# Israeli Cryptography Startup QIZ Security Raises $17 Million to Combat Post-Quantum Threats


## Seed Funding Powers Growth of Platform Designed to Govern Encryption at Scale


Israeli cybersecurity startup QIZ Security announced Thursday it has secured $17 million in seed funding to accelerate development of its cryptographic posture and post-quantum cryptography (PQC) management platform. The funding round was led by Bessemer Venture Partners and Merlin Ventures, with participation from Evolution Equity Partners, Qbeat Ventures, Singtel Innov8, and Qino Cyber Capital.


The investment underscores growing enterprise concern over cryptographic risk management and the looming transition to quantum-resistant encryption standards. For organizations operating across hybrid, cloud, and on-premises environments, the ability to discover, inventory, and remediate encryption vulnerabilities has become a critical operational challenge—one that existing security tools often fail to address comprehensively.


## The Company and Its Founders


Founded by Ben Volkow (CEO), Lenny Ridel, and Itan Barmes, QIZ Security positions itself as a specialized player in the emerging cryptographic governance market. The company's name and branding suggest a focus on precision and control—qualities essential when managing encryption across complex, multi-tenant infrastructure.


The founding team brings experience from Israeli cybersecurity and defense technology sectors, where cryptographic and quantum-resistant security development has been a research priority for years. This background informs the platform's architecture, which emphasizes continuous visibility and API-driven orchestration rather than agent-based discovery or network-level interception.


## The Post-Quantum Cryptography Imperative


The urgency behind QIZ Security's market entry stems from a fundamental industry challenge: the quantum computing threat to current encryption standards.


Today's widely deployed public-key cryptography systems—including RSA, ECDSA, and elliptic curve algorithms—are vulnerable to attacks by sufficiently powerful quantum computers. While practical, cryptographically-relevant quantum computers remain years away, adversaries are already executing "harvest now, decrypt later" attacks, collecting and storing encrypted communications to break retroactively once quantum capabilities mature.


In response, the U.S. National Institute of Standards and Technology (NIST) finalized post-quantum cryptography standards in August 2024, and organizations face an unprecedented migration challenge:


| Challenge | Impact |

|-----------|--------|

| Discovery | Organizations cannot identify all cryptographic implementations across hybrid estates |

| Prioritization | Without visibility into business criticality, remediation efforts lack strategic focus |

| Coordination | Multiple teams (compliance, engineering, application owners) lack shared governance frameworks |

| Continuous Risk | One-time assessments fail to catch new cryptographic weaknesses as systems evolve |


As CEO Ben Volkow noted in the announcement: "Post-quantum readiness is quickly becoming a board-level cybersecurity and business priority. Enterprises cannot migrate what they cannot see, and they cannot manage cryptographic risk through one-time assessments."


## QIZ Security's Platform Capabilities


QIZ Security's platform addresses the discovery and governance gap through a unified cryptographic visibility layer designed for scale:


### Core Features


Continuous Discovery & Mapping

  • Identifies cryptographic assets across on-premises, cloud, and hybrid environments
  • Maps encryption implementations to applications, services, and business systems
  • Catalogs protocol versions, cipher suites, key management mechanisms, and certificate chains
  • Discovers cryptographic gaps in data-in-transit and data-at-rest protection schemes

  • Risk Identification & Prioritization

  • Flags outdated protocols (SSL 3.0, TLS 1.0/1.1)
  • Identifies weak cipher suites and insufficient key lengths
  • Detects missing encryption and unprotected data flows
  • Ranks findings by severity and business impact, allowing CISOs to focus remediation efforts

  • Remediation Planning & Orchestration

  • Generates prioritized remediation roadmaps
  • Supports collaboration between CISOs, compliance teams, and application owners
  • Integrates with existing infrastructure through API-based workflows
  • Enables continuous monitoring rather than periodic assessments

  • ### Technical Architecture


    Unlike agent-based or network probe-dependent approaches, QIZ Security relies on API-first integration, reducing deployment friction and operational overhead. This design philosophy reflects lessons learned from endpoint detection and response (EDR) tools, which struggle with deployment complexity and false positives at scale.


