
Most enterprise security systems are designed to keep threats out. The more difficult issue is what to do once an attacker is already inside, moving through the network and escalating their level of access. This can go on for weeks before any alerts are triggered. Creating a detection infrastructure that can reliably identify this activity without generating excessive noise that obscures important signals has remained an operational challenge.
Beelzebub, an Italian cybersecurity startup founded by Mario Candela, has built its platform around the assumed-breach model. Three integrated components cover the detection and response cycle. Arcangelo continuously simulates targeted attacks to test how defences hold up in practice. Beelzebub Managed deploys AI-powered decoy infrastructure inside the network - including honeypots covering SSH, HTTP, Kubernetes, cloud APIs, IoT and MCP - designed to attract attackers attempting lateral movement and trigger confirmed alerts with no false positives. Caronte, the platform's automated malware analyst, reverse-engineers captured malicious software and generates structured incident reports without analyst intervention. The platform is available as SaaS or as a fully on-premises solution, and is designed to meet NIS2 compliance requirements.
Beelzebub has just closed a €3 million seed round led exclusively by United Ventures, following a €300,000 pre-seed round from strategic investors and advisors. This brings the total funding to €3.3 million. The capital will support the expansion of the research team and the opening of commercial offices in Rome and San Francisco, as well as accelerating customer acquisition across NIS2-subject organisations in Europe.
Sources: Beelzebub | Crunchbase
Founders: Mario Candela