Security

PortSwigger, the company behind the Burp Suite of security testing tools, swallows $112M

Comment

Blue binary code on black background interspersed with open and closed locks.
Image Credits: JuSun / Getty Images

Sometimes the most successful startup ideas come from people building tools to solve their own needs. Such was the case with Dafydd Stuttard, a security expert who goes by Daf. 

Nearly two decades ago, living in the small market town of Knutsford in Cheshire in the northwest of England, Daf was working as a security consultant for different clients. 

On the side, he built apps that he could use himself to speed up some of the more routine parts of his work. He would give each tool a random name, use it for a while and move on; sometimes he would tell others in his community about the tools in case they were useful. (Daf already had a reputation as an ethical hacker and author in the security community so there was a ready audience for that.)

One day, tooling that he built to assist with penetration testing – named Burp for no specific reason at all – was one of his creations that he shared with others. It caught on, fast, and Daf decided to see how much further he could take it. 

Fast forward to today, you can see the fruits of Daf’s instincts on the value of the tool. 

Burp is now Burp Suite, which is the centerpiece of a startup called – playing on the drinking theme – PortSwigger. It has more than 20,000 organizations as customers across 170 countries, with 80,000 individuals and “well over” 1,000 enterprises and organizations using its paid enterprise edition. (The enterprises include  Microsoft, Amazon, FedEx, Salesforce and more.) Another operation under the PortSwigger umbrella, an educational platform called Web Security Academy, has more than 1 million users. And yes, there are now dozens more employees besides Daf.

PortSwigger, at 17 years old, has been bootstrapped and profitable from the start. Now, for the first time, Daf has decided to take on a substantial outside investment of $112 million to take the company to the next level. Brighton Park Capital from the U.S. is the sole investor. 

“We need more expertise to achieve our ambition,” Daf said in an interview. “The market is getting bigger and more complicated and our customers’ needs are getting bigger.”

“But capital wasn’t the biggest driver since we are cash-flow positive, and we had our pick of firms to work with,” he continued. That inbound interest came not just from investors but potential acquirers. 

The company owes some of its success to Daf’s own reputation and modest accessibility.

(“Got an email from Daffyd Stuttard @portswigger today in response to a question about burp extender,” someone noted once on Twitter, now known as X. “Kinda feel like god just sent me an eml.”

But its rise also comes at the same time that cybersecurity has taken on a much bigger profile.

There are a number of point solutions provided by vendors across a vast, complex and rapidly evolving security landscape – a landscape that has been formed out of the fact that security breaches and vulnerabilities are rising at record rates and causing more damage than ever  before, not least because of the injection of AI into the equation – and that has led to the creation of yet more applications and approaches to tackle that. 

But one constant in that mix has been the role of individuals with deep area expertise: ethical hackers and human testers continue to play a major role in how problems get identified and fixed. 

But these individuals need assistance and tooling, and that is where a company like PortSwigger comes in. 

There are others like HackerOne and Bugcrowd that have aimed to productise the role of individual white hat hackers in security operations. Daf notes that these are not competitors to PortSwigger: they partner and his startup provides tooling to those platforms and others like them, which in turn get used by their users. 

Longer term, it will be interesting to see what impact newer technologies and architectures will have on the role of individuals in tackling and solving security problems. 

Although you might assume that a newer innovation like AI might present a threat in that regard, that is not the case, at least for now. Daf notes that there are a number of repetitive actions that penetration testers might perform that can be improved with automation. 

Its sole investor agrees.

“We believe that despite automation, pen testers are still going to be required,” Tim Drager, a partner at Brighton Park, said in an interview. “Experts really understand. The attack surface has grown massively, and APIs have become prime targets, but when you couple that with the shortage of cyber professionals who have deep domain expertise… that’s why you need tools to help those who know what to do be more efficient. We see this as a prime area for growth. PortSwigger gives them super powers.”

More TechCrunch

Orby AI, is building a generative AI platform that attempts to automate a range of different business workflows, including workflows that involve data entry, documents processing and forms validation.

Orby is building AI agents for the enterprise

Sometimes the most successful startup ideas come from people building tools to solve their own needs. Such was the case with Dafydd Stuttard, a security expert who goes by Daf. …

PortSwigger, the company behind the Burp Suite of security testing tools, swallows $112M
Image Credits: JuSun / Getty Images

Amazon is facing another competition lawsuit in the UK. The latest claim, which was filed Thursday, is seeking more than £2.7BN in damages — or around $3.4BN at current exchange…

Amazon hit with fresh class action-style suit in UK — $3.4BN in competition damages sought for 200,000+ sellers

Securing cloud services remains a challenge for enterprises. That’s why several companies have been working on security solutions that specifically address that need. In the latest example of that, Odaseva…

Odaseva raises $54M to secure Salesforce users

When Ironspring Ventures launched in 2020 to back startups in industrial sectors like construction and manufacturing, it was one of very few early-stage venture firms paying attention to those capital-intensive…

Austin-based Ironspring Ventures raised $100m to invest in industrial revolution

Social network Bluesky has added a new feature for users to create a curated list of people and custom feeds to follow. This feature, called “Starter Pack,” is intended to…

Bluesky lets you curate accounts and feeds to follow with its “Starter Pack” feature

French startup Dust has raised a $16 million Series A funding round led by Sequoia Capital. With Dust, companies can create custom AI assistants and share them with their employees…

Dust grabs another $16 million for its enterprise AI assistants connected to internal data

Google said today that it is adding support for 110 languages to its translation service. The company has used its PaLM 2 AI model to power translations. 