    By centralizing cryptographic visibility through APIs, the platform avoids:

  • Agent sprawl and management complexity
  • Network packet inspection overhead
  • Performance degradation from continuous traffic analysis
  • Blind spots in cloud and containerized environments

  • ## Market Context and Competitive Positioning


    The $17 million funding round arrives as the cryptographic governance market reaches inflection point. Prior 2026 investments in related spaces—including Keyfactor's $1 billion+ valuation for AI-enhanced post-quantum security and 8Layers' $2.9 million for identity-focused crypto controls—signal strong investor appetite.


    Unlike point solutions focused solely on certificate management or key rotation, QIZ Security's platform attempts to unify the end-to-end cryptographic risk lifecycle. This positions it squarely between legacy certificate management vendors and emerging AI-augmented security platforms.


    ## HackWire Analysis


    Why This Matters Now: The Disconnect Between Urgency and Capability


    QIZ Security's funding reveals a painful reality organizational leaders are finally confronting: *most enterprises have no idea what cryptography they're running.* This gap between threat perception and operational visibility represents both a market opportunity and a legitimate emergency.


    The NIST post-quantum migration deadline creates artificial urgency, but the real problem predates quantum threats. Organizations have spent two decades deploying encryption across application stacks, cloud platforms, and third-party integrations—and the mental model of where it all lives exists only in fragmented tribal knowledge. When a compliance officer asks an engineering director "are we using AES-128 or AES-256?"—that conversation often ends in guessing.


    What's particularly notable about QIZ Security's market positioning is its rejection of "one-time assessment" approaches. Most security vendors sell periodic scans or annual audits; QIZ's emphasis on *continuous* governance reflects hard-won lessons from incident response: environments change faster than governance can react, and a remediation plan validated last quarter is often obsolete by quarter-end.


    The API-first architecture also signals something important: this is being built for infrastructure complexity that agent-based tools can't scale with. Kubernetes clusters, multi-cloud deployments, serverless functions, and container registries move at speeds that traditional asset discovery struggles to match. QIZ's bet is that surveying cryptographic *interfaces* (rather than hunting through storage and configuration) gets you 80% of the actionable visibility with 90% less operational friction.


    However, one lingering question: how does this scale when cryptographic implementations hide inside SaaS offerings, managed services, or third-party APIs where the organization has no direct visibility? QIZ's announcement doesn't address the "black box" integration challenge—the cryptographic assumptions embedded in Stripe, AWS managed services, or corporate SaaS platforms. That may be the harder problem than what happens on your own infrastructure.


    HackWire Editorial


    ## Recommendations for Organizations


    For Security Leaders:

  • Audit your current cryptographic visibility—can you enumerate all encryption implementations across your infrastructure within 48 hours? If not, this is a material risk.
  • Begin post-quantum migration planning now, even if quantum threats feel distant. NIST standards are final; migration will take years.
  • Inventory which systems store "long-term sensitivity" data that could be harvested and decrypted retroactively by quantum computing.

  • For Compliance Teams:

  • Document your organization's cryptographic governance baseline—including discovery methods, remediation cycles, and stakeholder accountability.
  • Map regulatory requirements (SOC 2, HIPAA, PCI-DSS, GDPR) against current cryptographic practices and identify gaps.
  • Establish metrics for cryptographic risk and create board-level dashboards to track migration progress.

  • For Engineering Leadership:

  • Advocate for cryptographic governance as a platform engineering concern, not a bolt-on compliance task.
  • Establish standards for which encryption algorithms, key lengths, and protocols are approved for new applications.
  • Build remediation capabilities into your deployment pipelines to enable continuous cryptographic compliance.

  • ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Compliance](https://www.hackwire.news/category/compliance)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)