# Frame Security Lands $50M to Scale AI-Powered Employee Security Training Platform


Frame Security, a US- and Israel-based cybersecurity startup founded by veterans of Wiz and Team8, emerged from stealth mode this week with $50 million in Series A funding to expand its human risk management platform. The funding round was led by prominent investors including Team8, Index Ventures, Picture Capital, Elad Gil, Cerca Partners, and Tesonet, signaling strong market confidence in the employee-focused security awareness space.


## The Announcement


Frame Security unveiled its comprehensive human risk management platform designed to reduce organizational vulnerability to social engineering, phishing, and emerging attack vectors that exploit human behavior. The company's platform automates and personalizes cybersecurity awareness training, combining simulated attacks with AI-driven threat analysis and continuous risk scoring.


The startup has already gained traction with early customers spanning startups and Fortune 500 companies, though the company did not disclose specific customer counts or names at launch. With the fresh capital, Frame plans to:


  • Expand its engineering team to accelerate product development
  • Deepen AI and cybersecurity research capabilities
  • Scale go-to-market operations across the United States and internationally

  • CEO Tal Shlomo emphasized the timing and opportunity: "We have the right team, the right investment partners, and the right visionary customers working with us on solving a major problem that impacts all enterprises."


    ## Platform Capabilities


    Frame Security's platform consolidates several distinct security functions into a unified interface:


    ### Simulation and Phishing Training


    The core simulation engine generates personalized phishing, voice, and video deepfake scenarios tailored to each employee's role and communication patterns. Rather than deploying generic training content, the platform analyzes how individual employees interact with email, voice calls, and other channels, then crafts targeted scenarios that mimic real threats they're likely to encounter.


    The platform enables security teams to rapidly build and deploy training programs that adapt to emerging attack techniques. When new malware families or social engineering tactics emerge in the threat landscape, training content can be updated quickly across the organization.


    ### Human Risk Scoring Engine


    Frame's continuous risk-scoring mechanism aggregates signals from multiple sources:


  • Simulation performance — how employees respond to phishing tests
  • Behavioral patterns — communication habits and security practices
  • Organizational context — role, department, access levels
  • Threat exposure — which attack types the employee is most vulnerable to

  • This scoring provides real-time visibility at three levels: individual employee, team, and organization-wide.


    ### Threat Triage Module


    When employees report suspicious messages across email, chat, messaging apps, or other channels, Frame's AI analyzes and scores them in real time. This closes a critical gap in many organizations: most phishing awareness programs teach employees to report suspicious content, but lack a system to quickly validate reports and provide feedback.


    ## Founding Team and Background


    Frame Security was founded by Tal Shlomo (CEO) and Sharon Shmueli (CTO), both with deep security industry experience.


    Shlomo was an early employee at Wiz, the cloud security unicorn that raised $600 million at a $10 billion valuation before going public. Wiz pioneered cloud-native security scanning and achieved rapid scale by addressing a critical market need. Shlomo's tenure at Wiz likely provided both technical expertise in building security platforms and insight into enterprise sales dynamics at scale.


    Shmueli previously served as CTO of Team8, the Israeli venture group that invests in and incubates cybersecurity companies. Her role overseeing technical direction across Team8's portfolio provides deep understanding of security architecture, technology evaluation, and enterprise requirements.


    The founding team pairing — one from successful scaling and one from deep technical/investment perspective — suggests a product-focused approach to a well-defined problem.


    ## Market Context and Trends


    Frame's emergence reflects several converging trends in enterprise cybersecurity:


    1. Human Risk as a Primary Attack Vector

    Despite years of investment in technical controls, employees remain the most exploited vulnerability. Phishing and social engineering consistently rank among the top initial access vectors in breach reports. As technical defenses improve, adversaries increasingly focus on human manipulation.


    2. AI-Powered Attack Sophistication

    Voice deepfakes, video synthesis, and generative AI-assisted phishing emails have raised the bar for employee awareness training. Static training modules cannot keep pace with AI-generated attack variations. Dynamic, personalized simulation is becoming necessary.


    3. Regulatory and Compliance Pressure

    Frameworks like HIPAA, PCI-DSS, GDPR, and industry-specific regulations increasingly mandate security awareness training. Organizations face audit requirements to demonstrate not just that training occurred, but that it reduced measurable human risk.


    4. Competitive Funding in Awareness and Training

    Frame joins a growing category of well-funded awareness platforms. Recent comparable fundings include:

  • Herd Security (AI-powered training) — $3 million
  • Boost Security (SDLC defense) — $4 million
  • XBOW (autonomous offensive security) — $35 million
  • Spectrum Security (emerging from stealth) — $19 million

  • This wave of investment suggests venture capital sees human risk management as underserved and high-margin.


    ## HackWire Analysis


    Frame Security's $50 million funding reflects a market reality that most enterprises still underinvest in targeted, data-driven security awareness. The emergence of AI-generated phishing and deepfakes — combined with compliance mandates — has shifted awareness training from "nice to have" to critical infrastructure.


    What's noteworthy here is the personalization and continuous scoring approach. Traditional awareness programs deploy the same generic phishing test to all employees, measure click rates, and call it done. Frame's model inverts this: it profiles individual risk profiles, generates role-specific scenarios, and continuously measures human risk the way organizations measure technical risk. This is a sophisticated application of machine learning to a human behavior problem.


    The founding team's pedigree also matters. Shlomo's experience scaling Wiz suggests understanding of how to build security products that achieve enterprise adoption at speed. Shmueli's role at Team8 indicates deep patterns around what security CIOs actually need. This is not a team building from first principles; it's a team applying proven scaling playbooks to a specific problem.


    However, the real test comes in execution. Awareness training is ultimately about behavior change, which is notoriously difficult to measure and sustain. Competitors include both specialized vendors and general IT security training platforms offered by larger vendors. Frame will need to prove that AI-personalized simulations significantly outperform generic training in reducing actual breach risk — not just phishing click rates.


    For enterprises, this funding validates that human risk management deserves investment and that AI-driven personalization is becoming table stakes. Organizations that have relied on annual compliance training should treat this market signal as a prompt to re-evaluate their approach. — HackWire Editorial


    ## Implications for Enterprises


    Organizations should evaluate whether their current awareness programs are keeping pace with evolving threats:


    | Current Approach | Limitation | Modern Alternative |

    |---|---|---|

    | Annual compliance training | Static, forgettable, one-size-fits-all | Continuous, personalized, role-specific |

    | Automated phishing tests to all employees | Low signal for targeting, no behavior change | AI-generated scenarios matched to individual risk profile |

    | Manual threat triage | Slow, inconsistent, dependent on analyst expertise | ML-driven real-time analysis and scoring |

    | Self-reported metrics (completion rates) | Measures training, not behavior change | Continuous risk scoring across organization |


    ## Recommendations for Organizations


    Security teams should consider:


    1. Audit current awareness programs — Measure not just completion rates, but actual reported phishing incidents, user engagement with content, and retention of security principles. Use this as a baseline.


    2. Evaluate AI-assisted simulation — Platforms that generate personalized phishing and voice/video deepfake scenarios require less manual content creation and can adapt faster to emerging threats.


    3. Implement continuous risk scoring — Move beyond annual training cycles to continuous assessment of human risk at individual, team, and organizational levels.


    4. Close the reporting loop — Ensure that when employees report suspicious content, they receive rapid, confident feedback. This reinforces good behavior and prevents alert fatigue.


    5. Integrate with incident response — Connect awareness metrics to actual breach data. Identify whether high-risk employees correlate with high incident involvement. Use this to refine training targeting.


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)