Ultimate magazine theme for WordPress.

Which cyber provider will be first on the IPO starting block?

Application security, governance and risk management, IT risk management

Cato Networks, Rubrik and Snyk are interested in an IPO, but have no concrete plans

Michael Novinson (MichaelNovinson) •
March 20, 2024

Shlomo Kremer, co-founder and CEO, Cato Networks (Image: Cato Networks)

A number of cybersecurity startups want to test-drive an IPO, but no one wants to be the crash test dummy.

See also: Live Webinar | Attack Surface Management: Actionable insights against new, known and unknown threats

The cybersecurity IPO car has been sitting on the parking lot since ForgeRock went public in September 2021, and no one has any idea how well it will fare after a tough economic reset that has made profitability more important than growth and performance more important than potential. Because of this dramatic shift in investor preferences, many cybersecurity startups want to go public, but no one wants to go public first.

Rubrik dipped its toe into the IPO waters last spring, and Reuters reported that the high-profile privacy provider is working with Goldman Sachs, Barclays and Citigroup to prepare for an IPO that could take place this year if the market becomes friendlier. After the company scaled back its plans, The Information said in January that Rubrik had scheduled additional meetings with potential IPO investors (see: Why Rubrik is trying to break cybersecurity's IPO dry spell).

Now another company is considering testing its luck on the public market. Tel Aviv-based Cato Networks hired Goldman Sachs, JPMorgan Chase and Barclays to prepare an initial public offering in New York that could take place by 2025, Reuters reported on Tuesday. The late-stage SASE startup is looking to raise more than $500 million and could go public later this year if stock markets recover, Reuters reported.

Cato Networks declined a request for comment from Information Security Media Group. The Reuters story aligns with The Information's January report that Cato planned to hire bankers for an IPO by March. The company received a $238 million investment from LightSpeed ​​Venture Partners in September, valued at $3 billion, to make cloud apps easier to access and protect sensitive data in transit and at rest (see: Cato Networks raises $238 million at $3 billion valuation to move into the higher end of the market).

The company's valuation rose 20% from $2.5 billion in October 2021, despite a significantly weaker macroeconomic climate. Cato Networks is founded and led by Shlomo Kremer, who previously led public application, API and data security provider Imperva and network security provider Check Point founded and helped. Cato wants to better address the functional and performance needs of large enterprises.

What other cybersecurity providers might pursue an IPO?

Rubrik and Cato Networks aren't the only security startups eyeing the public market. The Information reported in January that Snyk was drafting its IPO investor prospectus and could file it confidentially with regulators in the next few months. The company is more likely to go public in 2025 than in 2024, partly due to a sharper-than-expected slowdown in revenue growth, which has been between 45% and 50%.

According to public filings in the United Kingdom, the Boston-based application security provider lost $266 million in 2022 on revenue of just $247 million. The company was able to reduce its losses in 2023, but The Information could not determine exactly by how much. A Snyk spokesman declined to comment on The Information's report.

Snyk closed a $196.5 million Series G funding round in December 2022 at a $7.4 billion valuation to expand its developer security platform through organic investments and acquisitions. That's $1.1 billion less than the $8.5 billion Snyk received in September 2021 following a $530 million Series F funding round. T. Rowe Price cut Snyk's valuation to $6.9 billion in mid-2023 (see: Snyk raises $196.5 million, weeks after laying off 14% of workforce).

Since then, the company has been extremely acquisitive, acquiring Israeli application security posture management startup Helios in January to help enterprise security teams more effectively manage their application security programs. Three months earlier, Snyk bought Portuguese startup Reviewpad to help developers secure pull requests. In total, Snyk has completed ten deals since it was founded eight years ago.

At the same time, Snyk has carried out three rounds of layoffs, laying off 128 workers – or 11% of its workforce – in April 2023, as market conditions are expected to persist into early 2024. These cuts came less than six months after Snyk cut 198 employees and less than 10 months after laying off 30 employees. According to IT-Harvest, Snyk's number of employees has fallen by 20% since October 2022 to 1,148 employees today.

In contrast, Cato Networks has increased its headcount by more than 40% to 869 employees over the same period, while Rubrik has increased its headcount by almost a quarter to 3,588 employees since October 2022. Despite concerns, none of these companies are committed to going public this year, next year, or at any point in the future.

For now, Cato Networks, Rubrik and Snyk are content to sit in the garage along with several other cybersecurity startups, waiting for another company to hold the key to the IPO.

Comments are closed.

%d bloggers like this: