Cybersecurity’s Infrastructure: Why Europe’s Next Security Unicorns May Be Built Around Sovereignty – 0100 Weekly Brief
Hello there,
Europe’s cybersecurity market appears to be entering the same transition that fintech experienced over the last few years.
For much of the past decade, cybersecurity innovation was largely measured through products that sat visibly in front of users: endpoint protection, security awareness training, vulnerability scanning, authentication tools, and threat detection dashboards.
But the latest funding activity suggests investors are beginning to focus on something deeper. The next wave of cybersecurity may be about controlling the infrastructure underneath Europe’s digital economy.
The End Of The Security Tool Era
For much of the last decade, cybersecurity competition centered around visibility. Security teams needed better ways to identify threats, monitor systems, and respond to attacks. As cloud adoption accelerated and digital infrastructure expanded, companies built increasingly specialized tools to address each new vulnerability.
That model created a highly fragmented ecosystem. Organizations often manage dozens of separate security products across identity, compliance, endpoint protection, cloud infrastructure, and threat detection.
As AI expands, the number of potential attack vectors is becoming increasingly difficult to manage. Investors appear to be responding accordingly. Rather than funding a growing number of cybersecurity startups, capital is beginning to concentrate around a smaller number of companies building broader security platforms.
Global cybersecurity deal value remained around $5bn during the first quarter of 2026, while transaction volume fell to its lowest level since 2018.
The divergence suggests investors are deploying similar amounts of capital into fewer companies. Rather than backing every new security product, capital appears increasingly concentrated around businesses capable of becoming core infrastructure layers.
Early-stage is Leading in Europe
European cybersecurity startups attracted roughly $1bn in venture funding during the first quarter of 2026, putting the sector on pace to approach last year’s near-record levels. Yet only 61 transactions closed during the quarter, suggesting investors are making fewer but significantly larger bets on perceived category leaders.
Early-stage companies accounted for a growing share of that capital, with six of the eight largest European rounds going to younger startups building AI-native security platforms and cyber resilience infrastructure.
Rather than expanding the number of companies receiving capital, investors appear increasingly willing to concentrate funding behind businesses they believe can become foundational layers of the security stack.
AI Creates New Security Categories
AI is also reshaping where investors believe entirely new categories can emerge. One example is Frame Security, which recently raised $50m from investors including Index Ventures.
The company is built around a simple observation: employees remain one of the most common entry points for cyber attacks, but AI has dramatically improved the quality and realism of phishing campaigns.
Instead of traditional awareness training, Frame uses AI-generated simulations designed around how employees actually work, creating highly personalized attack scenarios that mirror real-world threats.
Historically, security awareness training was often viewed as a compliance exercise. AI is transforming it into a security infrastructure category. When attackers can generate convincing voice clones, highly personalized messages, and contextual social engineering attacks at scale, human behavior itself becomes part of the attack surface.
That assumption is becoming harder to defend. Verizon’s 2025 Data Breach Investigations Report found that roughly 60% of breaches involved a human element, including phishing, stolen credentials, and user error.
At the same time, AI is increasing the sophistication and scale of social engineering attacks. Security researchers reported a 1,265% increase in AI-generated phishing activity since 2023, while AI-enabled scams surged more than 1,200% during 2025. Modern attacks increasingly use contextual information, perfect grammar, voice cloning, and deepfake content to create highly personalized deception campaigns.
The security perimeter expands from networks and devices to people. That may explain why investors are willing to fund entirely new categories that would have struggled to attract attention only a few years ago.
Sovereignty Becomes A Security Requirement
Perhaps the most important trend is visible outside cybersecurity itself.
Across Europe, concerns around digital sovereignty are moving from political debate into infrastructure decisions. For years, cloud infrastructure was primarily evaluated through performance, scalability, and cost. Increasingly, however, infrastructure ownership itself is becoming part of the security discussion.
The numbers help explain why. AWS, Microsoft Azure, and Google Cloud now control roughly 70% of the European cloud market, while European providers collectively account for only around 15%. The gap has remained remarkably persistent despite years of investment into local alternatives.
