Cyolo

Identity AccessNetwork SecurityInfrastructure

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2020
Funding $85M
Last updated 2026-08-22

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Cyolo sells zero-trust remote access for operational technology, having narrowed from broader IT and OT access, and in February 2026 Gartner listed it in a market guide for that category. Cyolo PRO connects employees and outside vendors to industrial control systems and adds identity checks, credential vaulting, session recording, and supervision to legacy equipment. Public financial proof has not followed: after raising $85 million by mid-2022, it reports doubling its customer base in 2025 and an approximately 80% two-year compound annual growth rate, yet has disclosed no funding since June 2022 and no revenue, so only its own numbers back it. Cyolo keeps credentials, keys, and policies inside each customer’s boundary by design, and no cross-customer data asset appears in the record.

Sourced Details

Description Secure remote privileged access company whose Cyolo PRO platform connects employees and third-party vendors to operational technology systems, adding identity-based authentication, credential vaulting, session recording, and supervision to legacy and air-gapped industrial environments. [f1]
Founded 2020 [f2]
HQ Tel Aviv, Israel [f3]
Funding $85M total [f4]
Latest funding Series B, $60M (June 2022) [f5]

Products

Product What it does
Cyolo PRO Remote privileged access platform with identity-based authentication, zero-trust connectivity, session recording, and supervision for on-prem, air-gapped, or cloud-connected OT environments.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Cyolo PRO mediates and supervises privileged remote access to industrial systems, with identity checks for users, per-application policies, and OT asset discovery. It defends conventional infrastructure and is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Cyolo names the OT and security buyer, but the pain stays qualitative (oversight of access that already exists) and the non-vendor grounding is limited to Industrial Cyber's spending-shift reporting (s17), a single source rather than multiply-sourced quantified pain. [s1, s6, s17]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Cyolo's documentation portal redirects to a customer login, and the external signal is trade press relaying vendor feature announcements (s18) rather than a demo, open-source code, or third-party evaluation, leaving concrete vendor-page detail without an external product validation point. [s2, s18, s7, s4]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Cyolo’s own February 2026 announcement reports a Gartner Market Guide dedicated to CPS secure remote access with Cyolo listed as a Representative Vendor, and Industrial Cyber describes industrial security spending moving toward the category, buyer-side signals inside twelve months that support strong timing. The underlying change is recent, with remote connectivity to industrial systems now the norm, and Cyolo quotes the guide on organizations pivoting from secure connectivity to secure operations. A CPS platform or PAM incumbent could close the window by bundling access into renewals. [s12, s6, s17]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Co-founders Almog Apirion, Dedi Yarkoni, and Eran Shmuely are press-identified and Almog brings a former-CISO background, while a Cyolo security researcher is a named OWASP Non-Human Identities Top 10 contributor and the company’s head of security research disclosed a Microsoft RDP Gateway vulnerability. No founder exit or category-defining record appears and the disclosed research targets third-party products rather than Cyolo PRO, so the team is credible but undifferentiated. [s16, s14, s3, s28, s29]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Published case studies name Rapac Energy, Tata Chemicals, Lillehammer Municipality, Maddalena, and PIB Insurance with concrete outcomes, and the TD SYNNEX distribution agreement and Dragos, IBM QRadar, and NVIDIA technology integrations extend its reach. Growth metrics remain vendor-stated, so the score stays below exceptional. [s4, s10, s9, s11, s25, s17]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Cyolo's last disclosed raise was June 2022 (s21, s14) with no later round and no revenue figure since, and CB Insights independently lists the same $85.2M total against an unattributed-VC latest round (s27), a stale raise past a normal funding cycle whose claimed growth (s6, s17) stays vendor-stated and unverifiable. [s14, s21, s6, s17, s27]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 CPS secure remote access is a newly formed Gartner Market Guide category reaching the reader through vendor materials (s12), and Cyolo also leans on a second label, remote privileged access, a forming placement rather than an established budget line. [s12, s17, s10]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Air-gapped deployment, agentless access, and identity retrofit for legacy equipment exceed a quarterly feature for cloud-routed IT access vendors. Claroty sells a broader CPS platform to the same buyer and PAM incumbents sell adjacent remote privileged access, and Cyolo’s customer-boundary architecture leaves no proprietary data flywheel in evidence, so no structural moat is visible. [s2, s24]
Business Risks Claroty or another cyber-physical systems platform vendor could bundle secure remote access into platform renewals, collapsing the standalone purchase Cyolo depends on…
  • Claroty or another cyber-physical systems platform vendor could bundle secure remote access into platform renewals, collapsing the standalone purchase Cyolo depends on.
  • Privileged access incumbents such as BeyondTrust already hold enterprise agreements with the same buyers, and could win Cyolo’s compliance-driven deals through those relationships.
  • Cyolo has disclosed no capital raise since June 2022, so a flat extension, down round, or quiet sale would reveal that the claimed growth did not convert into financial strength.
  • The growth metrics are vendor-stated, and public churn of a named anchor customer such as Tata Chemicals or Rapac Energy would undercut the traction story those accounts carry.
  • TD SYNNEX distributes thousands of products, and a distributor shift toward a rival secure remote access vendor would cut the channel reach Cyolo’s go-to-market motion depends on.
  • Buyers consolidating onto IT-side zero-trust platforms could fold OT access into enterprise agreements with vendors such as Zscaler, shrinking Cyolo’s addressable deals to fully air-gapped sites.
Problem & Market Cyolo sells visibility and control over remote connections into industrial environments…

