New York’s Next Line of Defense: Cybersecurity Companies to Watch
August is a fitting month to take a closer look at cybersecurity.
Earlier this month, hackers, security researchers, and cybersecurity leaders descended on Las Vegas for DEF CON, one of the world’s biggest gatherings of the hacking and security community.
And summer itself can be an especially vulnerable time for companies, as vacation schedules and reduced IT staffing can create longer response times and fewer eyes watching for suspicious activity, giving attackers more room to operate.
At the same time, the threat landscape is only getting more complicated. AI is making it easier to launch sophisticated phishing and social-engineering campaigns, while companies are adopting new AI tools and agents that introduce an entirely new set of systems, data, and permissions to secure.
Investors are taking notice and New York’s cybersecurity ecosystem is seeing significant growth.
NYC-area cybersecurity companies have raised $2.3 billion across 45 VC deals so far in 2026, according to PitchBook data.
That’s already more capital than the sector raised in all of 2025, when New York cybersecurity companies brought in just under $2 billion across 75 deals.
It also puts 2026 on track to be one of the strongest funding years for New York cybersecurity startups in recent years.
The opportunity is producing a new generation of New York founders tackling security from different angles — helping companies safely deploy AI, finding vulnerabilities before attackers do, simplifying security for smaller organizations, and protecting the increasingly complex systems businesses rely on every day.
Against that backdrop, we caught up with four NYC builders working on the next generation of cybersecurity.
For this edition of Companies to Watch, meet:
Kyle Bhiro, founder, Pensar
Khadem Badiyan, founder, Polyguard
Rohan Kumar, founder, QuickSecure
Katie Kuzin, founder, Spotlight Security
Pensar
“I was born here, went to college here, and started Pensar here. It’s New York or nowhere for me.”
What does your company do? What problem is it working to solve?
Threat actors are using AI to hack at a speed and scale that human security teams can’t match. Pensar deploys offensive security agents to continuously attack your systems and uncover vulnerabilities before threat actors do.
A question we like to ask every founder — why New York?
My story is a New York story. My mom worked in the Twin Towers and my dad was an electrical contractor on the Freedom Tower. I was born here, went to college here, and started Pensar here. It’s New York or nowhere for me.
You help run the monthly AI Demos series with Tech:NYC and Two Trees — what have you learned from putting the product in front of people live, and has that changed how you build or talk about Pensar?
What makes AI Demos a great event is the fact that it’s all live. I give huge kudos to everyone who gets on stage because that means they have some degree of confidence in their product.
Mark Dorsi, CISO of Netlify and Advisor of Pensar likes to say our product “has to be like Levis jeans… it just works.” There’s no smoke and mirrors, doing a live demo means you have a real product that actually does what it says it does.
As coding agents write a larger share of production software, do you think security ultimately becomes agent-vs-agent, with one AI writing code and another continuously trying to break it? What does that world look like five years from now?
This is already the reality. We’re seeing an arms race of sorts taking off. As quickly as we’re developing ways to harden our systems, there are those who wish to do us harm by moving just as fast… if not faster. The ability to horizontally scale your efforts with AI is a huge step. But what’s next? I think we’ll be welcoming agents into restricted environments and giving them unfettered amounts of context. We’re starting to see the beginning of this.
What have you learned from real customer deployments that surprised you most, either about how attackers behave or about what security teams actually want automated?
Unfortunately, most teams are not equipped to handle the threats in front of them. Earlier this year, Cal.com one of the largest public, production-grade Next.js codebases, made the difficult decision to go closed source. Peer Richelsen, Co-Founder of Cal.com made an honest post about why, stating that “unless you have a $100M security budget,” there’s no keeping up. He’s right. S-tier is a dedicated team of security researchers focused on your threat model. Only now is it possible to have agents do this on our behalf. For our customers, that’s what Pensar is.
What was the moment when Pensar went from an interesting technical idea to something you knew companies would actually pay for?
Early on in our journey, a large financial institution was evaluating our product. They pay for every tool under the sun, have an internal team of pentesters, and get regularly 3rd party pentested. Their criteria for our pilot was simple: “Surface one critical finding and we’ll turn Pensar on.” We found six. We’ve been pretty uphill since.
