Fig Security Pitch Deck: All 9 Slides + Teardown

See all 9 slides of the Fig Security pitch deck — a 2024 Series A deck — with a slide-by-slide teardown of what the deck does well and where it falls short.

Fig Security’s 9-slide Series A deck is a departure from traditional, data-heavy cybersecurity presentations. Instead of leading with threat landscapes or market TAM, the company focuses entirely on the operational pain of the Security Operations Center (SOC). The deck uses a consistent visual metaphor—a colorful, unstable block tower—to represent the fragility of security infrastructure. By categorizing the problem into 'Drift' and 'Planned Changes,' Fig creates a clear binary for their solution to address. While the deck is notably light on financial metrics, competition, and a formal 'Ask,…

Key takeaways

The Narrative Strategy: Simplicity Over Complexity

Fig Security’s pitch deck is a masterclass in focused storytelling. With only nine slides, the company managed to secure a $38M Series A in 2024. The deck does not attempt to explain the entire cybersecurity landscape; instead, it focuses intensely on a single, painful friction point: the fragility of the Security Operations Center (SOC). By using a consistent visual metaphor of a Jenga-like tower, the founders communicate the precarious nature of modern security infrastructure without needing walls of text.

Slide 1: The Hook

The title slide features the company logo and the tagline: "Don't break for a change." The visual is a tall, colorful tower of blocks. This immediately sets the tone. It suggests that the company is about stability, resilience, and managing the complexity of many moving parts. The branding is clean and modern, moving away from the typical 'dark mode' aesthetic of most cybersecurity firms.

Slide 2: The Founding Team

Slide 2, titled "About Fig," establishes the company's baseline credibility. It lists the headquarters as New York and Tel Aviv , a common corridor for high-growth cybersecurity startups. The team size is stated as 25 . Curiously, the slide lists the year founded as 2025 , which is likely a typo or a reference to a future milestone, given the reported 2024 raise date. The core of this slide is the founder bios: Roy Haimof (CTO) , Gal Shafir (CEO) , and Nir Loya Dahan (CPO) . Their previous experience at Google, Siemplify, and Cymulate provides the 'founder-market fit' necessary to raise a large Series A with a relatively short deck.

Slide 3: Problem 1 - Drift

The deck identifies two primary enemies of the SOC. The first is "1. Drift (Unplanned Changes)." The slide uses the block tower metaphor again, this time showing a disco-ball wrecking ball smashing into the middle of the stack. The text breaks down the Cause (upstream data changes like renamed fields or log updates), the Effect (detection rules breaking silently), and the Aftermath (a false sense of security followed by weeks of 'soul-crushing data plumbing'). This is a highly specific pain point that resonates with SOC engineers.

Slide 4: Problem 2 - Planned Changes

The second problem is "2. Planned Changes." Here, the visual shows characters (a sloth, a duck, and a wolf) cautiously inspecting the tower. The Cause is the SOC engineers themselves trying to update parsers or add new sources. The Effect is described as "Paralyzing fear," where the stack is treated like an "unexploded bomb." The Aftermath is a "snail's pace" for deployments. This slide effectively highlights the opportunity cost of a fragile system: it prevents the team from doing the very work they were hired to do.

Slide 5: The Solution Architecture

Slide 5 introduces "Security Operations Resilience." It features a diagram of the Fig platform in action. The UI shows integrations with Data Sources (AWS, Windows, Salesforce), Data Processing (Splunk, Cribl), Detection (Splunk), Data Lakes (Snowflake), and SOAR (Torq). The diagram includes percentage health markers (e.g., 89%, 96%, 78% ) and issue counts, suggesting that Fig provides a real-time observability layer across the entire security telemetry pipeline. The promise is to "Keep your detection and response working through any change."

Slide 6: Addressing Drift

Slide 6 dives deeper into how Fig handles unplanned changes. It splits the solution into "Drift Detection" and "Drift Repair." The visuals show the block tower leaning and then being straightened by a mechanical arm. The text emphasizes speed: "Catch change the moment a detection or response breaks. No mystery." This slide positions Fig as an automated fix for the 'soul-crushing plumbing' mentioned earlier in the deck.

Slide 7: Managing Planned Changes

Slide 7 addresses the second problem: "Planned changes." It introduces two features: "Model Changes" and "Deploy to Production." The visual shows a blueprint of the block tower, representing simulation. The text promises that users can "simulate your initiatives and see the impact before anything hits production." The deployment side promises "one click, version control, [and] easy rollbacks." This frames Fig as a DevOps-style tool for security operations.

Slide 8: The Value Proposition

Slide 8 summarizes the benefits: "With change under control, you..." It lists five outcomes: "Get operational resilience," "Ditch the plumbing," "Ship 10x faster, risk free," "Maximize security coverage," and "Do less chores, more cyber." The use of the "10x faster" claim is a standard venture capital trope, but it is supported by the previous slides' explanation of how automation replaces manual meetings and approvals.

