Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

Tessian raised $65M to use behavioral AI against social engineering. Proofpoint later acquired it.

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Tessian raised $65 million in a Series C round announced on May 25, 2021. March Capital led the financing, which reportedly valued the U.K. email-security startup at approximately $500 million. The company’s technology used machine-learning-based behavioral modeling to identify unusual email activity, phishing, impersonation and accidental data loss.

The important current update is that Tessian is no longer an independent startup. Proofpoint announced its acquisition in October 2023 and completed the transaction on December 19, 2023. Tessian’s technology now forms part of Proofpoint’s email-security and data-loss-prevention offerings.

What Tessian’s $65 million funding round covered

The Series C included existing investors Accel, Balderton Capital, Latitude and Sequoia Capital, along with new investor Schroder Adveq. March Capital led the round. Contemporary reports said the financing brought Tessian’s publicly reported funding to more than $120 million, although totals varied: some reports cited $123.7 million or $137 million depending on which earlier financings were counted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The reported valuation was approximately $500 million. That was a reported private-market valuation, not a public-market capitalization or a disclosed acquisition price.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Tessian said it had about 350 customers across sectors including legal services, financial services, healthcare and technology. Its stated plans for the new capital included product development, hiring, expansion of its North American sales organization and moving beyond email into messaging, web activity and collaboration platforms.

Those expansion plans were a 2021 roadmap announcement. They should not be read as proof that every proposed product or integration was subsequently launched.

The problem: attacks and mistakes at the human layer

Tessian focused on the part of cybersecurity involving people’s decisions and communication patterns. In this context, social engineering means manipulating someone into clicking a malicious link, revealing credentials, trusting an impersonated executive or supplier, transferring money, replying to an attacker-controlled address or sending sensitive information to the wrong place.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Email security has traditionally emphasized threats such as known malicious URLs, malware, sender reputation and deny-lists. Those controls remain important, but they may not recognize an otherwise ordinary-looking message that is unusual for a particular employee or organization.

Examples include:

  • An employee sends a sensitive attachment to a new external recipient instead of a familiar customer contact.
  • A message imitates an executive or supplier and requests an urgent payment.
  • A user sends confidential information to a personal email account.
  • A compromised account sends an unusual message to contacts it has never previously contacted.
  • An employee attaches the wrong file or mistypes a recipient’s address.

Tessian’s “human-layer” thesis covered both malicious attacks and accidental data loss. That distinction matters: the product was not only intended to stop phishing, but also to prevent legitimate users from making risky disclosures.

How Tessian’s behavioral AI worked

Public descriptions portray Tessian as a machine-learning-based behavioral detection system, not a generative-AI or ChatGPT-style company. It analyzed patterns in an organization’s email activity and built models of normal behavior, including communication relationships, typical sending patterns, recipients and destinations.

When activity deviated from those patterns, Tessian could warn the user, hold the message or block the action, depending on the situation and configured policy. A warning might explain that the recipient was new, the destination was unusual, the attachment was sensitive or the message resembled an impersonation attempt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

The available public material does not establish Tessian’s precise model architecture, training methodology, false-positive rate or the balance between supervised and unsupervised learning. The most accurate description is therefore “behavioral machine learning” or “context-aware email protection,” rather than a claim about a particular AI architecture.

Why the timing mattered in 2021

The round arrived during the COVID-19-era shift toward remote work. Employees were working outside managed offices, businesses were relying more heavily on cloud email and collaboration tools, and phishing and business-email-compromise attacks had become highly visible enterprise risks.

Tessian and its investors said the company’s Fortune 500-level customer base had tripled over the preceding year. That was a company-reported growth claim, not an independently audited metric. Remote work was one plausible driver, alongside larger security budgets, heightened awareness of data-loss risks and demand for cloud-oriented email protection.

Traditional secure email gateways and static data-loss-prevention rules could be difficult to tune for context. Tessian’s pitch was that organization- and user-specific behavior could provide another layer of evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The company’s funding history

Tessian was founded in 2013 under the name CheckRecipient. According to TechCrunch, it raised a reported $13 million Series A in 2018 and a reported $40 million Series B in January 2019. The $65 million Series C followed in May 2021.

Contemporary coverage differed on the exact cumulative funding total. The safest summary is that the Series C brought Tessian’s publicly reported funding to more than $120 million. Different totals may reflect differing treatment of earlier rounds, extensions, debt or database methodology.

