Cybersecurity has spent two decades getting better at detecting attacks after they happen, and comparatively little better at preventing the design flaws that make those attacks possible in the first place.
Despite record global spending on security tools, breaches keep tracing back to the same root causes: architectural weaknesses, insecure configurations, and design decisions made long before any attacker shows up. As AI-assisted engineering lets teams design and ship software faster than ever, the gap between what a system was designed to do and what actually gets deployed is only widening.
That’s the gap Mahdi Abdulrazak is trying to close. Abdulrazak is the co-founder and CEO of Dawnguard, an Amsterdam-based startup building a platform that embeds security directly into a system’s architecture from day one, rather than bolting it on after the fact.
In July 2026, Dawnguard publicly launched its platform and added $3.3 million in fresh pre-seed funding, bringing total funding past $6.3 million just one year after emerging from stealth. Here is how an ethical hacker who started at 15 built a company around a simple, contrarian bet: that the only security which holds up is the kind designed correctly from the start.
The Cybersecurity Problem Nobody Was Solving
For most of the last twenty years, security has been treated as something added after a system is already built: a scan here, a patch cycle there, a review before launch. That model was always somewhat fragile, but Dawnguard’s founders argue it becomes actively indefensible once attackers start operating at machine speed, probing systems continuously and cheaply with AI-assisted tools of their own.
The deeper problem is what Dawnguard’s CTO, Kim van Lavieren, has described as the gap between what a system was designed to do and what actually gets deployed, a gap that widens every time engineering and security teams rely on static documents, spreadsheets, or diagrams instead of enforceable, living code. As AI-generated code and autonomous engineering workflows accelerate how fast software ships, that translation gap between intent and reality becomes the place where real risk quietly accumulates.
Meet Mahdi Abdulrazak
Mahdi Abdulrazak began hacking systems at age 15, not to break them, but to understand how they worked, according to an interview published by revel8. That early curiosity turned into a career spanning more than two decades at the center of cybersecurity, including a role as Group Information Security and Risk Officer at SHV Energy, board membership at CISO Platform Nederland, and service as an ambassador to the European Cyber Security Organisation.
Abdulrazak studied at Rotterdam School of Management, Erasmus University, according to his LinkedIn profile, and has described his career shift from operating as a CISO inside large organizations to founding Dawnguard as a move from managing security reactively to building the tools that make reactive security unnecessary in the first place.
Abdulrazak’s Route Into Cybersecurity
Abdulrazak co-founded Dawnguard with Kim van Lavieren, who serves as chief technology officer. The founding team, beyond its two co-founders, includes cybersecurity veterans who previously worked at IBM, Microsoft, and Amazon, as well as several members with military security backgrounds, according to Tech.eu, giving Dawnguard a founding bench with deep experience running large-scale security operations before ever building a product of their own.
That combination, hands-on CISO experience paired with big-tech-scale security engineering, shaped Dawnguard’s core thesis directly: the people who most needed a tool like Dawnguard were the same people building it.
Inside Dawnguard’s Product
Dawnguard’s platform automates security architecture, embedding validation directly into how cloud-native systems are designed, built, and operated, from what the company calls “day zero through day 10,000.” Rather than scanning finished deployments or automating after-the-fact reviews, the platform gives engineering and security teams a shared canvas to collaborate on secure, compliant architecture that also accounts for cost, resilience, and sustainability, according to the company’s own launch materials.
Abdulrazak has described the current moment in stark terms. “Cybersecurity has become trapped in an endless cycle of detection, response, and patching,” he said at Dawnguard’s most recent funding announcement. Dawnguard’s answer is to turn security architecture into enforceable code that continuously validates whether a system still matches its original secure design, rather than trusting that a one-time review holds up as the system evolves.
The $6.3 Million Story, Explained
Mahdi Abdulrazak Dawnguard emerged from stealth in July 2025 with $3 million in pre-seed funding. A year later, in July 2026, the company added $3.3 million in additional pre-seed funding from existing investor BNVT Capital in the UK, with new participation from Curiosity VC in the Netherlands and eCAPITAL in Germany, bringing total funding to more than $6.3 million. The new capital arrived alongside Dawnguard’s move from limited enterprise design partnerships into full general availability, plus the opening of a New York City office alongside its Amsterdam headquarters.
That funding pattern, roughly a year between stealth and full commercial launch, with additional capital arriving right as the product reaches general availability, reflects a fairly disciplined path: Dawnguard spent its first year validating the product with real enterprise partners before asking the broader market to pay for it.
Early Signs It’s Working
Ahead of its general availability launch, Dawnguard built design partnerships with roughly 15 large organizations, according to Forbes, using their feedback to shape the platform before opening it to the wider market. The company says its platform now secures more than 100,000 cloud resources across its customer base, according to a company anniversary post on LinkedIn.
That combination, direct enterprise validation before a public launch, plus a concrete infrastructure-scale usage number, gives Dawnguard a more grounded traction story than many pre-seed cybersecurity startups can point to at a comparable stage.