Slide 9: Conclusion

The final slide is a simple "Thank you" featuring all the animal characters working together to build a stable, large-scale version of the block tower. It reinforces the brand identity and the idea of collective, organized construction rather than chaotic, fragile stacks.

What Fig Security Does Well

The primary strength of this deck is its visual consistency . The block tower is not just a pretty picture; it is a functional metaphor that evolves as the deck progresses. It represents the problem (fragility), the cause of failure (impact), and the solution (blueprints and repair). This allows the reader to grasp the core value proposition without needing to understand the technical minutiae of log parsing or API drift.

Furthermore, the problem framing is excellent. By categorizing issues into 'Unplanned' and 'Planned' changes, Fig creates a comprehensive scope for its product. It acknowledges that the SOC is not just failing because of external factors, but also because its own internal processes are too slow and fearful. This dual-threat model makes the solution feel more necessary.

What is Missing from the Deck

While the deck is effective as a narrative piece, it omits several standard Series A components. There is no market size (TAM) slide , which is usually required to prove the venture-scale potential of the business. There is also no mention of the business model —how they charge, what the typical contract size is, or what the sales cycle looks like.

The deck also lacks a competitive landscape . In the cybersecurity space, observability and 'security for security' are growing niches. Investors would typically want to see how Fig differentiates itself from general observability tools (like Datadog) or other security-specific pipeline tools (like Cribl). Finally, there is no 'Ask' slide . We know from publisher reports that they raised $38M, but the deck itself does not state the amount sought or the intended use of funds.

Lessons for Founders

Founders can learn two major lessons from Fig Security. First, invest in high-quality design . In a crowded market, a deck that looks like a cohesive brand rather than a collection of stock icons commands a higher level of respect and perceived value. It signals that the founders care about user experience and clarity.

Second, leverage your pedigree . If you have a team that has worked at Google or successfully exited companies like Siemplify, you don't need to spend 20 slides proving you know the market. You can afford to be brief and narrative-focused because your resume provides the 'proof of work.' If you lack that pedigree, you will likely need to supplement a narrative deck like this with much more data on traction, market size, and competitive moats.

Frequently asked questions

Why does the deck omit market size and financial projections?
For a Series A round involving experienced founders (Google, Siemplify), the 'why now' and 'product-market fit' are often demonstrated through design and narrative rather than speculative spreadsheets. The $38M raise suggests that the problem—SOC fragility—was already validated by investors, allowing the deck to focus on the unique way Fig solves it rather than justifying the existence of the cybersecurity market.
What is the significance of the 'Drift' terminology used in the deck?
In cybersecurity, 'Drift' refers to the gradual deviation of a system from its intended secure state. By focusing on 'silent' failures (Slide 3), Fig positions itself as a monitoring layer for the security tools themselves. This moves the conversation away from 'detecting hackers' to 'detecting when your hacker-detection tools break,' a specific and underserved niche.
How does the team slide contribute to the $38M raise?
Slide 2 is arguably the most important slide in this short deck. By listing three founders with deep domain expertise in cybersecurity (Cymulate, Siemplify) and big tech (Google), Fig reduces the perceived execution risk. Investors are more likely to fund a 9-slide narrative when the team behind it has a proven track record of building and exiting companies in the same sector.
Is the visual style of the deck too 'unprofessional' for cybersecurity?
On the contrary, the high-quality, custom illustrations and consistent color palette signal a premium brand. In a sea of dark-themed, 'hacker-style' cybersecurity decks, Fig’s bright and metaphorical approach stands out. It frames the problem as an engineering and operational challenge rather than a scary, external threat, which appeals to modern CISO sensibilities.
What are the 'silent failures' mentioned in the publisher summary?
As described on Slide 3, silent failures occur when upstream data changes (like a renamed IT field or a SaaS log update) cause detection rules to stop working without triggering an alert. The deck argues that these failures lead to a 'false sense of security,' which Fig aims to eliminate through automated drift detection and repair.
Cover slide of the Fig Security pitch deck — Series A 2024
Fig Security pitch deck, slide 1 (2024)

Fig Security pitch deck: the facts

Company
Fig Security
Year
2024
Stage
Series A
Slides
9
Sector
Cybersecurity
Deck type
Series A Pitch Deck
Outcome
$38M Raised
Headquarters
New York, Tel Aviv

Fig Security pitch deck PDF

The full Fig Security deck is embedded on this page and can be read slide by slide in the browser — no download or account required. Each slide is covered in the breakdown above.

Related fundraising guides (24)

Decks from the same year (1)

Decks from the same region (1)

Decks with a similar raise (1)

Browse companies alphabetically (1)

More pitch deck teardowns (16)

Recently published pitch deck teardowns (12)

Fundraising library · Pitch deck examples · Investor directory · Founder database