Opens in a new tab
vmblog logo 2024 wht (updated)

From Stealth to $55M Series A: How CYGNVS is Revolutionizing Cyber Incident Response with Out-of-Band Crisis Management – VMblog QA

Share: 

David Marshall | Published: August 5, 2025

 

When cyber attackers strike, they don’t just target your data, they systematically dismantle the very communication and collaboration tools organizations rely on to respond. Email systems go dark, single sign-on platforms become compromised, and response teams find themselves scrambling across personal phones and WhatsApp groups, creating chaos that can destroy legal privilege and regulatory compliance. It’s this fundamental flaw in traditional incident response that drove Arvind Parthasarathi, a 12-year cybersecurity veteran and serial entrepreneur, to emerge from stealth mode in January 2023 with CYGNVS�a platform designed to operate completely “out-of-band” from an organization’s primary infrastructure.

Built on research conducted with nine leading universities including Stanford, MIT, and Oxford, CYGNVS has rapidly scaled from startup to serving over 2,500 organizations, backed by $55 million in Series A funding from Andreessen Horowitz. The platform transforms static, hundred-page incident response plans into interactive mobile workflows that can coordinate response efforts among thousands of participants, from internal IT teams to external forensics firms, insurance companies, and legal counsel, all while maintaining strict access controls and legal privilege. With cyber incidents becoming an inevitable reality rather than a preventable risk, Parthasarathi’s vision represents a fundamental shift from reactive firefighting to proactive crisis preparedness, turning what he calls “black swan events” into manageable, muscle-memory responses.

++ 

VMblog: CYGNVS emerged from stealth mode in January 2023. Can you tell us about the genesis of the company? What specific pain points in cyber incident response did you and your team witness that drove you to create this platform?

Arvind Parthasarathi:  The genesis of CYGNVS comes from a crossroads I found myself at. I’ve been in the cybersecurity space for 12+ years and launched two previous, successful companies. I came to a point where I wanted to do something for the industry – to give back.

So, I began working pro bono on a nonprofit, which was a research collaborative with about nine universities globally including Standford, MIT, the University of Tokyo, Oxford, and the University of Munich. That project truly brought together researchers from around the world, all working on this problem to build a standard of care for cybersecurity. We needed something that supported not just IT and the security crowd, but also worked for board members, executives, leadership, operations, finance, legal, etc.

One of the first key findings everyone agreed on was that cyber threats are kind of an existential threat in today’s world. They’re going to happen. Everyone is focusing on how to try and prevent the unpreventable. Meanwhile, very few are thinking about how do you actually prepare for the inevitable? How are you going to practice for it? How are you to respond to it? And how are you going to report on it?

When our research came out, a lot of the people we spoke with said “This is great, but-“

The issue was they did not have the necessary infrastructure to build out everything they knew they needed. They wanted something already built, a turnkey solution. That was the genesis of CYGNVS. This need for a solution to deal with cyber threats not just during, but before and after the event, it is where we came from and why we are named CYGNVS. Cygnus is Latin for swan and we are purpose-built to help organizations prepare, practice, respond, and report on cyber attacks – or, as they’re commonly called in the industry: black swan events.

VMblog: Your platform is specifically described as an ‘out-of-band’ solution for cyber crisis management. For our readers who may not be familiar with this concept, can you explain what out-of-band means in the context of incident response, and why this approach is critical when an organization’s primary communications infrastructure may be compromised?

Parthasarathi:  The guiding principle of out-of-band is that when an organization goes through an incident or an outage, a lot of the core systems that they rely upon – things like email, single sign on, etc., are some of the first things being targeted by attackers. The attackers may shut down access to those systems so you cannot access them. You might shut down access to the systems so the attackers don’t have access. You may have issues where you don’t know if the bad guys are in your email. What are they reading? What access do they have into various systems? When SSO is down or email is compromised, and you’re dependent on those tools to respond, it brings everything tumbling down like a house of cards.

Then you have organizations turning to personal communication channels like cell phones, slack, WhatsApp, etc. This adds more chaos to an already chaotic situation. Now, a year later when a regulator shoes up and starts asking: “How did you actually respond? What did you know? When did you know it? How did you figure it out?” You can’t track down or recreate everything that was going on, because it’s in these ad hoc, unowned, uncontrolled, untracked systems.

The whole idea of an out-of-band platform is kind of like when you have a tornado and people go into a bunker. You need a place that is separated from your corporate network and from all of your corporate infrastructure. Where the IT and security teams are working on this incident and the response along with your business teams like executives, your board, your PR teams, your risk teams, your compliance teams, in-house legal, etc., as well as your external providers – like your forensic vendors, your outside counsel. Sometimes you could have four different outside counsel because you’re four different jurisdictions or your insurance company or consulting firms. These people working on the incident need to be in a separate environment, completely isolated from the organization and the attack while you figure out: what happened, what’s the extent of the damage, how do we recover, what do we need to do?

This is important because a lot of the recent attacks have seen organizations try to respond using their normal in-band systems. And so, let’s assume you’re using a corporate messaging tool and people are talking “Oh my gosh, we have this incident. This is how we’re going to respond, etc, etc.” Well, the bad guys are in that corporate messaging tool. They are reading those messages. They’re listening to the conference calls because they have access to all of this. They are inside your network. So, if you say I’m going to block this, they say “Aha, well, the company’s gonna block this so let’s go do this other thing instead.”

Increasingly, because these events and incidents are all about going after your communications, going after your collaboration tools, going after your messaging, your email, your single sign on, your contact directories, organizations need a separate place to be able to think about what the response is, how do you enforce privilege, etc. It’s kind of like the drawbridge of a castle. You really want to be able to be completely isolated from everyone to be able to resolve and think about this problem.

Now, a lot of people who are somewhat familiar with out-of-band get hung up on the idea that it is just for comms. Out-of-band is more than just your communication channels or at least it should be. It needs to be a place where you prepare and store your response plans because you don’t want anyone else-especially the threat actors-to have access to those plans. Out-of-band needs to be where you define access control and run your tabletops because there is nothing worse for you than the attacker getting access to your tabletops and knowing your gameplan. You have to manage all of your response out-of-band. All of your reporting also needs to be done out-of-band because you don’t want the bad guys getting a whiff of any of this stuff. 

VMblog: CYGNVS converts static breach response plans into interactive, guided workflows. Can you walk us through how this works in practice? What does the platform look like during an actual cyber incident, and how does it orchestrate collaboration between IT/Security teams, business units, and external providers like insurers or forensics firms?

Parthasarathi:  I think most organizations in the world nowadays have response plans for various scenarios and most of them are static Word docs or PDF files. These response plans are hundreds of pages long. And the first challenge is when they were written – this was built by XYZ and it was done two years ago. How often are these response plans updated? Are the people who built them even still with the company? The people who are mentioned or referenced in the response plan-have they read it? Are they familiar with it? Do they understand it? Does the PR team know that their section of response starts on page 75 of the incident response plan? But, if it’s a data breach, it’s on page 27, if it’s ransomware it’s on page 123?

Those plans tend to be very dense and very focused on regulatory and compliance items. These incident response plans show, yes, we have thought about these issues and we have a plan for how to deal with them. But, these incidents and attacks are constantly changing, constantly evolving. So one of the core challenges with these plans is it’s hard to keep them up to date. It’s hard to keep people who know the plans, who have access to the plans, who understand the plans.

And access can be a challenge because it’s very common that a plan was put in a shared folder inside the company’s standard document storage system. Well, incidents happen email is down, the shared infrastructure is down, and so is that plan. You can’t even access the plan because it’s on a folder that is no longer accessible.

And what CYGNVS does is it turns that static 200-page Word document into a mobile app in everyone’s pocket. Now, it’s interactive. It’s guided. I don’t have to read all 200 pages. The app, the plan is now customized to me. It tells me, Arvind, you gotta do these three things and then when Arvind’s done with his second thing, Sara gets a notification that her first thing is due and then when Sara’s done with that, it goes to Jane and so forth. Being able to be interactive, be guided is pivotal.

During a cyber crisis, someone might get told to do 20 things. They’re not going to do it. Often, they’re not even going to know where to start. However, if we give them three things to do, in order, it gets a lot easier. They get those three things done and now the system gives them three more things to do. It does this until everything they need to be done is completed. That makes that list of 20 things tenable, achievable. You need to be able to turn that stressful situation into something where people can digest and absorb in bite-size bits.