Cyolo sells visibility and control over remote connections into industrial environments. The buyers it names are OT and security teams who must let employees, third-party vendors, and OEMs reach critical systems without disrupting production. The homepage lists agentless third-party access, OEM support access, privileged access control, and regulatory compliance as the four jobs the product performs.

Independent coverage corroborates the demand. Industrial Cyber reported in February 2026 that industrial cybersecurity spending is shifting toward secure remote access. Cyolo’s own announcement that same month says Gartner published a Market Guide dedicated to CPS secure remote access and listed Cyolo among the Representative Vendors. The vendor also displays a series of Gartner recognitions across 2025 on its homepage.

Almog Apirion frames the problem as too much access rather than too little. In the company’s 2026 momentum announcement he argued that most industrial organizations already have remote access and now need to see and control what users do while connected. That framing matches the product’s emphasis on supervision, session recording, and approval workflows over pure connectivity. [s1, s17, s12, s6]

Product Capabilities Cyolo PRO (Privileged Remote Operations) is the company’s product, a remote access platform built around OT constraints…

Cyolo PRO (Privileged Remote Operations) is the company’s product, a remote access platform built around OT constraints. The product page describes identity-based authentication, zero-trust connectivity, and oversight controls for OT and CPS environments, with deployment on-prem, air-gapped, or cloud-connected. The architecture has two components, an IDAC (ID Access Controller) that acts as the brain and a Gateway that customers place on-prem or in the cloud, and the decentralized design keeps credentials, keys, and policies inside the customer’s boundary.

Identity modernization for legacy systems is the distinctive capability claim. Cyolo states the product adds MFA, credential vaulting, and password rotation to systems that cannot support them natively, including end-of-life Windows machines and dated PLCs and HMIs, without infrastructure changes. The agentless model extends access to third-party vendors who decline to install software on personal devices.

Version 7.0 widens the product beyond access mediation into OT visibility. The 2026 release added session intelligence that turns recordings into searchable transcripts, passive OT asset and traffic discovery through a Fabric Controller that reads telemetry from existing switches, and consolidated dashboards. Industrial Cyber relays the same capability list, and the earlier Intelligent Supervision release announced per-session risk scoring and AI monitoring that would pause a suspicious session, capabilities the cited announcement states in future tense rather than as shipped.

Public depth stops at the marketing layer. Cyolo’s documentation portal redirects to a customer login, no public API reference or self-service tier exists, and the company promotes a SANS Institute product briefing rather than an independently initiated evaluation. Named case studies with concrete outcomes, including Rapac Energy and Tata Chemicals, provide the external validation instead. [s2, s7, s18, s8, s4, s1]

Competitive Positioning Cyolo positions against VPNs, jump boxes, and IT-centric remote access tools rather than against named rivals…

Cyolo positions against VPNs, jump boxes, and IT-centric remote access tools rather than against named rivals. Its homepage argues that access tooling built for IT disrupts OT operations, and its product page contrasts Cyolo PRO with legacy secure remote access on deployment flexibility, legacy-system identity support, and oversight controls.

The competitive field spans specialists and adjacent incumbents. Dispel and Xona sell secure remote access for OT and ICS directly. Claroty approaches the same industrial buyer with a broader cyber-physical systems platform, and privileged access incumbents such as BeyondTrust sell remote privileged access to the same enterprises from the IT side. Zero-trust access vendors such as Zscaler hold the corporate remote-access budget line, and some buyers fold OT access into it.

Cyolo’s visible differentiators are architectural. The decentralized model keeps secrets inside the customer’s boundary, the same software runs in air-gapped sites where cloud-routed access services cannot operate, and the identity retrofit reaches equipment PAM tools typically skip. None of this blocks a well-resourced incumbent, but together the constraints raise the engineering bar above a quarterly feature release. [s1, s2, s22, s23, s24]

Go-to-Market & Traction Cyolo runs a channel-first go-to-market…

Cyolo runs a channel-first go-to-market. The partners page states the company is built to work hand-in-hand with partners, and Cyolo called the TD SYNNEX distribution agreement the cornerstone of the Cyolo PRO launch, opening that distributor’s integrators, VARs, and MSSPs as a route to industrial buyers. Technology partnerships extend the reach, with Dragos co-positioning Cyolo PRO alongside its OT monitoring platform, an IBM QRadar integration that the technology-integrations page describes as correlating secure-access data with threat intelligence for OT and IT visibility, and an NVIDIA cybersecurity AI integration aimed at managed service providers.

