Cybersecurity has repeatedly swung between proactive protection and reactive detection/response as environments and threats evolved. The early “castle-and-moat” era relied on perimeter defenses like firewalls and intrusion prevention systems, but cloud adoption, mobile technologies, and increasingly open connectivity eroded the traditional perimeter. This shifted industry emphasis toward detecting and responding to incidents in real time, elevating SIEM as a central standard. Yet the growth in incident volume and complexity—paired with a shortage of skilled practitioners—reduced SOC efficiency, and even AI/ML has not fully closed the gap. Meanwhile, a proliferation of specialized tools (NDR, EPDR, ITDR) improved certain workflows but also added operational complexity and confused buyers with overlapping categories.
As multi-cloud architectures and post-COVID mobile workforces increase heterogeneity, proactive protection is resurging—now grounded in Cyber Threat Intelligence (CTI) rather than classic perimeter walls. CTI aggregates signals from sources such as public threat feeds, vendor research, and dark web monitoring, translating indicators of compromise and adversary TTPs into actionable insights. This supports Attack Surface Management (ASM) by discovering unknown assets and vulnerabilities, contextualizing threat likelihood, enabling threat hunting and incident response, and providing continuous external monitoring of an organization’s “virtual perimeter.”
KELA, founded in 2015 in Tel Aviv by veterans of military intelligence, evolved from traditional CTI into an “External Cyber Security” platform. It unifies external signals into a single data model, leverages historical artifacts plus real-time feeds, and blends expert research with automation to deliver contextualized risk findings across ASM, third-party risk, identity security, ransomware prevention, and more—without agents or access to internal networks. Modular capabilities (e.g., Threat Landscape, Threat Actors, Investigate, Identity Guard, TPRM, Monitor, Technical Intelligence, AiFort) integrate with SOCs via APIs, while challenges include add-on remediation, complex licensing, and limited end-to-end compliance monitoring.
See All Locations
See All Locations