This is how they exchange data and orchestrate all of that in a transparent fashion and manage access control. If the response plan is one giant Word document, guess what? Well, this team only needs access to this. And that team only needs access to that other portion. So, someone now has to cut the Word document into different pieces. Whereas now we can actually say: that’s the PR section and only the PR team has access to that and this incident response section where I’m working with outside forensic teams, I can control what it is that they see.

So, being able to manage that access control and enforce privilege because you were very worried that the wrong person gets access to this and you lose privilege. Now you can actually say, “Outside counsel was involved and that area is privileged.” It is not just about turning that static Word document in an interactive, guided workflow in everyone’s pocket, but also being able to manage that orchestration, that access control, and that privilege because all of those must be exact and specific and accurate.

Once you have lost privilege, you can never get it back. This is important, especially when you have large teams. We have seen incidents where you have a thousand people working on it, because it’s so big and it’s global, so it’s a lot of incident IT security teams, different business teams from various functions, and external providers. One of our customers had an incident and they brought in 22 third party organizations to help them-22! So, how do you manage all of that access control and choreography when you have that many people? You just can’t do it with people and paper and Word documents anymore.

VMblog: The cyber incident response space has traditionally been dominated by consulting services and manual processes. How does CYGNVS differentiate itself from traditional incident response approaches, and what advantages does a platform-based solution offer over the current market alternatives?

Parthasarathi:  When we first built CYGNVS we understood that there is a lot of expertise that an organization needs to respond to an incident. They need expertise in house in their IT and their security teams, in their internal legal and PR teams, etc. They will also lean on and leverage expertise from third party firms. That could be forensic firms, there could be outside counsel for different jurisdictions because they may have an incident across four geographies and they need four different counsel. Or they might have counsel with different specialties – one counsel team for reporting, a different counsel team for planning. You could also be involving your insurance partners, credit monitoring firms, ransomware negotiators, and so on. There is an entire panoply of vendors that organizations might need to work with.

What we have found in every one of these incident response teams is a combination of internal IT, security, business teams, and these external providers and there is never just one external provider – usually there’s quite a few. So, the current approach of bringing in specialized expertise is important and CYGNVS is not a services firm. We don’t provide that expertise of how to do any of these functions. What we provide is, when you’ve got 7 third-party firms, 7 business teams, and multiple teams from IT/security, and you need to coordinate all of that activity – where you need to have a playbook that spans in-house counsel, outside counsel, forensics, internal PR, outside comms firm, etc. Maintaining and organizing all of that needs a system. You cannot just do this off phone calls and Word documents.

What CYGNVS is designed for is to be that platform where the organization brings in IT,  security, all their business people, and all their external providers and coordinates and collaborates to execute on that incident. Our goal is to be the underlying platform where we are not trying to replace consulting or services firm. In fact, one of our strengths is that we have 185 of these services firms already on the platform. So, if a new customer comes to CYGNVS, more likely than not, the firms that they will use for legal services, forensic services, technology services, negotiation services, etc., are all probably already in the platform because some other customer’s already brought them in. You need an ecosystem approach and you need a platform to support that and drive that where you can manage access control, manage privilege, you can decide which firms get involved, how they get involved, what they see.

A very common thing we see in incidents is vendors being rotated. You know, three to four days into an incident an organization might part ways with one of the consulting firms and bring in a different consulting firm to help them with some aspect of what they’re doing. How do you do that if you don’t have a platform? That’s the use case we solve for. How does the organization collaborate with these third-party firms and providers and those process and automate as much as you can through this sort of platform-based approach.

VMblog: We’ve noticed strong endorsements from major insurance companies like Axis, QBE, and Marsh, with testimonials emphasizing the platform’s value during cyber crises. Can you explain the relationship between cyber insurance and incident response platforms? How do these partnerships benefit both insurers and their policyholders?