Named customers span energy, water, manufacturing, and insurance. Rapac Energy, Tata Chemicals, Lillehammer Municipality, Italian manufacturer Maddalena, and PIB Insurance appear in published case studies, with concrete outcomes that include Maddalena cutting secure remote access costs by 70% and a smart-energy operator connecting over 2,000 users to more than 150 systems.

The growth numbers are the company’s own. Cyolo reported more than doubling its global customer base in 2025, a five-fold increase over two years, expansion accounting for 45% of 2025 growth, and an approximately 80% compound annual growth rate. Industrial Cyber relayed those figures without independent verification, and Cyolo discloses no revenue or customer count, so the traction story combines vendor-stated metrics with named case studies. [s5, s10, s9, s11, s25, s4, s6, s17]

Team & Credibility Cyolo’s three co-founders are CEO Almog Apirion, CTO Dedi Yarkoni, and Chief Architect Eran Shmuely…

Cyolo’s three co-founders are CEO Almog Apirion, CTO Dedi Yarkoni, and Chief Architect Eran Shmuely. Press coverage of the Series A identifies all three, and Almog describes himself as a recovering CISO who built the product he could not find as a buyer. SecurityWeek quotes the same founding story in its Series B coverage.

The executive layer extends well past the founders. The company page lists a chief strategy officer, a CFO, a chief customer officer, and vice presidents for global sales, marketing, R&D, product, customer success, and systems engineering, and the February 2026 announcement expanded the go-to-market roles of Joe O’Donnell, Asa Kedar, and Mark Edge.

Domain pedigree shows up in research more than in exits. A Cyolo security researcher is a named contributor to OWASP’s Non-Human Identities Top 10, and the company’s head of security research disclosed a Microsoft RDP Gateway vulnerability, CVE-2023-35332, through coordinated disclosure. No founder exit appears, and the disclosed work targets a third-party product rather than Cyolo PRO, so the record speaks to security-research craft rather than category-defining standing.

The investors and the public registry round out the picture. Glilot Capital led the Series A and National Grid’s venture arm led the Series B alongside Merlin Ventures, Flint Capital, and Differential Ventures, while CB Insights also lists IBM Ventures among the backers, a tie that matches the company’s IBM QRadar integration. The Israeli Corporations Authority records Cyolo Security Ltd as an active private company incorporated in January 2020. [s16, s3, s14, s6, s20, s15, s28, s29, s27, s26]

Trust Readiness Cyolo’s trust pitch is architectural…

Cyolo’s trust pitch is architectural. The product page states that the decentralized design keeps all credentials, keys, policies, and other secrets inside the customer’s trusted boundaries at all times, which directly answers the vendor-compromise concern an inline access broker raises.

Public trust artifacts are missing. No trust center, SOC 2 attestation, ISO certification, or penetration test summary appears on the public site, while the footer does link a vulnerability disclosure policy, and the documentation portal requires a customer login. The footer also links a regulatory-compliance page that maps Cyolo capabilities to mandates its customers must meet, such as NIS2, IEC 62443, and ISO 27001, so compliance appears in the marketing as something the product helps customers achieve rather than something the vendor evidences about itself.

Cyolo still sells to compliance demand. The homepage names access control, supervision, session recording, and segmentation as requirements of industry and regional mandates that the product implements, which positions the company for regulated buyers whose audits ask for exactly those controls. [s2, s1, s30]

Competitors Dispel, Xona, Claroty, BeyondTrust, CyberArk, Zscaler…
Company Relationship Note Compare
Dispel competes with Sells secure remote access and data streaming for OT and ICS, contesting the same industrial remote-access purchase.
Xona competes with Zero-trust secure remote access platform for OT and ICS environments, a direct alternative in the same evaluations.
Claroty competes with Cyber-physical systems protection platform vendor selling to the same industrial buyer, with the breadth to bundle secure access into platform deals.
BeyondTrust adjacent Privileged access incumbent whose Privileged Remote Access product reaches the same remote privileged access budget from the IT side.
CyberArk adjacent
Zscaler adjacent Zero-trust network access incumbent for IT environments whose cloud-routed model stops short of air-gapped industrial sites.