Google Translate adds support for 110 languages, representing 614 million speakers

What is AI good for? Automating repetitive tasks for the very busy people running small businesses, reckons Berlin-based startup Synthflow, which is announcing a $7.4 million seed round for its…

Synthflow picks up $7.4M for no code voice assistance for SMEs

NASA has selected SpaceX to develop a spacecraft that will de-orbit the International Space Station in 2030 — a contract valued at as much as $843 million, the agency announced…

SpaceX scores $843M NASA contract to de-orbit ISS in 2030

U.S. prosecutors say the WhisperGate cyberattack was designed to “sow concern” among Ukrainian civil society ahead of Russia’s invasion.

US charges Russian civilian for allegedly helping GRU spies target Ukrainian government systems with data-destroying malware

Can chatbots replace human therapists? Some startups — and patients — claim that they can. But it’s not exactly settled science. One study found that 80% of people who’ve used…

Sonia’s AI chatbot steps in for therapists

Sierra Space said that despite the slip, its first Dream Chaser spaceplane is still on track for its maiden mission before the end of the year.

Dream Chaser spaceplane is off the manifest for ULA’s second Vulcan launch

Facing new competition from startups like Arc, Google announced on Wednesday that it’s bringing five new features to the Chrome browser on mobile devices, each designed to enhance the search…

Google improves search experience in the Chrome mobile app

At this early stage, Persona’s pitch doesn’t stray far from the various humanoid firms with which it’s set to compete.

Persona’s founders are certain the world can use another humanoid robot

Hiya, folks, and welcome to TechCrunch’s regular AI newsletter. This week in AI, music labels accused two startups developing AI-powered song generators, Udio and Suno, of copyright infringement. The RIAA,…

This Week in AI: The fate of generative AI is in the courts’ hands

Like Instagram, Whee also supports the use of photo filters and includes messaging. However, the company’s plans for Whee aren’t clear.

TikTok’s Instagram rival, Whee, has no traction

You can barely go an hour these days without reading about generative AI. While we are still in the embryonic phase of what some have dubbed the “steam engine” of…

Data lakehouse Onehouse nabs $35M to capitalize on GenAI revolution

Four startups will share €1 million in prize money and 8 million GPU hours to train their models on a couple of the bloc’s HPC supercomputers over the next 12…

Unbabel among the first AI startups to win millions of GPU training hours on EU supercomputers

The perfect device is one that never breaks in the first place, while still allowing for easy user repair access when needed.    

Apple stresses device longevity, extends self-service repair to Europe

The Supreme Court on Wednesday rejected a Republican-led challenge to the Biden administration’s communication with social media companies to combat online misinformation on topics related to COVID-19 and the 2020…

Supreme Court rejects claim that Biden administration pressured social media firms into removing misinformation

Starfish Space and aerospace giant Intelsat have signed a new satellite servicing agreement that could permanently change the paradigm for satellite operations. Under the contract, Starfish will use its Otter…

Starfish spacecraft will extend the life of an expensive GEO satellite in 2026 mission

Featured Article

Kaspersky resellers deride US government ban: ‘Complete bulls—t’

“It’s just a lot of time lost for nothing,” a U.S.-based Kaspersky reseller told TechCrunch, following the news of a US sales ban.

22 hours ago
Kaspersky resellers deride US government ban: ‘Complete bulls—t’

A hacker claims to be selling an extensive database associated with an Indian government portal meant for blue-collar workforce emigrating from the country.

Hacker claims data breach of India’s eMigrate labor portal

Formation builds tech-forward solutions for clinical trials and drug development.

Formation Bio raises $372M to boost drug development with AI

We’re incredibly excited to announce that we’ve added a dedicated Fintech Stage to TechCrunch Disrupt 2024. It joins Space, SaaS and AI as the other industry-focused stages — all under…

Announcing the agenda for the Fintech Stage at TechCrunch Disrupt 2024

When Napster emerged in the late 1990s, it made it easy for people to grab music files without compensating the content owners. The iPod and the iTunes music store changed…

Dappier is building a marketplace for publishers to sell their content to LLM builders

Hyperplane focused on allowing banks to train their own models to power tools across their risk, collections and marketing departments.

Nubank acquires AI-for-banks startup Hyperplane

Retool’s focus is on business apps, not the next social network.

Retool expands its low-code platform for creating internal apps to support external apps, too

Samsara Eco makes and sells fossil-free polymer resins. These resins can be integrated into supply chains and potentially replace plastic packaging and textile products with more sustainable alternatives. The Australian…

Samsara Eco is working to replace plastic packaging with fossil fuel-free alternatives