Cybereason

Cybereason is a cybersecurity company focused on helping defenders predict, understand, and end cyberattacks through an AI-driven, operation-centric approach. Its portfolio centers on The Cybereason Defense Platform, which unifies endpoint prevention, detection, investigation, and response around the company’s MalOp methodology so security teams can see the full attack story instead of isolated alerts.

Beyond software, Cybereason combines platform technology with managed detection and response, incident response, and retainer-based consulting services. Its deployment options span SaaS, on-premises, private cloud, and air-gapped environments, allowing it to support organizations that need flexibility in how cyber defense is deployed and operated.

Offerings, Capabilities, and Integrations

Cybereason delivers prevention, detection, response, and cyber resilience capabilities through a unified security architecture built around one lightweight agent and a centralized console. Its approach emphasizes correlated attack narratives, guided or automated remediation, and reduced alert noise so defenders can act faster with more context.

Cybereason also supports broad ecosystem interoperability. Through Cybereason Connect, its XDR capabilities ingest and correlate telemetry from more than 65 sources across endpoint, identity, workspace, network, cloud, mobile, and operational technology environments. The company pairs these product capabilities with managed services, incident response, and consulting to support both customer-run and expert-operated security programs.

Products and Services

  • The Cybereason Defense Platform: AI-driven security platform that combines prevention, detection, investigation, and response with one lightweight agent and one console, built to expose and end malicious operations across the environment.
  • Cybereason XDR: Extended detection and response offering that correlates telemetry across endpoint, identity, workspace, network, cloud, mobile, and other sources to create a unified attack story and speed response.
  • Cybereason EDR: Endpoint detection and response solution that uses behavioral analysis and cross-machine correlation to identify advanced threats and enable rapid remediation actions such as isolation and file quarantine.
  • Cybereason NGAV: Next-generation antivirus offering with multi-layered prevention designed to stop known and unknown threats, including ransomware, through behavioral and machine learning-based protection.
  • Cybereason Endpoint Controls: Endpoint control capabilities for managing device and policy enforcement, including controls for removable media, network access, and disk encryption-related security settings.
  • Cybereason Vulnerability Management: Integrated capability within The Cybereason Defense Platform that continuously assesses endpoint applications for known vulnerabilities, identifies CVEs, and delivers prioritized patch guidance.
  • Cybereason Mobile Threat Defense: Mobile security offering for corporate-owned and BYOD environments that provides real-time, on-device protection for Android, iOS, and ChromeOS devices.
  • Cybereason On-Prem: On-premises deployment option for organizations with private, offline, or air-gapped environments that need Cybereason endpoint protection and EDR capabilities without a public-cloud model.
  • Cybereason Managed: Managed security service portfolio anchored by MDR, giving customers access to 24×7 monitoring, triage, threat hunting, and response support from Cybereason security operations teams.
  • The Resilience Retainer: Incident response retainer program that provides prioritized access to cyber response expertise along with flexible use across consulting services such as assessments, tabletop exercises, and related preparedness work.
  • Incident Response Services: Product-agnostic digital forensics and incident response services that support investigation, containment, eradication, recovery, and broader breach response activities.

Target Customers

Cybereason serves security operations teams that need stronger endpoint and cross-domain visibility without expanding tool sprawl. Its packaging and services address both small and medium enterprises and larger organizations that want to improve prevention, detection, and response outcomes with either self-managed or expert-operated models.

Cybereason is also well suited to government, critical infrastructure, and other compliance-sensitive environments that require on-premises, private cloud, or air-gapped deployment options. In parallel, its partner and MSSP programs support service providers that want to build managed security offerings on top of The Cybereason Defense Platform.

Cloud Integrations and Marketplace

  • Google Cloud Marketplace: Cybereason has verified presence on Google Cloud Marketplace, where Cybereason XDR and Cybereason EDR are offered as part of its Google Cloud go-to-market motion.
  • Google Cloud: Cybereason offers Cybereason XDR powered by Google Cloud, combining Cybereason detection and response capabilities with Google Cloud security analytics and scale.
  • Microsoft Azure: Cybereason XDR includes native integrations with Microsoft Azure to incorporate cloud telemetry into detection, investigation, and response workflows.
  • AWS: Cybereason XDR includes native integrations with AWS for monitoring cloud activity and correlating AWS telemetry with other enterprise security signals.
  • Oracle Cloud: Cybereason also positions The Cybereason Defense Platform powered by Oracle Cloud for visibility into Oracle Cloud applications and workloads.

Key People

  • Manish Narula: Chief Executive Officer
  • Gregory Puff: Chief Administrative Officer, General Counsel
  • Vincent Peulvey: President, NA & EMEA
  • Ben Demonte: Chief Operating Officer, Global Consulting
  • Israel Barak: Chief Information Security Officer, Global Head, R&D
  • Hitotaka Sakurada: President, JPAC
  • Allyson Carr: Head, People

Key Facts

  • Headquarters: La Jolla, California, United States
  • Employees: 1,001-5,000
  • Annual Revenue: Approx. $120M
  • Parent Company: LevelBlue
  • Subsidiaries: Cybereason Government Inc., Cybereason Ltd, Cybereason Germany GmbH, and Cybereason G.K.
  • Publicly Listed: Not publicly listed

Analyst Recognitions

  • Gartner: Representative Vendor in Gartner Market Guide for Digital Forensics and Incident Response Retainer Services (2025). Leader in Gartner Magic Quadrant for Endpoint Protection Platforms (2022).
  • Forrester: Contender in The Forrester New Wave™: Extended Detection and Response (XDR) Providers, Q4 2021. Strong Performer in The Forrester Wave™: Managed Detection and Response, Q1 2021.
  • IDC: Major Player in IDC MarketScape: Worldwide Modern Endpoint Security for Enterprises 2021 Vendor Assessment (2021). IDC Innovator in IDC Innovators: Artificial Intelligence-Infused Security Solutions (2018).

Enter a search