Skip to content
  • X
  • LinkedIn
Subscribe
Techopia
  • Home
  • News
  • Insights
  • AI
  • Enterprise
  • Growth
  • Impact
  • Security
Growth, News, Security

Milan’s cyber decoys pull in €3m

Beelzebub has raised seed funding for automated decoys designed to expose attackers inside cloud, industrial, and AI-connected systems.

July 28, 2026
4 minutes

Read Time

Milan’s cyber decoys pull in €3m
Summary
  • Beelzebub has raised €3 million to expand an automated cyber deception and analysis platform.
  • Honeypots are established security tools, while AI is changing how realistic decoys are operated and analysed.
  • Enterprise adoption will depend on verified detection quality, safe automation, integration, and evidence beyond vendor claims.

A Milan cybersecurity startup has raised €3 million for software that draws attackers into realistic but isolated systems, using automation to analyse their behaviour before they reach production infrastructure.

Beelzebub secured the seed round from Italian deep technology investor United Ventures. Combined with an earlier €300,000 pre-seed investment, the company’s reported funding now totals €3.3 million.

The capital will support research, European sales, and commercial offices in Rome and San Francisco, with regulated organisations affected by NIS2 among the intended customers. Beelzebub is also developing tools designed to detect attacks involving AI agents and the connections those agents make to external software or data.

Security researcher Mario Candela began the technology as an open-source project before incorporating Beelzebub as a business in 2025. The commercial platform combines deception environments, attack simulation, malware analysis, containment, and incident reports for security operations teams.

Established defence gains new machinery

Cyber deception has a long history because honeypots have been used for years to imitate vulnerable servers, services, identities, and credentials. An attacker entering the decoy reveals techniques within a controlled environment, while defenders gain evidence that may be difficult to collect from production systems.

Automation can make those traps more convincing and reduce the manual work required to operate them. Beelzebub’s open-source runtime supports protocols including SSH, HTTP, TCP, Telnet, and the Model Context Protocol used by some AI agent systems, while language models can generate interactions intended to keep an attacker engaged.

The underlying attraction is stronger signal. Conventional security platforms often produce large alert volumes because legitimate activity can resemble malicious behaviour, whereas a carefully isolated decoy should receive little authorised traffic.

Beelzebub claims that its platform produces no false positives, but enterprise buyers should test that assertion against their own environment. Vulnerability scanners, monitoring tools, researchers, authorised testing, and configuration errors can all touch a decoy without representing a confirmed breach.

Automated containment requires similar caution. Malware can be detonated and analysed inside a sandbox, while a decision to isolate a production asset or block an identity may interrupt legitimate operations if the underlying evidence is wrong or incomplete.

AI agents create fresh routes into systems

The company’s work around Model Context Protocol honeypots reflects the security problem created when businesses connect AI agents to databases, applications, file stores, and workflow tools. An agent able to act across those systems can automate useful work, but the same connections create routes for prompt injection, credential theft, manipulated data, and unauthorised tool use.

A decoy built for agent-mediated attacks may reveal whether an automated system follows poisoned instructions or attempts to reach resources beyond its permissions. Its value depends on where the trap is placed and whether it resembles a target that an attacker or compromised agent would genuinely pursue.

Beelzebub describes its platform as capable of autonomous analysis and response. Deployments will need to separate actions that are safe inside an isolated environment from consequential decisions affecting live systems, particularly in healthcare, finance, transport, government, and manufacturing.

NIS2 provides the startup with a receptive market because affected organisations need stronger risk management, incident handling, supply chain oversight, and reporting. Buying a deception platform cannot provide compliance on its own, since customers must still integrate alerts into incident procedures, assign ownership, retain evidence, and test whether response times improve.

Open source can open doors, not close deals

The €3 million round is modest beside the funding available to large security platforms, but it can support a focused engineering and research team. Beelzebub’s open-source roots may also reduce initial adoption friction by allowing technical users to inspect the runtime and run controlled trials.

Enterprise contracts bring additional requirements involving penetration testing, independent certification, data handling, service levels, integration, and support. A technically interesting framework must become a dependable product that remains effective as cloud architectures, attackers, and AI agent protocols change.

Beelzebub also competes with established deception specialists, endpoint vendors, extended detection platforms, cloud security suppliers, and security operations automation products. Its opportunity lies in making realistic traps easier to deploy across cloud native and agent-based systems rather than treating deception as a separate appliance.

Funding gives the company time to turn an open-source project into a supportable European security business. Progress will be measured by whether its platform produces useful evidence during real incidents, reduces rather than adds operational noise, and allows security teams to automate routine analysis without surrendering control over decisions that can disrupt production.

Latest News

View All

  • News, Policy, Security

    A UK court gives spyware a local address

    July 28, 2026
    A UK court gives spyware a local address
  • AI, Enterprise, News

    AI use is outrunning workplace training

    July 28, 2026
    AI use is outrunning workplace training
  • Growth, News, Security

    Milan’s cyber decoys pull in €3m

    July 28, 2026
    Milan’s cyber decoys pull in €3m
  • AI, Growth, News

    Smaller AI models draw a €500m round

    July 28, 2026
    Smaller AI models draw a €500m round
  • Enterprise, News

    Vodafone grows while Europe loses 1,200 roles

    July 28, 2026
    Vodafone grows while Europe loses 1,200 roles

You May Have Missed

View All

  • A UK court gives spyware a local address
    News, Policy, Security

    A UK court gives spyware a local address

    July 28, 2026
  • AI use is outrunning workplace training
    AI, Enterprise, News

    AI use is outrunning workplace training

    July 28, 2026
  • Milan’s cyber decoys pull in €3m
    Growth, News, Security

    Milan’s cyber decoys pull in €3m

    July 28, 2026
  • Smaller AI models draw a €500m round
    AI, Growth, News

    Smaller AI models draw a €500m round

    July 28, 2026
  • Vodafone grows while Europe loses 1,200 roles
    Enterprise, News

    Vodafone grows while Europe loses 1,200 roles

    July 28, 2026

About Techopia

Techopia covers business-facing technology across the UK and Europe, with reporting on AI, cybersecurity, enterprise tech, digital transformation, public interest technology and the policy shaping them.

We focus on what technology means in practice — for businesses, institutions and the wider economy — without the fluff, hype or gadget filler.

Latest News

  • A UK court gives spyware a local address

    A UK court gives spyware a local address
  • AI use is outrunning workplace training

    AI use is outrunning workplace training
  • Milan’s cyber decoys pull in €3m

    Milan’s cyber decoys pull in €3m
  • Smaller AI models draw a €500m round

    Smaller AI models draw a €500m round
  • Vodafone grows while Europe loses 1,200 roles

    Vodafone grows while Europe loses 1,200 roles

Categories

AI Enterprise Growth Impact Insights News Policy Security

Topics

Search

Copyright © 2026. All rights reserved. | 2b Publishing