Insights

The Best Angel Syndicates in Cybersecurity (2026)

The cyber angel syndicates that actually co-invest: SVCI, Venture in Security's practitioner group, Cyber Club London, and why the CISO funds aren't syndicates.

By Alexej Pikovsky  ·  Updated

A cybersecurity angel syndicate is a group of security insiders who pool their own money, deal by deal, to back early cyber startups. The logic is simple and it is the reason these groups exist at all: the people who run security programs and the people who build the tooling see new attack vectors and new categories before any analyst or generalist fund does. If you can turn that visibility into capital, you get a first look at the next wave.

I work with security-adjacent businesses, including inside a national MSP, and I track the cyber capital stack closely because it decides which vendors an MSP can safely build on. This page is the map of who actually co-invests at the angel stage in security, sorted by what they really are. That last part matters more than it sounds, because half the "syndicates" you find on Google are funds with a CISO on the masthead, and a few are communities that never write a check at all.

Key Takeaways

  • The two syndicates worth knowing first are SVCI (Silicon Valley CISO Investments), the oldest and most active CISO angel group with a real named exit, and the Venture in Security Angel Syndicate, the practitioner-led group that opened the model to engineers and analysts rather than only CISOs.
  • There is a hard line between three things people call "syndicates": true co-investing angel groups (SVCI, ViS Angels, Cyber Club London), VC funds that keep CISOs as advisors (NightDragon, Ballistic, Rain Capital), and pure networking communities that invest nothing (Team8 CISO Village, ClubCISO). Confusing them is the fastest way to waste a fundraising quarter.
  • The edge these groups sell to a founder is not the money. The checks are small, often a few hundred thousand dollars across many members. The edge is design-partner access: the members are your buyers.
  • Geography has opened up. SVCI is Bay Area, Cyber Club London covers the UK, Europe and Israel, and Israeli vehicles like KMEHIN and Elron's CyberFuture cover Tel Aviv. Where you raise your angel round increasingly signals where your first buyers are.
  • Verified July 2026 against each group's own site and primary coverage. Where a group would not confirm a founder name, a portfolio, or a check size, this page says so rather than guessing.

Quick Answer

If you are a security founder raising a first round, target SVCI if your buyer is a Bay Area CISO and you can get a member to sponsor you, the Venture in Security Angel Syndicate if your product is bought by practitioners rather than the CISO, and Cyber Club London if your market is European or Israeli. If you are a security engineer or operator who wants to start angel investing, ViS Angels is the only group on this page built for you rather than gated to the CISO title. Everything else labelled a "cyber syndicate" is either a conventional fund or a community, and this page separates them out so you do not pitch the wrong kind of money.

What Counts as an Angel Syndicate, and What Doesn't

Before the list, the distinction that saves you the most time.

A true angel syndicate is a group of individuals who each invest their own money into a specific deal, usually through an AngelList-style special purpose vehicle, deciding one company at a time. No committed fund, no management fee in the classic sense, no board seats. SVCI, ViS Angels, Cyber Club London, and the operator-led AngelList groups belong here.

A fund with a CISO layer is a committed institutional vehicle that happens to keep security executives around as advisors or operating partners. The CISOs add credibility and pattern recognition, but the capital and the decision belong to the fund. NightDragon, Ballistic Ventures, Rain Capital, and the Cyber Mentor Fund sit here. They are worth knowing, but they are not syndicates, and I keep them in a clearly separate section below.

A community is a private forum of security leaders that runs summits, surveys, and introductions but writes no checks as an entity. Team8 CISO Village and ClubCISO are the clearest examples. Useful to be near, but do not send them a deck expecting a term sheet.

The CISO-Led Syndicates

These are gated to people who hold or held the top security job. The thesis is that CISOs are the buyers, so their money and their reference are worth more than the dollars alone.

SVCI (Silicon Valley CISO Investments)

SVCI is the anchor of the whole category. It was formed in September 2019 by a group of Bay Area CISOs alongside Oren Yunger, then at GGV Capital and himself a former CISO. Founding members read like a security-leadership roster: Joel Fulton (Splunk), Harshil Parikh (Medallia), David Tsao (Marqeta), Al Ghous, Clint Maples, Jonathan Jaffe, Ody Lupescu, and Ralph Pyne, among others. It has since grown to somewhere north of fifty CISOs.

The model is invite-only and CISO-only. If you are a security engineer, you cannot join, which is exactly the gap the practitioner syndicates later tried to fill. SVCI runs on a quarterly cycle: startups submit through an intake form, members meet twice a quarter, there is a pitch day, then diligence. The unwritten rule founders miss is that you want an SVCI member sponsoring you before you apply, not after.

