When Gal Tal-Hochberg sold his last company to Workday for approximately $530 million, he could have coasted. Instead, he started asking security chiefs a pointed question: How much of your budget goes toward storing logs you'll never actually use?
The answers, apparently, were uncomfortable enough to warrant a new startup.
Beacon Security emerged from stealth earlier this year with what founders describe as an "intelligent data layer" for security operations—a decidedly unsexy term for what amounts to industrial-grade plumbing. Think of it as a filtration system that sits between the torrent of raw telemetry data generated by corporate networks and the expensive tools meant to make sense of it all. On July 16, the New York- and Tel Aviv-based company announced it had raised $13 million in seed funding to expand the platform.
Notable Capital led the round, with participation from Holly Ventures, AlphaDrive Ventures, SVCI (Silicon Valley CISO Investments), Jefferies Family Office, and a sprawling syndicate of more than 60 founders and security executives. Among them: founders from Talon, Descope, Gem Security, Dig Security, and Cider Security. Notable Capital's Oren Yunger joined Beacon's board.
The pitch is straightforward, if a bit wonky. Security operations centers drown in telemetry—logs from firewalls, endpoint agents, cloud platforms, SaaS applications, you name it. Most of that data flows directly into SIEMs (security information and event management systems) or sprawling data lakes, where it sits, largely inert, racking up storage fees. Beacon's software intercepts that flood upstream, normalizing formats, enriching context, and routing only what's useful downstream.
It's not entirely clear how novel this is. Data pipeline companies like Cribl and Tenzir have been chipping away at similar problems for years, and modern SIEM vendors such as Hunters and Panther Labs increasingly tout "lake-first" architectures designed to sidestep traditional ingestion costs. What Beacon seems to be betting on—beyond better engineering—is timing.
Enter the Agents
In March, Beacon launched what it calls its Agentic Data Layer, positioning the product as foundational infrastructure for AI-driven security workflows. The framing matters. At RSA Conference 2026, held that same month, a parade of vendors—Cisco, Proofpoint, Corelight, Salt Security, HiddenLayer—rolled out "agentic" security products within days of one another. Google Cloud joined the chorus in April with its own "Agentic Data Cloud" messaging.
Whether this represents a genuine paradigm shift or simply the industry's latest buzzword cycle remains to be seen. But Beacon's argument is that AI agents can't function reliably if the underlying data is messy, duplicative, or formatted inconsistently across vendors. Clean, enriched data becomes the prerequisite.
The company also offers what it calls Beacon Agents—specialized tools for tasks like shadow-AI detection and alert triage. Additional modules for investigation workflows are reportedly in development, though "coming soon" is doing some heavy lifting in that sentence.
Exits and Unit 8200
Tal-Hochberg's résumé lends credibility, even if it doesn't guarantee success. Before co-founding Beacon in 2024, he built HiredScore, an AI-powered talent platform that Workday acquired for approximately $530 million in March 2024, according to SEC filings. Earlier, he served as group CTO at Team8, the Israeli cybersecurity foundry, and co-founded ClearX, a blockchain-based settlement startup in telecom.
His co-founders bring their own pedigrees. CPO Or Mattatia spent over a decade in Israel's famed Military Intelligence Unit 8200 before serving as VP Product at Mitiga, a cloud incident response firm. CTO Iddo Israely is a Talpiot alumnus—Israel's elite military tech training program—who spent 13 years in Unit 8200 on projects that earned the country's Defense Prize. He later served as VP of R&D at Skyline AI, which JLL acquired in 2021.
That kind of offensive security and intelligence background shows up in the product, which emphasizes detection and enrichment capabilities that feel tailored for enterprises worried about sophisticated threats—or at least sophisticated enough to justify the spend.
Traction, or the Promise of It

Beacon says its ARR grew more than 300 percent in the first half of 2026. The figure comes from the company itself, disclosed in the funding announcement, so treat it with the usual grain of salt reserved for startup-reported growth metrics. The startup claims "dozens of enterprises" as customers, spanning fintech, healthcare, and hospitality.
Cerebras, the AI chipmaker, is a named customer. In the funding release, the company's director of detection and response called Beacon "a core part" of building its security operations. Beacon has also published a case study on Lemonade, the insurtech company, detailing how the platform helped overhaul its security data pipeline. Both are respectable logos, though not quite the marquee enterprise names that would signal unequivocal product-market fit.
In May, Notable Capital named Beacon to its Rising in Cyber 2026 list, a recognition program where 150 CISOs vote on 30 emerging startups. The following month, the company won "Best SaaS Security Solution" at the Cloud Security Awards. Such accolades are useful for brand building, if not always predictive of long-term staying power.
The Economics, Sort Of
The business case hinges on the escalating cost of SIEM ingestion. Vendor estimates—and they should be taken as just that—suggest enterprises processing 5 terabytes of security data daily can face annual SIEM bills between $3.6 million and $7.3 million. Beacon's value proposition is that by cleaning and routing data more intelligently upstream, enterprises can shrink those costs and simplify migrations between SIEM vendors.
It's a compelling pitch, particularly for security teams facing flat or declining budgets. But the ROI calculation gets murky fast. How much does Beacon itself cost? What's the total cost of ownership once you factor in integration time, ongoing tuning, and the operational overhead of managing yet another layer in the stack?
Those questions weren't addressed in the funding materials, and startups rarely volunteer unflattering details during victory laps.
What Comes Next

Beacon plans to use the $13 million to accelerate development of its agentic data layer and expand its agent library. The company is also investing in enterprise go-to-market, which is consultant-speak for hiring salespeople who can navigate procurement cycles at large organizations.
The seed round arrives during what has been, by most accounts, a robust funding environment for cybersecurity startups. According to Crunchbase News, privacy and cybersecurity companies raised $4.4 billion in Q2 2026 alone, with overall cyber funding holding at elevated levels throughout the year. Whether that momentum persists is anyone's guess.
For now, Beacon is placing a bet—one shared by its founders' track records and a syndicate of security insiders—that as enterprises race to operationalize AI in their security operations, the real bottleneck won't be the models or the automation. It'll be the data.
Whether that thesis holds, and whether Beacon can execute on it before the market moves or competitors catch up, is the $13 million question.
