The radar logged 31 product launches from tracked security companies this week. 14 put the word "agent" in the announcement. Zscaler shipped an agentic SOC. Okta shipped real-time control over what agents can access. Recorded Future shipped an AI triage agent. Wiz, Commvault, Kovrr and Qodo are on the list too. Add the three acquisitions and that's 17 moves in one week by companies that already own a workflow. All of them adding agent control to it.
The mechanism is simple. To a CISO, an agent isn't a new asset class. It's a user with an API key that runs faster and never sleeps. The controls that matter for it already have owners: identity, data classification, runtime policy, logging. When a buyer asks "who secures our agents", the honest answer is "your identity vendor, your data vendor and your SOC vendor, each for their part". A standalone agent-security console is a fourth pane of glass for a problem the first three are racing to solve.
When the pitch says "new category". The CFO hears "CISO wants a fourth vendor for the thing the other three promised".
Harvey is the clearest case. A law-firm AI vendor didn't buy a security product. It hired a guardrails team so the guardrails live inside the product its customers already trust. Kiteworks did the same for data in motion. SecureSky did it for data at rest. None of them will ever be sold as "agent security". They'll be sold as file transfer, MDR and legal AI that happen to be safe with agents.
If you're a founder selling agent security, sell to the workflow owner, not the CISO. Your real customer is the vendor whose product your control sits inside. Price and position like a feature they need to ship this year. That's how you get bought at fifteen months instead of dying at thirty-six. If you want to stay standalone, pick the one control point where no incumbent owns the data yet. This week that was identity, and Cymphony got paid for it.
If you're a CISO with budget, don't open a new line item for agent security before you've asked your identity, data and SOC vendors what ships in the next two quarters. Run a 90-day test on one agent workflow with the tools you already pay for. Buy a standalone only where the test fails.
Where this is wrong: Cymphony's $30M at a post-money above $100M, and AIR Security's $50M seed the week before, say some of the best investors still believe in a standalone category. If agents become the majority of identities in an enterprise, the standalone bet gets its own budget line after all.
I'm betting the other way. Most of the money in agent security will be made by companies that never use the words.
Radar signals
Things the radar caught this week that nobody else reports.
- Huntress cut Managed EDR from $8.99 to $7.99 per endpoint and Managed ITDR from $4.80 to $3.60 per identity. Volume tiers are gone from the pricing page. No announcement.
- Hoxhunt removed the 100-user minimum from its pricing form. The floor for a first deal just dropped.
- Pentera's Chief Product Officer disappeared from the leadership page on Saturday. No announcement yet. Treat it as a question, not a fact.
- Corma's homepage now says "Identity, Access & Asset infrastructure on Autopilot for your Employees and their Agents". In March it said "the simplest license & access governance platform". Caught by the radar this week.
- 11 of 18 executive moves on the radar this week were sales, marketing or regional expansion hires. Zero Networks alone added a CFO, two VPs of Sales, a VP of Product and a VP of Engineering in one release.
One question
If you're building or backing agent security: are you selling a category or a feature? Reply and tell me who you think buys you, and why they won't get it from their identity or data vendor first. The best replies get quoted, anonymously, next week.
Thank you for reading.
If you want more than the newsletter: get the full market picture on the Mandos platform, and if you are building or investing in this space, let's talk.
Talk to you next Monday.
Nikoloz