TL;DR: Most enterprises deploying AI in 2026 can’t tell the difference between human activity and AI agent activity inside their own systems. That visibility gap has quietly become one of the biggest blockers to enterprise AI adoption. Cyera built a platform aimed at closing that gap, and investors just priced that bet at $12 billion, raising $600 million at an implied 80x ARR multiple. Five acquisitions and 20% of the Fortune 500 as customers later, Cyera is now racing to own the full AI governance stack. A pending $1 billion deal to add non-human identity management is the latest move in that direction.

Most enterprises deploying AI in 2026 have a problem they haven’t solved yet. According to a Cloud Security Alliance survey, 68% of organizations cannot tell the difference between human activity and AI agent activity inside their own systems. They’ve built out the models, the compute, and the workflows. What they haven’t built is the layer that governs what AI can actually see and do.

That gap is where Cyera has planted its flag. More importantly, investors are pricing that position very aggressively.

Reports from June 2026 put Cyera’s ARR above $150 million. Cyera disputed those figures, and the company has never publicly disclosed its ARR. What it did confirm, in its official Series G announcement, is that it tripled ARR three consecutive years in a row. At a $12 billion valuation, the implied multiple from reported figures lands at 80 times ARR, higher than most fast-growing AI startups command.

Evolution Equity Partners led the $600 million Series G. Accel, Coatue, Blackstone, Cyberstarts, and Temasek all participated. These aren’t firms writing checks based on momentum alone. After all, firms at this stage are betting on where a market is headed, not just where it stands today. So what are they actually seeing?

The short answer is this: investors aren’t valuing Cyera as another cybersecurity startup. They’re betting it could become the infrastructure layer enterprises rely on to govern AI itself.

AI Didn’t Create the Data Security Problem. It Made It Unavoidable.

Cloud adoption created the original complexity. Enterprises spent a decade moving data into cloud environments, and it sprawled fast, across SaaS tools, databases, multi-cloud infrastructure, and now AI systems. Security teams often had no clear picture of where sensitive data sat or who could reach it.

Here’s the difference: AI changed the cost of that messiness. Excessive permissions, unsecured repositories, and unknown data exposure were manageable risks when humans operated at human speed. AI agents operate at machine speed, reading data, calling APIs, and triggering actions across systems continuously. The governance frameworks enterprises built for human users simply weren’t designed for this.

Gartner predicted in 2023 that more than 20% of organizations would deploy DSPM technology by 2026, driven by urgent requirements to identify previously unknown data repositories and mitigate associated risks. That forecast reflected a category moving rapidly from early-adopter curiosity to operational necessity. Cyera was founded in 2021 and emerged from stealth in 2022, right as that shift was beginning.

What One-Fifth of the Fortune 500 Actually Signals

As of its Series F announcement in January 2026, Cyera claimed 20% of Fortune 500 companies as customers, spanning financial services, healthcare, retail, and global telecom.

At first glance, that number may not seem extraordinary. However, it matters far more than it appears. Enterprise security procurement doesn’t move quickly. Vendors go through months of legal review, compliance assessment, and technical evaluation before getting access to sensitive infrastructure. The fact that Cyera cleared that bar at 20% of the largest companies in the world, within four years of its founding, is a signal worth sitting with.

It doesn’t prove retention, expansion revenue, or long-term stickiness; Cyera hasn’t disclosed any of that. What it does show is that the platform earned organizational trust at scale, in the kinds of environments where trust is hardest to earn. In other words, that’s a very different signal from ARR growth alone.

A Platform Being Built in Real Time

Look closely at how Cyera has spent its capital, and the strategic intent becomes clear.

Between October 2024 and June 2026, Cyera completed five acquisitions. Trail Security came first, acquired for a confirmed $162 million, adding data loss prevention capability. Ryft followed, which Cyera described as a secure and automated data lake built for AI agents, with media reports estimating the price at $100 to $130 million. 