Who’s Writing the Checks
Dawnguard’s investor base spans three European countries: BNVT Capital in the UK, which backed the company from its earliest pre-seed round and returned for the latest extension, alongside new participation from Curiosity VC in the Netherlands and eCAPITAL in Germany. That geographic spread mirrors Dawnguard’s own positioning as a distinctly European cybersecurity company building for a global enterprise market, rather than a Silicon Valley-first startup expanding into Europe.
Industry data cited by BeBeez put total 2026 funding across adjacent European cybersecurity automation, AI-agent security, and cloud infrastructure security startups at roughly €224 million, a signal that Dawnguard is raising within a broader wave of investor interest in security tooling that moves beyond reactive monitoring toward earlier-stage design and governance controls.
The Competitive Landscape
Mahdi Abdulrazak Dawnguard is attempting to carve out a distinct category, security architecture automation, positioned against both legacy cybersecurity vendors like McAfee and Symantec and newer AI-driven point solutions focused on specific parts of the security stack, such as software supply-chain protection or AI-agent governance. According to MapCo, Dawnguard’s pitch to potential customers rests on being more agile and design-first than the legacy players that still dominate enterprise security budgets.
Abdulrazak has framed the moment shaping this competition as what Dawnguard calls the “Mythos Era,” an environment in which AI, autonomous systems, and increasingly complex digital infrastructure evolve and get exploited faster than traditional, reactive security processes can keep pace with. Whether that framing becomes an industry-standard term or remains a Dawnguard-specific pitch will likely depend on how quickly rivals adopt comparable design-first approaches of their own.
What Comes Next
With its platform now generally available and a New York office freshly opened, Dawnguard’s near-term priorities center on converting its existing design partnerships into a broader base of paying enterprise customers, particularly in regulated industries where compliance requirements make security-by-design especially valuable. The company’s international expansion, adding a U.S. presence alongside its Amsterdam base, suggests an ambition to compete for enterprise budgets well beyond the European market where it built its earliest traction.
Longer term, Abdulrazak has spoken publicly about the need for greater collaboration across academia, government, and the private sector on cybersecurity, describing digital sovereignty and local innovation in security as matters of national, not just corporate, importance, a framing that positions Dawnguard’s ambitions as extending beyond a single product category.
Takeaways for Founders
The Mahdi Abdulrazak Dawnguard story offers a few clear lessons for founders building in deeply technical, trust-dependent categories like cybersecurity. First, his own hands-on CISO experience at SHV Energy meant Dawnguard was built by someone who had personally lived the exact frustration the product solves, rather than identifying the opportunity from the outside. Second, recruiting co-founders and early team members with credentials from IBM, Microsoft, Amazon, and military security backgrounds gave Dawnguard a level of technical credibility that is difficult for outsider-founded security startups to replicate quickly. Third, spending a full year in design partnerships with roughly 15 enterprise customers before general availability let Dawnguard refine its product against real, high-stakes environments rather than launching to the broader market on unproven assumptions.
Frequently Asked Questions
What does “shift-left” security mean? Shift-left security refers to embedding security practices earlier in the software development process, at the design and architecture stage, rather than testing for vulnerabilities only after a system is built and deployed.
What is Dawnguard? Dawnguard is an Amsterdam-based cybersecurity startup building a security architecture automation platform that embeds security into a system’s design from the earliest stage, continuously validating that deployed systems match their original secure architecture.
Who is Mahdi Abdulrazak? Mahdi Abdulrazak is the co-founder and CEO of Dawnguard. He began hacking systems at age 15 and spent more than two decades in cybersecurity, including as Group Information Security and Risk Officer at SHV Energy, before founding Dawnguard.
Who co-founded Dawnguard with Mahdi Abdulrazak? Dawnguard was co-founded by Mahdi Abdulrazak, who serves as CEO, and Kim van Lavieren, who serves as chief technology officer, alongside a founding team with backgrounds at IBM, Microsoft, Amazon, and the military.
How much funding has Dawnguard raised? Dawnguard has raised more than $6.3 million total, including $3 million at its July 2025 stealth launch and an additional $3.3 million pre-seed round in July 2026, led by BNVT Capital, Curiosity VC, and eCAPITAL.
What does Dawnguard call the “Mythos Era”? The “Mythos Era” is Dawnguard’s own term for the current period in which AI, autonomous systems, and rapidly evolving digital infrastructure move faster than traditional, reactive cybersecurity processes can track and defend against.
Where is Dawnguard based? Dawnguard is headquartered in Amsterdam, the Netherlands, and opened a New York City office in July 2026 alongside the general availability launch of its platform.
Conclusion
Whether “security by design” becomes the cybersecurity industry’s next real standard, or simply a well-timed pitch for a crowded pre-seed funding wave, will depend on whether Dawnguard’s architecture-first approach proves durable once it’s tested against attackers actually operating at machine speed. What’s clear already is that Mahdi Abdulrazak built Dawnguard from firsthand frustration rather than an outside read on the market, spending two decades inside the exact reactive security model he’s now trying to replace. For readers following other founders building infrastructure-first companies rather than chasing consumer hype, Ben Volkow’s post-quantum cybersecurity startup QIZ Security, Tom Reno’s profitable infrastructure play at Agave, and Rron Rexha’s AI-native wealth platform Arca are worth a look on Denote Press.
