Key Takeaways
- Exein raised $270 million at a $1.7 billion valuation in a Series C led by Headline.
- The funding will support a machine-telemetry foundation model and autonomous security agents for robots, vehicles, and connected devices.
- The embedded approach differentiates the company from network-focused security vendors, though execution and competitive pressure remain significant factors.
A compromised laptop can expose sensitive information, while a compromised robot, drone, vehicle, or industrial controller can create a physical hazard. Exein addresses this physical risk by building an embedded security layer for these systems, securing a $1.7 billion valuation from investors for its Rome-based operations.
Exein has raised $270 million in a Series C led by Headline, according to the company’s announcement reported by Business Wire. Sofina, Goldman Sachs, the European Investment Bank Group through the European Tech Champions Initiative, KfW Capital, and T.Capital joined as new investors. Returning backers included Balderton, HV, Intrepid Growth Partners, 33N Ventures, Lakestar, Supernova Invest, Blue Cloud Ventures, and Geodesic Capital.
The oversubscribed round makes Exein one of Europe’s most valuable cybersecurity startups. The organization reported its valuation has risen 30-fold in two years, while it noted that annual recurring revenue during the first half of 2026 was four times higher than a year earlier.
Founded in 2018, Exein took a different route from security vendors that monitor connected equipment through network traffic. Its Photon runtime technology is embedded at the kernel and processor level, where it is designed to stop malicious code before execution.
Photon is now present across more than 2 billion chips from vendors including Nvidia, Arm, MediaTek, and AWS. That distribution gives Exein exposure to devices used in industrial automation, automotive, energy, healthcare, aerospace, semiconductors, and robotics.
Autonomy inherently compresses the response window for threat mitigation. A monitoring platform might detect unusual network behavior and send an alert, but an AI-controlled machine could act before an analyst reviews it. Exein relies on protection operating inside the device to respond closer to the point of execution.
“Frontier models are pushing the patch window to zero,” the founder and chief executive said. “Attacks now happen at machine speed, so defense has to as well.”
The larger strategy involves turning Exein’s installed footprint into training data. Exein plans to develop a foundation model using two years of machine telemetry, meaning operational signals from connected equipment rather than the human-generated text typically used to train large language models.
Autonomous agents will operate on top of that model, identifying and responding to attacks without waiting for human approval. Exein is targeting the underlying architecture by the end of 2026 and its first foundation models in the first quarter of 2027.
Telemetry from billions of deployed chips could become a defensible data advantage. Rivals can raise capital and recruit security researchers, but reproducing years of device-level activity across multiple industries remains difficult. The remaining challenges concern data quality, hardware diversity, false positives, and how much operational authority customers will give autonomous defenses.
The market backdrop is accelerating, as IoT Insider reported that the financing is aimed at securing connected and autonomous devices. Separately, Market Intelo estimated that IoT attacks increased 78% between 2023 and 2025 and projected more than 32 billion IoT devices by 2030. The NIST Cybersecurity Framework, updated in 2024, offers organizations a baseline for managing these risks, while the EU Cyber Resilience Act introduces mandatory security requirements for connected products.
Exein will also use the funding, alongside an expanded revolving credit facility led by J.P. Morgan with KfW as an additional lender, to grow in the US and Asia-Pacific. Plans include a Bay Area office and a South Korean office expected by 2027. Exein already has an APAC headquarters in Taiwan and a legal entity in Japan, with the company reporting roughly half of its revenue coming from Asia-Pacific.
Competition spans several layers. Claroty, Nozomi Networks, and Armis monitor operational technology and connected assets, while AIR Security and Onyx Security address emerging risks around AI agents. HIVE and Embedd are not direct security rivals, but their work around industrial machines, robots, and drones reflects the same migration of AI from screens into hardware.
Substantial funding does not settle the architectural debate. Network visibility will remain useful, and embedded controls can face integration, computing, and lifecycle constraints. Exein now has the capital and device footprint to establish physical AI security inside the machine. Its next test is converting that position into a reliable product before larger security vendors close the gap.
⬇️