In late 2025, we invested in Cybeats Technologies
$CYBT.CN $CYBCF via private placement at $0.12 CAD and lead the follow on this month at $0.17 CAD).
Cybeats - Every Government Is Writing the Same Law. One Company Has the Solution.
Imagine buying a snack with no ingredient list. No idea if it contains something you're allergic to. No idea if it's healthy. Do you just trust and hope? I don’t think so.
That's how software has worked for forty years.
Big companies use hundreds of software vendors. Each vendor's product is made of thousands of pieces of code borrowed from other places. Most of it is free, open-source, and untracked. Nobody actually knows what's inside anything. When a dangerous bug shows up in one of those hidden pieces, companies spend weeks trying to figure out if they're affected. Attackers exploit the same blind spots to break in.
The industry finally gave the fix a name: Software Bill of Materials. SBOM for short. An ingredient list for code.
Seven years ago, SBOMs were a nice idea nobody was forced to care about. That changed.
The Regulatory Hammer
Three governments got tired of waiting.
The United States kicked it off with Executive Order 14028 in 2021, requiring SBOMs from any software supplier selling to federal agencies.
The European Union followed with the Cyber Resilience Act. It entered into force December 10, 2024. Vulnerability reporting becomes mandatory September 11, 2026. SBOMs become mandatory December 11, 2027. Fines run up to €15 million or 2.5% of global revenue.
Then the rest of the developed world lined up. South Korea in October 2025, effective 2027. Japan already requires SBOMs for medical devices through PMDA and is expanding scope. India is phasing in requirements through CERT-In guidelines (published July 2025) and SEBI's cybersecurity framework for regulated financial entities.
If you sell software into any of these markets, you will need an SBOM solution. It's no longer a debate.
Why Cybeats?
Cybeats is a market leader. Their CTO, Dymitry Raidman, is one of the earliest voices in the SBOM movement and sits on multiple standards bodies shaping how the industry works. Gartner has cited Cybeats in the past. Their customer list includes Emerson, Schneider Electric, Rockwell Automation, Orange which is exactly the industrial and telecom base that regulation will hit first.
Most competitors only generate an SBOM. A one-time snapshot. A photo of the ingredients the day the product ships.
Software doesn't stay still. New vulnerabilities are discovered every week in code that's already sitting inside products customers bought years ago. A snapshot rots the moment it's taken.
Cybeats' SBOM Studio does something different. It ingests SBOMs, enriches them, distributes them, and monitors them continuously for the entire life of the software. Policy-based alerts. DevSecOps integration. Most importantly, verifiable audit trails for regulators.
Customers cut vulnerability review from days to minutes.
What about AI?
You'd think AI would solve this. It's making it worse.
Every AI model is itself software. It's built on hundreds of open-source dependencies like PyTorch, CUDA libraries, model weights of unclear provenance, training data of unclear licensing. Regulators noticed. New rules for "AIBOMs", AI-specific bills of materials, are already being drafted in the US, EU, and G7.
Cybeats already has the plumbing. Competitors are starting from zero. AI doesn't shrink the problem. It multiplies it.
The MOAT
If you search SBOM solutions in Google, you’ll find other companies with SBOM solutions, but they are only SBOM generators. A company deploying multiple SBOM generators still have a manual process that forces them to scramble every time something changes. New SBOM’s are generated every day, and the quality of the SBOM is critical.
SBOM’s is easy. Managing them is where organizations fail. Cybeats SBOM studio absorbs SBOM’s from any generator, organizes them, gives each SBOM a quality score, and updates missing or incorrect component versions in real time.
Cybeats now has a five-year data lake of SBOM data which is its growing competitive advantage. The product isn’t the software. The product is the accumulated context that makes the software useful. Any competitor spinning up an SBOM platform today starts with an empty database. They can generate SBOMs on day one, but they can’t tell you:
· Which open-source components have historically shipped with the most vulnerabilities
· Which vendors patch quickly versus which ignore CVEs for years
· Which software libraries are actively maintained versus quietly abandoned
· How specific components have evolved across versions over time
· Which combinations of dependencies correlate with security incidents
Cybeats can. They've been ingesting, enriching, and monitoring SBOMs since before most competitors existed. That history is the product. In addition, the vulnerability response time gets faster with more history.
