Cribl, a telemetry platform provider, has announced the acquisition of CardinalOps, an Israeli company that develops detection engineering solutions. The acquisition expands Cribl’s platform with threat detection capabilities and positions the company as an open alternative to traditional SIEM systems.
Security teams are processing increasingly large volumes of telemetry data. At the same time, the costs for storing and analyzing this data are rising. Many teams have extensive data and powerful tools but cannot say with confidence where they are covered and where they are not. Cribl aims to address these challenges through the acquisition of CardinalOps. The combined platform is designed to enable organizations to use telemetry data more selectively, continuously validate detected threats, and improve detection quality.
Clint Sharp, co-founder and CEO of Cribl, emphasized that security teams do not need additional isolated tools. Instead, they need a better way to convert telemetry data into effective detections. CardinalOps complements Cribl’s open data infrastructure with detection engineering functions, thereby forming the foundation for an open alternative to existing SIEM stacks.
Cribl follows a platform-oriented approach. The company offers a vendor-independent solution that allows customers to analyze, collect, move, store, and respond to telemetry data across their entire environment. A federated model makes it possible to search and process data where it resides, without having to migrate everything into a central system. With CardinalOps, Cribl expands its platform with fundamental detection engineering capabilities. Everything that a SIEM provides should be able to build on the existing telemetry infrastructure of customers.
CardinalOps was founded in early 2020 and is led by Michael Mumcuoglu and Yair Manor. Both are serial founders and former members of the Israeli cyber unit Unit 8200. Their previous companies were acquired by Palo Alto Networks and Microsoft, respectively. CardinalOps uses AI-supported methods to continuously evaluate and improve the detection coverage of organizations. Security controls are compared with real attacker behavior. The solution automates detection engineering tasks, helps teams identify and close coverage gaps, and identify and correct faulty or noisy rules.
Michael Mumcuoglu, co-founder and CEO of CardinalOps, explained that many security teams have good data and powerful tools but do not feel protected. CardinalOps aims to support SOC teams in understanding and improving their coverage, rather than just managing more distracting false alarms. The merger with Cribl makes it possible to integrate these capabilities directly into the telemetry layer and develop an open, AI-native alternative to SIEM systems, where customers pay for better protection rather than for more data volume.
As part of the acquisition, Cribl is opening a new office in Tel Aviv. The company wants to gain access to the Israeli pool of cybersecurity talent and accelerate the development of its security solutions. Israel is considered one of the world’s most active innovation centers for cybersecurity.
Javier García Quintela, Global CISO of the energy company Repsol, confirmed the practical benefit of the combination. Repsol operates a diverse and distributed security environment. CardinalOps strengthens the detection position across various platforms, while Cribl provides the flexibility to efficiently manage and analyze telemetry data in that same environment.
Cribl remains true to its brand core: an open platform with lightweight solutions that build on it, and the freedom for customers to use exactly what they need without entering into vendor dependencies. The acquisition also creates a foundation for future security offerings based on the Cribl platform.
Cribl plans to integrate CardinalOps technology into its existing platform. The company aims to create a comprehensive and open alternative to traditional SIEM architectures. Customers should be able to modernize their security environments gradually without entering into new vendor dependencies. The goal is a model where organizations pay for better protection rather than for more data volume.
Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de
Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de