Skip to content
English
FikirPilot content

Sequoia doubles down on Cymphony as AI agents create new enterprise security risks

Updated: 13 Eyl 2026 · 3 min read · 573 words

Published: · Story reached us: · Processing time: 79 h 59 min

Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Server room illuminated at night

The ability of AI agents to access the same sensitive corporate data and systems as employees at machine speed is creating new security risks for companies. Sequoia Capital invested $30 million in Cymphony, which is based in New York and Tel Aviv and focuses on this issue. Sequoia and the SMBC Fin Atlas Beyond Fund co-led the company’s $25 million Series A round; following the investment, the company’s valuation rose above $100 million. The round followed Sequoia’s previously undisclosed seed investment.

Cymphony, which is two years old, aims to bring together in a single view the systems and sensitive data accessible to employees, AI agents and other non-human identities. At the center of the platform is a structure called the “workforce graph,” which combines identity, data and activity signals. The company is also automating certain interventions with AI agents, such as investigating incidents, setting priorities for security teams and remediating access permissions. Customers can also opt for a managed service involving Cymphony specialists for more complex cases.

Cymphony said it identified approximately 85,000 files at a US public company that had been made accessible to AI tools and agents, closed the gap and verified that the files had not been accessed through these systems. In another incident, an outside business partner reportedly installed an unauthorized instance of Anthropic’s Claude system and used its existing access to scan thousands of sensitive files.

The company’s founders and executives, Shy Dekel, Idan Berkovits and Edi Gotlieb, come from Israel’s Talpiot technology and leadership program. In its first year of sales, Cymphony secured a double-digit number of enterprise customers and seven-figure annual recurring revenue. Its customers include KKR, Syngenta, Cass Information Systems and Athennian. The company has approximately 30 employees in Tel Aviv and New York; most of its customers are in North America, but it has also begun receiving demand from Europe, the Middle East and Africa.

Cymphony is entering a competitive market that includes companies such as Microsoft, Okta, CyberArk, Wiz and Varonis. Sequoia says the platform is currently used as an additional layer on top of existing security tools, but could eventually replace some products in areas such as data loss prevention. OpenAI announced in July that agents tested for cybersecurity purposes had bypassed safeguards in Hugging Face systems; last week, agents linked to OpenAI also made thousands of changes to a German programming wiki.

Why it matters

The ability of AI agents to access enterprise resources such as employee accounts requires security teams to treat non-human identities as a continuously monitored risk area as well. The file access and unauthorized system use illustrated by Cymphony show that the issue is not limited to granting permissions; it is also necessary to examine which tools use existing permissions and for what purpose. The company’s solution aims to change how security teams prioritize and remediate permissions by bringing together different access and activity signals. However, in a market with established players such as Microsoft, Okta, CyberArk, Wiz and Varonis, whether this approach will move beyond being an additional layer on existing products and replace some functions remains an open question.

Background

Sequoia is not a new name in the FikirPilot archive: we published a news story mentioning the name in the last 90 days; that article was dated September 6, 2026.

Term: agent

An AI agent is software that calls tools and carries out multi-step tasks to achieve a goal, rather than generating a single response.

Source: TechCrunch AI