Fig Security Pitch Deck: All 9 Slides + Teardown

See all 9 slides of the Fig Security pitch deck — a 2024 Series A deck — with a slide-by-slide teardown of what the deck does well and where it falls short.

Fig Security’s 9-slide Series A deck is a departure from traditional, data-heavy cybersecurity presentations. Instead of leading with threat landscapes or market TAM, the company focuses entirely on the operational pain of the Security Operations Center (SOC). The deck uses a consistent visual metaphor—a colorful, unstable block tower—to represent the fragility of security infrastructure. By categorizing the problem into 'Drift' and 'Planned Changes,' Fig creates a clear binary for their solution to address. While the deck is notably light on financial metrics, competition, and a formal 'Ask,…

Key takeaways

The Narrative Strategy: Simplicity Over Complexity

Fig Security’s pitch deck is a masterclass in focused storytelling. With only nine slides, the company managed to secure a $38M Series A in 2024. The deck does not attempt to explain the entire cybersecurity landscape; instead, it focuses intensely on a single, painful friction point: the fragility of the Security Operations Center (SOC). By using a consistent visual metaphor of a Jenga-like tower, the founders communicate the precarious nature of modern security infrastructure without needing walls of text.

Slide 1: The Hook

The title slide features the company logo and the tagline: "Don't break for a change." The visual is a tall, colorful tower of blocks. This immediately sets the tone. It suggests that the company is about stability, resilience, and managing the complexity of many moving parts. The branding is clean and modern, moving away from the typical 'dark mode' aesthetic of most cybersecurity firms.

Slide 2: The Founding Team

Slide 2, titled "About Fig," establishes the company's baseline credibility. It lists the headquarters as New York and Tel Aviv , a common corridor for high-growth cybersecurity startups. The team size is stated as 25 . Curiously, the slide lists the year founded as 2025 , which is likely a typo or a reference to a future milestone, given the reported 2024 raise date. The core of this slide is the founder bios: Roy Haimof (CTO) , Gal Shafir (CEO) , and Nir Loya Dahan (CPO) . Their previous experience at Google, Siemplify, and Cymulate provides the 'founder-market fit' necessary to raise a large Series A with a relatively short deck.

Slide 3: Problem 1 - Drift

The deck identifies two primary enemies of the SOC. The first is "1. Drift (Unplanned Changes)." The slide uses the block tower metaphor again, this time showing a disco-ball wrecking ball smashing into the middle of the stack. The text breaks down the Cause (upstream data changes like renamed fields or log updates), the Effect (detection rules breaking silently), and the Aftermath (a false sense of security followed by weeks of 'soul-crushing data plumbing'). This is a highly specific pain point that resonates with SOC engineers.

Slide 4: Problem 2 - Planned Changes

The second problem is "2. Planned Changes." Here, the visual shows characters (a sloth, a duck, and a wolf) cautiously inspecting the tower. The Cause is the SOC engineers themselves trying to update parsers or add new sources. The Effect is described as "Paralyzing fear," where the stack is treated like an "unexploded bomb." The Aftermath is a "snail's pace" for deployments. This slide effectively highlights the opportunity cost of a fragile system: it prevents the team from doing the very work they were hired to do.

Slide 5: The Solution Architecture

Slide 5 introduces "Security Operations Resilience." It features a diagram of the Fig platform in action. The UI shows integrations with Data Sources (AWS, Windows, Salesforce), Data Processing (Splunk, Cribl), Detection (Splunk), Data Lakes (Snowflake), and SOAR (Torq). The diagram includes percentage health markers (e.g., 89%, 96%, 78% ) and issue counts, suggesting that Fig provides a real-time observability layer across the entire security telemetry pipeline. The promise is to "Keep your detection and response working through any change."

Slide 6: Addressing Drift

Slide 6 dives deeper into how Fig handles unplanned changes. It splits the solution into "Drift Detection" and "Drift Repair." The visuals show the block tower leaning and then being straightened by a mechanical arm. The text emphasizes speed: "Catch change the moment a detection or response breaks. No mystery." This slide positions Fig as an automated fix for the 'soul-crushing plumbing' mentioned earlier in the deck.

Slide 7: Managing Planned Changes

Slide 7 addresses the second problem: "Planned changes." It introduces two features: "Model Changes" and "Deploy to Production." The visual shows a blueprint of the block tower, representing simulation. The text promises that users can "simulate your initiatives and see the impact before anything hits production." The deployment side promises "one click, version control, [and] easy rollbacks." This frames Fig as a DevOps-style tool for security operations.

Slide 8: The Value Proposition

Slide 8 summarizes the benefits: "With change under control, you..." It lists five outcomes: "Get operational resilience," "Ditch the plumbing," "Ship 10x faster, risk free," "Maximize security coverage," and "Do less chores, more cyber." The use of the "10x faster" claim is a standard venture capital trope, but it is supported by the previous slides' explanation of how automation replaces manual meetings and approvals.

Slide 9: Conclusion

The final slide is a simple "Thank you" featuring all the animal characters working together to build a stable, large-scale version of the block tower. It reinforces the brand identity and the idea of collective, organized construction rather than chaotic, fragile stacks.

What Fig Security Does Well

The primary strength of this deck is its visual consistency . The block tower is not just a pretty picture; it is a functional metaphor that evolves as the deck progresses. It represents the problem (fragility), the cause of failure (impact), and the solution (blueprints and repair). This allows the reader to grasp the core value proposition without needing to understand the technical minutiae of log parsing or API drift.

Furthermore, the problem framing is excellent. By categorizing issues into 'Unplanned' and 'Planned' changes, Fig creates a comprehensive scope for its product. It acknowledges that the SOC is not just failing because of external factors, but also because its own internal processes are too slow and fearful. This dual-threat model makes the solution feel more necessary.

What is Missing from the Deck

While the deck is effective as a narrative piece, it omits several standard Series A components. There is no market size (TAM) slide , which is usually required to prove the venture-scale potential of the business. There is also no mention of the business model —how they charge, what the typical contract size is, or what the sales cycle looks like.

The deck also lacks a competitive landscape . In the cybersecurity space, observability and 'security for security' are growing niches. Investors would typically want to see how Fig differentiates itself from general observability tools (like Datadog) or other security-specific pipeline tools (like Cribl). Finally, there is no 'Ask' slide . We know from publisher reports that they raised $38M, but the deck itself does not state the amount sought or the intended use of funds.

Lessons for Founders

Founders can learn two major lessons from Fig Security. First, invest in high-quality design . In a crowded market, a deck that looks like a cohesive brand rather than a collection of stock icons commands a higher level of respect and perceived value. It signals that the founders care about user experience and clarity.

Second, leverage your pedigree . If you have a team that has worked at Google or successfully exited companies like Siemplify, you don't need to spend 20 slides proving you know the market. You can afford to be brief and narrative-focused because your resume provides the 'proof of work.' If you lack that pedigree, you will likely need to supplement a narrative deck like this with much more data on traction, market size, and competitive moats.

Frequently asked questions

Why does the deck omit market size and financial projections?
For a Series A round involving experienced founders (Google, Siemplify), the 'why now' and 'product-market fit' are often demonstrated through design and narrative rather than speculative spreadsheets. The $38M raise suggests that the problem—SOC fragility—was already validated by investors, allowing the deck to focus on the unique way Fig solves it rather than justifying the existence of the cybersecurity market.
What is the significance of the 'Drift' terminology used in the deck?
In cybersecurity, 'Drift' refers to the gradual deviation of a system from its intended secure state. By focusing on 'silent' failures (Slide 3), Fig positions itself as a monitoring layer for the security tools themselves. This moves the conversation away from 'detecting hackers' to 'detecting when your hacker-detection tools break,' a specific and underserved niche.
How does the team slide contribute to the $38M raise?
Slide 2 is arguably the most important slide in this short deck. By listing three founders with deep domain expertise in cybersecurity (Cymulate, Siemplify) and big tech (Google), Fig reduces the perceived execution risk. Investors are more likely to fund a 9-slide narrative when the team behind it has a proven track record of building and exiting companies in the same sector.
Is the visual style of the deck too 'unprofessional' for cybersecurity?
On the contrary, the high-quality, custom illustrations and consistent color palette signal a premium brand. In a sea of dark-themed, 'hacker-style' cybersecurity decks, Fig’s bright and metaphorical approach stands out. It frames the problem as an engineering and operational challenge rather than a scary, external threat, which appeals to modern CISO sensibilities.
What are the 'silent failures' mentioned in the publisher summary?
As described on Slide 3, silent failures occur when upstream data changes (like a renamed IT field or a SaaS log update) cause detection rules to stop working without triggering an alert. The deck argues that these failures lead to a 'false sense of security,' which Fig aims to eliminate through automated drift detection and repair.
Cover slide of the Fig Security pitch deck — Series A 2024
Fig Security pitch deck, slide 1 (2024)

Fig Security pitch deck: the facts

Company
Fig Security
Year
2024
Stage
Series A
Slides
9
Sector
Cybersecurity
Deck type
Series A Pitch Deck
Outcome
$38M Raised
Headquarters
New York, Tel Aviv

Fig Security pitch deck PDF

The full Fig Security deck is embedded on this page and can be read slide by slide in the browser — no download or account required. Each slide is covered in the breakdown above.

What the Fig Security pitch deck was used for

This pitch deck is from Fig Security, a cybersecurity startup focused on Security Operations Resilience for SOC teams, used to raise a combined Seed and Series A round totaling about $38M.[1][2][3][5][8][9][14][15] The deck was circulated around their emergence from stealth in early March 2026, framed as a Series A-led fundraise by Ten Eleven Ventures with prior seed backing from Team8.[2][3][5][7][8][14] It positions Fig as the guardian of the reliability of security detection systems, emphasizing the fragility of modern SOC infrastructure and how Fig keeps detection and response working through constant change.[1][3][5][6][11][12][15] The slide text provided (Slide 8) highlights outcomes for customers—operational resilience, eliminating data plumbing work, shipping changes faster without added risk, maximizing security coverage despite drift, and reducing tedious SOC chores.[provided OCR]

Business model: Fig Security provides a Security Operations Resilience platform for modern SOC (Security Operations Center) teams, monitoring data flows and security tooling across the SecOps stack to detect and fix broken security processes caused by constant change and drift.[5][11][12][13]

Lead investor
Ten Eleven Ventures (Series A lead) and Team8 (Seed lead).
Investors
Team8, Ten Eleven Ventures, Doug Merritt (former CEO of Splunk), Rene Bonvanie (former CMO of Palo Alto Networks), Founders of Demisto, Founders of Siemplify, Crosspoint Capital Partners, U&I Ventures
Founded
2025[6][11]
Founders
Gal Shafir, Nir Loya Dahan, Roy Haimof
Headquarters
New York, New York, United States, with operations in Tel Aviv, Israel.[6][10][11]
Industry
Cybersecurity; Security Operations / SecOps resilience.[6][11][12][13]

Round: Series A (with combined disclosure of Seed + Series A totaling about $38M).

Year: 2026 (public announcements of the combined Seed and Series A raise and emergence from stealth).[2][3][5][7][8][14][15]

Raised: Approximately $38M across Seed and Series A rounds, with some sources specifying a $30M Series A and prior $8M Seed.[2][3][5][7][8][14][15]

Total funding: Approximately $38M raised across Seed and Series A rounds as of March 2026, with some sources listing total funding at $46M (likely including additional capital or updated data beyond the initial announcement).[2][3][5][6][8][13]

Use of funds as presented: Funding is earmarked for product development, team expansion (including tripling headcount), and go-to-market efforts, particularly in North America and with large enterprises.[3][5][14][15]

What happened after the Fig Security deck

As of 2026, Fig Security has successfully raised significant early-stage funding, emerged from stealth with backing from major cybersecurity VCs and operators, and is actively building and deploying its Security Operations Resilience platform with a focus on large enterprise SOCs.[2][3][5][6][8][11][12][13][14][15]

What the Fig Security deck got right

What could have been stronger

How an investor would read this deck

What draws attention

Risks that stand out

Questions this deck invites

What founders can take from the Fig Security deck

Fig Security pitch deck: common questions

What does Fig Security do?

Fig Security is a cybersecurity startup that builds a Security Operations Resilience platform to keep detection and response working despite constant infrastructure and configuration change, by tracing data flows across the security stack and identifying when rules and tools silently break.[3][5][11][12][13]

How much funding has Fig Security raised and who invested?

Public funding announcements and investor communications state that Fig raised roughly $38M across Seed and Series A rounds, led by Team8 and Ten Eleven Ventures, with participation from security industry angels such as former Splunk and Palo Alto Networks executives and the founders of Demisto and Siemplify.[2][3][5][7][8][14][15] Some databases now list total funding at about $46M, likely reflecting updated or additional capital.[13]

What problem is Fig Security solving for SOC teams?