What’s a belief you have about the future of cybersecurity that others in the space still disagree with?
Early on in our journey, a sentiment shared with us was that “if you’re going to build a great security company, you have to build on the West Coast” and I couldn’t disagree with that more. Exhibit A. Datadog. Built right here in NYC. I believe we’re going to be successful and NYC is a huge reason why. A large portion of our customers are a subway ride away, there’s really strong talent in all boroughs, and access to the right capital partners.
Time for some New York-themed rapid fire questions — where is your favorite place to grab a slice of pizza in New York?
Upside Pizza near the Pensar office. We order large pies by the dozens for events.
Where is your favorite coffee shop in New York?
Abraco on E 7th St. Not a place to do laptopping, just good coffee.
Do you have a favorite spot to escape the noise of the city?
Gratefully, I don’t have to go very far to get some quiet. Without exposing my opsec, I like to get a deli breakfast and hangout in a park near my apartment. Nothing can bother me.
What’s one piece of advice — that you’ve shared or was shared with you — on building a startup in New York City?
The reason I love living here is because of the people. A wide array of people. I socialize with friends in publishing, finance, entertainment… and of course tech. Constant idea sharing and stimulation makes me feel pretty alive. As it pertains to building Pensar, it’s those same relationships and asking for help that has gotten us to this point. I think that makes NYC really special.
Polyguard
“I chose New York for the serendipity. The intro you didn't ask for, the customer you meet at a gelateria at 10pm. Early-stage companies run on those unplanned collisions.”
What does your company do? What problem is it working to solve?
Recruiters are drowning in thousands of applications with no human behind them. Companies are discovering the person they hired isn’t the person they interviewed. These are early symptoms of the same shift. Every digital interaction rests on assumptions AI is breaking: that someone is present, that they have intent, and that they are who they claim.
Polyguard makes all three provable again. Faces, voices, and documents were only ever stand-ins for trust, and AI can now fake them all. We replace stand-ins with proof, starting with hiring and extending to help desk resets, payments, and anywhere trusting a human matters.
A question we like to ask every founder — why New York?
We built Polyguard here partly because our buyers, in finance, healthcare, and insurance, are within a few square miles. But I chose New York for the serendipity. The intro you didn't ask for, the customer you meet at a gelateria at 10pm. Early-stage companies run on those unplanned collisions. San Francisco has that for startups; New York has it for everything. Within two blocks of wherever you stand, there's a world-class drummer, economist, chef, founder. When you're building something that touches many industries at once, that breadth of luck is the whole game.
What have you learned from early Polyguard customers that has most changed the product roadmap?
Frequency drives learning. We started with a threat companies face once or twice a year, and when your product prevents something that rare, feedback barely exists. Nothing happens, and you’re not on anyone’s mind. When we shifted to a problem our customers face every day, thousands of AI-generated job applications, everything changed.
We ship something and hear about it tomorrow, because they see the impact daily. Customers are the only thing that should dictate your roadmap, and solving a daily problem is how you earn enough feedback to let them. For an early-stage company, quicker loops compound.
How do you think about the balance between making verification more secure and keeping it frictionless for users?
Historically, frictionless wins every time. Friction hits the top line directly, so the answer to every security concern has been detection and behavioral biometrics, using the signals already present in a session to spot abnormalities without ever interrupting the user. The problem is that any session carries a finite number of signals, and every one of them is knowable, reproducible, and fakeable. That hasn’t been abused at scale yet. I don’t see a future where it stays that way. My take is that over time, friction becomes the feature, and the difference will be in its taste and necessity.
Attackers are going to keep getting better very quickly. What do you think the identity-fraud landscape looks like three years from now, and what does Polyguard have to become to stay ahead of it?
In three years, an identity attack will cost almost nothing to run once, and nothing more to run a million times. I think we’ll see the division of KYC and identity-fraud tooling, because KYC was never built for fraud’s attack vectors and is by definition behind. The durable move is to reprice the attack itself.
For Polyguard, staying ahead means becoming less of a product and more of a layer: proof of a real, accountable person that any workflow can call on demand, expensive to fake once and impossible to fake at scale.
