Skip to content
TECH CEO Daily
StartupsFunding

RemoteThreat raises $7 million as ex-IBM hackers sell offensive cyber tools to red teams

Founded by former IBM X-Force Red leaders, the startup says it already serves a major bank and a securities exchange operator, and is courting US government mission teams.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1RemoteThreat raised $7 million in pre-seed funding led by Osage University Partners and DataTribe, emerging from stealth on September 29.
  • 2Its platform combines eight connected systems and, per its CEO, about 1,000 purpose-built tools for planning and running cyber operations.
  • 3The launch follows a US push for private-sector help on offensive missions, raising vetting, legal and reputational questions for buyers.

The news

RemoteThreat, a startup founded by former leaders of IBM's X-Force Red hacking team, emerged from stealth on September 29, 2026, with $7 million in pre-seed funding for a commercial platform built to plan and run offensive cyber operations.

Osage University Partners and DataTribe led the round, according to the company's announcement, issued through Business Wire with a Fulton, Maryland, dateline. Co-founder and CEO Chris Thompson founded IBM's first dedicated red team and later served as global head of X-Force Red, SiliconANGLE reported. Co-founder Shawn Jones is chief technology officer. A red team is a group that attacks an organization's own systems the way a real adversary would, to find weaknesses before criminals do.

The company calls its product the O/C/O Platform and says it links eight systems, covering mission planning, command and control (the infrastructure attackers use to direct compromised machines), implants, initial access, obfuscation, analysis and AI-assisted operations. Thompson told The Register the platform includes about 1,000 tools the team built from scratch, can work with large language models from OpenAI, Anthropic or open-weight alternatives, and can be operated by humans or by AI agents.

RemoteThreat says access is restricted to vetted enterprises, defense contractors and U.S. government customers. The release names its target users as enterprise and critical infrastructure red teams, U.S. government mission teams and vetted defense partners. The Register reported that customers already include a major bank, a securities exchange operator, a large U.S. healthcare company and a leading AI lab, none of them named, and that the company has 15 employees drawn from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors and government agencies.

The startup is also building government ties. It said it joined U.S. Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements (SOF RACER), and it named The Nakasone Group, founded by retired Army Gen. Paul M. Nakasone, former head of the National Security Agency and U.S. Cyber Command, as a strategic adviser. The Register also reported a partnership with Talon Defense, which supplies AI and cyber technology to national security, defense and intelligence customers.

Thompson described the market to The Register as "a bit of a gold rush," saying the government is being pushed to work with the commercial sector across every major program for the first time. The outlet pointed to the U.S. cyber strategy published in March, which calls for closer industry cooperation on defensive and offensive missions, and to an August presidential memorandum ordering a program in which vetted U.S. companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight.

The numbers

Pre-seed funding
$7 million
Connected systems in the platform
8
Purpose-built tools (CEO's figure)
About 1,000
Employees (per The Register)
15

Why CEOs should care

For chief information security officers (CISOs) at banks, exchanges and hospitals, the pitch is a sharper red team: attack emulation built by operators who, according to SiliconANGLE, have run engagements against nuclear facilities, infrastructure providers and major financial institutions. Before signing, ask how the vendor vets its customers, where its implants and tools are stored, what stops that code from leaking, and what logs you receive for every action taken on your network.

Boards and general counsel should treat offensive tooling differently from ordinary security software. The same platform that tests a bank's defenses is marketed to government mission teams, and the August memorandum points toward private companies acting against foreign groups under federal oversight. That brings legal and reputational questions: whether any activity outside the company's own systems has written government authorization, which countries the tools may be used in and under what export rules, and how a vendor relationship would look if its technology turned up in a public incident.

For investors and CFOs, $7 million is a small round, but the investor list, the SOF RACER membership and the Nakasone Group tie show where early money thinks demand is heading. RemoteThreat is betting that attack operations can be sold as an integrated product; Thompson said in the release that expert operators spend too much time assembling tools and building integrations.

The bigger picture

RemoteThreat's launch is one sign of a policy shift turning into a market. Washington's March cyber strategy and the August memorandum both invite private companies closer to offensive work, and startups are forming to supply tools and people for it. Jones framed the company's approach in the release as keeping skilled human operators in charge rather than selling another black-box automated penetration testing tool, a distinction regulators and customers are likely to probe as AI agents take on more of the work.

What’s next

Watch how the program ordered by the August memorandum is structured and whether RemoteThreat or its peers take part, whether SOF RACER membership turns into contracts, and whether the company names customers or raises a larger round. Buyers should also watch for any public rules on how vetted companies may use offensive tools.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

RemoteThreatIBM X-ForceOffensive cyberPaul NakasoneRed teaming

Earlier coverage of IBM

All IBM coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.