What the funding was meant to change

Tessian said the money would support three broad goals:

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  1. More product development: extending protection beyond traditional email workflows.
  2. Broader communication coverage: pursuing messaging, web and collaboration interfaces.
  3. Commercial expansion: increasing headcount and strengthening sales, particularly in North America.

The company also positioned itself as a potential replacement or complement for legacy secure email gateways and DLP tools. That was an ambitious enterprise-security proposition because it required reliable detection, low user friction, strong integrations and trust around sensitive communications.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened after the Series C?

Proofpoint announced a definitive agreement to acquire Tessian on October 30, 2023. Proofpoint announced that the acquisition closed on December 19, 2023. The purchase price was not disclosed in the cited announcements, so the 2021 valuation should not be treated as an acquisition value.

Proofpoint said it would combine Tessian’s behavioral and dynamic detection technology with its own threat intelligence, email protection and data-loss-prevention capabilities. The Tessian product areas identified in the acquisition materials included:

  • Tessian Guardian: protection against misdirected emails and mis-attached files.
  • Tessian Enforcer: protection against data exfiltration.
  • Tessian Defender: context-aware defense against email attacks, including user warnings.
  • Adaptive email DLP: controls informed by behavioral signals and message context.

Proofpoint’s current Tessian page continues to describe these capabilities within Proofpoint’s broader platform. In 2026, readers should understand Tessian as an acquired technology and product lineage, not as a standalone startup available for a separate Tessian contract.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What “AI-powered email security” does—and does not—mean

Behavioral detection can add context that static rules may miss. It can identify unusual recipients, communication relationships or data transfers and intervene at the moment a user is about to make a risky move. It can also address accidental disclosure, an area that inbound phishing defenses alone do not cover.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is not a complete security strategy. A compromised account may behave normally enough to evade anomaly detection. An attacker using a trusted or recently used address may appear legitimate. Users may repeatedly override warnings, and a misconfigured integration may prevent a message from being inspected.

Vendor-reported metrics also require care. Tessian and its investors cited figures such as an average 84% reduction in data exfiltration and phishing-simulation click-through rates below 1%. Those figures were company- or investor-reported; the cited public material does not provide enough methodology to treat them as independently verified benchmarks.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Trade-offs buyers should examine

Privacy and data governance

Behavioral modeling requires analyzing communication patterns and potentially sensitive metadata or message content. A buyer should ask what is processed, whether content is retained, where data is stored, how tenants are isolated, how retention and deletion are configured, and how employee profiles or risk scores are governed. Local privacy, labor and works-council requirements may also matter.

False positives and workflow disruption

Unusual does not always mean malicious. New hires, role changes, mergers, executive travel, crisis-response teams, seasonal businesses and newly onboarded suppliers can all generate legitimate anomalies. Evaluations should measure user interruption rates, analyst review volume, message-release times and false positives involving legitimate external recipients.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cold-start behavior

A new tenant, mailbox or employee has little historical behavior for a model to learn. Buyers should ask which protections operate before a baseline exists and how the system behaves after an acquisition or major organizational change.

Explainability

Security teams need actionable reasons for a decision. “AI detected risk” is not enough. The product should identify useful factors such as a new recipient, unusual destination, sensitive attachment, impersonation signal or policy trigger.

Deployment and integration

Proofpoint’s acquisition announcement described Tessian deployments with Microsoft 365 and Google Workspace, but that does not establish support for every edition, tenant configuration or integration currently available. Buyers should verify support for their mail platform, identity provider, SIEM or SOAR tools, shared mailboxes, mobile and web clients, investigation workflows and message release processes.

The practical investment lesson

Tessian’s funding reflected a broader enterprise-security thesis: email defense was moving from simple filtering toward context about users, relationships and data movement. That thesis remains relevant even though the startup was absorbed into Proofpoint.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For investors, the outcome also illustrates the difference between funding a category and preserving an independent company. Tessian raised a large round at a reported $500 million valuation, but its later path was acquisition rather than an independent public offering or continuing standalone operation.

For security buyers, the useful question is not whether a product uses “AI.” It is whether the system reliably reduces high-risk actions without overwhelming users, explains its decisions, protects sensitive data and integrates with the organization’s existing controls. Behavioral email security should complement—not replace—MFA, identity security, secure configuration, gateway protection, DLP, user training and incident response.

Readers evaluating Tessian’s original capabilities today should start with Proofpoint’s current offerings and compare them with products from Microsoft, Mimecast, Abnormal Security, IRONSCALES and Check Point. The comparison should focus on deployment model, DLP depth, explainability, privacy, analyst workload and total cost rather than the marketing label attached to the machine learning.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.