Marco Riccardi has been tracking threat actors for years. Now, he's wagering that European regulations—specifically, the kind that make corporate security officers break into a cold sweat—might finally work in his favor.
His company, QuoIntelligence, announced a €7.3 million Series A round on April 27, 2026, money the Frankfurt-based cybersecurity startup says it will use to expand across a continent suddenly quite serious about where its threat intelligence data lives. Elevator Ventures, the venture arm of Raiffeisen Bank International, led the round. BMH Beteiligungs-Managementgesellschaft Hessen—which does business as Technologiefonds Hessen IV—co-led. eCAPITAL Entrepreneurial Partners, which backed QuoIntelligence's €5 million seed round in July 2023, returned, along with Mercurius Private Equity.
The timing is deliberate. Europe's regulatory machinery has been churning: the NIS2 directive took effect in January 2023, with member states required to implement it by October 17, 2024, broadening cybersecurity mandates across 18 sectors. Then came the Digital Operational Resilience Act—DORA, in Brussels shorthand—which kicked in this past January, tightening operational risk standards for financial firms.
QuoIntelligence claims these rules collectively touch more than 160,000 European organizations, according to company sources. Still, the regulatory tailwind is real. And Riccardi, who founded the company in February 2020, has built his pitch around it.
An EU-Only Architecture, by Design
"Unified Risk Intelligence—cyber threats, physical risks, and geopolitical signals converging into decisions within hours of onboarding, under European law," Riccardi said in a statement announcing the funding. It's a mouthful. But the core message is simple: QuoIntelligence processes and stores all its data within EU borders, no exceptions.
That matters more now than it did even two years ago. Companies facing audits under NIS2 or DORA increasingly prioritize compliance with EU data sovereignty. QuoIntelligence's architecture—EU infrastructure, no third-party dependencies, European analysts vetting the output—positions it as the path of least regulatory resistance.
The company markets what it calls "finished intelligence," meaning human analysts review the machine-generated alerts before they reach customers. Its Mercury platform, according to QuoIntelligence, processes over 2 billion signals annually and produces more than 600 finished intelligence reports and 6,000 raw intelligence pieces. Last October, it introduced Agent Karla, an AI assistant that provides tailored briefings with confidence scores—still processed entirely within EU infrastructure, the company says.
Whether that model scales as gracefully as the fully automated platforms offered by U.S. competitors like Recorded Future or CrowdStrike remains an open question. But QuoIntelligence's customer retention numbers suggest it's resonating with someone: the company reported zero churn in 2025 and an increase in customer lifetime value, though these are self-reported figures. It declined to disclose revenue or valuation.
A Channel Play, and a Public-Sector Win

QuoIntelligence now employs around 40 people across Frankfurt, Rome, and Madrid, according to a March job posting. With the fresh capital—bringing total disclosed funding to approximately €12.3 million—it plans to lean harder into channel partnerships rather than direct sales. Perhaps that's pragmatic; in enterprise cybersecurity, partner networks often unlock deals faster than internal sales teams can.
The startup also landed a €1.4 million contract with the European Union Agency for Cybersecurity (ENISA) earlier this year, a stamp of credibility that likely didn't hurt when courting Elevator Ventures. The company holds the "Cybersecurity Made in Europe" label from the European Cyber Security Organisation, a marketing trust mark (not a formal certification, to be clear). As of September 2024, its Gartner Peer Insights profile showed a 5.0 rating based on 10 reviews—a small sample, but perfect nonetheless.
Elevator Ventures framed its investment as a bet on regulatory momentum. QuoIntelligence is "revolutionising the threat intelligence market" while staying compliant with EU rules, the firm said. ECAPITAL, the seed investor doubling down here, noted that threat intelligence is "moving into core risk management," which suggests the category is maturing beyond the domain of security operations centers alone.
Crowded Field, Narrow Wedge

Still, QuoIntelligence faces a market thick with competition. Recorded Future, now owned by Mastercard, has global reach and years of enterprise deployments. CrowdStrike's Falcon platform bundles threat intelligence with endpoint protection, making it a one-stop shop. Cyble, CloudSEK, and SOCRadar offer regional alternatives with their own flavors of localized intelligence.
QuoIntelligence's wedge—EU sovereignty—may prove narrow. Some buyers will prioritize it above all else; others will weigh feature breadth, global coverage, and the depth of threat actor tracking that comes from a truly worldwide sensor network. It's not yet clear which camp will be larger.
What is clear: Europe's regulatory environment is no longer theoretical. NIS2 transposition deadlines have passed. DORA enforcement is live. Companies are being audited, fined, and scrutinized. That creates urgency, which creates budget. And for a startup that built its entire stack around EU compliance from day one, the timing might finally be right.
Whether it's enough to carve out a lasting position in a market dominated by U.S. giants—well, that's the bet Riccardi and his backers are making.
