Industry Insights

Cybersecurity Innovation in the AI Era

Explore why code is no longer a sufficient moat in cybersecurity and how founders can build agile, category-defining solutions for the evolving AI threat landscape.

By Adi Greenwald | Aug 20, 2026

TL;DR

The cybersecurity market is accelerating on every axis at once. Exploit timelines have compressed from months to hours, AI agent incidents are spiking, and CISOs are under board-level pressure to secure this transformation. For founders building in this environment, two things matter most: the agility to evolve as the landscape shifts beneath you, and a moat that goes beyond the code itself. At YL Ventures, our job is to find and support the teams that get both right.

—–

We are living through a stretch of change that is hard to overstate. AI is being written into enterprise infrastructure faster than any technology before it, and the same tools are in the hands of the people attacking it. Security teams are absorbing both changes at once, with no quiet period in between to prepare for either.

The numbers make the shift concrete. In January 2025, the average time from vulnerability disclosure to a working exploit was 125 days. By April 2026, AI-assisted exploit development had compressed that window to less than twelve hours, according to research from Cogent Security covering more than 69,000 CVEs. At the same time, CrowdStrike recorded an 89% year-over-year increase in attacks by AI-enabled adversaries in 2025. Adoption and attack are accelerating on the same timeline, and security companies simply don’t get a moment to catch their breath. From my conversations with founders, operators, and security leaders in the ecosystem, two things matter most for anyone building in this environment.

 

Build for Adaptability

AI adoption has become a top-line priority for most enterprises, with timelines aggressive, budgets flowing, and the mandate coming straight from the board. CISOs don’t get to slow it down. They’re expected to secure a transformation they didn’t initiate and can’t delay, even as the attack surface shifts faster than any security program could reasonably anticipate. Under that kind of pressure, the conversation tends to collapse into whatever’s on fire this quarter.

The work that matters today is looking beyond the current quarter. The truth is that nobody knows what AI adoption will look like when the product you plan today fully matures. Founders have to commit to a view of where the risk is heading years before their buyers do, and a company built for next year’s risk still has to sell into a budget that was set for this year’s priorities. What that demands is agility: the ability to evolve as the technology evolves, and to keep reading where the next set of risks is forming even while solving the ones that exist today.

Founders who get this right hold their read on the risk steady and adapt the product to meet the risk as the market arrives. Aim Security (a YLV portfolio company, acquired by Cato Networks), for example, started building for enterprise GenAI risk while most CISOs had no budget line for it and no clear owner for the problem inside their organizations.  Matan Getz, the company’s Co-Founder & CEO, called it an “evolution” rather than a “pivot”. In his view, founders who understand that distinction, and who can read where the next gap is opening before it is obvious, are the ones who will lead the next wave of category-defining companies.

Find a New Moat

The second shift is on the building side. The cost of building software has dropped so dramatically that a capable engineer with the right tools can produce in an afternoon what used to occupy a team for weeks. That changes the question a security vendor has to answer. It is no longer whether the product solves the problem, but why a buyer should pay for something their own engineers believe they could build.

The code is rarely the moat now. What resists replication is knowing which problem will matter before the market names it, and being far enough ahead that the answer is already built when the market gets there. A CISO evaluating the product should see technology their own team could not reproduce, or a problem too urgent to wait on an internal build. Both come down to the same requirement: deep domain expertise and the resources to apply it.

Where We Come In

Reading where risk is heading and having the domain depth to be right about it are both hard to come by alone. The first takes exposure to more of the market than any one company sees. The second takes access to the people who will buy, test, and vouch for a product before it has a track record.

We have spent nearly two decades in this market, which means we see problems forming across dozens of companies rather than one. Once we invest, that view is what we hand founders: the read on where the risk is moving, and the CISOs and operators who will tell them whether they are right.

We backed Aim Security because the team knew the problem better than the market did. We tested their thinking against what we saw across the market, and brought them to the operators who would know whether they were right.

The founders who will define the next decade of security are already at work. Our job is to partner with them while the problem they are solving is still forming, and support them throughout their journey.