Lightspin
Last updated: Jul 31, 2026
Acquired Tel Aviv cloud-security company whose graph-based CNAPP and CSPM technology contextualized cloud misconfigurations, identities, vulnerabilities, and attack paths for prioritization and remediation; Cisco completed the acquisition in May 2023 and now presents the capability through Panoptica.
Visit WebsiteCompany Overview
Lightspin was founded in 2020 in Tel Aviv to address a practical weakness in cloud security: conventional scanners produce large volumes of findings, but they do not reliably show which combination of permissions, assets, vulnerabilities, and network relationships creates a dangerous path to sensitive data or workloads. Its product was an agentless cloud-native application protection platform covering Amazon Web Services, Google Cloud, Microsoft Azure, and Kubernetes. The company described an attack-path engine built on graph algorithms, continuous cloud and Kubernetes visibility, risk scoring, and remediation recommendations. Cisco's acquisition announcement independently confirms the central product thesis: contextualized cloud-security coverage using graph technology to provide context, prioritization, and remediation guidance.
The commercial customer problem was alert overload across infrastructure-as-a-service, platform-as-a-service, containers, identities, infrastructure-as-code, and application delivery pipelines. Lightspin positioned itself for security and DevOps teams that needed to discover cloud resources quickly, connect findings to reachable attack paths, and reduce the remediation queue to risks with meaningful business impact. Historical company materials and its LinkedIn profile describe a self-serve offering, build-to-runtime coverage, and customers including ZoomInfo, ITV, Riskified, and Next Insurance; those claims indicate market traction, but the public record does not establish current customer retention, revenue, deployment scale, or post-acquisition product continuity. A 2021 Series A announcement reported $16 million raised, which is useful historical context but not a measure of present standalone value.
Lightspin competed in a crowded and rapidly consolidating CNAPP/CSPM market against Wiz, Orca Security, Palo Alto Networks Prisma Cloud, Sysdig, Aqua Security, and native controls from the major cloud providers. Its defensible idea was not simply collecting more telemetry; it was representing relationships in a graph and using those relationships to prioritize exploitable or high-impact paths. That can improve analyst efficiency and remediation sequencing, especially where cloud identity, configuration, workload, and vulnerability data are fragmented. The limitation is that graph quality depends on connector coverage, permissions, asset attribution, cloud-provider API changes, and the accuracy of reachability and impact assumptions. Larger competitors could offer similar prioritization while bundling CNAPP, runtime, vulnerability, identity, and security operations functions into broader platforms.
Cisco announced its intent to acquire Lightspin on March 29, 2023, and updated the announcement on May 24 to state that the acquisition had completed. Cisco's FY2023 results also list Lightspin Technologies Ltd. among acquisitions closed in the fourth quarter. The acquired_asset classification therefore matters more than the historical startup label: there is no current independent financing or exit path to assess, and the former Lightspin website redirects to Cisco Outshift's Panoptica page. Cisco said the team would join its Emerging Technologies & Incubation organization and linked the technology to end-to-end security and observability from build to runtime. This is a credible strategic validation of the product and team, but public sources do not show how much of the original brand, staff, or code remains separately identifiable.
For national-security and defense readers, the relevance is substantive but indirect. Government, defense, and critical-infrastructure operators increasingly use multi-cloud, containers, Kubernetes, and identity-driven access controls, so graph-based asset context and attack-path reduction can help harden those environments. The technology supports defensive cyber hygiene, exposure management, and incident-prevention workflows; it does not by itself provide offensive capability, intelligence collection, or mission-specific assurance. Public evidence found for this record does not document a defense customer, government contract, security accreditation, or deployment in a classified environment. The strongest conclusion is therefore dual-use cybersecurity infrastructure with plausible government applicability, subject to deployment, data-residency, integration, and assurance diligence.
Dual-Use Assessment
Lightspin's core technology analyzes cloud assets, identities, configurations, workloads, and relationships to identify and prioritize attack paths. That has direct commercial value for enterprise cloud security and credible defensive applicability in government, defense, and critical-infrastructure environments that operate cloud-native systems. The relevance is indirect rather than mission-specific: public evidence does not establish defense deployments, classified use, offensive cyber capability, or government accreditation.
Strategic Fit Assessment
Lightspin is no longer an independent company that can be evaluated as a current venture investment: Cisco completed the acquisition in 2023, and the former company website now redirects to Panoptica. The historical product thesis was credible and the acquisition provides strategic validation, but there is no public basis here for valuing a standalone business, assessing current growth, or underwriting an independent financing event. The record is therefore useful for acquisition benchmarking and cloud-security technology diligence, not as a current priority signal.
Strategic Value to U.S.-Israel Alliance
The strategic value lies in contextual cloud-risk analysis that helps a large security platform connect asset inventory, identities, vulnerabilities, configuration findings, and remediation. Cisco's stated rationale links Lightspin to cloud-native security and observability from build to runtime, while Panoptica provides the current product context. For defense and critical infrastructure, the capability could improve defensive exposure management in cloud and Kubernetes estates, but its strategic value should be discounted until deployment evidence, assurance artifacts, integration depth, and operational ownership are verified.
Key Technologies
- Graph-based cloud asset and relationship modeling
- Attack-path analysis and prioritization
- Cloud security posture management across AWS, Azure, and Google Cloud
- Kubernetes and container security visibility
- Agentless cloud and cloud-native resource discovery
- Identity, permissions, misconfiguration, and vulnerability correlation
- Remediation recommendations and build-to-runtime risk workflows
Use Cases & Applications
- Prioritizing exploitable paths to sensitive cloud data and workloads
- Continuous posture management across AWS, Azure, and Google Cloud estates
- Kubernetes cluster, container, and workload exposure analysis
- Reducing excessive cloud permissions and identity attack paths
- Correlating infrastructure-as-code, configuration, and runtime findings
- Security triage for DevSecOps and cloud-platform engineering teams
- Defensive hardening of government or critical-infrastructure cloud environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- blogs.cisco.com Public source used for profile verification.
- cisco.com Public source used for profile verification.
- newsroom.cisco.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- lightspin.io Public source used for profile verification.
- aws.amazon.com Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Acquired asset
Why it may matter
Lightspin may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify technical claims
- Verify regulatory/export-control issues
Main investor questions
- Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
- What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Lightspin's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.