Vendor lineage
Illumio
Assumed the attacker is already inside, and made the whole product about what happens next.
Andrew Rubin and PJ Kirner founded Illumio on 23 January 2013 in Sunnyvale, having both left Cymtec the month before. They had met through a mutual friend's introduction over lunch, which Kirner has described as feeling like a blind date. Rubin took the commercial side, Kirner the technical - he had been a distinguished engineer in the security CTO office at Juniper Networks, which appears on this site as a career chapter of its own.
The founding thesis was unfashionable in 2013 and is now close to consensus: **perimeter security alone is not enough, breaches are inevitable, and the useful question is what an attacker can reach once inside.** Most security spending at the time went on keeping people out. Illumio's argument was that the containment problem deserved its own product.
The technical decision that follows is the interesting one. Segmentation had historically been a network problem - VLANs, zones, firewalls between them - which means the policy lives in the topology, and a workload's security depends on where it happens to sit. Illumio put enforcement at the workload instead, with policy computed centrally and pushed to hosts, so **the rule travels with the application rather than with the wiring**. That is why it works in a cloud where you do not own the network, and it is the reason a software-first approach could do what hardware segmentation could not keep up with.
**And then the part everyone underestimates, which the company has been honest about.** You cannot enforce a rule that nothing talks unless it has a reason to until you know what actually talks to what. In a data centre of any age, nobody does. So the first product problem was not enforcement at all but **real-time dependency mapping** - working out the actual conversation graph of a running estate - and the name comes from illuminate for exactly that reason.
That is also why the company spent **twenty-two months in stealth** before showing anything. It raised $12.5M from Andreessen Horowitz and General Catalyst in early 2013, emerged in October 2014 with a $30.2M Series B, and had Morgan Stanley and Plantronics as customers in the first year. A $100M round in 2015 took it past a billion.
Today the framing is zero-trust segmentation and breach containment, and the numbers reported are $557M raised, a $2.75B valuation, revenue past $100M a year, and roughly a fifth of the Fortune 100. Kirner stepped down as chief technology officer in May 2023 after a decade, staying on as an adviser.
**Read next to two other entries here, it completes a picture of how the perimeter dissolved.** Zscaler moved inspection out to where the users went. Netskope tackled what people were doing inside applications nobody had approved. Illumio addressed the inside of the data centre itself, on the assumption that the other two would sometimes fail. Three companies, three different pieces of the same admission: the boundary that security was organised around had stopped describing anything real.
- Wikipedia: Illumio - founded 2013 by Andrew Rubin and P.J. Kirner, Sunnyvale, breach containment and lateral movement
- Verdict CTO Talk with PJ Kirner - his time on Juniper Networks' security team in the CTO office, and the blind-date introduction to Rubin
- Contrary Research - both founders leaving Cymtec in December 2012, and Kirner stepping down as CTO in May 2023 while remaining an adviser
- Company history - the 23 January 2013 founding, 22 months in stealth building real-time dependency mapping, the $12.5M Series A from Andreessen Horowitz and General Catalyst, the October 2014 emergence with $30.2M, Morgan Stanley and Plantronics as early customers, and the name deriving from illuminate
- Interview with Andrew Rubin - $557M raised, $2.75B valuation, revenue past $100M, roughly 20% of the Fortune 100, and Kirner's Cornell background