“If the alarms are silent, are we actually safe, or just blind?”
That’s the question that kept coming up in my early conversations with the founders of Fig. It also perfectly captures a problem most security leaders feel but rarely see clearly: the quiet breakdown of security operations as environments change.
Enterprises invest heavily in SecOps- SIEMs, SOARs, data lakes, detections, playbooks, SOC workflows. But the more complex those environments become, the more fragile they get. A change to a data pipeline, a new SaaS integration, a cloud reconfiguration, even a “routine” upgrade can silently break a critical detection or response flow. No one gets an alert saying, “Your defense just stopped working.”
The result is a deeply uncomfortable reality for SecOps leaders: they know how to measure what’s supposed to be working, but not what has quietly failed.
Fig was created to solve that gap.
Fig has emerged from stealth with $38M across Seed and Series A rounds, and a platform focused on a concept we believe is foundational for the next decade: Security Operations Resilience - keeping detection and response working through constant change. The funding is backed by Team8 and Ten Eleven Ventures, alongside security leaders including Doug Merritt (former CEO of Splunk), Rene Bonvanie (former CMO of Palo Alto Networks), Daniel Bernard (CBO of CrowdStrike), and the founders of Demisto and Siemplify. The company launched just a few months ago and already works with multiple large enterprises, including Fortune 100 organizations.
This combination of problem, timing, and team is why we chose to invest.
The silent failures of modern SecOps
On the surface, many security operations programs look strong. There are detections for major threats, playbooks for common incidents, and dashboards showing that everything is “green.”
But under the surface, something else is happening.
Modern environments are in constant motion. IT systems are updated. Cloud services evolve. New SaaS applications are connected and disconnected. Data pipelines are refactored. Security teams push new content, deprecate old rules, and experiment with AI-driven SOC tools. Each of these changes can subtly alter how data flows, which events are visible, and whether a given detection or automation still works as intended.
Two dynamics make this especially dangerous.
First, the infrastructure is too sensitive for aggressive experimentation. Security teams are understandably cautious about touching production pipelines and configurations, because a small mistake can have outsized impact. That caution leads to slower changes, fewer tests, and more “do nothing” decisions, even when everyone knows the environment has evolved.
Second, there is very little end-to-end visibility. When a detection hasn’t fired in months, it’s hard to know whether that’s because the organization is genuinely safer or because something in the chain quietly broke. A SIEM rule might depend on a log source that was reconfigured. A SOAR playbook might rely on a field that is no longer populated. A SOC AI agent might be making decisions on incomplete data. None of this necessarily generates an obvious error. It just means the system stops seeing what it was designed to see.
This is what makes these failures so dangerous: they are invisible by default.
As environments grow more complex, the risk isn’t only that you’ll miss new threats. It’s that the defenses you think you have in place no longer behave the way you expect, and you won’t find out until it’s too late.
Fig is built around the idea that this reliability gap in SecOps deserves its own category and its own platform.
Fig’s approach: mapping and testing the SecOps stack end-to-end
Fig’s platform is designed to continuously ensure the reliability and efficacy of security operations across the entire stack.
With a frictionless integration that works on any tech stack, Fig autonomously discovers and maps an organization’s complete detection and response flows. It traces data lineage end-to-end: from its origin at data sources, through data pipelines, SIEMs and data lakes, all the way to SOAR platforms and SOC AI agents.
The result is a real-time map of how security operations actually work in practice, not just how they’re documented.
Once that map exists, Fig can watch for change. When updates in IT systems, cloud services, or SaaS tools begin to threaten detection or response capabilities, Fig alerts teams not just that “something” broke, but where in the flow the issue appears, what the potential impact is, and which use cases are at risk.
Equally important, Fig allows teams to evaluate and simulate fixes before pushing changes to production. Security engineers can see how a change to a pipeline, rule, or integration will affect downstream detections and playbooks, and can iterate safely instead of guessing.
In practical terms, this turns Security Operations Resilience into a continuous process:
- Understand how data and logic flow through the SecOps stack.
- Detect when those flows are at risk from unplanned or planned changes.
- Simulate and validate fixes before they affect live defenses.
Fig doesn’t replace existing SIEMs, SOARs, or AI systems. It sits across them as a resilience layer that keeps their combined behavior reliable over time.
Why now: constant change, rising complexity, and AI
The timing for Fig is not accidental.
Enterprise environments are changing faster than ever. Migration to the cloud, adoption of SaaS, and the layering of new security tools have all contributed to a SecOps stack that is both powerful and fragile. At the same time, security teams are under pressure to modernize their SOC, adopt AI, and automate more of their workflows.
Without a way to validate that detection and response still work as intended, every change introduces uncertainty.
This is exactly the concern Fig’s founders heard repeatedly from leaders running large operations:
- They know their environments are changing constantly.
- They know there are hidden dependencies across tools and pipelines.
- They know they can’t realistically test everything by hand.
What was missing was a platform that treats SecOps reliability as a first-class problem, not as an afterthought or a side effect of other tools.
Fig is, in our view, one of the first companies to define this explicitly as Security Operations Resilience: keeping detection and response working through constant change, so teams can move faster without shipping blind spots to production.
The founders: from Unit 8200 and Mamram to Google SecOps
Our conviction in Fig starts with the founders.
Gal Shafir (CEO), Nir Loya Dahan (CPO), and Roy Haimof (CTO) are all veterans of Israel’s elite technology units, Unit 8200 and Mamram, and later helped modernize some of the largest and most complex security operations centers in the world. Gal helped lead Siemplify through hypergrowth and its $500M acquisition by Google, then owned global security architecture for Google Cloud Security with a focus on SecOps. Nir served as VP Product at Cymulate and held product leadership roles at Siemplify, building products that sit in the critical path of SOC workflows. Roy, who started his cyber career at 16, was Director of Engineering at Cymulate, leading teams that built high-scale security validation and testing systems.
We invested in this team because they combine three rare qualities: they have seen SecOps fragility up close at Google and other large environments; they have already built and shipped core products into those environments; and their resilient, systems-first mindset was shaped in the Israeli military, where keeping mission-critical operations running through constant change is non-negotiable. Fig is a direct expression of that experience: a team that knows exactly where security operations quietly fail — and has the credibility and discipline to build the platform that keeps them reliable.
Looking ahead
Fig is still early, but its trajectory is already notable. The company has raised $38M across Seed and Series A, with backing from Team8, Ten Eleven Ventures, and some of the most experienced operators and builders in security. It has offices in New York and Tel Aviv, is already deployed with multiple large enterprises including Fortune 100 companies, and plans to triple headcount by the end of the year, with a focus on expanding its go-to-market presence in North America.
Fig has also been selected as a finalist in the RSAC Innovation Sandbox Contest at RSA Conference 2026, a strong signal of how relevant Security Operations Resilience has become in the broader industry conversation.
Fig’s mission is captured well in its own description:
Fig leads Security Operations Resilience, keeping detection and response working through constant change. Fig finds and fixes broken security flows across the SecOps stack, and lets you quickly design, simulate, and deploy planned initiatives. With Fig, change powers the SOC instead of breaking it.
We believe this is exactly where SecOps needs to go. Complexity and change are not going away. The organizations that adapt will be those that can move quickly and trust that their defenses are still working as intended.
That is the future Fig is building toward, and why we chose to invest.
Partner
Ori Barzilay is a Partner at Team8, where he invests in Cyber and Software Infrastructure companies.