What’s a belief you have about the future of cybersecurity that others in the space still disagree with?
That detection is a dead end. Most of the industry still invests in classifiers that spot artifacts in synthetic media, and those artifacts are disappearing on a predictable curve. Worse, generative models train directly against detectors, so every improvement in detection is training data for the next generation of fakes. We didn’t solve counterfeit websites by getting better at spotting them; we solved it with certificates. Identity will follow the same path, toward provenance and proof instead of forensic guesses.
Time for some New York-themed rapid fire questions — where is your favorite place to grab a slice of pizza in New York?
L’Industrie in Williamsburg. I will not be taking questions from the Joe’s loyalists.
Where is your favorite coffee shop in New York?
Outro NYC, near Union Square. Go in, then out the back, and you’ll see why.
Do you have a favorite spot to escape the noise of the city?
Southold, out in North Fork. Ocean, vineyards, and dark enough skies to see the stars.
What’s one piece of advice — that you’ve shared or was shared with you — on building a startup in New York City?
Say yes to the odd invitation, and invite them. The Shabbat dinner, the jam poetry night, the thing with no obvious payoff. New York pays out on presence, and you never know which room changes the company.
QuickSecure
“The talent here is remarkable, and there is a certain grit you pick up just walking around the city that seems to work its way into how a team operates.”
What does your company do? What problem is it working to solve?
QuickSecure is an all-in-one school safety and operations platform. When an emergency happens, we make sure teachers, staff, and first responders are working from the same information instead of five disconnected systems.
Our biggest goal is to arm the people on the ground with what they need in the moment it matters. On the other end of the spectrum, we also handle the day to day, from drills to visitor management to daily operations, taking work off the plate of staff who already have plenty on it.
A question we like to ask every founder — why New York?
The talent here is remarkable, and there is a certain grit you pick up just walking around the city that seems to work its way into how a team operates.
The education landscape mattered a lot too. Between the public system and the independent and charter networks, there is an enormous amount happening here, and being close to it helps us learn faster. We work out of the Gutter Capital office on Canal Street in Chinatown, and we plan to keep building here for a while.
What have you learned from working directly with schools that most changed your original vision for the product?
That showing up in person matters more than anything else we do.
We came in thinking the hard part was the technology. What we learned from working alongside our schools is that being there with them, walking their buildings, sitting in on their drills, and going through onboarding side by side, is what actually makes the product good. Almost every meaningful change we have made came out of something we saw in person rather than something we were told in a meeting. It is also our biggest differentiator. Most vendors in this space sell a system and disappear.
How do you think about building both hardware and software at such an early stage? Does owning both give you an advantage?
At QuickSecure we believe hardware matters enormously. The software layer is what connects the right people to the right information, but hardware is what turns that understanding into action inside the building.
That is true whether it is our own lockdown system or the infrastructure a school has already invested heavily into. Cameras, locks, and intercoms are already on the wall, and asking a school to start over is neither realistic nor fair.
If QuickSecure works exactly the way you hope, what does the company become five or 10 years from now?
The thing we care most about is reaching the schools that have been underserved by the incumbents.
That includes the small private school balancing safety spending against keeping the lights on, and the large county that has not found a platform flexible enough for how they actually operate. Both of them tend to get told they are the wrong size or too complicated. We would love for that to stop being the answer, and for schools across the country to have real safety infrastructure regardless of budget or complexity.
What’s a belief you have about the future of cybersecurity that others in the space still disagree with?
We do not have a particular position here, since we are a broader safety company rather than a cybersecurity one. But we think about it constantly.
Protecting schools makes us a likely target, so being prepared and forward thinking about our own security is not something we can treat as secondary. That comes from leveraging AI well, hiring exceptional people, and working with serious partners in the industry. It is easy to talk about security as a product. We would rather it be something we practice internally first.
Time for some New York-themed rapid fire questions — where is your favorite place to grab a slice of pizza in New York?
Lucia Pizza of SoHo.
Where is your favorite coffee shop in New York?
Derby Coffee.
Do you have a favorite spot to escape the noise of the city?
I am probably the wrong person to ask. We do not really want to escape it. The hustle and bustle is a big part of the charm, and it is one of the things we like most about being here.