Parthasarathi:  One of the reasons that we collaborated with the insurance industry is because of that fact that every organization on the planet only has limited experience with major incidents. That’s just the nature of this beast. It’s like car accidents with people. People have maybe one or two. Maybe you have been in or someone on your street has been in a car accident. However, that leads to very limited experience with car accidents. Your car insurance company, though, deals with thousands of car accidents. They have experience with car accidents like no one else. So, if you wanted to build out a really robust hardened system that could deal with common but also fringe cases, you need to look to where the most experience is with such cases.

What I have found is that a lot of incident response is just edge cases-outliers. With these incidents, nothing goes according to plan for someone going through an incident. So, the value of an incident response system is like the value of a defibrillator: you just want it to work when you need it to work. Our customers rely upon us for the same reason-we’re battle-tested because now have more than 2,500 organizations on the platform. We’re running over 2,600 major incidents a year and the reason we can be that battle-tested, proven solution is because of our partnership with insurance companies.

And that is why we partner with insurance because just like car accidents, you might only have one every five years and people in your circle of friends may have one every five or ten years, but the insurance company is seeing 20 today and 20 more tomorrow. That allows them to get the perspective of what happens during an incident-what happens when things go wrong, where are the bottlenecks, where are the improvements needed? Those cyber incidents are all bizarre scenarios. So, you need that robust, hardened system that has been built to handle all circumstances. To do that, you need to partner with people that have the volume, frequency, and complexity of these incidents. That’s what they have done for us.

And it helps give our customers peace of mind to know that we have partners with the expertise to build something that’s just going to work for them across all variety of issues-commonly seen and bizarre edge cases as well. 

VMblog: You’ve grown from stealth mode to serving over 2,500 organizations in a relatively short time, backed by $55M in Series A funding from Andreessen Horowitz. What does this growth trajectory tell us about the market demand for cyber incident response platforms, and how are you scaling to meet this demand?

Parthasarathi:  If you think about software markets most of them go through a trajectory. Every time someone comes out with a new piece of software, it typically follows the same path or trajectory. It starts with do I understand what you’re talking about? So many times there are all these esoteric tools, especially in cybersecurity. A lot of customers, when talking about new cybersecurity tools tell me, I don’t even understand what this does. So, the first step is understanding.

Then, the second thing is asking organizations about the need for the software from their perspective. Do they actually need something like this? And then the third step of that process is the actual internalization of asking do I have budget? How it it going to hit? How am I going to operationalize it?

And that is more the adoption phase of a new market. And for the out-of-band space, and even with the nonprofit that we worked on a few years ago, it was very clear that the customers had already scaled steps one and two by themselves. Like there have been enough incidents in the last 10 years, major incidents, debilitating incidents across the industry for organizations and for their peers that, you know, when we go into a company and we say, listen, this is what we do, they immediately understand it.

They go, Oh yeah, absolutely. I understand what you are saying. A separate out of band platform where we do all of this stuff, absolutely. And then because of the severity of a lot of these high-profile incidents, they immediately get the value proposition as well.

For us, I think what’s been most interesting has been going straight to Step 3, where when we start a conversation with a customer or a prospect, we’re not really having to explain what we do. We’re not having to explain why it’s of value. And to a large extent the demand that we have seen has been because customers have already scaled steps one and two and they’ve been waiting for a solution like ours. The other day we spoke to a large financial services company and they were telling us that coming out of 9/11 they went off and started to think about these kinds of problems and they spent a ton of money building a platform that does about 25% of what CYGNVS does and they look at something like what we built and they go, wow, OK, given the fact that you’ve built all of this stuff, it’s so nice for an organization to be able to say, yes, I’ll just buy it because in that build versus buy trade-off, an out-of-band platform is a classic buy, right? It’s very easy to make that case and the build is very hard. So, I think it’s one of those ideas whose time has not just come, but I think it’s probably been overdue.

And what you’re seeing in terms of our trajectory is the fact that more organizations are adopting this platform because it’s a thing that they understood and they saw the value of. The other thing I’ll say is that our adoption is also across the curve, right? Like we have like Fortune 10, 20 kind of companies. We also have SMBs. And we also have mid-market customers. We have almost all industries.  In our case we’re getting adoption across the board because I feel like the time has come for this particular problem/solution set. 

VMblog: As cyber threats continue to evolve and become more sophisticated, how do you see the incident response landscape changing? What trends are you observing in how organizations are preparing for and responding to cyber crises, and how is CYGNVS positioning itself for the future of this market?

