Telemetry Giant Bets $100M That the SIEM Era Is Ending

Cribl CardinalOps https://www.pexels.com/photo/woman-in-front-of-a-computer-screen-7534101/

The state of the modern enterprise and security strategies has led to an environment where security teams are drowning in telemetry volume and alert noise, unable to adequately address real concerns among a flood of false positives. There is a rapidly growing gap between the amount of data collected and the level of real detection confidence. The rising costs of legacy security information and event management (SIEM) platforms continue to put a strain on organizational budgets. This combination of factors has primed the industry for an architectural alternative to traditional solutions, not another tool added to the pile.

Cribl Buys Its Way Into Detection Engineering

Telemetry company Cribl recently announced an agreement to acquire CardinalOps, an agentic detection startup. The valuation of the deal has not been disclosed publicly, but the acquisition is estimated at around $100 million. The approximately 25 employees at CardinalOps will join Cribl, and a new Cribl office will be established in Tel Aviv in the wake of the acquisition.

The full terms of the agreement remain undisclosed, but the size of the deal signals strategic urgency. Cribl’s annual recurring revenue of over $300 million underscores the scale of the company’s bet on this deal. The telemetry capabilities and rapid growth of Cribl’s AI-powered platform have set the company up as a leader in the category, and the size of the deal demonstrates Cribl’s prioritization of and commitment to expanding and improving functionality.

What CardinalOps Offers

CardinalOps was founded in early 2020 by CEO Michael Mumcuoglu and CIO Yair Manor, whose track record includes previously built companies being acquired by major industry leaders including Palo Alto Networks and Microsoft. CardinalOps provides AI-driven mapping of security controls against real-world attacker behavior to enable organizations to improve their security assessment and coverage.

The technology automates the fixing of broken, noisy, or missing detection rules, helping security teams close the gaps in their capabilities. The integration of CardinalOps’ functionality will enable Cribl to offer expanded threat coverage and strengthened operations while reducing data costs. Customers can benefit from the AI-enhanced platform helping security teams manage telemetry volume, cost, and complexity with intelligence.

From Telemetry Pipeline to SIEM Alternative

With this acquisition, CardinalOps’ detection layer will be incorporated into Cribl’s existing data infrastructure, adding an extra layer of detection to Cribl’s scalable telemetry functions. The deal positions Cribl as an open, vendor-agnostic challenger to previously existing closed SIEM stacks. This shifts the value proposition of the platform from customers paying for data volume to customers paying for protection.

The combination of CardinalOps and Cribl’s capabilities allows customers to modernize security infrastructure at their own pace, rather than needing to rely on closed platforms. This means that the acquisition has the potential to provide another avenue for organizations feeling boxed in by SIEM platform options.

What This Signals for Security Leaders

Security leaders and defenders should look to this acquisition as a potential demonstration of where the industry may be headed. Coverage validation is becoming as important as data collection itself. Cribl’s acquisition of CardinalOps may be part of a growing trend of telemetry vendors consolidating functionality by absorbing detection engineering capability.

The industry is experiencing pressure building on legacy SIEM incumbents to justify the cost and rigidity of their platforms and protections. This acquisition serves as an early test of whether the open alternative to SIEM offered by Cribl can scale beyond messaging.

The Road Ahead

It remains to be seen how the aftermath of this acquisition will play out as CardinalOps is added into Cribl’s staff and operations. The risk of integrating a 25-person startup into a fast-scaling platform may present challenges, and Cribl may struggle to replicate the model across other security functions. If successful, this acquisition could be one point that marks the beginning of the decline of the SIEM platform in favor of flexible, AI-enhanced SOCs.

Author
  • Contributing Writer, Security Buzz
    PJ Bradley is a writer from southeast Michigan with a Bachelor's degree in history from Oakland University. She has a background in school-age care and experience tutoring college history students.