
French startup Riot has raised a $30 million Sequence B spherical after reaching $10 million in annual income in 2024. Initially targeted on educating workers about cybersecurity dangers, the corporate now desires to go one step additional and nudge workers in order that they decrease their assault floor.
Left Lane Capital is main at this time’s spherical with present buyers Y Combinator, Base10 and FundersClub taking part as soon as once more. From what TechCrunch has discovered, Riot’s has reached a post-money valuation north of $170 million following the Sequence B spherical.
Riot initially began with faux phishing campaigns. Staff frequently obtain emails that appear to be actual emails. However they’re designed to trick workers into clicking on the hyperlinks and coming into private data.
This manner, workers be taught that they need to be extra suspicious about incoming emails. Over time, the corporate added different instructional content material with a pleasant safety chatbot known as Albert. It may be accessed on Slack and Microsoft Groups.
That technique has been working nicely to this point, as Riot at the moment interacts with a million workers throughout 1,500 corporations. Shoppers embrace L’Occitane, Deel, Intercom and Le Monde. (A few years in the past, Riot solely labored with 100,000 employees.)
And but, cyber incidents are nonetheless on the rise with widespread penalties. A latest instance is the Change Healthcare knowledge breach that is affecting 190 million Americans and began with compromised credentials on a client service. An worker reused the identical password for his or her private account and Change Healthcare’s Citrix portal — there was no multifactor authentication on Citrix, both.
That’s why Riot desires to develop past educating workers. “Our job is to have a look at workers’ posture. Do they activate multifactor authentication? Have they got a safe code on their smartphone? Are their privateness settings on LinkedIn not too permissive? There are many issues that workers can put in place that can typically make life harder for hackers,” Riot founder and CEO Benjamin Netter instructed TechCrunch.
Riot calls its subsequent product an Worker Safety Posture Administration platform. It’s going to turn out to be a central cockpit to handle safety on the worker’s degree. Whereas there are numerous Posture Administration options, Riot believes workers have been uncared for for too lengthy.
Right here’s the place it would slot in the cybersecurity panorama based mostly on the corporate’s pitch deck:

“What we’re creating with the platform is that we’re going to routinely analyze the workers’ safety … and we’re going to offer a rating, which we’ve known as a karma rating, which might be an indicator of the worker’s posture,” Netter mentioned.
After that, Riot will nudge the worker to vary a setting right here, activate multifactor authentication there. “It’s the little issues you are able to do that can take you a minute or two, and that can mainly make life troublesome for hackers,” Netter added.
That is going to be an fascinating problem for Riot, as worker safety additionally will depend on their cyber hygiene on private gadgets and companies. Phishing campaigns now additionally occur on WhatsApp. LinkedIn profiles are broadly used for social engineering assaults as nicely.
That’s why this new safety product will look a bit extra like a client product, with good animations and a few gamification options to incentivize you to enhance your safety posture.
“My long-term imaginative and prescient is to construct an worker safety firm and to offer all of the instruments within the worker safety stack. So it’s doable that someday we’ll make — I’ll provide you with a foolish instance — an antivirus or a password supervisor,” Netter mentioned.
However first, with at this time’s funding spherical, the corporate additionally has more money to develop extra quickly. The workforce plans to open new places of work in different nations and develop its shopper base to develop these extra refined merchandise.