What’s one piece of advice — that you’ve shared or was shared with you — on building a startup in New York City?
Build the thing nobody else wants to build. New York has no shortage of people working on the elegant problems. The industries still running on legacy systems are wide open, and the people inside them are usually thrilled that someone is finally paying attention.
Spotlight Security
“New York rewards proximity, and almost every good thing that happened to Spotlight started as an in-person conversation.”
What does your company do? What problem is it working to solve?Spotlight Security builds AI security agents for hardware that can’t afford downtime, focused on manufacturing and gaming.
Most security tools find problems and leave you to triage and patch them. In the environments we focus on, the equipment is hardest to reach and least likely to get patched, so the list of problems just grows. A two-person IT team at a manufacturing plant is not short on alerts.
Our agents map every device on the network, find the threats, explain them in plain English, and fix them remotely. We work on the devices standard IT tools can’t actively manage.
A question we like to ask every founder — why New York?
Density is the real advantage. In one week we can sit with an infrastructure operator, an investor, and a design partner in person, without getting on a plane.
The talent is here too. We hired senior engineering roles out of the city.
I’m an artist (https://www.kuzinartstudios.com) and Alex is a writer. The energy and diversity the city provides gives us creative energy we use to recharge and ultimately feed into Spotlight.
A lot of utilities and smaller infrastructure operators have tiny security teams and limited budgets. How has building for that customer changed the way you think about product design and pricing?
It made us ruthless about delivering value on day one with limited work to get up and running. A one-person IT team does not need a dashboard, they need the fix executed. So we designed for zero added headcount: the Spotlight agent surfaces a list of easily explained to-dos to the one-person IT admin, finds anomalies, and logs all actions.
To reach as many people as possible we’re launching self-serve on October 1 at $10 per endpoint, with ten free agents and a free trial. A manufacturing IT manager can try it without opening a procurement cycle or sitting through a sales process.
There’s a trust hurdle in letting an AI agent change configurations or remediate something on a live industrial system. How do you earn that trust from customers, and where do you deliberately keep a human in the loop?
We start with boring. The first thing we deliver is a map of the fleet with nothing changed, so the customer sees we’re accurate to build trust. Permissions are tiered, and a human approves anything that touches a live device.
We also let the operator own the schedule. A reboot during a production shift is a dealbreaker. Most of the trust comes from the customer keeping control of timing and scope.
As AI gets better, what part of cybersecurity do you think is going to change the fastest?
It already changed. One in four malicious breaches is now AI-enabled, up 56% in a year, and 62% of those attacks hit critical infrastructure. Uncensored attack models like WormGPT and FraudGPT have sold for as little as $200 a month.
Anthropic disclosed the first large-scale cyberattack run with almost no human involvement, an agent working through about 30 targets on its own.
Defenders haven't caught up. Our north star is a defensive AI ecosystem as strong as the offensive one.
So the thing we are changing fastest is remediation, because today it’s the only part still moving at human speed.
What’s a belief you have about the future of cybersecurity that others in the space still disagree with?
Alerts are worthless.
The industry still sells visibility and treats remediation as somebody else's problem. Usually the customer’s, or an expensive professional services contract sold by — guess who — the same people who sold you the visibility layer. The visibility layer SaaS sellers.
At Spotlight we think the only defensible product is the one that acts swiftly and within the bounds of human control.
Time for some New York-themed rapid fire questions — where is your favorite place to grab a slice of pizza in New York?
Joe’s on Bleeker and Carmine’s.
Where is your favorite coffee shop in New York?
Cafe 9 in Astoria. I love working from the back patio.
Do you have a favorite spot to escape the noise of the city?
TFANA (Theatre for a New Audience). The way they designed their stage is totally soundproof (the stage and audience is suspended on 3 feet of rubber supports) so you never hear outside noise or feel the subway rumbling underneath you.
What’s one piece of advice — that you’ve shared or was shared with you — on building a startup in New York City?
New York rewards proximity, and almost every good thing that happened to Spotlight started as an in-person conversation. The density of the city gives you an unfair number of personal connections and fun run-ins that become points of serendipity for your company.
Ask for the thing while you’re still in the room.