Parthasarathi:  The cyber environment is unfortunately only getting significantly worse. It’s getting worse because of all the macro events happening, the geopolitics, and so forth. It’s getting worse because of the technology being deployed by the bad guys.

And, increasingly, a lot of organizational data is not controlled by an organization in a world of outsourcing and globalization. It’s a lot of weak links that you can go after. So, unfortunately, I think the problem is only getting exacerbated.

And the second thing I would say is the incidents that organizations are having are also increasing. So we do about 2,600 incidents a year on the platform and very few of them hit the front page of the Wall Street Journal. So that means there’s a lot of incidents that are what I like to call are near misses. Because by leveraging this platform, they’re able to mobilize quickly. What used to take 72 hours of mobilization, you can do instantaneously.  What used to take 96 hours to align, you can now do instantaneously. The fact that you’re able to react more quickly is actually reducing the severity of these incidents. And that is the trajectory that a lot of our customers are planning for, which is they’re planning for a world where the attacks are going to increase, the threat vectors are going to be hard.

And frankly, the number of these incidents is going to keep increasing and the number of times you’re going to have to use CYGNVS to resolve these incidents is going to keep increasing. But by having a platform like CYGNVS, you can actually reduce the severity. You can catch these things. You can turn them into something that’s just a daily occurrence and go, you know what, I got this under control.

And that I think is the most beautiful thing that that we can help engender in this marketplace, where we can stop these incidents from becoming existential issues for organizations, where they’re affecting shareholders and supply chains and all that stuff.

It should just become this thing that’s just part and parcel of the world we live in. They’ve found a way to manage that risk more effectively. The first aspect of it is just accepting the increase in quantity and but focusing on severity reduction by using a platform like this. The 2nd aspect of it is recognizing that the response actually starts with readiness, right? It’s about your playbooks, it’s about your practicing and your tabletops. It’s about having all the various reporting setups for customers, for regulators, and having the entire platform ready: people onboarded, access control defined, third party vendors identified and onboarded, all of that. Then prepare and practice is really the next aspect of making those incidents become lower severity because you’re just ready for them.

You know what to do and the organization is operating on muscle memory. So you’re able to breathe a little easier and react as “that was just another incident” rather than it being a big deal. We’re just going to deal with it. But CYGNVS and the preparation we’ve done in it, the practice we’ve done in it, doing more and more of those tabletops and drills and simulations builds that kind of muscle memory. And so for us, basically what we see the next two to three years all about where the threat vectors increase, the breaches and incidents increase, but organizations are building that muscle using CYGNVS or a platform like ours to prepare and practice and respond and report more effectively. So it just becomes another kind of risk that they’ve just learned how to manage and deal with effectively. And I think that is sort of how we solve or work ourselves out of the cyber existential problems crisis that we’re having. 

VMblog: Your platform emphasizes both preparation and response – from creating playbooks and running tabletop exercises to managing actual incidents. This seems to reflect a shift from reactive to proactive incident management. Can you share your philosophy on this approach and how organizations can build ‘cyber resilience’ rather than just incident response capabilities?

Parthasarathi:  It’s all about preparation and practice. I was reading an article the other day about nuclear submarines. And one of the interesting things about these nuclear submarines is the fact that they’re underwater for six months. And their entire day while they’re underwater is just composed of preparing and practicing. They come up with playbooks and they practice those drills and they and they go, well, how does it affect the reactor team? How does it affect the missile team? How does it affect the food team? How does it affect the bridge? The organization of the submarine is divided into all these functions, and all they’re doing is continuously updating and refining their playbooks and practicing them. Literally, that’s what they do for six months. And then they come up and then they go back down again for six months. They do the exact same thing.

And that is sort of the gold standard for how organizations should be thinking about cybersecurity – saying, listen, I don’t want to do 1 tabletop a year. I want to do 12. I want to do one with outside counsel. I want to do one with a critical vendor. I want to do one with my board. I want to do one with this division, one with that division. You’ve got to continuously keep practicing. And the same thing with the playbooks – those practices help you refine and update your playbooks, then you practice it again. That cycle of prepare and practice is critical because the response has to become pure muscle memory.

##