Tamar Bar-Ilan

Co-founder and CTO of Cyera, a cloud data security company

Overview

Tamar Bar-Ilan is co-founder and CTO at Cyera[1], a position Bar-Ilan has held since March 2021[3]. Prior to founding Cyera, Bar-Ilan worked as a Software Architect at Lynxight in 2020[4] and spent seven years in research and development roles with the Israel Defense Forces from 2013 to 2020[5]. Bar-Ilan's educational background includes participation in the Talpiot Program as a cadet from 2010 to 2013[6] and a Bachelor of Science degree in Physics and Computer Science from The Hebrew University of Jerusalem, completed in 2013[7].

Career history

  1. Co-Founder & CTOMar 2021 to PresentCyera
  2. Software Architect2020 to 2020Lynxight
  3. R&D2013 to 2020Israel Defense Forces
  4. Cadet2010 to 2013Talpiot Program

Education

  1. Bachelor of Science - BS, Physics and Computer Science2010 - 2013The Hebrew University of Jerusalem

Insights & ideas

The through-line

One observation sits underneath everything Tamar Bar-Ilan says about data security: enterprises do not know what sensitive data they hold. "When we started out and and started meeting with security teams, what we heard from pretty much everyone was, 'I don't know what sensitive data my organization has and I don't know where it is and what's happening with it.' Pretty scary notion, right?" [1] That gap is old, but it has become acute because data no longer lives in one or two databases. It sits across hundreds and even thousands of types of systems, in the cloud and in AI systems, and knowing what you have, where it resides, how it is used, by whom and for what purpose "sounds so trivial, but to do it at enterprise scale and to do it at the speed of technology today is a huge challenge" [1].

The shift over time is in what makes the problem solvable and what makes it urgent. Large and small language models are, in her account, the transformational technology that turned a decades-old problem with no good solution into something "that's solvable and and feasible and really works at enterprise scale" [1]. The same wave of AI that supplies the tooling also supplies the threat: agents plugged into corporate systems consume data at a rate not previously seen, which turns latent exposure into live exposure. She has been making the case for Cyera in founder-facing settings as well as customer ones, including as one of the founders featured in the TWiST500 coverage [2].

On the visibility gap as the first product

Visibility is not a preliminary step in her telling, it is the thing customers react to first. She describes the initial reaction to Cyera as logging into the data stores page and seeing "the hundreds of thousands of data stores in your environment with kind of a granular breakdown of every type of data, every file that's contained within each one," and notes that "most CISOs and CTOs have had never had that kind of visibility before" [1]. The response she looks for is exploratory rather than alarmed, users who "want to just go and explore and see what's in there" [1]. The framing she heard from the market on the way in was that "data is the new oil or data is our most important asset," which made the absence of an inventory of that asset the natural place to start, and it is where customers pointed the company initially [1].

On why AI agents break the old assumptions

Her sharpest argument is that most enterprise security has been resting on human laziness. "We buried a lot of sins in the access people had to data that they never used. We all have access to millions of documents, countless data that we've never touched and we'll never touch as human beings" [1]. Agents remove that protection: "they move much faster, they read much faster, and they're able to go through endless quantities of data, and everything and anything they can put their hands on is going to rise to the surface" [1]. She is explicit that this is not a marginal change in risk posture but a structural one, since "a lot of the security at present state is just based on the fact that humans never look for it. They never dig all the way through, they never rummage through every drawer and and and try to find the secrets, and the agents do. And that's a material change that everybody is experiencing" [1]. The autonomy that makes agents valuable is the same property that creates the exposure: agents "have this independence and autonomy and can really do a lot more than a simple application, but but that's also a potential risk that that needs to be managed and and curtailed," which is why she argues for "automated visibility and control into how these agents are are behaving and and and what they're doing" [1].

On guardrails, and going fast safely

Her prescription is controls that sit around the agent rather than restrictions on adoption. Guardrails are described as controls to prevent an agent from doing something, for example blocking questions on topics the enterprise does not want answered, and the concrete failure mode she flags is an agent that touches healthcare and other sensitive data with no guardrails configured at all, where the recommendation is to put guardrails in place "to prevent it from sending sensitive data to the wrong person" [1]. Cyera treats such a misconfiguration as an "issue," a violation that might introduce risk [1]. The governing metaphor is automotive: "you do not want to take a car and drive it at 200 mph without an airbag and a seatbelt. You want good brakes, you want an airbag, you want a seatbelt, and that that's what makes you comfortable to drive really fast" [1]. Safety equipment, in other words, is what permits speed rather than what limits it.