Add analyzed competitors to compare them side by side with Cyolo.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 11 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Cyolo’s protections are circumstantial rather than accumulated. Regulated industrial buyers run procurement, safety, and legal review before any swap, compliance mandates require supervised access, and the broker sits in the connection that vendors and operators use daily, so replacement is a project rather than a quick switch. Customers keep credentials, keys, and other secrets inside their own boundary by design, and no cross-customer dataset appears in the record, though the cited pages do not rule out aggregation of derived telemetry. A rival that clears the same compliance bars and can match the air-gapped deployment faces years of OT-specific engineering, but it faces no wall, and the access-broker pattern is well understood across the privileged and secure remote access industries.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy and run Cyolo PRO as software, directly or through channel partners. Cyolo operates no managed oversight service and accepts no accountability for customer outcomes in reviewed materials.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Replacing an inline access broker means re-onboarding vendor identities, policies, recording workflows, and SIEM and ITSM integrations across many sites, which is meaningful friction. Customer data stays in the customer’s boundary by design, so data gravity adds nothing and migration remains a project rather than a wall.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Industrial mandates for access control, supervision, and session recording drive demand for the category. The cited pages name no certification regime or mandate specific to Cyolo, and they do not constitute a search of such regimes, and a rival that qualifies clears the same bars, so this is a category tailwind that lifts every qualified vendor rather than a moat that locks in Cyolo.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3 Brokering identity and access across air-gapped networks, end-of-life Windows, PLCs, and HMIs without agents or infrastructure changes is non-trivial domain engineering. Competing OT remote-access platforms show the broker pattern is already commercialized, which caps the difficulty.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Cyolo sells to regulated industrial enterprises and critical infrastructure operators such as power plants, water utilities, and chemical manufacturers, where procurement, safety review, and legal sit between an incumbent and any replacement.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 1/3 Cyolo PRO is an access tool that brokers remote connections, not a platform layer others build on. No customer application is built on top of it, and a buyer can revert to VPNs and jump boxes, so nothing depends on Cyolo as a foundation it cannot replace.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The decentralized architecture keeps credentials, keys, policies, and other secrets inside the customer boundary, and no proprietary data claim appears in reviewed materials. The cited pages do not establish session-data residency specifically, nor rule out aggregation of derived telemetry such as generated session-risk scores.
Strategic Market Segmentation Cyolo targets industrial enterprises and critical infrastructure operators…

Cyolo targets industrial enterprises and critical infrastructure operators. The published customer set, under the names the case-studies page itself uses, includes Rapac Energy, Tata Chemicals, Lillehammer Municipality and its water and wastewater operations, Italian manufacturer Maddalena, and PIB Insurance, a roster that matches the company’s manufacturing-heavy messaging.

The sale runs through two personas at once. Cyolo pitches operations leaders on uptime and simplicity while pitching IT and security leaders on visibility, control, and zero-trust enforcement, a pairing the homepage compresses into built for OT, backed by IT. The featured Tata Chemicals testimonial comes from an IT manager who emphasizes session recording and manager-approval workflows for vendor access, which shows the oversight persona inside the buying group.

Reach is international for a company of this stage. Case studies span operators in several countries, the site localizes into German, Spanish, French, and Italian, and the TD SYNNEX distribution agreement is global. The cyolo.io navigation lists per-industry solution pages for Manufacturing, Energy & Utilities, and AI Data Centers, and whether those pages amount to vertical packaging or industry messaging stays open. No deal-size or segment signals are public.

The newest public proof of demand is current. The record-year announcement arrived in February 2026, the Gartner Market Guide naming Cyolo as a Representative Vendor carries a February 4, 2026 publication date, the v7.0 release followed within weeks, and the cited pages carry 2025 Gartner Hype Cycle mentions. A buyer checking for momentum finds evidence from the past two quarters rather than launch-era references.

Product Capabilities & AI Advantages Cyolo documents its capabilities at the feature level rather than the slogan level…

Cyolo documents its capabilities at the feature level rather than the slogan level. The product page enumerates identity-based authentication with MFA for legacy systems, credential vaulting and password rotation, just-in-time access, supervised access, session recording, per-application policies with time and geo-location parameters, agentless third-party connections, and multi-tenant management across hundreds of sites.

Cyolo applies AI to the oversight burden its own product creates. Cyolo says Intelligent Supervision will score each remote session for risk and oversee sessions in progress, with the capability presented prospectively in the cited announcement, while the released v7.0 session intelligence converts recorded sessions into searchable transcripts so teams stop reviewing hours of footage. The announced NVIDIA integration points the same direction for managed service providers, with availability stated prospectively in the cited announcement. AI is a feature stack on a conventional access product here, and the supervised asset is the human or machine session rather than an AI system.

No proprietary data advantage is evidenced or claimed in the reviewed materials. The architecture keeps credentials, keys, and policies inside each customer’s boundary, which is the trust pitch, and no cross-customer dataset is shown to accumulate from it, though the session-risk metadata the product generates is the kind of signal a vendor could aggregate. Whether the new asset-discovery telemetry follows the same residency design is an inference the cited pages do not yet confirm.