Genie Security, an endpoint DLP startup founded in late 2025, was reported at approximately $50 million. Otterize and Shape AI, both focused on non-human identity, were acquired in between. Cyera did not officially confirm the prices of those latter acquisitions.

None of these appear to be defensive moves. Each one filled a specific capability gap in a platform that Cyera was actively assembling. DSPM, DLP, identity, agentic security: the pieces are being connected deliberately.

Then in July 2026, Cyera signed a letter of intent to acquire Oasis Security for $1 billion, pending close. Oasis specializes in non-human identity, the governance of AI agents and what they’re permitted to access. That acquisition, if it closes, would stitch together data intelligence and machine identity governance on a single platform, something no competitor currently offers at that scale.

And this week at Black Hat, Cyera launched Agent Guardian and Cyera Endpoint, new capabilities that secure enterprise AI agents by providing visibility into agent activity, governing what they can access, and enforcing runtime controls across cloud and endpoint environments.

The platform isn’t a pitch deck anymore. It’s shipping.

The Valuation Is a Bet on Where the Category Is Going

You could argue that investors are betting data security will consolidate around a smaller number of broader platforms. If Cyera becomes one of them, its value will eventually depend more on platform position than current revenue.

Cyera’s valuation progression tells part of the story: $1.4 billion in April 2024, $3 billion in November 2024, $6 billion in June 2025, $9 billion in January 2026, and $12 billion in June 2026. Revenue more than tripled for three consecutive years. More tellingly, the valuation grew even faster than that, which means investors are pricing something beyond current growth.

They appear to be pricing category ownership. Enterprise software categories historically consolidate around one or two dominant platforms. The window to become one of them is shorter than it appears, and once large enterprises standardize on a security vendor, the switching costs: technical, organizational, and contractual, become a real moat. That thesis is unproven for Cyera specifically, but the Fortune 500 penetration and acquisition pace suggest the company is actively trying to make it true.

The Problem the Rest of the Market Is Still Catching Up To

Data security has spent years being treated as a compliance function. Something you buy to satisfy an audit, renew because switching is painful, and deprioritize when budgets tighten.

That way of thinking is becoming obsolete. When AI agents are reading internal databases, calling APIs, and making decisions autonomously across enterprise systems, data governance stops being a compliance question. It becomes an operational one. Cyera framed its entire Series G around building what it calls “the trust layer for enterprise AI,” the infrastructure layer that governs what AI can see and do. You could even argue that’s no longer a security pitch. It’s an infrastructure pitch.

The companies that own infrastructure layers inside the Fortune 500 tend to be very hard to displace. Whether Cyera holds that position, or whether a larger platform absorbs the category around it, is the open question.

What This Actually Comes Down To

The ARR figure is disputed. The company isn’t profitable. The Oasis acquisition hasn’t closed. And a $12 billion valuation for a five-year-old company is not a conservative bet by any measure.

Now, step back for a moment from the funding numbers and look at what Cyera has actually built: five acquisitions that systematically expanded a platform from data discovery into DLP, identity, and agentic security; 20% of the Fortune 500 already inside the platform; over 1,500 employees across 18 countries; and new products shipping at Black Hat that extend the platform to AI agents running on employee devices.

The investors writing nine-figure checks into Cyera aren’t reading the burn rate. They’re looking at where the company sits in the stack, and betting that as AI becomes central to how enterprises operate, the layer that governs what AI can see and do becomes some of the most valuable enterprise infrastructure. 

That’s ultimately what investors appear to see while much of the market still treats Cyera as a security story rather than an infrastructure story. Whether they’re right, and whether Cyera becomes the company that owns that infrastructure layer, is a question the next three years will answer.

Author

She enjoys breaking down complex topics into content that feels clear, useful, and easy to connect with. When she isn’t writing, she’s usually lost in a book or spending time with her three cats who bring equal parts chaos and companionship to her day.Follow Poulami on LinkedIn.

Write A Comment