On inline detection and insider risk

Beyond posture and configuration, she describes a real-time layer that sits in line, reading prompts and responses and watching what tool calls an agent makes, then judging behaviour in context: given the employee, the agent in use and the types of data being sent, "does this make sense? Is are they doing something malicious or is this part of their day job?" [1] The worked example is an employee who supplied an embargoed Q2 earnings call transcript containing non-public information to ChatGPT and then solicited investment advice based on it, surfaced as an insider trading solicitation alert with full details attached [1]. The point of the example is that the signal only becomes legible when data sensitivity, identity and intent are read together.

On building a platform rather than a point product

She frames Cyera's product line as a set of layers over the same data understanding: DSPM for data security posture management; Omni DLP, a DLP orchestration and enhancement product built with AI; an endpoint client that replaces legacy endpoint DLP while also securing AI on the endpoint, including tools like Cloud Co-Work; and identity products that protect how identities interact with data and map which identities, human and non-human, exist in the enterprise IT ecosystem and in identity security [1]. The company works through integrations with tools including Microsoft Sentinel, ServiceNow and Okta [1].

On speed, capital and acquisitions

Her stated reason for raising is time, not runway. "The name of the game today is speed," and the round is justified because "it accelerates us. It allows us to move even faster than we move before and deliver the value that our customers need at a pace that their business is moving it with AI, which is uh extremely fast" [1]. Capital is directed at doubling down on the product and platform organically, and at inorganic growth "by making acquisitions, strategic acquisitions into spaces where we we see our customers needing us to be, and we're not there yet" [1]. Her acquisition criterion is people first: "we feel that bringing in a team that has that fundamentality and the ability to go and really strike a path in the market, it's not often that we meet a team that we really want to spend the next four years together with, but when we do get those opportunities, we we act on them" [1]. Acquired teams and their technology are threaded directly into the core platform, a pattern applied with Trail Security, Rift and Genie Security [1]. Investor Logan Bartlett, who helped lead the Series B, has said the first acquisition felt too early to him given the difficulty of managing culture at that growth rate, and that it nonetheless worked [1].

On trust as the actual product

The ambition she states is positional rather than technical: that within three years Cyera becomes "the standard for secure AI adoption across the enterprise," viewed by customers as their strategic partner for adopting and innovating with AI [1]. Underneath that sits a claim about what security is for. "Safeguarding digital trust while we innovate and reinvent the rules of the game, the rules of the the universe if you will, is not trivial. Trust is not guaranteed. It's something that can easily erode and deteriorate," and the role she wants for the company is securing the trust of enterprises with their data and of their customers with them [1].

Takeaways

  • The founding insight came straight from security teams saying they did not know what sensitive data they had, where it was, or what was happening with it [1].
  • Language models, large and small, are what made a decades-old data classification problem solvable at enterprise scale [1].
  • Existing security quietly depends on humans never exhausting their access; agents that read everything they can reach dissolve that assumption [1].
  • The fix for agent risk is automated visibility plus guardrails, controls that block an agent from sending sensitive data to the wrong recipient, treated as configuration issues when missing [1].
  • Sitting in line on prompts, responses and tool calls allows behaviour to be judged in context, as with an employee pasting an embargoed earnings transcript into ChatGPT and then soliciting investment advice [1].
  • The platform spans DSPM, Omni DLP orchestration, an endpoint client replacing legacy endpoint DLP, and identity products covering human and non-human identities [1].
  • Capital is deployed for speed, both organically and through strategic acquisitions into gaps customers need filled, with team quality as the deciding test [1].
  • The stated three-year goal is to be the standard for secure AI adoption, on the premise that "trust is not guaranteed" [1].

Media & appearances

  • Tamar Bar-Ilan, co-founder and CTO of Cyera, discusses how enterprises lack visibility into their data across hundreds or thousands of systems and how AI agents pose new security risks by accessing data at scale. She explains Cyera's products including DSPM, DLP orchestration, and identity security tools, and emphasizes the need for automated visibility and controls around AI agent behavior, including guardrails to prevent sensitive data exposure.YouTube
    Cyera Co-Founder and CTO Tamar Bar-Ilan talks about its ...
  • This Week in Startups is brought to you by… Oracle - Oracle Cloud Infrastructure, or OCI, is a single platform for your infrastructure, database, application development, and AI needs. Save up to 50% on your cloud bill at https://w⁠⁠⁠⁠ww.oracle.com/twist⁠⁠ Intercom - Intercom's AI-first service is the best thing to happen to your customers since you. TWIST listeners can get 90% off Intercom's platform at https://www.intercom.com/twist Lemon.io - Hire pre-vetted remote developers, get 15% off your first 4 weeks of developer time at https://www.Lemon.io/twist * Todays showApple Podcasts
    Floor Talk with Cyera Co-Founder and CTO Tamar Bar-Ilan ...We are kicking off our coverage of the TWiST500 with three fantastic founders: Kyle Hanslovan of Huntress (11:44), Olivia Joslin and Toshit Panigrahi of TollBit (36:40), and Tamar Bar-Ilan of Cyera (56:44).

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.