External validation of the capability claims is thin. Industrial Cyber re-reports the vendor’s capability lists, and no independent benchmark, red-team result, or technical customer write-up appears in the public record. The case studies carry outcome claims, including a 70% cost reduction at Maddalena, but the vendor publishes those itself.

Sales Engagement & Go-to-Market Cyolo describes itself as channel-first and structures launches accordingly…

Cyolo describes itself as channel-first and structures launches accordingly. The TD SYNNEX agreement, which Cyolo called the cornerstone of the Cyolo PRO launch, opens a global distributor’s integrators, VARs, MSSPs, and carriers as a route to industrial buyers, and the CyoloVerse partner program frames technology alliances such as Dragos. The partners page recruits with revenue-expansion language and a named partner testimonial about removing VPN friction.

Technology alliances place Cyolo next to vendors the buyer already trusts. Dragos pairs Cyolo PRO with its OT network monitoring platform under a joint security-controls story, the technology-integrations page pairs Cyolo with IBM QRadar to correlate secure-access data with threat intelligence, and the NVIDIA cybersecurity AI integration, which Cyolo announced for global availability in Q2 2025, targets managed service providers. Each alliance is also a dependency, since none of these partners sells Cyolo exclusively.

The selling motion has moved past the founders. Mark Edge runs global sales, Joe O’Donnell holds the strategy and channel portfolio, and Asa Kedar owns customer success, with all three roles expanded in the February 2026 announcement while Almog Apirion still fronts the public narrative. For a company four years past its last disclosed raise, a hired go-to-market organization is stage-appropriate rather than premature, though undisclosed revenue means the ratio of sales capacity to repeatable proof cannot be checked.

Distribution breadth is partly evidenced. Cyolo lists AWS Marketplace, Azure Marketplace, Okta, and IBM Application Exchange entries, though it publishes no partner counts and the growth metrics that would prove channel productivity are vendor-stated. The visible reach, marketplace listings plus one global distributor and named alliances, is real but reproducible by a funded rival.

Pricing Model Cyolo publishes no pricing…

Cyolo publishes no pricing. Every product path on the site ends in a demo request, no packaging tiers appear, and the charging unit is undisclosed, so a buyer cannot tell whether Cyolo charges per user, per site, per application, or per connected asset.

The opacity is consistent with the motion. Channel-mediated enterprise deals into regulated industrial buyers are negotiated against downtime and compliance risk rather than metered consumption, and hidden price sheets usually accompany exactly that posture. Multi-tenancy, which lets one software instance serve multiple client organizations, suggests the economics also support service providers reselling access as a managed offering.

The open question is the unit. Sites and connected vendors look like the natural way to size this problem, and if buyers do size it that way, a vendor charging by some other unit invites procurement friction. Nothing public answers how Cyolo contracts scale across the hundreds of sites the product claims to span.

Product Delivery & Operations Deployment flexibility is the product’s central operational claim…

Deployment flexibility is the product’s central operational claim. Cyolo PRO deploys on-prem, fully offline, or cloud-connected from the same Docker-based software, with the IDAC controller and Gateway placed to fit the environment, and Cyolo states that no infrastructure changes are required. The agentless model removes software installation for third-party users.

Operational integration runs in both directions. Cyolo PRO connects inward to any identity provider and to OT switches for the new asset discovery, and outward to SIEM, SOAR, and ITSM platforms, with v7.0 adding consolidated dashboards for active sessions, identity sources, and approval workflows. Rapac Energy’s case study headline claims weeks of work saved securing OT and SCADA systems.

Inline delivery cuts both ways. Vendor connections run through Cyolo daily, so an outage interrupts remote operations rather than just degrading a detection layer, and the company’s uptime messaging acknowledges that bar. The reviewed public pages carry no SLA, no regional data-residency options, and no support-model detail, so operational depth cannot be inspected externally.

Earning Customers' Trust Cyolo’s strongest trust argument is what it never holds…

Cyolo’s strongest trust argument is what it never holds. The decentralized architecture keeps credentials, keys, policies, and other secrets inside the customer’s trusted boundaries at all times, so a compromise of Cyolo exposes less than a compromise of a cloud-routed access broker would. For industrial buyers wary of vendor-side incidents, that is a procurement-relevant property.

Compliance evidence about Cyolo’s own posture is thinner than the supervision it sells. The reviewed pages surface a vulnerability disclosure policy and a regulatory-compliance page, yet no public trust center, no SOC 2 or ISO attestation, and no penetration test summary appear, a notable gap for a vendor selling supervision and auditability to regulated buyers. The regulatory-compliance page maps Cyolo capabilities to mandates its customers must meet, such as NIS2, IEC 62443, and ISO 27001, which is framework-alignment marketing for customers rather than an attestation of Cyolo’s own controls. Procurement teams may receive attestations privately, but the public record leaves that question open.

