Spencer Thompson has been thinking about the same problem for years: How do you know your security tools actually work?
It's a question that keeps chief information security officers up at night, and one that has now drawn $16 million in new capital to Thompson's startup, Prelude Security. The Seattle-based company announced the funding on September 25, 2025, with Brightmind Partners leading the round and previous backers Sequoia Capital and Insight Partners returning. The investment brings Prelude's total haul to $45 million—not astronomical by cybersecurity standards, but enough to suggest investors see something substantive in a company that essentially stress-tests enterprise defenses.
Founded in 2017, Prelude operates in what Gartner and other analysts have started calling continuous threat exposure management, or CTEM. The premise is straightforward, if uncomfortable: most organizations have no rigorous way to confirm whether the endpoint detection tools, the SIEM platforms, and the rest of their security apparatus would actually catch an attack. Periodic penetration tests offer snapshots. Prelude's pitch is continuous validation—automated simulations that run, well, constantly.
"Think of it as unit testing for security controls," Thompson suggested in an earlier interview, back when the company was still pivoting from its initial adversary emulation tools. Thompson, who previously founded and sold CareerExplorer in 2021, has guided Prelude through several product iterations. The current platform transforms threat intelligence reports into executable tests, checking whether a customer's CrowdStrike deployment or Microsoft Defender setup would flag the techniques described in, say, the latest APT advisories.
The approach resonates in a market that's grown skittish about assumed protection. When Prelude demonstrated its system in May 2024 by converting Volt Typhoon intelligence—a China-linked espionage campaign—into detection tests, the exercise underscored a gap many enterprises are only beginning to acknowledge. Having the tools is one thing. Knowing they're configured correctly, with detections firing as intended, is another entirely.
The Competitive Landscape
Prelude isn't alone in courting this anxiety. The security validation market has attracted substantial capital in recent years, though not always under the same labels. Pentera, which describes its offering as automated security validation, raised $60 million in 2025 at a valuation reportedly exceeding $1 billion. Cymulate, another player in the breach and attack simulation category, secured $70 million in 2022. AttackIQ raised $44 million in 2021.

Each company positions itself slightly differently—some emphasize red team automation, others focus on compliance workflows—but they're all circling the same insight. Enterprises spend heavily on security products yet struggle to answer basic questions about efficacy.
Stephen Ward, a general partner at Brightmind Partners, joined Prelude's latest round as his firm doubled down on what he calls the "security validation thesis." The investment signals sustained confidence in a company that has, perhaps more quietly than some of its competitors, expanded from emulation tools into a broader control validation platform with integrations across major security stacks—Splunk, SentinelOne, and others.
Prelude's employee count, somewhere in the range of 11 to 50 according to recent LinkedIn data, suggests a lean operation. That's either discipline or constraint, depending on how you read it.
Beyond Detection: What's Coming
The September announcement hinted at new research directions, including work on runtime memory detection—specifically, user-mode memory telemetry designed to catch code execution that appears out of context. It's a technical tangent that suggests Prelude may be pushing beyond straightforward control validation into detection engineering itself, though the company hasn't detailed how far that expansion will go.
Thompson's earlier Series A, a $24 million round led by Sequoia in April 2022, came during a frothier moment in venture capital. The new funding, smaller and quieter, arrives in a more cautious environment. Early investors—IA Ventures, Four Rivers Capital, and Revolution's Rise of the Rest Seed Fund, which backed Prelude's $1.8 million seed in August 2020—have stuck around, which matters. Retention signals something worked, even if the path wasn't linear.
The CTEM Moment
Gartner research from earlier this year suggests organizations prioritizing continuous threat exposure management could reduce breach likelihood by a factor of three compared to traditional periodic testing. That's the kind of stat that gets circulated in board decks, and it's given CTEM—a framework that includes not just validation but also discovery, prioritization, and mobilization—new prominence in enterprise conversations.

Validation sits at the core of that methodology, which is where Prelude has staked its claim. The startup positions itself as the continuous validation layer for enterprises already running extensive tooling but lacking confidence in what actually functions under pressure.
Whether that positioning translates into sustained growth will depend on execution and, frankly, on whether the CTEM category lives up to its billing. For now, Brightmind Partners and Sequoia seem willing to find out. Thompson, for his part, has $16 million more runway to prove the thesis—and to keep asking the uncomfortable question.
