Zurich-based xorlab has secured €5 million in Series A+ funding to expand its AI-powered email security platform across Europe. Founded by two ETH Zurich computer science graduates, the company is targeting one of cybersecurity’s most persistent problems: sophisticated email attacks that increasingly look completely legitimate.
Email remains one of the most effective entry points for cyberattacks.
Generative AI can help attackers create highly convincing messages, adapt language to individual targets and scale personalized phishing campaigns faster than traditional manual approaches. At the same time, many modern attacks no longer require malware.
A perfectly written email asking an employee to change payment details, transfer money or disclose sensitive information may contain no malicious attachment, no obviously suspicious link and no known malware signature.
That is precisely the problem Zurich-based cybersecurity company xorlab is trying to address.
The Swiss company has raised €5 million in a Series A+ funding round to accelerate its expansion across Europe.
The round was led by existing investor Spicehaus Partners, with Grapha Holding, EquityPitcher Ventures and ZKB Start-up Finance also participating again.
The company plans to use the additional capital to expand particularly across the DACH region, Benelux and the Nordic countries.
For the European cybersecurity market, the story is interesting for another reason: xorlab sits at the intersection of three rapidly developing trends — AI-powered cyberattacks, contextual threat detection and European digital sovereignty.
From ETH Zurich to Enterprise Cybersecurity
xorlab was founded in 2015 by Antonio Barresi and Matthias Ganz, both computer science graduates from ETH Zurich.
The company has since focused on protecting organizations against advanced email threats, including phishing and Business Email Compromise.
Its publicly referenced customers include organizations such as Swisscom, Julius Baer, Vontobel, G+D and CERN.
These are significant references for a security company operating in a market where trust is critical.
Banks, telecommunications companies and research organizations typically operate complex environments with strict security, privacy and regulatory requirements.
Winning these organizations as customers provides xorlab with an important foundation as it attempts to scale internationally.
The Email Security Problem Is Changing
Traditional email security has relied heavily on indicators such as known malicious domains, malware signatures, suspicious attachments, URLs and reputation data.
These mechanisms remain important.
But sophisticated social engineering can bypass many of them.
Consider a simple scenario.
An employee receives an email apparently related to an existing business process. The language is professional. There is no malware attached. The sender requests a bank account change or asks the employee to initiate a payment.
Technically, the email may look harmless.
Contextually, however, something may be wrong.
Perhaps that sender has never requested a payment before.
Perhaps the communication pattern has suddenly changed.
Perhaps the request is inconsistent with the historical relationship between the sender and recipient.
This is where contextual analysis becomes increasingly important.
Using AI to Understand Communication Context
xorlab’s approach is designed to analyze more than an individual message.
Its technology examines communication behavior and relationships within an organization to establish an understanding of what normal communication looks like.
That context can then help identify deviations.
An unusual sender, an unexpected financial request or a change in established communication patterns can become relevant security signals even when the email contains no conventional malicious payload.
This approach is particularly relevant as generative AI improves the quality of social engineering.
Poor grammar and awkward wording were once useful warning signs.
They are becoming less reliable.
Large language models can generate fluent, professional and highly personalized messages in seconds.
The defensive challenge therefore moves from simply asking:
“Is there something malicious inside this email?”
to a more difficult question:
“Does this communication make sense in this context?”
That is a much more challenging security problem.
AI Is Changing Both Sides of the Cybersecurity Equation
Generative AI is often discussed as an offensive accelerator.
Attackers can use AI to improve phishing content, translate campaigns, automate reconnaissance and generate personalized social-engineering messages.
But AI can also strengthen defensive systems.
Security platforms can analyze relationships, communication histories, behavioral patterns and large volumes of signals that would be impossible for human analysts to evaluate manually at enterprise scale.
The result is an emerging AI-versus-AI dynamic.
Attackers use automation to make malicious communication more convincing.
Defenders use automation to identify the subtle inconsistencies those messages leave behind.
Email security is becoming one of the clearest examples of this transition.
European Cybersecurity Sovereignty Becomes a Business Factor
There is another dimension to xorlab’s expansion strategy: European digital sovereignty.
European organizations are increasingly examining where critical security platforms are operated, where sensitive information is processed and how dependent their infrastructure is on non-European technology providers.
This question becomes particularly sensitive in cybersecurity.
Security platforms can potentially process highly confidential information about users, communications, infrastructure and incidents.
xorlab positions itself as a European provider and supports different deployment models.
According to the company, customers can operate the platform on-premises, in hybrid environments or through the cloud.
For its cloud model, xorlab emphasizes European data centers and operations by teams located in Europe.
For regulated organizations, this flexibility can become an important procurement consideration.
DORA and NIS2 Increase the Pressure
The European regulatory environment is reinforcing this trend.
Frameworks such as DORA and NIS2 are increasing expectations around cyber resilience, third-party dependencies, risk management and the security of critical digital services.
For CISOs, this means vendor selection is increasingly about more than detection capabilities.
Questions such as these are becoming strategically important:
Where is security data processed?
Who operates the platform?
Can the technology be deployed on-premises?
What dependencies exist in the underlying technology stack?
How easily can the organization demonstrate regulatory compliance?
European cybersecurity companies that can combine effective security technology with deployment flexibility and data sovereignty may therefore have an increasingly attractive position.
€5 Million to Scale Across Europe
xorlab now intends to use its new funding to capitalize on that opportunity.
Its next growth phase will focus particularly on the DACH region, Benelux and Northern Europe.
The company is entering a highly competitive market dominated by some of the world’s largest cybersecurity and technology vendors.
But specialized security providers can still create significant positions when they solve a narrowly defined problem particularly well.
xorlab already has several elements in place: more than a decade of development, enterprise customers, specialized email-security technology and now additional capital for international expansion.
What CISOs Should Watch
The xorlab funding round is interesting beyond the company itself.It illustrates a broader shift in enterprise security.The first generation of email security focused heavily on known malicious content.
The next generation increasingly needs to understand identity, behavior, relationships and context.
That shift is likely to accelerate as generative AI makes malicious messages harder for users and traditional filters to distinguish from legitimate business communication.
For CISOs, the strategic lesson is therefore broader than choosing one particular email security vendor. Organizations should ask whether their current controls can detect attacks that contain:
- no malware,
- no known malicious URL,
- no obvious linguistic mistakes,
- and no previously observed attack signature.
If the answer is no, generative AI may be widening an already important detection gap.
A Swiss Cybersecurity Company With European Ambitions
xorlab’s latest financing also highlights Switzerland’s ability to turn academic expertise into specialized cybersecurity businesses.
Founded by two ETH Zurich graduates and headquartered in Zurich, the company has built a customer base that includes major financial, telecommunications and research organizations.
The next challenge is international scale. Five million euros is modest compared with the enormous funding rounds seen across parts of the AI industry.
But enterprise cybersecurity is not won by fundraising numbers alone. It is won by solving meaningful security problems, earning customer trust and demonstrating that the technology works in complex environments.
And the problem xorlab is targeting is becoming more important.
As generative AI makes social engineering increasingly convincing, email security will need to move beyond identifying malicious objects toward understanding whether the communication itself makes sense.
That could make contextual threat detection one of the most important battlegrounds in the next generation of enterprise email security.
For xorlab, the €5 million Series A+ provides the capital to take that approach beyond Switzerland — and attempt to build a stronger position in the European cybersecurity market.