On check size the sources diverge, and I will not pretend they agree. SVCI's own guidance asks founders to allocate at least $350K for the group to invest, with no board seats taken. Some third-party write-ups cite ranges up to several million at seed and Series A, but I would trust SVCI's own number over the aggregators. The portfolio is the real proof: sixteen companies since 2019, including Orca, Drata, Tines, Island, Traceable, Endor Labs, Descope, and Polyrize, which was acquired by Varonis in 2020 and stands as the clearest named exit. For a group investing its members' personal money, that is a serious track record. Many of these names also show up when you map the most active cybersecurity VCs, because the good angel deals and the good Series A deals are the same deals seen one round apart.

Cyber Club London

Cyber Club London is the best entry outside Silicon Valley. Founded around 2021, it is an invite-only club of fifty-plus cybersecurity executives that positions itself, in Ross Haleliuk's own description, somewhere between SVCI and the practitioner syndicates: a CISO-and-operator blend rather than a pure CISO gate. It is London-based and invests into European and Israeli startups, which makes it the natural angel-stage counterpart to the funds in my UK cyber investors and European cyber investors lists.

Members decide individually whether to invest based on their own accreditation and judgment, so it is a club-and-syndicate hybrid rather than a pooled fund. Startups need a working product or proof of concept and present to members, who evaluate on team, market, and technology. Named portfolio companies across sources include Clutch Security, Noma Security, Seal Security, Miggo, Aim Security, Oligo Security, and Tracebit, several of which also landed in the AWS and CrowdStrike EMEA cybersecurity accelerator. I am deliberately not naming a single founder for the club, because the one name floating around online could not be corroborated against a primary source, and a wrong attribution in print is worse than an omission.

KMEHIN Ventures and CyberFuture (Israel)

Israel produces a disproportionate share of security companies, so it has its own CISO-adjacent vehicles, but both come with a categorization caveat I want to be honest about.

KMEHIN Ventures is a Tel Aviv group described by several databases as a CISO-led early-stage cyber investor in the SVCI mold, with Oligo and Wib (acquired by F5 in 2024) among its names. But its principals are not publicly disclosed, and a fund entity, Kmehin Ventures Fund I, appears in Israeli filings, so it may be closer to a small fund than a pure syndicate. CyberFuture is Elron Ventures' "Global CISO Investment Alliance," launched in 2023, pairing an Elron-run vehicle with a rotating alliance of named CISOs including Vijaya Kaza (Airbnb) and Gerhard Eschelbeck (ex-Google), with Astrix Security, CyVers, Entitle, and Scribe in the portfolio. Both are worth a founder's time in Israel, but treat them as fund-plus-CISO structures rather than member-run syndicates. For the full Israeli picture see my Israel cyber investors breakdown.

The Practitioner-Led Syndicate

Venture in Security Angel Syndicate (ViS Angels)

This is the one that changes the model, and it is the syndicate behind the podcast that prompted this page. Ross Haleliuk, who writes the widely read Venture in Security newsletter and wrote the book Cyber for Builders, co-launched ViS Angels in early 2023 on a specific bet: the CISO syndicates capture the buyers, but the people who see new attack techniques first are the practitioners, the security engineers, SOC analysts, detection engineers, and pentesters doing the work. So ViS Angels is deliberately open to practitioners, not gated to the CISO title.

The mechanics are built for that audience. Members can participate with as little as roughly $1,500 to $2,500 per deal, far below the entry point of a traditional angel group, and there are incentives for members who source deal introductions. The focus is seed-stage US cyber companies. The honest caveat: I could not find a named, public portfolio for the syndicate, so I frame it as thesis-forward rather than track-record-proven. The thesis itself is sound, and Ross has been candid that co-investing with practitioners is harder than it looks, because a practitioner's exposure to a vendor comes through the tool they use rather than a board meeting. If you want the deeper argument for why operators make better cyber investors than financiers, I made that case separately in why the best cyber VCs were operators first, and Ross's newsletter is one of the sources I track in the cyber investor newsletters worth reading.

Operator- and Platform-Led Syndicates

Not every security syndicate is gated to a title. Two are open on AngelList to accredited investors and run by founders and operators rather than sitting CISOs.

The Enterprise Security Syndicate, led by Ed Roman and Kevin Rowney, the founder of Vontu (acquired by Symantec), writes roughly $258K a deal across about four investments a year, into enterprise-security SaaS broadly rather than a narrow CISO thesis. The Alumni Ventures Cybersecurity Syndicate is a deal-by-deal product from the large Alumni Ventures platform that lets retail-accredited investors co-invest alongside firms like a16z and Sequoia, with JumpCloud, Eclypsium, and Lightbeam among cited names. Neither carries the buyer-access edge of a CISO or practitioner group, but both are real vehicles a smaller investor can actually access.

Adjacent: Funds With CISO Firepower, Not Syndicates

These come up constantly in "cyber syndicate" searches. They are funds. The CISOs are advisors, not co-investors deciding deal by deal. Keeping this straight is the single biggest credibility risk in this whole topic, so here it is in one table.

Firm What it actually is The CISO layer Note
NightDragon Late-stage growth SecureTech fund (founded 2018, Dave DeWalt) 50-plus member advisory council Not seed, not angel, not a syndicate
Ballistic Ventures Institutional cyber VC (Kevin Mandia, Ted Schlein) CISO-in-residence and operating partners Traditional fund, $360M Fund II
Rain Capital Cyber VC fund (Chenxi Wang, 2018) Founder is ex-Forrester, ex-Twistlock First women-led cyber fund; a fund, not a syndicate
Cyber Mentor Fund Mentorship-driven cyber fund (Tim Eades, 2018) Entrepreneur-mentor community $100K to $5M checks, still a fund

If your round is past the angel stage, these and the broader private equity firms in cybersecurity and the cyber accelerators and venture studios are the right doors. Just do not pitch them as if they were a member-run syndicate.

Communities That Aren't Syndicates

Two names round out the confusion. Team8 CISO Village is an invite-only community of 600-plus CISOs run by the Team8 venture studio; the Village produces a summit, surveys, and a pitch competition, but Team8 the fund does the investing, not the Village. ClubCISO is a 500-plus member private forum in the UK and Europe that is explicitly non-commercial: peer discussion and surveys, zero investing function. Be near them for the relationships and the market signal. Do not send them a term sheet.

How to Actually Get Into One

For founders: the pattern across every real syndicate here is a member sponsor. Cold applications to SVCI or Cyber Club London go nowhere; a warm introduction from a member who will vouch for you in the room is the whole game. Have a working product, because these buyers evaluate the tool, not just the deck. And match the group to your buyer: a CISO syndicate is worth far more than its check if CISOs are who you sell to, and close to useless if your product is bought bottom-up by practitioners, where ViS Angels is the better room.

For would-be investors: if you hold the CISO title, SVCI and Cyber Club London are the premium rooms but invite-only, so the path in is being known to a member. If you are a practitioner, ViS Angels was built for you. If you are simply an accredited investor who wants cyber exposure, the Enterprise Security and Alumni Ventures syndicates on AngelList are open in a way the gated clubs are not.

How This List Was Built

I pulled each group's own site and primary press coverage in July 2026, and I categorized every entity by what it actually does with money, not what it calls itself. Where a group would not confirm a detail, I left it out: I do not name the Cyber Club London founder, because the only name I found was uncorroborated, and I frame ViS Angels as thesis-forward because it has no public portfolio yet. I also left out at least one group that self-describes as a large "security syndicate" but has no verifiable founder, site, or portfolio. If a check size or an exit is not stated here, it is because I could not stand behind it, not because it does not exist. If you run one of these groups and want a detail corrected, tell me and I will update it.

FAQ

What is a cybersecurity angel syndicate?

It is a group of security insiders, usually CISOs or practitioners, who invest their own money into early cyber startups one deal at a time, typically through an AngelList-style vehicle. Unlike a fund, there is no committed pool or management structure making the call; each member decides per deal. The value to a founder is less the capital than the fact that the members are often the exact buyers the startup is trying to reach.

Which is the best cyber angel syndicate to raise from?

If your buyer is a CISO, SVCI is the most established and active, with the clearest track record, though it is invite-only and Bay Area-centered. If your product is bought by security practitioners rather than the CISO, the Venture in Security Angel Syndicate is built for exactly that. If your market is European or Israeli, Cyber Club London is the strongest fit. The best syndicate is the one whose members are your customers.

Is SVCI open to non-CISOs?

No. SVCI is invite-only and gated to current or former CISOs. That gap is precisely why the Venture in Security Angel Syndicate launched, opening angel investing in cyber to security engineers, analysts, and other practitioners rather than only the top title.

Are NightDragon and Ballistic Ventures angel syndicates?

No. Both are institutional venture funds that keep CISOs as advisors or operating partners. The capital is a committed fund and the decisions belong to the firm, not to members co-investing deal by deal. They are worth knowing if you are raising a larger round, but pitching them as a member-run syndicate misreads what they are.

How do you get into an invite-only cyber syndicate?

Through a member. Every real syndicate on this page runs on member sponsorship, so the path in for a founder is a warm introduction from someone inside who will vouch for you before the pitch. For investors, it is being known and trusted by existing members, or, if you want an open door, using the accredited-investor syndicates on AngelList that do not gate by title.