Connect with us

NEWS

Beelzebub’s €3 Million Raise Rides a Wave of EU Cyber Deadlines

Italian startup Beelzebub raised €3 million as NIS2 and Cyber Resilience Act deadlines push European firms toward assumed-breach AI security tools.

Published

on

Beelzebub has closed a €3 million seed round led exclusively by Milan investor United Ventures, pushing the Italian cybersecurity startup’s total funding to €3.3 million. The company builds AI tools that hunt attackers already inside a network, rather than ones still trying to break in.

Two overlapping EU laws start charging real consequences within the next few months. Italy’s technical security deadline under the NIS2 Directive falls this October. The Cyber Resilience Act’s first mandatory reporting duty lands across the bloc a month earlier, in September. That calendar bought Beelzebub a Rome office and a shot at San Francisco.

Arcangelo, Caronte and the Assumed-Breach Wager

Most cybersecurity budgets still go toward keeping attackers out. Beelzebub bets on the opposite premise: assume someone is already inside, and build tools fast enough to catch them before real damage spreads. The company calls this an assumed-breach model, and it runs the idea through three named products, each borrowed from Italian folklore.

Arcangelo, the archangel, continuously simulates targeted attacks to pressure-test an organisation’s live defences. Beelzebub Managed deploys AI-generated decoy infrastructure, a modern honeypot, to lure and detect attackers already on the network.

Caronte, the ferryman of the underworld in Dante’s Inferno, is the platform’s AI malware analyst. Once a threat is caught, it reverse-engineers the malicious code and writes an incident report on its own. That report can stay fully on-premises for clients who cannot let malware samples leave the building.

Component Role Output
Arcangelo Simulates targeted attacks against live defences Continuous pressure-test results
Beelzebub Managed Deploys AI-generated decoy infrastructure inside the network Real-time attacker detection and engagement logs
Caronte Reverse-engineers malware once a threat is caught Automated incident reports, cloud or on-premises

The whole stack ships as SaaS or as an on-premises install, built to satisfy NIS2’s stricter security requirements rather than bolted on afterward.

What Do NIS2 and the Cyber Resilience Act Require?

NIS2 requires ‘essential’ and ‘important’ entities across critical sectors to register with national authorities and hit minimum security standards. The Cyber Resilience Act sets security-by-design rules for any connected product sold in the EU, with vulnerability reporting starting this September and full enforcement in December 2027.

Italy transposed NIS2 into national law through Legislative Decree No. 138/2024, which entered into force on 16 October 2024. A mandatory registration window closing in February 2025 covered essential entities first, and Italy’s national cybersecurity agency still has to finalise the technical security annexes companies must meet by October 2026.

Brussels has not made this easy on anyone. Many EU member states missed the original October 2024 transposition deadline for NIS2 entirely, according to law firm White & Case. That left a patchwork of national timelines, and vendors like Beelzebub now sell into one country at a time.

  1. 16 October 2024: Italy’s Legislative Decree No. 138/2024 transposes NIS2 into national law.
  2. December 2024 to February 2025: Essential entities register with Italian authorities under the new rules.
  3. September 2026: Cyber Resilience Act vulnerability and incident reporting duties become mandatory across the EU.
  4. October 2026: Italy’s technical security annexes for NIS2 compliance come due.
  5. December 2027: The Cyber Resilience Act reaches full enforcement across all 27 member states.

Those dates do not move for a three-person IT team at a mid-sized manufacturer that just learned it counts as an ‘important entity.’

Mid-Market Firms Cannot Look Away Now

NIS2 does not stop at banks and power grids. Its ‘important entity’ category pulls in mid-sized manufacturers, logistics operators, food producers and digital service providers that never budgeted for a dedicated security team. Attackers have noticed the shift.

ENISA is the EU’s cybersecurity agency. It logged 4,875 security incidents across the bloc between July 2024 and June 2025 for its 2025 Threat Landscape report. The agency found that criminal groups are scaling their operations fast. Small and mid-sized firms, once considered too minor to bother with, are now routine targets.

Mario Candela, Beelzebub’s founder and chief executive, has said the rise of AI-powered attackers changed cybersecurity fundamentally, and that organisations now need AI-based systems working alongside human analysts at machine speed. The product, he said, “adapts to new types of malware and is always updated to match the current state of the most sophisticated attacks.”

This seed round will supercharge our efforts to bring modern cybersecurity to the companies who cannot afford to compromise.

Candela said in the funding announcement. Those are the same mid-market firms NIS2 just pulled into scope, most of which never had budget for enterprise-grade security tooling before.

A Honeypot Side Project Becomes a Company

Beelzebub did not start as a company. Candela built it as an open-source honeypot framework that uses large language models to autonomously mimic live systems and lure attackers into a fake environment.

On GitHub, where the original honeypot project still lives as open code, Candela describes himself as an independent security researcher and a member of the Honeynet Project’s SysCenter Chapter. The chapter studies attacker behaviour through decoy systems.

The jump from open-source maintainer to venture-backed founder is a familiar arc in security tooling, though few honeypot maintainers get a seed round out of it. Beelzebub’s path started with a €300,000 pre-seed backed by strategic investors and advisors, then the €3 million United Ventures round that followed.

Milan’s Money Chases a Rome-to-San-Francisco Path

United Ventures is a Milan-based venture firm founded in 2013, and it led this round exclusively, without a syndicate. The firm runs two early-stage funds worth €190 million and has previously backed Exein, another Italian cybersecurity startup.

Seed-stage AI security funding has stayed active elsewhere in Europe too. StrongestLayer’s $4.1 million raise for AI email security closed in a similarly crowded field. Investors across the continent are betting that machine-speed detection tools are becoming a standard line item in IT budgets, across companies of every size.

Beelzebub plans to put the new money toward four things, according to the company.

  • Expand the research and engineering team building Arcangelo, Beelzebub Managed and Caronte
  • Open commercial offices in Rome and San Francisco before the end of the year
  • Accelerate customer acquisition across Europe, prioritising organisations subject to NIS2
  • Develop new tools aimed specifically at protecting AI agents from attack

The San Francisco office is the more unusual bet for a seed-stage Italian company. It puts Beelzebub inside the same market as the largest cybersecurity buyers and the toughest competition, well before most European seed companies plant a US flag.

Italy’s technical security annexes for NIS2 come due in October. The Cyber Resilience Act’s vulnerability reporting mandate lands across the bloc a month earlier, in September. Beelzebub’s Rome and San Francisco offices are due to open before either deadline passes.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending