Cybersecurity · Industry brief
Top three stories shaping Cybersecurity today, written for someone who already works in the industry: regulation, M&A, new entrants, notable filings, and any precedent worth pulling. Cite the trade publication (e.g. trade press, government source, court docket) directly so I can follow up.
Island and Cyera double down; EU breach reporting live; agent security races forward
2 Min. Lesezeit
Island and Cyera $400M rounds
Two cybersecurity unicorns just doubled their valuations in one week.
Island, a Dallas-based secure operations platform, closed a $400 million Series F from Evolution Equity Partners at $6.4 billion—more than double its 2024 valuation [Source: Crunchbase News]. Cyera, the New York data-security firm we covered three days ago, hit the same $400 million ticket in a Series G extension, also led by Evolution and backed by Goldman Sachs Growth Equity. Both deals landed this week, signaling that late-stage security buyers still command top-tier valuations despite macro headwinds.
Watch whether either files for IPO or gets acquired before year-end.
EU Cyber Resilience Act live
Europe's breach-reporting clock started September 11.
Manufacturers of products with digital elements sold in the EU now face a 24-hour reporting requirement for actively exploited vulnerabilities, with 72-hour escalation deadlines and fines up to €15 million or 2.5% of global turnover [Source: JD Supra]. U.S. vendors are treated as manufacturers with full duties. Reports flow through ENISA's CRA Single Reporting Platform, and the obligation applies retroactively to products sold before the December 2027 compliance deadline.
Vendors should audit their EU customer base and breach-response playbooks this quarter.
Outerlimit emerges on AI control
A new Zero Trust startup just raised $16 million on agent security alone.
Outerlimit, founded by Egress Software alumni Tony Pepper and Neil Larkins, emerged from stealth with backing from AlbionVC, Evolution Equity, and Crane Venture to build decentralized authorization for autonomous AI agents [Source: Pulse2]. The platform extends Zero Trust principles to individual agent actions using cryptographic enforcement, already deployed at Fortune 500 and FTSE 100 firms. The founders' track record selling Egress to Vista Equity's KnowBe4 in 2024 signals serious enterprise pedigree.
This confirms the agent-control-point thesis from previous issue is accelerating.
Epiq acquires Canopy for breach response
Legal tech is moving into breach response infrastructure.
Epiq closed the acquisition of Canopy on September 25, integrating the startup's agentic AI platform for data assessment, sensitivity detection, and impact identification into Epiq's Service Cloud [Source: Legal Technology]. Canopy's patented automation cuts incident response timelines by flagging exposed records and affected individuals without manual review. The move positions Epiq to bundle breach response into its enterprise incident-handling workflows.
Watch whether other legal-tech platforms now rush to acquire breach-response capabilities.
The Week's 10 Biggest Funding Rounds: Cybersecurity, AI And ...9 hours ago ... So far this year, global startups have secured at least 114 Series A rounds of $100 million or more, per Crunchbase data. That's the highest annual... M&A - ...news.crunchbase.com

Island and Cyera each raised $400 million in cybersecurity funding this week, leading the sector's major rounds. Island, a Dallas-based developer of secure enterprise digital operations tools, closed a Series F round led by Evolution Equity Partners at a $6.4 billion valuation, more than double its 2024 valuation. Cyera, a New York-based enterprise data security provider, secured a Series G extension round also led by Evolution Equity Partners and backed by Goldman Sachs Growth Equity, bringing its total funding to $2.7 billion. Both deals were announced during the week of September 19-25, 2026, per Crunchbase data.
Epiq acquires data breach response tech company Canopy10 hours ago ... The acquisition enables organizations to manage cyber incidents more efficiently and accurately by combining the Canopy platform with the global scale, cyber ...legaltechnology.com

Epiq acquired Canopy, a data breach response technology company, on September 25. The acquisition combines Canopy's patented platform—which assesses exposed data, detects sensitive information, and identifies impacted individuals using agentic AI for automated review—with Epiq's global scale and cyber expertise. The Canopy platform will be integrated into Epiq AI and made accessible through the Epiq Service Cloud to help organizations manage cyber incidents more efficiently and reduce risk exposure through proactive preparedness and strengthened post-event response.
Outerlimit Raises $16 Million Pre-Seed To Launch Zero Trust ...10 hours ago ... Outerlimit, a New York-based cybersecurity startup, has emerged from stealth with $16 million in pre-seed funding from AlbionVC, Evolution Equity Partners, ...pulse2.com
Outerlimit, a New York-based cybersecurity startup founded by Tony Pepper, Neil Larkins, and Dr. Peter Vincent, has raised $16 million in pre-seed funding from AlbionVC, Evolution Equity Partners, and Crane Venture Partners. The company is developing a decentralized security platform that extends Zero Trust principles to control individual actions taken by autonomous AI agents within enterprise environments. Pepper and Larkins previously led Egress Software, which was acquired by KnowBe4 (a Vista Equity Partners portfolio company) in 2024. Outerlimit's platform addresses security gaps in existing identity and access management systems by providing cryptographically enforced authorization at the individual agent action layer, with a phased deployment approach covering discovery, visibility, and deterministic enforcement. The startup has already partnered with Fortune 500 and FTSE 100 companies and has attracted strategic angel investors including Brian Murphy (founder and CEO of ReliaQuest) and Scott Price (founder and CEO of A-LIGN).
EU Cyber Resilience Act Reporting Is Now Live: A 7-Step Plan for ...11 hours ago ... ... breach-notification laws. Then test the process with a tabletop exercise ... Cyber Security Incident Response Team (CSIRT). + Follow x Following x ...jdsupra.com

The EU Cyber Resilience Act's reporting requirements took effect September 11, 2026, and manufacturers of products with digital elements sold in the EU now face a 24-hour reporting clock for actively exploited vulnerabilities and severe incidents. The law applies broadly to software, hardware, and connected devices, with maximum administrative fines of 15 million euros or 2.5% of worldwide annual turnover for noncompliance. Manufacturers must submit reports through ENISA's CRA Single Reporting Platform with tiered deadlines: early warning within 24 hours, vulnerability or incident notification within 72 hours, and final reports within 14 days to one month depending on category. The reporting obligations apply even to products sold before the December 11, 2027 product-compliance deadline, and US companies selling into the EU are treated as manufacturers with full reporting duties. Additional product-security requirements take effect December 2027, including secure-by-default configurations, automatic security updates, and protection against known vulnerabilities, with penalties enforced by Member States within the maximum thresholds.