메뉴
BL
TechCrunch AI • 16일 전

AI 에이전트 보안 위협 노린 심포니, 세쿼이아 3천만 달러 투자

IMP
7/10
핵심 요약

AI 에이전트가 인간 직원과 같은 기업 데이터·시스템 접근권을 가지면서 새로운 보안 리스크가 생기자, 세쿼이아 캐피탈이 보안 스타트업 심포니(Cymphony)에 총 3천만 달러를 투자했다. 심포니는 직원과 AI 에이전트 등 비인간(non-human) ID를 통합 조회하는 '워크포스 그래프' 플랫폼으로 AI가 접근 가능한 민감 데이터를 추적하고 자동 조치까지 지원한다. 기업의 AI 도입 확대에 따라 비인간 신원 관리가 보안의 핵심 과제로 떠오른다는 점에서 주목할 만하다.

번역된 본문

AI 에이전트가 인간 근로자와 동일한 민감한 기업 데이터와 시스템에 접근하면서 기계 속도로 작동함에 따라 기업들은 새로운 보안 위험에 노출되고 있다. 유서 깊은 벤처캐피탈 세쿼이아 캐피탈은 이러한 변화에 큰 돈을 걸고 있으며, 스타트업 심포니(Cymphony)에 3천만 달러 자금을 지원하며 기업이 계속 늘어나는 AI 인력을 통제할 수 있도록 돕고 있다. 이번 자금은 세쿼이아와 SMBC Fin Atlas Beyond Fund가 공동 리드한 2,500만 달러 시리즈 A를 포함하며, 투자 후 뉴욕과 텔아비브에 기반을 둔 이 스타트업의 기업가치는 1억 달러를 넘어섰다. 이번 라운드에 앞서 세쿼이아의 시드 투자가 비공개로 있었던 것으로 알려졌다.

AI 에이전트는 반드시 직원과 동일한 접근 및 신원 관리 통제를 거치지 않으면서도 여러 시스템에 접근하고 대량의 기업 데이터를 다룬다. 이 때문에 기업은 누가 무엇에 접근할 수 있는지 추적하기가 어렵다. 심포니는 보안 팀에게 직원, AI 에이전트, 기타 비인간(non-human) 신원과 그들이 접근할 수 있는 시스템 및 민감 데이터를 단일 화면으로 보여주는 방식으로 이 격차를 해결하려 한다. 설립 2년 차인 이 스타트업은 플랫폼의 핵심에 '워크포스 그래프(workforce graph)'라 불리는 기능을 구축했다. 이는 신원, 데이터, 활동 신호를 하나로 통합한다.

"기업 보안은 인간 직원을 위해 설계되었다"고 심포니 공동 창업자이자 CEO인 샤이 데켈(사진 위 가운데)이 단독 인터뷰에서 말했다. "실질적으로 워크포스에 합류하는 독립적 개체들이 점점 더 많아지고 있는데, 그들은 더 이상 사람이 아니다."

심포니는 이미 대기업 내에서 이러한 위험을 발견하고 있다고 밝혔다. 미국의 한 상장기업에서 이 스타트업은 AI 도구와 에이전트가 접근 가능한 약 8만 5천 개의 파일을 발견했다고 전했다. 심포니는 이 노출을 차단하는 데 도움을 주었고, 해당 파일들이 AI 시스템을 통해 접근되지 않았음을 확인했다. 다른 사례에서 데켈은 외부 협력업체가 승인되지 않은 앤스로픽의 Claude 인스턴스를 설치해 기존 접근 권한을 이용해 수천 개의 민감 파일을 스캔했다고 테크크런치에 밝혔다.

위험 식별 외에도 심포니는 AI 에이전트를 활용해 사고를 조사하고, 보안 팀이 우선적으로 다뤄야 할 사항의 우선순위를 정하며, 접근 권한 수정 등 일부 수정 작업을 자동화한다. 데켈은 플랫폼이 대부분 자동으로 작동할 수 있다고 말하며, 고객은 더 복잡한 사안에 대해 심포니의 보안 전문가가 참여하는 관리형 서비스를 선택할 수도 있다고 덧붙였다.

세쿼이아가 거듭 투자한 이유

세쿼이아의 초기 베팅은 심포니가 해결하고자 하는 문제조차 정하기 전에 이루어졌다. 세쿼이아 파트너 보고밀 발칸스키에 따르면, 2년 넘게 전 시드 라운드를 리드했을 당시 심포니는 제품도, 명확한 제품 방향도 없었다. 이 투자는 사실상 데켈과 공동 창업자인 이단 버코비츠(사진 위 오른쪽), 에디 고틀립(사진 위 왼쪽)에 대한 베팅이었으며, 세 사람 모두 이스라엘 군의 극히 선별적인 기술·리더십 프로그램인 탈피오트(Talpiot) 출신이다. 세쿼이아는 Wiz를 포함한 이전 사이버보안 투자를 통해 이 프로그램을 이미 잘 알고 있었다. 발칸스키는 "우리는 세쿼이아가 큰 성공을 거둬온 유형의 이력을 가진 놀라운 젊은 인재 세 명을 발견한 것"이라고 말했다.

그럼에도 발칸스키는 시리즈 A 단계에서는 창업자들의 이력 이상의 것을 보고 싶었다고 밝혔다. 심포니는 제품을 만들었고, 두 자릿수의 기업 고객을 확보했으며, 영업 첫 해에 7자릿수(백만 달러 이상)의 연간 반복 매출(ARR)을 달성했다고 밝혔다. 고객으로는 KKR, 신젠타(Syngenta), Cass Information Systems, Athennian 등이 있다. 발칸스키에 따르면 세쿼이아는 개발 초기부터 내부적으로 심포니의 제품을 사용해왔다. 그는 심포니 고객의 수준과 폭, 그리고 기존 고객이 플랫폼 사용을 확대하고 있다는 점을 벤처사가 재투자를 결정한 핵심 이유로 꼽았다.

