Saturday, 22 August 2026 · Europe
EUR/USD 1.17 EUR/GBP 0.8567 EUR/CHF 0.9353 EUR/PLN 4.308 All rates →
Sign in · Join
EUROPES The European Report
European Edition Saturday, 22 August 2026
LATEST
Tech & Startups

Act Security raises $60m to replace cloud patching with strict access controls

Act Security raises $60m to replace cloud patching with strict access controls

Israeli cybersecurity startup Act Security has secured $60m in funding to shift enterprise cloud defence away from endless vulnerability patching toward strict access control, challenging a decades-old industry model strained by artificial intelligence.

Act Security launched on Tuesday after raising $60m in venture capital. The Israeli startup secured a $20m seed round led by Team8 and Bessemer Venture Partners, followed by a $40m Series A led by Notable Capital with backing from Lux Capital.

Founded in 2025 by the team that previously sold Medigate to Claroty for roughly $400m, the company argues that artificial intelligence has broken traditional cloud defence. Chief executive Jonathan Langer says Anthropic’s Mythos confirmed that the industry cannot simply fix the issue with faster updates, stating, “We can’t patch our way out of everything.”

The first major hurdle is the sheer volume of new threats. The Forum of Incident Response and Security Teams projects approximately 59,000 new common vulnerabilities and exposures this year, averaging 161 daily. Recent patch cycles highlight this strain, with Oracle fixing over 1,400 flaws, Microsoft patching a record 622, and Chrome addressing 429 in a single release.

The second issue is dormant cloud permissions. Act estimates that nearly 97 per cent of cloud access at its customers remains unused but live. When artificial intelligence agents inherit these permissions, they turn quiet sprawl into an active threat if misconfigured or hijacked.

Langer notes that visibility tools “surface thousands of findings” while “the root cause, the access architecture, goes unaddressed.” He added that agents run “at machine speed, with none of the judgment a person would apply,” which can facilitate rapid lateral movement across an environment similar to a rogue OpenAI model spreading through Hugging Face.

Rather than chasing individual flaws, Act’s platform removes the conditions that make them exploitable by reasoning over identity and network reachability. It enforces tight boundaries around users, workloads and agents using existing cloud controls and pushes these limits into software pipelines.

Crucially, the system simulates changes before applying them to avoid disrupting legitimate business operations. This reflects the founders' experience securing hospital devices at Medigate, where an overly restrictive rule could cause as much damage as a loose one.

The investment arrives alongside a broader wave of Israeli access-security deals, including Way Security and Mate Security. For European enterprises and investors, Act’s success will test whether action-centric security can outperform incumbent cloud posture and entitlement management tools.

The company's ultimate edge rests on enforcing safer access without breaking legitimate workflows. If Act proves this model in production, it could redefine enterprise cloud security; if it fails, it will simply add another dashboard to an already crowded market.

More from Tech & Startups