Cyber asset management: Why ThreatAware’s $25m bet could redefine secops

For years, security operations teams have been drowning in point tools, each producing its own alerts, blind spots and data formats. ThreatAware’s $25 million raise from One Peak is a bet that cyber asset management can become the connective tissue for modern SecOps.

That is because the first rule of security still applies: you cannot protect what you cannot see, a point echoed in our interview with Rik Ferguson of Forescout. ThreatAware says its own data shows 10% of devices accessing corporate networks go undetected by existing tools, while 30% of security controls are missing, misconfigured or failing silently.

Cyber asset management moves beyond inventory

ThreatAware’s pitch is that cyber asset management should not stop at discovery. Its platform is built to detect every device, validate each security control and identify gaps missed by other systems. That matters as enterprises consolidate security operations and rethink tool sprawl, especially when many CISOs are under pressure to reduce overlapping platforms.

The company’s trajectory is also unusual. 

ThreatAware reached profitability and more than 100 enterprise customers across sectors including retail, financial services and energy before taking external capital. The $25 million is therefore less a rescue round than a scale-up fund for North America and the launch of its AI security workspace.

That workspace is the more interesting part. 

In practice, it could turn cyber asset management into a working control plane: one place to query asset state, validate controls, trigger remediation and build workflows. This is in line with our coverage of AI-driven security operations, where data quality and integration matter as much as automation.

The competitive field is crowded. 

Axonius, Armis, JupiterOne and Sevco Security all speak to parts of the same problem. ThreatAware’s differentiation is its focus on cyber hygiene validation, not just asset discovery. For buyers, the key questions are coverage depth, integration breadth, AI query quality and whether the platform can provide evidence that controls are actually working.

The bigger trend is SecOps platform consolidation. 

As we noted last year in our interview with Andy Norton of Armis, unified exposure management depends on asset intelligence, risk prioritisation and operational context.

ThreatAware’s bet is that cyber asset management becomes the foundation for that model. The challenge now is execution: scaling fast in North America without losing the product discipline that made ThreatAware fundable in the first place.

About The Author

Kihara Kimachia
Kihara Kimachia

Kihara Kimachia is a seasoned technology writer and journalist with more than 20 years of experience. He's a contributor at TechFinitive where he covers Enterprise technology and has written for publications such as TechRepublic, eSecurity Planet and The Epoch Times.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.