An Iranian Cyberattack Inspired the Security Tool They Couldn't Find

In an interview with Cybertech, Onit Security Co-Founder Tom Winter explains why security teams' race to clear vulnerability backlogs is exactly what attackers are counting on, and how intelligent automation can shift the balance

An Iranian Cyberattack Inspired the Security Tool They Couldn't Find

Onit founders, right-to-left: Ofer Amitai, Tom Winter, Elad Ben-Meir. Photo credit: Studio Maysa

Before Onit Security was a company – before there was a product or funding round – there was a moment when three friends realized they were looking at a problem that had yet to be solved.

For years, Elad Ben-Meir, Ofer Amitai, and Tom Winter had been close friends and neighbors. They had already founded companies, built products, and achieved successful exits. When they began discussing the idea of starting a company together, one incident kept resurfacing: a cyberattack that Amity, founder and CEO of Portnox, had experienced not long before. It was later determined that the attack had been carried out by an Iranian threat group.

"That incident really stayed with us. It was something Ofer went through as a CEO, and as his friends, we witnessed it from the sidelines and experienced it alongside him," says Tom Winter, co-founder and CTO of Onit Security, in an interview with Cybertech.

"When we started thinking about what we wanted to build together, AI and cybersecurity felt like exactly the right space," he continues. "We told ourselves that if agentic AI – agents capable of handling the painstaking work of combing through massive vulnerability backlogs and accurately identifying weaknesses – had existed when Ofer's company was attacked, there's a good chance the breach could have been prevented. The response would have been much faster.

"We didn't know exactly where everything was, but we knew where the pain was."

When there are too many vulnerabilities and too little time

To understand the pain Winter is describing, it's important to understand one of the biggest challenges facing enterprise cybersecurity today. Organizations don't suffer from a lack of information about threats – quite the opposite. They're drowning in it.

Security tools continuously scan networks, servers, and source code, generating long lists of vulnerabilities. These tools are effective at identifying issues and assigning severity ratings: critical, high, medium, or low.

Within this flood of information, an organization's vulnerability backlog can grow to hundreds of thousands, even millions, of items. For security teams, that means making constant prioritization decisions under severe resource constraints: What gets fixed now, and what has to wait?

In Ofer Amitai's case, that prioritization process became part of the problem.

"What actually happened was that the vulnerability involved wasn't classified as critical," Winter explains. "It fell somewhere in the medium-to-low range. The kind of issue that, in any organization dealing with a large vulnerability backlog, probably wouldn't be addressed anytime soon. And it was precisely in that gap that the attackers got in."

Winter adds that beyond the initial severity score, every vulnerability requires extensive investigation: determining whether it is actually exploitable, identifying the affected asset, understanding its business importance, and figuring out who inside the organization is responsible for fixing it.

"You have to start investigating: What does this vulnerability actually mean? Is it relevant to my environment? Can it really be exploited? What server is this? Who owns it? What's its business impact? There's an enormous amount of painstaking work involved, creating an almost unimaginable burden on security teams."

Replacing painstaking manual work with intelligent automation

That gap ultimately led to the creation of Onit Security. Ben-Meir serves as CEO, Amity as Chief Product Officer, and Winter as CTO.

The company has developed an AI-powered exposure management platform that integrates with an organization's existing security stack and deploys AI agents to prioritize, investigate, and manage vulnerabilities. The agents analyze data from multiple enterprise systems to understand the broader context surrounding every exposure: whether it represents a genuine risk, who owns it, and the most effective way to mitigate it.

"We connect to different systems across the organization and gather pieces of information that help us identify who is responsible for a particular asset," Winter explains. "Once we've established ownership, we can route that unit of work directly to the right person."

He emphasizes that the goal is not to replace security professionals, but to free them to focus on more strategic work.

"Security teams already have an endless workload. They're managing projects, deploying new tools, and building processes. Vulnerability management is often highly tactical. By shrinking that workload, we allow people to spend their time on the things that matter most."

In March, Onit Security emerged from stealth and announced an $11 million seed funding round led by Hetz Ventures and Brightmind Partners. The new capital will support product development and expansion among large enterprises worldwide. The company's goal is to fundamentally change how security teams manage exposures: replacing endless manual reviews with the ability to quickly understand what truly requires attention—and how best to address it.

"Ultimately, our agents are there to do the difficult, repetitive work of working through these massive vulnerability backlogs," Winter concludes. "The goal is to make sure no company is compromised because of a small vulnerability that was left behind. It's about staying one step ahead of the attackers."