Dossier · Acquired asset · 4 independent sources
empow
Last updated: Jul 31, 2026
empow was an Israeli security-analytics company that developed an AI-assisted SIEM and XDR platform for correlating heterogeneous telemetry, inferring attacker intent, and orchestrating adaptive response. Cybereason acquired the company in July 2021 and announced that its technology and team would be incorporated into Cybereason XDR; Empow is no longer a standalone operating company.
Company Overview
empow developed an AI-powered security information and event management platform for turning fragmented security telemetry into decisions and response actions. Its product model was broader than a conventional log-search interface: it sought to understand the intent behind data generated by existing network and security infrastructure, determine whether separate observations represented a real attack, and adapt the response to the threat. Cybereason's acquisition announcement specifically describes a patented machine-learning prediction algorithm that correlated endpoint, network, identity, and application telemetry, together with an adaptive decision-making engine and predictive response capabilities. This is a credible description of security-operations automation, although the public record does not establish the algorithm's performance relative to current foundation-model or modern data-lake approaches. The available evidence describes the capability at the product and acquisition level; it does not justify treating marketing language about prediction as independently validated detection efficacy.
The target customer problem was persistent alert overload in enterprise security operations. Financial institutions and other large organizations often operate many partially overlapping firewalls, endpoint products, email gateways, identity systems, cloud services, and threat-intelligence feeds. A platform that can normalize those inputs, reduce duplicate or low-confidence alerts, and present an attack sequence can lower analyst workload and shorten the time from detection to containment. empow's reported integration library, which Cybereason said covered more than 70 IT and security vendors, was commercially important because integration breadth is a practical barrier to SIEM, SOAR, and XDR adoption. The trade-off is that integration maintenance, data quality, deployment permissions, and customer-specific tuning can determine whether an apparently intelligent workflow works in production. Historical coverage also points to native UEBA and an i-XDR product, but those announcements are evidence of product direction rather than proof of durable market share.
The acquisition is the clearest public traction signal and the most important current status fact. Cybereason stated that empow's predictive response technology, integrations, and engineering and product talent would be folded into its XDR offerings; the announcement also quotes empow founder and CEO Avi Chesla. Startup Nation Central records empow as acquired and inactive, with a July 2014 founding date, Ramat Gan location, 1–10 employees, historical total funding of $21 million, and an undisclosed July 2021 exit. Those records support a product and commercialization history, but they do not prove continuing empow revenue, a standalone product roadmap, named customers, or successful post-acquisition deployment. The later acquisition of Cybereason by LevelBlue in November 2025 adds another layer of ownership and makes independent diligence on empow's surviving technology especially difficult. A current researcher should therefore follow the technology through Cybereason and LevelBlue product, patent, and personnel records rather than search for a presumed active Empow business.
Competitive pressure was substantial. empow operated at the intersection of SIEM, SOAR, UEBA, and XDR, competing with established platforms such as Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar, Exabeam, Securonix, and LogRhythm, as well as endpoint vendors extending into XDR. Its plausible edge was not raw telemetry collection; it was intent-oriented correlation and a predictive response layer that could use existing tools. That differentiation would only be durable if it produced measurable reductions in false positives, analyst handling time, or dwell time and remained explainable enough for security teams to trust automated recommendations. The acquisition itself is evidence that Cybereason saw strategic complementarity, but it is not evidence that Empow won a head-to-head category position or that all of its capabilities survived integration.
The defense and national-security case is substantive but bounded. Military, government, and critical-infrastructure SOCs face the same multi-source telemetry, scarce analyst, and rapid-containment problems as commercial enterprises, and cross-domain correlation plus response prioritization can be useful in those settings. However, the public evidence shows commercial security positioning and an acquisition into an enterprise XDR product, not a confirmed defense deployment, government contract, classified workload, or accreditation. Any defense adoption would require validation on mission-specific data, support for segmented or disconnected environments, clear human authorization controls, reproducible model behavior, and evidence that automation does not create dangerous false positives. Data sovereignty, cross-domain transfer restrictions, and the need to preserve forensic auditability would be especially important in government environments. empow is therefore best represented as a historically relevant dual-use security-analytics asset whose strategic value lies in technology transfer and acquisition fit, not as an active strategically relevant startup.
Dual-Use Assessment
The underlying capability has substantive dual-use potential because correlating endpoint, network, identity, and application telemetry and prioritizing response are relevant to enterprise, government, critical-infrastructure, and military SOCs. The evidence supports technical adjacency and acquisition interest, but does not confirm defense customers, classified deployments, or accreditation; the defense case therefore remains conditional on mission-specific validation and controlled human authorization.
Strategic Fit Assessment
empow is not a current standalone investment candidate: the company was acquired by Cybereason in July 2021 and is recorded as inactive. Its technology offers a credible strategic-security case, but ownership, product continuity, financial performance, customer retention, intellectual-property transfer, and post-acquisition outcomes are not sufficiently public for a current standalone priority signal.
Strategic Value to U.S.-Israel Alliance
The strategic value is as an acquired security-analytics capability that could strengthen XDR by making heterogeneous telemetry more contextual and response workflows more predictive. It is relevant to national-security analysis as a model of how Israeli cyber technology can be absorbed into a larger platform, while the absence of public evidence for defense deployment limits claims about operational mission value.
Key Technologies
- Machine-learning prediction of attacker intent and next steps
- Semantic or intent-aware interpretation of security events
- Cross-domain correlation of endpoint, network, identity, application, and cloud telemetry
- Adaptive decision-making and predictive response orchestration
- SIEM, UEBA, and XDR workflow automation
- Prebuilt integrations with 70+ IT and security vendors
Use Cases & Applications
- Enterprise SIEM enrichment and attack-sequence reconstruction
- SOC alert deduplication, prioritization, and analyst triage
- Correlation of endpoint, identity, network, email, and cloud indicators
- Adaptive recommendations for containment and preventative response
- XDR telemetry and response integration inside Cybereason
- Financial-services security operations with heterogeneous controls
- Government or defense SOC augmentation subject to disconnected-environment and human-approval validation
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 4 public references used for company identity, status, positioning, or material-claim review.
Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- cybereason.com Public source used for profile verification.
- finder.startupnationcentral.org Public source used for profile verification.
- cybereason.com Public source used for profile verification.
- calcalistech.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.