Cyber threat intelligence startup Osavul said on October 1, 2026, that it raised €8.5 million, about $10 million, in Series A funding led by 33N Ventures. The Ukrainian-founded company, now headquartered in Luxembourg, wants to take its AI-assisted warning system beyond government and defence customers into banks, transport operators and other critical businesses. Its real test is whether it can identify a credible threat early enough for those organisations to act, without mistaking online noise for an impending attack.
- Osavul says the Series A brings its disclosed total funding to about €12 million; Balnord, G+D Ventures and existing investor 42CAP joined the round.
- The company seeks signals across information, cyber and physical domains, a broader brief than ordinary network-alert software.
- Its NATO connection is through support for a Brandwatch–Blackbird.AI consortium, according to Osavul’s earlier statement, not an independently verified direct contract with NATO.
- Claims about the number of data points processed, countries served and threats detected are company statements, not independent proof of predictive accuracy.
Osavul’s October 1 company announcement names 33N Ventures as lead investor and Balnord, G+D Ventures and 42CAP as participants. Separately reported accounts from SecurityWeek, The Next Web, Tech.eu and Resilience Media corroborate the financing and strategic expansion. They do not constitute four independent validations of the company’s threat-prediction performance.
What the cyber threat intelligence funding will finance
The immediate news is an €8.5 million Series A round. Osavul says it will use the money to deepen its AI capabilities, build commercial capacity and expand to enterprises and critical-infrastructure operators while continuing government and defence work. The announcement does not break the money into product, sales and hiring budgets, and it does not disclose revenue, profit or a valuation.
That leaves a practical way to read the round. Investors have financed an attempt to turn a specialist security-intelligence product into a repeatable commercial service. Selling to a government team responding to information operations is different from selling to an airport, port, power company or bank. Commercial buyers need to know exactly which risk is being monitored, how alerts connect to assets they operate and how staff should respond.
The company’s proposition starts upstream of an incident. Many security products record malicious code, unusual logins or data moving inside a network. Osavul says it also looks for activity that precedes or accompanies attacks: coordinated narratives, networks of suspicious accounts, hostile planning signals and information that may relate to a facility, supplier or employee. The word “hybrid” describes a campaign that crosses more than one domain, such as an online influence push timed with cyber intrusion or physical disruption.
That broader view is potentially useful, but it raises the difficulty of interpretation. An online rumour is not an attack. A hostile post is not evidence of a specific actor’s plan. Even a genuine cyber incident may have no connection to simultaneous public discussion. A serious buyer should therefore ask how the system links separate observations, what evidence a human analyst sees and how often a warning is later confirmed.
From disinformation monitoring to broader warning
The founders, Dmytro Plieshakov and Dmytro Bilash, developed Osavul after Russia’s full-scale invasion of Ukraine in 2022, according to the company and The Next Web. The early problem was disinformation and coordinated online influence. Osavul now describes a wider system for detecting hostile intent across digital information, cyber risk and possible physical targets.
Resilience Media’s separately reported October 1 interview with Plieshakov offers a more specific account of that transition. The company’s chief executive said its systems monitor more than one billion data points a month across over 100 countries. These are vendor-supplied figures from an interview, not measurements audited by the publication or a third party. Volume also says little by itself about whether the most important signal was found.
More data can produce more false leads. A social-media message may be satirical, automated, copied from another channel or unrelated to an organisation’s real exposure. Valuable cyber threat intelligence needs methods for distinguishing original sources, mapping identities with appropriate confidence and preserving the chain of evidence. Osavul says human analysts review its assessments and that deployments can run inside a customer’s infrastructure. Buyers should test those assertions with real workflows and contractual controls.
The company’s claimed focus on people, facilities and supply chains shows why this is different from generic media monitoring. A port operator cares whether a narrative is being amplified by accounts connected to a sabotage campaign, whether a supplier is being impersonated and whether an actual physical site is at risk. A bank cares whether a phishing campaign, targeted leak and manufactured public panic are related. Treating each observation separately could miss a coordinated operation; treating everything as connected could create equally costly false alarms.
What the NATO connection actually means
Osavul’s announcement says its platform is used by NATO. Its February 2026 statement gives a narrower description: Osavul is deploying technology in support of a Brandwatch–Blackbird.AI consortium selected by the NATO Communications and Information Agency for an Information Environment Assessment Capability. That is a meaningful reference point, but it should not be simplified into a claim that Osavul alone won the main NATO contract.
NATO’s public explanation of its Information Environment Assessment programme describes a system designed to monitor and analyse the information environment to support decision-making. The programme’s existence and purpose are independently documented. The details of Osavul’s role within the named consortium come from the company’s statement; the public material reviewed here does not establish its contract value, access level or operational outcome.