Compliance is sold as a customer outcome rather than evidenced as a vendor posture. The homepage markets access control, supervision, session recording, and segmentation as mandate requirements the product implements for customers, while the company publishes no equivalent evidence about its own operations.

Platform Strategy & Ecosystem Positioning Cyolo now markets a Secure Connectivity Platform spanning remote access, microsegmentation, and asset discovery, an expanding OT suite that still completes other vendors’ stacks rather than serving as a platform others build on…

Cyolo now markets a Secure Connectivity Platform spanning remote access, microsegmentation, and asset discovery, an expanding OT suite that still completes other vendors’ stacks rather than serving as a platform others build on. Integrations run inward to identity providers and OT switches and outward to SIEM, SOAR, and ITSM tooling, and the Dragos pairing slots Cyolo into the access layer of a broader OT security architecture.

Buyers can encounter Cyolo without meeting a Cyolo seller. TD SYNNEX puts the product in front of thousands of integrators, VARs, MSSPs, and carriers, Dragos co-positions it inside critical infrastructure accounts, and the announced NVIDIA integration aims at managed service providers building OT security offerings. That is genuine indirect distribution, though Cyolo publishes no integration or partner counts, and a funded rival could sign comparable agreements.

Version 7.0 pushes into adjacent territory. Passive asset and traffic discovery overlaps the visibility product of partner Dragos, which converts the access product into a beachhead for broader OT security spend and simultaneously strains the partnerships the channel motion depends on.

Team & Execution Capability Cyolo’s founding trio pairs a former CISO with technical co-founders…

Cyolo’s founding trio pairs a former CISO with technical co-founders. CEO Almog Apirion is a former CISO who says he started the company after failing to find a remote-access product that met his standards as a buyer, and co-founders Dedi Yarkoni and Eran Shmuely hold the CTO and chief architect roles. All three remain in post six years after founding.

The leadership bench is broad for a private company of this size. Beyond the founders, the company page names a chief strategy officer, a CFO, a chief customer officer, and vice presidents for global sales, marketing, R&D, product, customer success, human resources, and global systems engineering, thirteen named leaders in all. The February 2026 announcement expanded the go-to-market remits of Joe O’Donnell, Asa Kedar, and Mark Edge.

The investor table doubles as a go-to-market asset. National Grid Partners, the venture arm of a major energy utility, led the Series B, Glilot Capital led the Series A through its early-growth fund, and Merlin Ventures, a cybersecurity investor, holds Cyolo in its portfolio. Strategic money from an energy operator aligns the cap table with the critical-infrastructure buyer Cyolo sells to.

