility and control.”
official 2026-08-18
s5 Cybellum automotive page: manufacturer names, CSMS framing and award listing
“Track and manage all CSMS activities with the CSMS Cockpit, allowing you to comply with WP. 29. much more efficiently.”
official 2026-08-18
s6 Cybellum medical page: FDA framing and named medical manufacturers
“Use pre-mapped requirements of medical device regulations such as the FDA Premarket Guidance to automatically identify compliance gaps and produce audit-ready reports in a click of a button”
official 2026-08-18
s7 Cybellum industrial page: the third industry line
“Detect and mitigate vulnerabilities, coding weaknesses and malware from design to post market, manage SBOMs, and analyze Threat Models, all from one place”
official 2026-08-18
s8 Cybellum SBOM management page: formats and merge sources
“Create reliable and complete assets & SBOMs by combining data from binary scanners, source code and external SBOM sources in SPDX, CycloneDX or CPEs CSV formats.”
official 2026-08-18
s9 Cybellum compliance page: regulatory templates and evidence generation
“Use regulatory templates for common regulations such as FDA PMA, ISO 21434, EU CRA and others, or upload your own custom framework”
official 2026-08-18
s10 Cybellum red-team automation page: weakness detection workflow
“The red-team’s job is complex, time consuming and expensive. Teams need to scale their analysis, understand the relevancy and priority of risks, hand over findings to R&D and meet strict deadlines, all at the same time. This is why automation is key.”
official 2026-08-18
s11 Cybellum services page: the managed and deployment service lines
“Managed services for SBOM analysis, vulnerability management and incident response, as well as customization services for Product Security Platform enterprise deployments. All services are performed by a team of experts, and amplified by automation and AI.”
official 2026-08-18
s12 Cybellum careers page, fetched 2026-08-18: named manufacturers and the openings list
“That's right -- software. We are a cybersecurity company specializing in keeping physical devices like cars and medical devices cyber secure. Companies like Audi, Rolls Royce, Danaher and Mobileye use our Product Security Platform every day to keep their products' software safe from cyber risks.”
official 2026-08-18
s13 Cybellum blog index, fetched 2026-08-18: newest post and its date
“Introducing Cybellum v3.7”
official 2026-08-18
s14 Cybellum disclosure policy: vulnerability research scope and CVE handling
“Reserve the CVE number: Cybellum will also initiate the reservation of a CVE number within 72 hours after having sufficient information on the vulnerability unless the vulnerability is meant to remain private.”
official 2026-08-18
s15 Cybellum automotive regulations page: the standards it maps to
“The ISO/SAE 21434 cybersecurity standard requires OEMs maintain cyber resilience throughout the lifecycle of each vehicle.”
official 2026-08-18
s16 Cybellum partners page: partner program and integration ecosystem
“The Cybellum partner program combines the industry’s most knowledgeable professionals with our award-winning Product Security Platform to help you design and deliver the product cybersecurity risk management solution your customers need.”
official 2026-08-18
s17 LG Corp newsroom: LG to acquire Cybellum
“The deal allows LG to assume an approximate 64 percent stake in the tech company valued at USD 140 million, a strategic move that will enhance LG’s cybersecurity capabilities and accelerate its efforts to become an Innovation Partner for Future Mobility.”
official 2026-08-18
s18 TechCrunch: LG is acquiring automotive cybersecurity startup Cybellum in a $240M deal
“As it stands now, if the valuation remains consistent, the deal in total will be worth some $240 million (market forces or the company’s own business funnel could impact this).”
press 2026-08-18
s19 SecurityWeek: LG to acquire vehicle cybersecurity firm Cybellum
“South Korean electronics giant LG Electronics on Thursday announced plans to acquire Israel-based automotive cybersecurity company Cybellum for roughly $240 million.”
press 2026-08-18
s20 CTech: LG acquiring Israeli vehicle cybersecurity startup Cybellum for at least $140 million
“Cybellum, founded in 2016, had raised just $15 million in total to date from investors including RSBG Ventures, Blumberg Capital, and Target Global.”
press 2026-08-18
s21 THE ELEC: LG Electronics acquires automotive cybersecurity firm Cybellum
“LG Electronics said on Thursday that it has acquired Israel-based cybersecurity startup Cybellum.”
press 2026-08-18
s22 Infosecurity Magazine: LG to acquire Cybellum
“Cybellum was founded in 2016 in Tel Aviv by CEO Slava Bronfman and CTO Michael Engstler, both of whom served in the elite Israeli military intelligence group, Unit 81.”
press 2026-08-18
s24 Geektime (Hebrew): LG acquires Cybellum in a $240 million exit
“. לשאלתי איך סייבלום הצליחה לפעול עם מצבור מזומנים יחסית נמוך, כשבשאר השוק חוגגים עם גיוסי ענק, ענה לי סלבה בורנפמן, מנכ"ל ומייסד החברה, שהעובדה שהחברה יצאה עם המוצר שלה בשלב יחסית מוקדם (מה שהוביל להכנסות ממכירות) ושימוש במתודולוגיית פיתוח Lean איפשרו לה לפעול בלי גיוסים גדולים.”
press 2026-08-18
s25 S&P Global AutoTechInsight: Steelbird partners with automotive cybersecurity company Cybellum
“Steelbird International has tied up with Israel-based cybersecurity company Cybellum Technologies under which it will introduce Cybellum’s advanced product security platform to Indian OEMs and component manufacturers, the Financial Express reported on 1 March.”
press 2026-08-18
s26 NVD: CVE-2023-42419, a hard-coded key in a Cybellum distribution, assigned by Cybellum
“Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key.”
regulatory 2026-08-18
s27 NVD: CVE-2022-38132, a Linksys router flaw assigned by Cybellum
“Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands.”
regulatory 2026-08-18
s29 FDA guidance: cybersecurity in medical devices, premarket submission content
“This document provides FDA’s recommendations to industry regarding cybersecurity device design, labeling, and the documentation that FDA recommends be included in premarket submissions for devices with cybersecurity risk.”
regulatory 2026-08-18
s30 UN Regulation No 155 as published in the EU Official Journal: cybersecurity type approval
“Approval Authorities shall grant, as appropriate, type approval with regard to cybersecurity, only to such vehicle types that satisfy the requirements of this Regulation.”
regulatory 2026-08-18
s31 Cybellum product risk management page: the centralized dashboard for product security managers and supplier risk
“Uncover the reality of your product security posture with a centralized dashboard purposely built for product security managers.”
official 2026-08-18
s32 Cybellum newsroom: LG and Cybellum debut the CSMS Cockpit at CES 2024
“, the automotive cybersecurity company acquired by LG in 2021, the CSMS Cockpit platform monitors and maintains vehicle cybersecurity.”
official 2026-08-18
s34 Cybellum newsroom: the v3.7 release notes of May 2025
“We’re excited to launch”
official 2026-08-18
s35 Finite State resource page: a competitor-published comparison datasheet against Cybellum
“Finite State vs Cybellum”
official 2026-08-18
s36 Cybellum news index, fetched 2026-08-18: the newest press item and its date
“Cybellum Receives Frost & Sullivan’s Competitive Strategy Award for its Innovative Product Security Solutions”
official 2026-08-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.