Dossier · Acquired asset · 1 independent source
XM Cyber
Last updated: Jul 31, 2026
XM Cyber develops continuous exposure management software that models validated attack paths across external, cloud, identity, and on-premises environments, then prioritizes the fixes most likely to reduce compromise of critical assets. The Israel-founded company is now owned by Schwarz Digits and remains in a strategic technology transition following a 2026 agreement for CrowdStrike to acquire its intellectual property.
Visit WebsiteCompany Overview
XM Cyber's core product is a continuous exposure management platform built around attack-path analysis. It ingests information about assets, identities, privileges, vulnerabilities, misconfigurations, security controls, and external exposure, then models how an attacker could chain those conditions into a route toward a sensitive asset. The practical promise is different from a conventional vulnerability scanner: instead of presenting thousands of isolated findings, it attempts to validate which combinations are reachable and to identify the smaller set of remediation actions that breaks the most consequential paths. The company's public materials also describe a digital-twin approach, continuous discovery, automated security validation, and remediation workflows.
The commercial customer problem is credible and persistent. Large organizations operate hybrid estates in which cloud permissions, legacy on-premises infrastructure, identity relationships, third-party access, and security tooling create interactions that are difficult to reason about manually. XM Cyber is aimed at security and risk teams that need to connect exposure data to business-critical assets and give infrastructure owners actionable remediation priorities. Its 2016 founding date, global go-to-market presence, public customer-facing product materials, and LinkedIn-reported company size of 201-500 employees indicate an established enterprise software operation rather than an early prototype. The earlier Series B announcement reported $17 million raised in 2020 and $49 million in cumulative funding at that time; later ownership changes make old venture-financing figures an incomplete measure of current capitalization.
Competition is broad and comes from several directions: vulnerability-management vendors such as Tenable, Rapid7, and Qualys; cloud and external attack-surface platforms such as Wiz and Microsoft; security validation and breach-and-attack-simulation products; and broader security platforms that increasingly add attack graphs or exposure prioritization. XM Cyber's potential advantage is the combination of attack-path visualization, exploitability-oriented validation, identity and privilege context, and remediation guidance across hybrid environments. That advantage is not automatically durable. Buyers will compare the quality of the graph and its integrations with tools they already own, and large incumbents can bundle adjacent capabilities. The product must therefore demonstrate that it changes remediation decisions and measurable exposure, not merely that it produces a compelling visualization.
The current ownership context changes the diligence frame. XM Cyber's official company page says it is part of Schwarz Group through Schwarz Digits, while a July 2026 Schwarz Digits announcement says CrowdStrike signed a definitive agreement to acquire XM Cyber's intellectual property and that customers will have an opportunity to adopt the Falcon platform over time. XM Cyber's own LinkedIn communication says it will continue to operate and support customers, so this record should not treat the company as already defunct; however, the transaction creates uncertainty around product continuity, roadmap control, employee retention, customer migration, and the boundary between the operating business and the transferred IP. This is now better understood as an acquired strategic asset in transition than as an independent venture financing opportunity.
The dual-use case is defensive rather than offensive. Attack-path modeling and safe security validation can help commercial enterprises, critical-infrastructure operators, and government organizations understand lateral movement, excessive privilege, segmentation failures, cloud-to-on-premises paths, and third-party exposure. That supports resilience and hardening of sensitive networks, but public sources reviewed here do not establish a specific defense contract or classified deployment. Strategic relevance is consequently meaningful at the cyber-resilience and sovereign-security layer, especially given Schwarz Digits' stated European digital-sovereignty context, but it should not be overstated into a weapons or intelligence capability. The key diligence questions are whether the technology remains differentiated after the IP transaction, how customers are supported during migration, what independent operating capability remains at XM Cyber, and whether validated attack paths produce repeatable risk reduction in real customer environments.
Dual-Use Assessment
XM Cyber has substantive defensive dual-use potential because its attack-path modeling, identity and privilege analysis, and continuous security validation apply to commercial enterprises as well as critical-infrastructure and government networks. The capability can expose lateral-movement routes and prioritize hardening of sensitive systems, but the evidence supports a resilience and defensive-security thesis rather than an offensive or kinetic one. No specific government or defense deployment is asserted here.
Strategic Fit Assessment
XM Cyber has credible enterprise technology and a strong defensive-security use case, but it is no longer an independent startup financing opportunity: it is part of Schwarz Digits and its intellectual property is subject to a definitive acquisition agreement with CrowdStrike. The strategic value of its technology may be significant, yet ownership transition, customer migration, roadmap control, retention, and the scope of the remaining operating business dominate current diligence. The record therefore flags it as an important strategic cyber asset to monitor, not as a venture-priority signal or investment recommendation.
Strategic Value to U.S.-Israel Alliance
XM Cyber's strategic value lies in turning complex hybrid-environment exposure into prioritized, attacker-relevant remediation decisions. That is useful for large enterprises, regulated sectors, critical infrastructure, and government-adjacent resilience programs where identity compromise and lateral movement can create outsized consequences. Its association with Schwarz Digits also connects the technology to a broader European digital-sovereignty and security ecosystem. The value is tempered by the 2026 IP transaction: the durability of the XM Cyber product, customer base, and independent operating capability requires direct diligence.
Key Technologies
- Continuous exposure management and CTEM workflows
- Attack-graph and validated attack-path analysis
- Breach-and-attack simulation and automated security validation
- Hybrid cloud, on-premises, and external attack-surface modeling
- Identity, privilege, and lateral-movement analysis
- Digital-twin security posture modeling
- Risk-based remediation prioritization and orchestration
Use Cases & Applications
- Breaking validated attack paths to crown-jewel enterprise assets
- Prioritizing vulnerability and misconfiguration remediation by reachability
- Finding toxic combinations of identity permissions and network access
- Assessing cloud, on-premises, and third-party exposure during security programs
- Continuously validating segmentation and security-control effectiveness
- Supporting cyber-resilience reviews for critical infrastructure and public-sector networks
- Communicating technical exposure and remediation progress to executives
- Supporting customer migration or consolidation into broader security platforms
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- xmcyber.com Public source used for profile verification.
- xmcyber.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- schwarz-digits.de Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.