TechSignal.news
IoT

Exein's €70M Series C Signals Budget Shift Toward Runtime IoT Security

Italian embedded-security vendor Exein raised €70 million in Series C funding, intensifying competition for device-side prevention over network monitoring. Enterprise buyers now face clearer trade-offs between point tools and platform suites.

TechSignal.news AI4 min read

€70 Million Bet on Device-Side Prevention

Exein closed a €70 million (~$81 million) Series C led by Balderton, marking one of the largest recent capital inflows into runtime security for embedded and IoT devices. The funding positions the Italian vendor to compete directly with network-layer visibility platforms such as Armis, Ordr, Claroty, and Nozomi Networks—all of which sell fleet discovery and segmentation but rely less on runtime enforcement at the device level.

The distinction matters for procurement teams trying to secure heterogeneous IoT estates. Network monitoring surfaces devices and tracks behavior, but runtime security enforces policy and blocks threats before they propagate. Exein's approach targets embedded and AI-native devices, a segment where traditional endpoint agents fail and network visibility alone cannot prevent exploitation. Buyers evaluating RFPs should expect more differentiated language around secure update mechanisms, runtime enforcement, and embedded-device controls rather than passive discovery alone.

ServiceNow's $7.75 Billion Armis Acquisition Reshapes the Market

ServiceNow's planned $7.75 billion cash acquisition of Armis demonstrates how central asset visibility and proactive device security have become to enterprise platform strategy. That valuation—the largest IoT security exit to date—shows enterprises value tools that unify IT, OT, and IoT risk management within broader service management and incident response workflows.

The move pressures stand-alone device-intelligence vendors and forces buyers to compare best-of-breed point tools against platform suites. A point tool may offer deeper runtime controls or more granular device behavior analytics, but a platform can fold device risk into ticketing, procurement workflows, and exposure management across the entire enterprise attack surface. Buyers should budget for integration costs and staff time when choosing between approaches. A siloed IoT security tool may win on features but lose on operational overhead.

Lifecycle Management Becomes a Procurement Gate

Forrester's 2026 IoT security research reinforces that security and lifecycle management are now procurement gates rather than post-deployment concerns. The report emphasizes secure update mechanisms for deployed devices, long-term patching, firmware governance, and fleet policy controls. This favors vendors that can prove multi-year support windows and auditable update cadence over vendors that ship devices without documented patch schedules or secure boot capabilities.

Enterprise buyers must budget for lifecycle security—not just device purchase cost. Patchability, update cadence, and support windows are purchase criteria, not afterthoughts. A cheap device with a two-year firmware support window creates a technical debt that exceeds any upfront savings.

U.S. Cyber Trust Mark Sets Baseline Security Criteria

The U.S. Cyber Trust Mark program, a voluntary certification tied to NIST security criteria, requires all IoT devices procured by U.S. federal agencies to meet baseline controls for device authentication, encryption, and software updates. Even outside federal procurement, buyers can use Cyber Trust Mark-style criteria as a vendor screen for patchability, update support, and basic hardening.

McKinsey reports that 60% of IoT buyers now prioritize cybersecurity criteria when selecting devices. Vendors that can clearly document authentication, encryption, update policy, and lifecycle support are better positioned than commodity hardware suppliers. Buyers should treat firmware support quality and secure boot availability as hard requirements for connected infrastructure purchases, especially where replacement cycles are long.

Unmanaged Devices Drive Budget Toward Inventory and Exposure Management

Ordr's reporting highlights the risk from unmanaged IoT and OT devices and proposes a maturity model centered on asset identification, risk assessment, remediation, and proactive policy enforcement. Unmanaged assets remain the primary problem because they sit outside traditional endpoint management tools and often lack agent support.

This shifts budgets toward asset inventory, segmentation, and risk-based prioritization rather than purely perimeter controls. Buyers evaluating IoT security platforms should compare vendors on coverage breadth—can the tool discover and classify devices across IT, OT, and IoT environments—and on remediation workflow integration. A discovery tool that cannot feed risk data into ticketing, network segmentation, or patch management creates alert fatigue without reducing exposure.

What to Watch

Exein's funding will likely accelerate product velocity and increase competitive pressure on incumbent platform vendors. Expect more vendor consolidation talk and more RFP language around runtime enforcement rather than passive discovery alone. Buyers should also watch for secondary effects from the ServiceNow–Armis deal: smaller vendors may seek acquisition targets or partnerships to compete with integrated platform offerings.

The U.S. Cyber Trust Mark program will likely influence private-sector procurement even where it is not legally required. Buyers can use the criteria as a minimum baseline and layer additional requirements—such as secure boot, coordinated disclosure practices, and documented patch SLAs—on top. Recent IoT security incidents, including a hidden backdoor in 20 router models and six U-Boot flaws impacting 50+ releases, reinforce that firmware support quality and supply-chain hardening are not optional.

IoT SecurityDevice ManagementEmbedded SecurityArmisServiceNow

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in IoT