What began as a cloud discussion looks like a cybersecurity discussion. As AI systems, financial infrastructure, healthcare data, and government workloads become more deeply interconnected, infrastructure control becomes increasingly inseparable from security itself.
Recent criticism surrounding DeepL’s decision to expand its use of AWS highlighted how sensitive the issue has become. The debate was not centered on whether AWS was secure. Instead, it focused on who ultimately controls the infrastructure and which legal frameworks govern access to the data flowing through it. Similar concerns have prompted growing scrutiny around the U.S. CLOUD Act and the ability of foreign authorities to access data managed by U.S.-controlled providers.
The response is becoming visible across the market. AWS has launched a dedicated European Sovereign Cloud initiative designed specifically to address sovereignty requirements, while European cloud providers and industry groups have increasingly warned against what they describe as “sovereignty washing” by foreign hyperscalers. Earlier this year, dozens of European cloud executives urged EU policymakers to prioritize ownership, governance, and operational control when shaping future cloud regulation.
The next generation of cybersecurity infrastructure may not simply protect data. It may determine where data resides, who governs it, and how resilient critical systems remain during periods of geopolitical uncertainty.
The Defence Connection
Another reason investors are paying closer attention is cybersecurity’s growing impact inside defence. Much of the recent defence-tech boom has focused on drones, autonomous systems, satellites, and military hardware. Yet many investors increasingly describe cybersecurity as the digital backbone supporting those technologies.
Modern defence systems are becoming software-defined. Battlefield communications, intelligence systems, satellite networks, autonomous platforms, and critical infrastructure all depend on secure data flows and trusted digital environments. As these systems become more connected, cyber resilience becomes a prerequisite for operational effectiveness.
This trend is reflected in military dogma itself. NATO now formally recognizes cyberspace as a domain of operations and considers cyber defence part of its core deterrence and defence mission. In practical terms, cyberspace is now treated alongside land, sea, air, and space as a strategic operating environment.
The implications extend far beyond traditional enterprise security. A vulnerability in a cloud environment may affect government systems. A compromised satellite network may disrupt communications. A successful cyber intrusion can impair critical infrastructure without a single physical asset being attacked. As a result, cybersecurity is being evaluated through a resilience lens rather than a software lens.
Investors are beginning to follow the same logic. The opportunity is no longer limited to protecting corporate networks. It increasingly includes securing sovereign infrastructure, defence systems, critical communications, and national digital assets.
Much like fintech evolved from consumer applications to financial infrastructure, cybersecurity appears to be expanding beyond enterprise software to become a foundational layer of economic and national resilience.
That expansion may significantly increase the category’s long-term addressable market. For investors, cybersecurity is no longer simply a software sector.
The Missing Layer in European Cybersecurity
Europe accounts for roughly 30% of global cybersecurity spending, yet attracts only around 12% of cybersecurity venture capital. According to Carlos Alberto Silva, Founding Partner at 33N Ventures, the issue is not a lack of talent or demand. Instead, Europe continues to struggle with turning promising cybersecurity startups into global platforms.
While a healthy seed ecosystem has emerged across the continent, many companies still face a structural funding gap as they move from early traction to international scale.
That observation mirrors a broader trend visible across the cybersecurity market. As investors increasingly concentrate capital into fewer companies, the challenge is no longer simply creating new security products. It is building category-defining infrastructure businesses that can scale globally. Europe’s opportunity is not to create regional champions but global ones. The next generation of cybersecurity leaders may emerge from Europe, but only if the ecosystem can support companies long enough to become foundational platforms rather than acquisition targets.
Let’s Continue the Conversation at 0100 Emerging Europe
These themes will continue at 0100 Emerging Europe 2026 in Budapest (23–24 September), where private equity, venture capital, private wealth, and institutional investors will gather to explore how capital is moving across the broader Central and Eastern European region.
The agenda includes discussions on allocation trends, the scale-up funding gap, strategic autonomy, secondaries and liquidity solutions, defense and dual-use innovation, and what LPs are looking for in managers today.
We look forward to continuing the discussion in Budapest.







