Cybersecurity · Industry brief
Top three stories shaping Cybersecurity today, written for someone who already works in the industry: regulation, M&A, new entrants, notable filings, and any precedent worth pulling. Cite the trade publication (e.g. trade press, government source, court docket) directly so I can follow up.
Cohen joins WilmerHale; Cyera hits $12B; DOJ tightens contractor screws
2 Min. Lesezeit
Cohen returns to WilmerHale
The revolving door between government and BigLaw just swung again.
David S. Cohen, who served as CIA Deputy Director through 2025 and Treasury Under Secretary for Terrorism and Financial Intelligence, has rejoined WilmerHale as senior counsel [Source: WilmerHale]. He will advise on national security enforcement, CFIUS review, and cybersecurity compliance for clients navigating government investigations. His hire signals BigLaw's appetite to deepen expertise at the intersection of AI regulation and defense policy.
Expect vendors facing NIST compliance scrutiny to add him to their speed dial.
Cyera raises $400M at unicorn-plus valuation
Data security just proved venture math still works at scale.
Cyera closed a $400 million Series G extension from Goldman Sachs Alternatives at a $12 billion+ valuation, bringing total funding past $2.7 billion [Source: SecurityWeek]. The company unified data posture management, loss prevention, and identity governance into a single platform while adding agentic access control and AI data monitoring via its $1 billion Oasis acquisition. Cyera now claims 20% of Fortune 500 deployments across 1,500+ customers.
Watch whether Fortune 100 CISOs treat unified data governance as table stakes or optional.
DOJ tightens NIST compliance enforcement
Cybersecurity gaps now carry False Claims Act liability even without a breach.
Honeywell Aerospace settled a $2 million qui tam case with the DOJ for failing to meet NIST SP 800-171 controls on a Defense contract, marking a shift in enforcement focus away from incident-driven penalties toward compliance posture gaps [Source: JD Supra]. The Civil Cyber-Fraud Initiative recorded 1,297 qui tam whistleblower filings in fiscal 2025—the record high—with DOJ explicitly flagging contractors' knowing violations of cybersecurity requirements as priority targets. Defense contractor LOGZONE similarly paid $507,000 earlier this year for the same offense.
Prime contractors and subcontractors should treat DFARS 252.204-7012 compliance as an audit liability, not optional hardening.
Exein hits $1.7B on Physical AI security play
Europe's embedded security story just got venture capital's attention.
Italian startup Exein closed a $270 million Series C from Headline, Sofina, Goldman Sachs, and the EIB, reaching $1.7 billion valuation and joining Europe's unicorn roster [Source: Orrick]. The company builds autonomous security agents for connected devices using a proprietary foundation model trained on telemetry from 2+ billion units. Funding will bankroll U.S. and Asia-Pacific expansion plus next-generation agent development.
Enterprise buyers now have a non-U.S. contender in the agentic security stack race.
Former CIA Deputy Director and Treasury Undersecretary David S ...12 hours ago ... ... enforcement actions. He will draw on decades of experience at the highest ... At Treasury, he led policy, regulatory, enforcement, and intelligence ...wilmerhale.com

David S. Cohen, former CIA Deputy Director and Treasury Under Secretary for Terrorism and Financial Intelligence, has returned to WilmerHale as senior counsel. Cohen will advise clients on national security and regulatory enforcement matters, including cybersecurity, CFIUS review, and defense of government investigations and enforcement actions. His return strengthens WilmerHale's capabilities in handling complex regulatory and enforcement issues at the intersection of national security and emerging technologies like artificial intelligence.
Cyera Raises $400 Million at $12+ Billion Valuation - SecurityWeek12 hours ago ... Funding/M&A · Cybersecurity Funding · M&A Tracker · Cyber AI · Cybersecurity News ... The data security company received the new investment from Goldman Sachs ...securityweek.com

Cyera, a data security company, raised $400 million at a $12 billion valuation from Goldman Sachs Alternatives as an extension of its Series G round, bringing total funding to over $2.7 billion. The company acquired agentic access management provider Oasis Security for $1 billion in late July. Cyera's platform unifies Data Security Posture Management, Data Loss Prevention, and identity access governance, with capabilities for securing AI operations and monitoring data inputs to language models. The company serves over 1,500 employees and claims its solutions are used by 20% of Fortune 500 companies.
“DOJ's $2 Million Honeywell Settlement Under the Civil Cyber-Fraud ...5 hours ago ... Key Takeaways · What Were DOJ's Allegations Against Honeywell Regarding NIST SP 800-171 Compliance? · How Do Qui Tam Whistleblower Actions Drive Cybersecurity FCA ...jdsupra.com

DOJ settled with Honeywell Aerospace Inc. for $2,042,518 over allegations that a business unit submitted false claims for payment while failing to comply with NIST SP 800-171 cybersecurity requirements mandated through DFARS 252.204-7012 on a Department of War contract. The settlement, announced September 1, originated from a 2022 qui tam whistleblower action by a former employee and underscores DOJ's Civil Cyber-Fraud Initiative launched in 2021 to pursue contractors for cybersecurity compliance failures. DOJ reported a record 1,297 qui tam lawsuits filed in FY 2025, the highest ever recorded, with the agency specifically identifying contractors' knowing violations of cybersecurity requirements as a continued enforcement priority. Notably, the government focused on Honeywell's failure to satisfy required NIST SP 800-171 controls rather than any identified cyberattack or breach, confirming that FCA exposure can arise from gaps between contractual cybersecurity obligations and actual compliance posture absent a security incident. Defense contractor LOGZONE Inc. similarly agreed to pay $507,144 earlier this year for alleged NIST SP 800-171 non-compliance under Navy contracts through the same enforcement mechanism, reflecting an emerging pattern of regulatory action against defense contractors on cybersecurity compliance grounds. The source is JD Supra reporting on DOJ enforcement actions.
Exein Becomes Italian Unicorn at $1.7 Billion Valuation After New ...9 hours ago ... Sofina, Goldman Sachs, the European Investment Bank (through the European Tech Champions Initiative), KfW Capital and T.Capital (the corporate venture capital ...orrick.com
.jpg)
Exein, an Italian cybersecurity startup specializing in Physical AI security for connected systems, reached a $1.7 billion valuation after closing a $270 million Series C financing round led by Headline in September 2026. The oversubscribed round included participation from Sofina, Goldman Sachs, the European Investment Bank, KfW Capital, Deutsche Telekom's T.Capital venture arm, and existing investors. The funding will support Exein's expansion into the United States and Asia-Pacific markets, as well as development of autonomous security agents powered by a proprietary foundation model trained on telemetry from over 2 billion devices. Orrick LLP advised Headline on the transaction.