Contact
Portfolio

Selected, not collected.

ICM represents cybersecurity companies founded by Turkish entrepreneurs, and only those. Every product here had to answer a question no other product in this portfolio already answers.

DefensX

DefensX

Secure workspace

Secures the browser your staff already use

Read more
GuardPot

GuardPot

Deception

Plants decoys that only an intruder would open

Read more
Cyberthint

Cyberthint

Threat intelligence

Finds what is being leaked and sold about you

Read more
CyberCyte

CyberCyte

Exposure and vulnerability

Verifies the security tools you paid for are really running

Read more
Procenne

Procenne

Data and cryptography

Keeps encryption keys inside certified hardware

Read more
Forestall

Forestall

Identity security

Maps who can reach what, across directory and clouds

Read more
BeamSec

BeamSec

Human layer

Trains staff against phishing, and manages what they report

Read more
Vultage

Vultage

Exposure and vulnerability

Merges every scanner's findings into one ranked list

Read more
S4E

S4E

Exposure and vulnerability

Runs CTEM from outside in, starting from a domain name

Read more
Xcitium

Xcitium

Endpoint security

Runs unknown files in a cage, so ransomware changes nothing

Read more

Data security and masking

upcoming

API security

upcoming

AI runtime security

upcoming

Network security

upcoming

How a product gets in

We have to be able to name what it does that the tools a buyer already owns do not. It has to be ready to sell rather than ready to demo, which means documentation, packaging and a support path that hold up the first time someone who did not build it deploys it. And it has to work under the conditions the region procures under, including data residency and an on-premise option where a tender asks for one.

One product per question

A distributor's catalogue usually carries two or three products per category, because the catalogue grew by opportunity. This one grew from a rule. A product enters an area when the area has no product, or when it answers a question the product already there does not answer.

For a partner that means a quote is not undercut from inside our own portfolio. For a buyer it means the shortlist we hand over has one name on it per problem.

The hardest case is the one to volunteer. Three products sit in exposure and vulnerability, and from a distance they look alike. They are not in the same place. They are in three different ones.

S4E
looks from outside in, and needs no access to anything.
CyberCyte
looks from inside out, and reports on the controls themselves.
Vultage
sits above both, and does no scanning of its own.

Sold together they build one picture. Sold against each other they would build nothing, which is the test each of them had to pass before it was taken on.

The second case sits on one laptop. DefensX controls the browser, where most work now happens. Xcitium controls the operating system underneath it. Neither covers the other's surface, and a partner who has sold one has a reason to come back for the other.

Not sure which one you need?

Start from the problem. We will tell you which of these fits, or that none of them does.

Talk to usBrowse by area