심포니는 사이버보안 기업들이 앞다투는

원문 보기
원문 보기 (영어)
As AI agents gain access to the same sensitive corporate data and systems as human workers while operating at machine speed, enterprises are prone to new security risks. Storied venture firm Sequoia Capital is betting big on that shift, backing startup Cymphony as it emerges with $30 million in funding to help companies keep their growing AI workforce in check. The funding includes a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at more than $100 million after investment. The round follows a previously undisclosed seed investment from Sequoia. AI agents do not necessarily go through the same access and identity controls as employees, but they have access to multiple systems and handle large amounts of corporate data. This makes it hard for enterprises to track who has access to what. Cymphony is trying to address that gap by giving security teams a single view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access. At the core of its platform, the two-year-old startup has built what it calls a "workforce graph". This brings together identity, data, and activity signals. "Enterprise security was designed for human employees," Cymphony co-founder and CEO Shy Dekel (pictured above, center) said in an exclusive interview. "More and more, there start to be independent entities that are practically joining the workforce, but they're no longer people." Cymphony says it is already finding those risks inside large companies. At one U.S. public company, the startup said it found about 85,000 files that had become accessible to AI tools and agents. Cymphony stated it helped close the exposure and verified that none of the files had been accessed through those AI systems. In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic's Claude that used the collaborator's existing access to scan thousands of sensitive files. Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize what security teams should address, and automate some remediation, including correcting access permissions. The platform can operate largely automatically, Dekel said, adding that customers can also opt for a managed service that brings Cymphony's security experts into the loop for more complex cases. Why Sequoia doubled down Sequoia's initial bet on Cymphony came before the startup had settled on the problem it wanted to solve. When the venture firm led its seed round more than two years ago, Cymphony had no product or even a clear product direction, Sequoia partner Bogomil Balkansky told TechCrunch. The investment was largely a bet on Dekel and his co-founders, Idan Berkovits (pictured above, right) and Edi Gotlieb (pictured above, left), all three of whom came through Talpiot, the Israeli military's highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz. "We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with," Balkansky said. Nonetheless, Sequoia, Balkansky said, wanted to see more than the founders' pedigree by the Series A. Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales, the startup told TechCrunch. Its customers include KKR, Syngenta, Cass Information Systems, and Athennian. Sequoia has also been using Cymphony's product internally since early in its development, Balkansky said. He noted the quality and range of Cymphony's customers, and that existing customers are expanding their use of the platform, as among the key reasons the venture firm decided to invest again. Cymphony is entering an increasingly crowded market as cybersecurity companies strive to address risks emerging from the growing use of AI agents. Recent incidents have added to those concerns. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face . Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki , using parts of the site to communicate and share ways to evade restrictions. Balkansky acknowledged that scores of companies are already positioning themselves around AI and agent security. He said, however, that Cymphony's approach stands out by treating identity and data security as part of the same problem. That distinction, Dekel and Balkansky both argue, becomes more important as companies deploy more AI agents across their operations. Unlike human employees with relatively stable roles and permissions, agents can take different routes to complete a task, acquire new capabilities, and, in some cases, create other agents, making their access harder to govern with security systems designed around people. "Agents are very different actors," Balkansky said, arguing that existing identity tools were not designed for agents that can change their behavior and capabilities at runtime. Cymphony is also in a race against established security companies that are expanding their offerings around identity, data, and AI, including Microsoft, Okta, CyberArk, Wiz, and Varonis. Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, he said without disclosing specifics, the company helped consolidate two existing tools and eliminated the need to buy a third. However, Balkansky sees Cymphony's role, at least for now, as more complementary than replacement. "Nobody's going to get rid of their Okta," he said, adding that customers are largely adopting Cymphony as an additional layer today. Over time, however, he told TechCrunch that the startup could begin displacing some point solutions, particularly in areas such as data loss prevention. Cymphony has about 30 employees across Tel Aviv and New York. Most of its customers are currently in North America, though Dekel told TechCrunch that the startup is beginning to see demand from enterprises in Europe, the Middle East, and Africa. That said, as Cymphony moves beyond its Series A and expands among large enterprise customers, it now has to prove that AI agent security can become a market of its own rather than a feature offered by larger security platforms. Balkansky believes spending in the area will grow as companies put more AI agents to work. "If companies are not spending money on agent security, I don't know what else they'll be spending money on in the next five to 10 years," he said. Topics AI , Enterprise , Israel , Security , Startups , United States When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Jagmeet Singh Reporter Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio October 13 - 15 San Francisco Don't miss out . The startup community will gather to answer a pivotal question: How do you build sustainably in the AI era? REGISTER NOW Most Popular OpenAI fought dirty on career-making math problem, says NYU mathematician Russell Brandom A secret new Elizabeth Holmes documentary stuns Telluride Connie Loizos TechCrunch Mobility: Tesla Cybercab hits the road — and a snag Kirsten Korosec Hikers rescued after using Google Gemini for planning Anthony Ha Feds launch investigation into Tesla's Cybercab deployment Sean O'Kane Kirsten Korosec Tesla is asking people if they want to buy and run Cybercab fleets Kirsten Korosec OpenAI launches Astra, its powerful (