That distinction matters commercially. A role in a defence consortium may help a young vendor demonstrate that its software can fit demanding workflows. It does not automatically show that the same product can be bought, deployed and used effectively by an airline or insurer. A private buyer will have different data feeds, response authority, privacy rules and reporting needs.
Can the product move into critical infrastructure?
Osavul says its target sectors now include energy, airports, ports, transport and finance. These organisations have physical operations and reputational exposure as well as computer networks. A misleading information campaign could be used to confuse a public response; a supplier compromise could affect logistics; a cyber intrusion could disrupt operational technology. That combination makes the category relevant beyond defence procurement.
Yet the commercial proof is still ahead. Osavul’s October announcement does not name enterprise contracts, disclose recurring revenue or publish externally measured alert quality. The Next Web reports the planned expansion, while SecurityWeek describes the platform’s proposed value in mapping intent to assets. Neither report offers an independent, multi-customer test of prediction accuracy.
For a large buyer, a pilot should begin with an agreed threat scenario and a known set of assets. The vendor and customer can then compare alerts with independently recorded events, note how much analyst time review requires and check whether warnings arrived before rather than after an incident. The trial should also document false positives and cases the system missed. Without those measures, a dashboard can look impressive while delivering little operational value.
Privacy and source governance are another test. Intelligence products may combine public data with material a customer provides under licence or confidentiality restrictions. A buyer needs to know where data is stored, whether it is used to train shared models, who may inspect it and how long evidence is retained. Osavul says it can deploy on premises and involve analysts in review; each customer should confirm the actual arrangement in a contract and technical assessment.
Why the development matters in India
The company has not announced an India office, Indian customers or a local sales plan in the materials reviewed for this report. Its financing should not be described as an India expansion. The India connection is a buyer question: Indian banks, ports, airlines, utilities and large digital platforms operate systems whose reputational, cyber and physical risks can overlap, sometimes across multiple countries.
Indian organisations considering cyber threat intelligence could compare a hybrid warning service with the tools they already use: security operations monitoring, brand protection, fraud intelligence and crisis communications. The value would lie in joining the signals and improving a decision, not merely adding another feed. As with the Armadin AI cybersecurity funding Lapaas Voice covered, capital can finance an ambitious approach but does not establish operational effectiveness.
The company’s AI element should also be understood accurately. A model can help sort large volumes of language, identify coordinated patterns and trace possible links. Human investigators still have to judge intent, context and consequence. Our coverage of Gemini 4 Argon’s limited cyber-defence rollout made a similar point: early access and vendor benchmarks are starting evidence, not proof that a system will succeed in every operational setting.
There is also a wider governance link. When an AI system produces recommendations about sensitive operations, organisations need permission boundaries, audit trails and accountable reviewers. The same principle appears in our report on enterprise controls for AI agents. Osavul’s task is intelligence rather than autonomous remediation, but a false accusation or an unsupported warning can carry consequences. Evidence quality and human review therefore matter as much as speed.
What to watch after the Series A
The first milestones to watch are customer deployments outside government, product documentation that clarifies what the system can and cannot infer, and case studies with measured lead time and error rates. An announced partnership or customer logo is useful context; a reproducible example of a warning that changed a decision would be stronger evidence.
Investors will be watching whether Osavul can build a commercial process around a specialised security capability. Public institutions may buy for strategic awareness, while private companies may demand shorter procurement cycles, clear return on analyst time and integration with existing incident-response systems. Those differences can change product design as much as a new AI model can.
Osavul’s €8.5 million Series A is a verified funding event. The proposition behind it is that cyber threat intelligence should connect weak signals across online, digital and physical environments before a crisis is obvious. The company has first-party support for the funding details and independent reporting on the round. Whether its broader early-warning promise works consistently for private-sector customers remains to be tested in disclosed, real-world use.
Frequently asked questions
How much did Osavul raise?
Osavul announced €8.5 million in Series A funding on October 1, 2026. It described the amount as about $10 million and said total funding is approximately €12 million.
What is hybrid threat intelligence?
It is analysis that connects information activity, cyber signals and possible physical risks to identify a coordinated threat. An alert is a lead for investigation, not proof of a specific actor’s intent or an imminent attack.
Does Osavul work directly for NATO?
Osavul says its technology supports a Brandwatch–Blackbird.AI consortium selected for a NATO information-assessment capability. Public materials reviewed here do not establish that Osavul alone holds the primary contract or disclose its contract value.
Is Osavul expanding to India?
The October 1 announcement did not identify an India launch or Indian customers. Its planned expansion is into enterprise and critical-infrastructure sectors more generally.
Reporting note: First-party records are Osavul’s October 1 financing announcement and February description of its consortium role, alongside NATO’s programme explanation. The financing and expansion were cross-checked with separately published reports by SecurityWeek, The Next Web, Tech.eu and Resilience Media. Deployment, data-volume and performance claims are explicitly attributed to the company; they have not been independently audited for this article.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



