Osavul raises $10M to spot hybrid threats before attacks
Luxembourg-based Osavul, which describes its business as hybrid risk intelligence, has closed a $10 million (EUR 8.5 million) Series A round. A Series A is usually a startup's first major institutional funding round after its early seed money. 33N Ventures led the investment, and Balnord, G+D Ventures and 42CAP also took part.
The round brings Osavul's total funding to roughly EUR 12 million.
What the platform does
Osavul sells an AI platform that analyzes both open and privileged data. Its goal is to detect hostile intent before an attack actually happens. The platform does this across three domains at once: cyber, physical and information.
For a customer, the platform tries to answer two questions. The first is who is targeting the organization. The second is how that intent maps onto the customer's people, facilities and supply chains.
The company says every assessment is evidence-traced and reviewed by human analysts. The platform can also run on-premises inside sovereign infrastructure, so sensitive data does not leave the customer's own systems. Government and defense buyers often treat that kind of deployment as a requirement.
Built during the war in Ukraine
Osavul first developed its technology during Russia's invasion of Ukraine. Today it serves government, defense and security institutions in more than 10 countries.
The company is also one of the technology firms delivering NATO's Information Environment Assessment Capability. NATO is the transatlantic military alliance.
Dmytro Plieshakov, the company's CEO, founded Osavul together with Dmytro Bilash. The two had previously sold their company, Captain Growth, to Perion.
Where the money will go
Osavul plans to use the funding in three areas. It will improve the platform's AI capabilities and expand into enterprises and critical infrastructure operators. It will also build out its existing government and defense work.
The move toward the private sector follows what the company calls growing hybrid activity by hostile states and their proxies. These campaigns combine cyberattacks with sabotage, espionage and information manipulation. According to Osavul, more than 150 state-linked incidents have been recorded across Europe since 2022.
"Hybrid attacks are no longer a government problem alone. The companies running energy, airports, ports, transport and finance now face the same adversaries, usually without the means to see them coming," said Plieshakov.
The Bigger Picture
Osavul's core argument is that threat intelligence should not stop at the network perimeter. For security teams at energy suppliers, airports, ports or banks, this points to a wider definition of the job. Physical sabotage and influence operations may sit alongside phishing and malware, and the same state-backed actors may be behind all of them.
Recent events show how closely these areas overlap. The internet outages in Kyiv after Russian strikes on data centers are one example of physical attacks causing digital disruption. In the US, the debate over voluntary cyber rules for telecoms after Salt Typhoon shows that private infrastructure operators are increasingly expected to defend against nation-state adversaries.
By current standards the round is modest, especially next to deals such as Armadin's $255.5 million raise. Osavul's pitch is narrower and depends more on analysts. One thing to watch is whether a product built for governments and defense agencies works for companies that often lack in-house intelligence teams. Another is how well the "evidence-traced" claims hold up when customers start acting on the assessments.