Fig’s platform focuses on monitoring and maintaining the reliability of security operations data pipelines, rules, and detection/response tools, helping SOC teams ensure their detection coverage, response playbooks, and automations remain effective despite patching, infrastructure changes, or tooling updates that can introduce silent failures.[3][5][6][11][12][15]

Who founded Fig Security and when was it founded?

Fig was founded in 2025 by cyber entrepreneurs including Gal Shafir, Nir Loya Dahan, and Roy Haimof, with backgrounds in Israeli cyber and intelligence units and leadership roles in prior security companies.[5][6][15]

Where is Fig Security based?

Fig is headquartered in New York City, with additional operations in Tel Aviv; the company lists an address on Madison Avenue in New York and a location on Yehuda and Noah Moses Street in Tel Aviv.[6][10][11]

Sources

Funding and outcome facts on this page were researched on 2026-08-30 from the pages below.

Fig Security pitch deck slides

Fig Security pitch deck slide 1 of 9
Fig Security pitch deck — slide 1 of 9
Fig Security pitch deck slide 2 of 9
Fig Security pitch deck — slide 2 of 9
Fig Security pitch deck slide 3 of 9
Fig Security pitch deck — slide 3 of 9
Fig Security pitch deck slide 4 of 9
Fig Security pitch deck — slide 4 of 9
Fig Security pitch deck slide 5 of 9
Fig Security pitch deck — slide 5 of 9
Fig Security pitch deck slide 6 of 9
Fig Security pitch deck — slide 6 of 9

What each slide of the Fig Security pitch deck says

Slide 2

About Fig 22 Founding Team | Headquarters New York, Tel Aviv £72 Bay Pull | Year Founded { 2025 Yor ) SVE A = [4 | Team Size A= | — Pa. | “4 1 1 1 Roy Haimof Gal Shafir Nir Loya Dahan Co-Founder and CTO Co-Founder and CEO Co-Founder and CPO ocymulate Google @ simplify @cymulate § simplify

Slide 3

Your SOC is deathly allergic to: 1. Drift (Unplanned Changes) > id LJ Xx The Cause: Upstream data changes that happen with no notice: A source stops sending RG data, IT rename a field, a SaaS vendor updates Po ® ‘ their logs, or a data pipeline filter is added. a= 1 Na X 53 i The Effect: Your detection rules and i be. on 57) PY automations break silently. No alert. No hint. a NF, ay | » + IN 0 The Aftermath: You have a false sense of | 0 security, followed by weeks of soul-crushing | data plumbing to find and fix the break. Na Ofig

Slide 4

Your SOC is deathly allergic to: 2. Planned Changes The Cause: SOC Engineers trying to actually do | their job - adding new sources, updating 9 c § i parsers, writing new rules, or modernizing their i & hb 8 > own SOC infrastructure. SE » J The Effect: Paralyzing fear. The stack is so 1 BN 2) b fragile that everyone treats it like an unexploded 7. TE YY bomb. < | = The Aftermath: You move at a snail's pace. A task ) | Nl \aEgy that should take three clicks drags into months (me | _ A of meetings, approvals, and anxiety before every oe, kL Wl production deployment. | — Ofig

Slide 5

SAY HELLO TO Security Operations Resilience Keep your detection and response working through any change = Ofig

Slide 6

Drift (unplanned changes) ri} Drift Drift 9] Detection Repair | “> Catch change the moment a Catch change the moment a — detection or response breaks. detection or response breaks. A deo No mystery. No “wait... when did 777 No mystery. No “wait... when did ; 5 that happen?” —Z that happen?” — rs CN Gfig 6

Slide 8

With change under control, you... Get operational resilience Keep your SOC running at full capacity no matter what changes around it. Ofig Ditch the plumbing Stop wasting time tracing the flow of data through your pipes. Ship 10x faster, risk free Design, test, verify, and deploy from one place on any infrastructure. Yes, even open source. Maximize security coverage Make sure your coverage is unaffected by Drift while rapidly expanding coverage. Do less chores, more cyber Eliminate the most soul-crushing part of your team's job and let them do what they signed up for.

Slide text above is read directly from the Fig Security deck PDF embedded on this page.

Related fundraising guides (24)

Decks from the same year (1)

Decks from the same region (1)

Decks with a similar raise (1)

Browse companies alphabetically (1)

More pitch deck teardowns (16)

Recently published pitch deck teardowns (12)

Fundraising library · Pitch deck examples · Investor directory · Founder database