Headcount and seniority below the named layer stay undisclosed. The last public employee figure is 27 at the 2021 Series A, no current engineering or sales headcount appears in the record, and the reviewed sources do not show a prior founder exit, so execution capacity beyond the named roster is an open question.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Cyolo product page official 2026-06-11
f2 Israeli Corporations Authority: Cyolo Security Ltd registry record, incorporation date regulatory 2026-07-02
f3 Industrial Cyber on the Cyolo Series B press 2026-06-11
f4 SecurityWeek on the Cyolo Series B press 2026-06-11
f5 Series B announcement via GlobeNewswire, June 28, 2022 press 2026-06-11
Profile Analysis Sources (30)
Id Source Tier Accessed
s1 Cyolo homepage
“Connect third-party vendors, remote workers, and privileged employees to critical assets in a way that’s secure, safe, and surprisingly simple.”
official 2026-06-12
s2 Cyolo product page
“Cyolo PRO (Privileged Remote Operations) is a lightweight, infrastructure-agnostic remote access solution that brings identity-based authentication, zero-trust connectivity, and crucial visibility and oversight capabilities to OT/CPS environments.”
official 2026-06-12
s3 Cyolo company page
“Almog Apirion, our CEO and co-founder, calls himself a ‘recovering CISO.’”
official 2026-06-12
s4 Cyolo case studies index
“How Italian Manufacturer Maddalena Modernized Secure Remote Access While Cutting Costs by 70%”
official 2026-06-12
s5 Cyolo partners page
“Cyolo is a channel-first company, built to work hand-in-hand with our partners.”
official 2026-06-12
s6 Cyolo momentum announcement
“In 2025, Cyolo more than doubled its global customer base, contributing to a 5x increase within two years. Customer expansion accounted for 45% of overall growth in 2025”
official 2026-06-12
s7 Cyolo PRO v7.0 release announcement
“Cyolo PRO v7.0 adds new features, including session intelligence, OT asset discovery, and enhanced dashboards, to amplify visibility and control across critical infrastructure.”
official 2026-06-12
s8 Cyolo Intelligent Supervision announcement
“Cyolo PRO will generate a score for each remote session based on the level of security risk it poses.”
official 2026-06-12
s9 Cyolo and Dragos partnership announcement
“The solution plans to integrate Cyolo PRO and the Dragos Platform through an API architecture or operator console.”
official 2026-06-12
s10 Cyolo and TD SYNNEX partnership announcement
“The partnership with TD SYNNEX serves as the cornerstone of the Cyolo PRO (Privilege Remote Operations) launch.”
official 2026-06-12
s11 Cyolo and NVIDIA integration announcement
“The Cyolo solution integrated with NVIDIA cybersecurity AI will be available globally in Q2 2025.”
official 2026-06-12
s12 Cyolo on the 2026 Gartner Market Guide listing
“Cyolo Security has been named a Representative Vendor in the recently released Gartner Market Guide for CPS Secure Remote Access report. The report emphasizes a major industry shift toward secure operations with fit for purpose cyber-physical systems secure remote access products.”
official 2026-06-18
s13 Cyolo Series B announcement official 2026-06-12
s14 SecurityWeek on the Cyolo Series B
“The Series B financing brings the total raised by the Tel Aviv-based Cyolo to $85 million and provides a solid runway for the company to compete in the ZTNA (Zero Trust Network Access) marketplace.”
press 2026-06-12
s15 Industrial Cyber on the Cyolo Series B
“announced Tuesday the completion of a US$60 million Series B round, taking the company’s total funding to $85 million, including a Series A round completed in 2021.”
press 2026-06-12
s16 CTech on the Cyolo Series A
“Cyolo was founded in 2020 by CEO Almog Apirion, CTO Dedi Yarkoni, and Chief Architect Eran Shmuely. The company employs 27 people and had previously raised $4 million.”
press 2026-06-12
s17 Industrial Cyber on the Cyolo record year
“The OT-focused secure access company reported an 80% CAGR (compound annual growth rate), expanded its customer base, and gained industry recognition as demand accelerated.”
press 2026-06-12
s18 Industrial Cyber on Cyolo PRO v7.0
“Cyolo PRO version 7.0 introduces a new Fabric Controller component that integrates with existing OT switches to collect telemetry data without requiring agents.”
press 2026-06-12
s19 Merlin Ventures portfolio page for Cyolo
“Cyolo provides secure remote privileged access for cyber-physical systems.”
other 2026-06-12
s20 Cyolo Series A announcement
“it has secured a $21 million Series A funding round led by Glilot Capital Partners, with a strategic investment from National Grid Partners and Merlin Ventures”
official 2026-06-12
s21 Series B announcement via GlobeNewswire
“TEL AVIV, Israel, June 28, 2022 (GLOBE NEWSWIRE)”
press 2026-06-12
s22 Dispel homepage
“Secure Remote Access & Data Streaming for OT and ICS”
other 2026-06-12
s23 Xona homepage
“Secure Remote Access for OT and ICS Zero Trust Platform”
other 2026-06-12
s24 BeyondTrust Privileged Remote Access product page other 2026-06-12
s25 Cyolo technology integrations page
“Cyolo and IBM QRadar deliver OT/IT visibility, correlating secure access data with threat intelligence to detect and respond to attacks faster.”
official 2026-06-18
s26 Israeli Corporations Authority: Cyolo Security Ltd registry record, company 516134376
“CYOLO SECURITY LTD ... תאריך התאגדות 09/01/2020 ... סטטוס חברה פעילה”
regulatory 2026-06-29
s27 CB Insights: Cyolo company profile
“Cyolo raised a total of $85.2M. ... Investors of Cyolo include IBM Ventures, Flint Capital, Differential Ventures, National Grid Partners, Glilot Capital Partners and 6 more.”
research 2026-06-29
s28 OWASP Non-Human Identities Top 10: project contributors
“Individuals that provided a significant contribution to the project: ... Dor Dali | Cyolo”
research 2026-06-29
s29 Cyolo: Dor Dali on the RDP Gateway vulnerability CVE-2023-35332
“Dor Dali is Head of Security Research at Cyolo. ... Mar 22, 2023, Vulnerability discovered and reported through the MSRC portal”
official 2026-06-29
s30 Cyolo regulatory compliance page (trust probe 2026-07-02, framework-alignment marketing, no attestation served)
“Let Cyolo keep you aligned with regional and industry-specific regulations around secure remote access”
official 2026-07-02
Deep-Dive Sources (27)
Id Source Tier Accessed
s1 Cyolo homepage
“Connect third-party vendors, remote workers, and privileged employees to critical assets in a way that’s secure, safe, and surprisingly simple.”
official 2026-06-11
s2 Cyolo product page
“Cyolo PRO is composed of two distinct components: the IDAC (ID Access Controller) and a Gateway . The IDAC serves as the “brain,” while the Gateway can be placed either on-prem or on-cloud, depending on the organization’s needs.”
official 2026-06-11
s3 Cyolo company page
“Almog Apirion, our CEO and co-founder, calls himself a ‘recovering CISO.’”
official 2026-06-18
s4 Cyolo case studies index
“How Italian Manufacturer Maddalena Modernized Secure Remote Access While Cutting Costs by 70%”
official 2026-06-11
s5 Cyolo partners page
“Cyolo is a channel-first company, built to work hand-in-hand with our partners.”
official 2026-06-11
s6 Cyolo momentum announcement
“In 2025, Cyolo more than doubled its global customer base, contributing to a 5x increase within two years. Customer expansion accounted for 45% of overall growth in 2025”
official 2026-06-11
s7 Cyolo PRO v7.0 release announcement
“Cyolo PRO v7.0 adds new features, including session intelligence, OT asset discovery, and enhanced dashboards, to amplify visibility and control across critical infrastructure.”
official 2026-06-11
s8 Cyolo Intelligent Supervision announcement
“Cyolo PRO will generate a score for each remote session based on the level of security risk it poses.”
official 2026-06-11
s9 Cyolo and Dragos partnership announcement
“The solution plans to integrate Cyolo PRO and the Dragos Platform through an API architecture or operator console.”
official 2026-06-11
s10 Cyolo and TD SYNNEX partnership announcement
“The partnership with TD SYNNEX serves as the cornerstone of the Cyolo PRO (Privilege Remote Operations) launch.”
official 2026-06-11
s11 Cyolo and NVIDIA integration announcement
“The Cyolo solution integrated with NVIDIA cybersecurity AI will be available globally in Q2 2025.”
official 2026-06-11
s12 Cyolo on the 2026 Gartner Market Guide listing
“Gartner, Market Guide for CPS Secure Remote Access, By Katell Thielemann, Wam Foster, Sumit Rajput, 4 February 2026.”
official 2026-06-11
s13 Cyolo Series B announcement official 2026-06-11
s14 SecurityWeek on the Cyolo Series B
“The Series B financing brings the total raised by the Tel Aviv-based Cyolo to $85 million and provides a solid runway for the company to compete in the ZTNA (Zero Trust Network Access) marketplace.”
press 2026-06-11
s15 Industrial Cyber on the Cyolo Series B
“announced Tuesday the completion of a US$60 million Series B round, taking the company’s total funding to $85 million, including a Series A round completed in 2021.”
press 2026-06-11
s16 CTech on the Cyolo Series A
“Cyolo was founded in 2020 by CEO Almog Apirion, CTO Dedi Yarkoni, and Chief Architect Eran Shmuely. The company employs 27 people and had previously raised $4 million.”
press 2026-06-11
s17 Industrial Cyber on the Cyolo record year
“The OT-focused secure access company reported an 80% CAGR (compound annual growth rate), expanded its customer base, and gained industry recognition as demand accelerated.”
press 2026-06-11
s18 Industrial Cyber on Cyolo PRO v7.0
“Cyolo PRO version 7.0 introduces a new Fabric Controller component that integrates with existing OT switches to collect telemetry data without requiring agents.”
press 2026-06-11
s19 Merlin Ventures portfolio page for Cyolo
“Cyolo provides secure remote privileged access for cyber-physical systems.”
other 2026-06-11
s20 Cyolo Series A announcement
“it has secured a $21 million Series A funding round led by Glilot Capital Partners, with a strategic investment from National Grid Partners and Merlin Ventures”
official 2026-06-11
s21 Series B announcement via GlobeNewswire
“TEL AVIV, Israel, June 28, 2022 (GLOBE NEWSWIRE)”
press 2026-06-11
s22 Dispel homepage
“Secure Remote Access & Data Streaming for OT and ICS”
other 2026-06-11
s23 Xona homepage
“Secure Remote Access for OT and ICS Zero Trust Platform”
other 2026-06-11
s25 Cyolo technology integrations page
“Cyolo and IBM QRadar deliver OT/IT visibility, correlating secure access data with threat intelligence to detect and respond to attacks faster.”
official 2026-06-15
s26 Cyolo regulatory compliance page (trust probe 2026-07-02, framework-alignment marketing, no attestation served)
“Let Cyolo keep you aligned with regional and industry-specific regulations around secure remote access”
official 2026-07-02
s27 Cyolo company page, customer stories (targeted recapture 2026-07-30)
“Rapac Energy, a leading power plant operator, needed to provide secure access to their OT and SCADA systems for external suppliers, global support teams, and customers.”
official 2026-07-30
s28 Cyolo case studies index (targeted recapture 2026-07-30)
“How Tata Chemicals Securely Connects Third-Party Vendors to Critical OT Resources [...] How Lillehammer Municipality Improved the Security of its Water and Wastewater Operations”
official 2026-07-30

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.