SBOM Studio software can theoretically be replicated. Give a competent engineering team eighteen months and a budget and they can build something functionally similar. What they can't replicate is five years of watching how the software supply chain behaves. That's the moat that widens every day Cybeats operates.
This is the same pattern as Palantir, Verisk, or Moody's. The software is table stakes. The data underneath is what nobody can catch up to.
A one-year-old SBOM platform sells compliance. A five-year-old SBOM platform sells intelligence. Once you have enough historical data, you can start selling vender risk scoring, predictive vulnerability alerts, procurement due diligence, and even insurance underwriting inputs.
The Scaling Mechanism
Cybeats grew ARR from $3 million to ~$5 million in six months. The average deal starts at $200,000 per year and grows with usage.
The sales team is a few people. They mostly field inbound, and that's the fascinating part. This is what growth looks like before the distribution engine turns on.
This February, Cybeats signed an OEM deal with Keysight Technologies ($KEYS, $55 billion market cap). Keysight will resell Cybeats' SBOM Studio and SBOM Consumer as the "Keysight SBOM Manager."
Through our channel checks we believe that Keysight is very selective with partnerships. For a $6 billion revenue company it doesn’t make much sense for Keysight to bother unless they believe revenue contribution can become material in 12-24 months. Last month the “Keysight SBOM Manager” won the grand prize in security assessment at Interop Tokyo 2026. This was a substantial achievement that resulted in an influx of interest from Japan.
Keysight sells testing equipment into industrial automation, aerospace and defense, automotive, telecom, and critical infrastructure. Every one of those industries is now legally required to produce and maintain SBOMs. Keysight already tests the hardware. Now they test the software inside the hardware, and instead of a one-time equipment sale, they add a recurring software subscription that renews every year.
Keysight is choosing an OEM partner (Cybeats) they'll be tied to for years. They don't want to pick the vendor with the shinier UI. They want the vendor whose data will still be the deepest in ten years. A five-year data lake tells Keysight's procurement team that Cybeats will still be the leader when the OEM deal is up for renewal. That's why the deal happened, and it's why the next big reseller will happen shortly for the same reason.
Keysight handles sales, deployment, and frontline support. Cybeats sits at fourth-level support. Each new customer takes about an hour of Cybeats' time to implement.
Our diligence suggests Keysight already has many customers in the pipeline (already more than Cybeats internal sales force). Sales cycles run six to twelve months, so the first contracts should start to land in Q4 2026.
Cybeats is working on additional resellers of Keysight's scale, targeting a couple more by year end. This just adds to the sales flywheel in 2027 and beyond.
The Upside
We don't have to guess what this business is worth. Someone just told us. In June 2026, Accenture acquired Netrise, one of two other credible SBOM platform providers, at 20x sales. That's a recent comp.
Cybeats trades at roughly $30 million CAD market cap. ARR is ~$5 million and breakeven is $6 million. The first Keysight-sourced contracts should start closing in Q4. As they compound through 2027, ARR could reach $10 million in H1 and $20 million by year-end 2027. This feels reasonable given the pipeline dynamics and the regulatory deadlines.
If we needed further proof of this cyber security area going mainstream, look no further than this J.P. Morgan report that came out this month (July 2026).
Google Search: "Patchmageddon - The race to patch software vulnerabilities before zero-day cyber-exploitations proliferate"
Cybeats isn’t cheap, but we believe the company could do well over the next 18 months. They have the right product at the right time.
The bet here is that sales traction will accelerate in Q4/Q1. The risk is it doesn't.
Disclosure: IFCM is long and wrong a lot.