Free tools Windows power users keep installed
One-click scans. No signup required.
Adaptive Security announced a $43 million early-stage funding round on April 2, 2025, co-led by Andreessen Horowitz (a16z) and the OpenAI Startup Fund. The startup, founded by Brian Long and Andrew Jones, is building software that simulates AI-assisted impersonation attacks across email, SMS and voice so organizations can train employees and improve response. The round was significant, but it is now only part of the company’s financing history: Adaptive later announced an $81 million Series B, bringing publicly reported funding to $146.5 million.
What happened in the $43 million round?
Adaptive’s April 2, 2025 announcement described an early-stage $43 million financing led by a16z and the OpenAI Startup Fund. Abstract Ventures, Eniac Ventures, CrossBeam Ventures and K5 also participated, according to SecurityWeek and the company’s funding announcement.
The announcement said the investment was OpenAI’s first cybersecurity investment. That is a characterization from the funding announcement, not evidence that Adaptive’s product has been independently validated.
Who founded Adaptive Security?
Brian Long and Andrew Jones are repeat entrepreneurs whose previous companies included TapCommerce and Attentive. Their advertising and messaging experience is relevant background for a company focused on convincing, personalized communications; it does not by itself establish the effectiveness of Adaptive’s security technology.
#1 Best Overall
What threat is Adaptive targeting?
Traditional phishing often arrives as a suspicious email. AI-assisted social engineering can combine a convincing executive persona, cloned voice, personalized text, synthetic images or video, and follow-up messages across several channels.
A typical attack chain
- An attacker uses public information to imitate a finance executive or employee.
- A personalized email requests a credential reset, payment or urgent review.
- A voice call or SMS reinforces the request and applies time pressure.
- The target acts through a legitimate account or business process, making malware-based defenses less useful.
Adaptive’s thesis is that companies should test these behaviors before criminals use them in live incidents. Its focus is therefore human-directed fraud and social engineering, not simply malware detection or network monitoring.
What Adaptive’s platform reportedly does
Multichannel attack simulation
Adaptive describes simulations delivered through email, SMS and voice calls, including role-specific spear-phishing and deepfake-oriented employee lures. Its later product descriptions emphasize personalized scenarios informed by organizational context and publicly available information.
Rank #2
Targeted training and risk scoring
When a user fails a simulation, the platform can flag the event, adjust a risk score and deliver training tied to the lure or behavior. Adaptive also describes using risk information to inform access decisions. Buyers should verify whether scores are used only to prioritize coaching or also influence privileges, employment decisions or other high-impact actions.
Recommended Free Tools
Threat triage
The company says it can analyze suspicious messages in real time, assign risk and help security teams respond when an employee reports a possible attack, rather than merely forwarding the report to IT.
Content generation
Adaptive says customers can create text, visual and video training content based on selected topics or organizational policies.
Rank #3
Broader product areas
As of August 2026, Adaptive’s public pages group its offering into Security Awareness Training, Email Security and AI Governance. The listed functions include phishing and compliance training, risk scoring, inbound email detection, impersonation protection, shadow-AI discovery, acceptable-use enforcement and data-leakage prevention. These are vendor-described capabilities; a buyer should test each module separately.
Why ordinary phishing training may not be enough
Annual courses and generic simulated emails can teach useful habits, but they may not test whether an employee can handle a voice clone, a text-message follow-up, an executive impersonation or a multistep request that crosses channels. Adaptive’s approach aims to make exercises more contextual and continuous.
That does not make conventional training worthless. The meaningful comparison is behavioral evidence: reporting rate, time to report, repeat-failure rate, false positives, response time and real incident outcomes—not only how many people clicked a simulated link.
Rank #4
What the funding and product do not prove
- Passing a simulation does not prove that an employee will reject a real payment or credential request.
- A simulated deepfake is not the same as forensic detection or authentication of live audio and video.
- Lower click rates do not establish that fraud losses fell.
- Investor participation demonstrates financing and market confidence, not technical efficacy.
- No independently established outcome data in the cited announcements demonstrates a specific reduction in real-world incidents.
Adaptive versus other security categories
| Category | Primary job | Example positioning |
|---|---|---|
| Adaptive Security | Human-risk management, multichannel simulation, email security and AI governance | Integrated platform for training, detection, triage and policy controls |
| KnowBe4 | Security-awareness training and email-threat defense | AI-assisted phishing detection, contextual warnings, sender analysis, link rewriting, QR-code detection and Microsoft 365/Defender integration |
| Reality Defender | Synthetic-media detection and identity or fraud protection | Deepfake detection for contact centers, access security, fraud prevention, video conferencing and executive impersonation |
KnowBe4 is an established awareness-training ecosystem and also markets AI-generated phishing, vishing, smishing and deepfake-training capabilities. Its North American Defend MSRP listed in January 2025 was $5.30 per seat monthly for 25–50 seats and $4.00 for 501–1,000 seats on a three-year term; deployments above 1,000 seats required a quote. Those figures are not a like-for-like comparison with Adaptive’s custom pricing.
Reality Defender addresses a different problem: determining whether audio, video or other media may be synthetic. Such detection can complement, rather than replace, employee simulations and payment-verification controls.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Later financing and current company status
Adaptive subsequently announced an $81 million Series B involving NVIDIA, Bain Capital Ventures, Capital One Ventures and Citi Ventures, alongside existing investors including the OpenAI Startup Fund and a16z. SecurityWeek reports publicly disclosed total funding of $146.5 million. Adaptive’s homepage says it serves more than 1,500 customers worldwide; that is a self-reported figure.
Best Value
Questions to ask before buying
Coverage and realism
- Can the platform simulate the channels employees actually use, including voice, SMS and mobile devices?
- Can it model executive impersonation, business-email compromise and department-specific workflows?
- What data is used to personalize scenarios, and can the customer restrict sensitive information?
Integration and evidence
- Does it integrate with Microsoft 365, identity systems, SIEM, SOAR, ticketing and access controls?
- Can security teams audit why a user was flagged and correct false positives?
- Will the vendor measure reporting time, repeat failures and real incident response—not just course completion?
- Can the organization run a controlled pilot against its existing controls?
Governance and employee protection
- Who authorizes executive-themed simulations, and what happens if an exercise resembles a live incident?
- Are employees told how testing works, and is there an appeal process for risk scores?
- Where are organizational and employee data processed, retained and deleted?
- Are simulations appropriate for regulated, unionized or employee-owned-device environments?
Controls that simulations cannot replace
A convincing voice should never authenticate a payment by itself. Organizations still need out-of-band callbacks to known numbers, dual approval for sensitive transactions, strong identity controls, email authentication, privileged-access management and an incident-response process.
Training also does not make an organization compliant by itself. Legal, regulatory, contractual and insurance requirements depend on the applicable framework and the controls actually operating in the environment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




