The Identity Revolution: How Oak Aims to Overhaul Enterprise Security in the Age of AI

In the modern enterprise, the concept of the "perimeter" has effectively evaporated. As businesses shift from physical offices to distributed cloud environments, the traditional badge-swipe security model has become a relic of the past. Today, the challenge is not just protecting buildings, but governing the complex, often chaotic interaction between human employees, automated software, and increasingly sophisticated AI agents.

Stepping out of stealth mode this week, Israeli startup Oak is positioning itself as the answer to this identity crisis. With a $60 million seed funding round already in the bank and a platform already deployed across several major enterprise clients, Oak is not merely launching a product; it is attempting to redefine the "control plane" for digital identity.

The Core Problem: Why Legacy IAM is Failing

Identity and Access Management (IAM) systems have long been the gatekeepers of corporate data. However, as organizations adopt hundreds of SaaS applications and integrate AI-driven workflows, these systems are buckling under the weight of their own complexity.

Current IAM tools are largely operational and manual, relying on periodic, human-led access reviews. In a fast-paced, AI-integrated enterprise, this is a dangerous vulnerability. If an employee leaves a company or moves to a new role, their old permissions often linger—a phenomenon known as "privilege creep." When attackers use AI to exploit these forgotten credentials, the damage can be catastrophic before a manual audit ever catches the discrepancy.

Oak identifies this gap as its primary battlefield. By building an AI-native connector framework, the company moves away from static, rules-based access toward a dynamic, risk-based model that maps permissions to actual app usage in real-time.

Chronology: From Stealth to Scale

The story of Oak is deeply intertwined with the pedigree of its founders, Shai Morag and Tal Marom. Their journey is a testament to the "serial entrepreneur" model that has become the hallmark of the Israeli cybersecurity ecosystem.

  • The Ermetic Era: Shai Morag previously founded Ermetic, a cloud identity and security startup that gained significant traction before being acquired by Tenable in 2023 for $265 million. Morag stayed on as Chief Product Officer during the integration phase.
  • A Pivot in Plans: Following the passing of Tenable CEO Amit Yoran, Morag stepped down from his post. He initially told his family he intended to retire.
  • The Genesis of Oak: The retirement was short-lived. Morag reconnected with Tal Marom, a former product team lead at Tenable who also brought extensive experience from Salesforce and the Israeli military. Together, they realized that the problems they were seeing in cloud identity were far from solved.
  • Stealth Development: While the world was focused on the generative AI boom, Morag and Marom spent months in "stealth mode," conducting deep-dive interviews with over 100 Chief Information Security Officers (CISOs) and IAM leaders. This research phase proved critical in shaping Oak’s product-market fit.
  • The Funding Surge: Late last year, Oak secured a massive $60 million seed round, co-led by venture capital heavyweights Accel, CRV, and Greylock Partners.
  • The Public Emergence: As of this week, Oak has officially moved out of stealth, with a fully operational platform already live in enterprise environments.

Supporting Data: The "Born as a Giant" Strategy

Raising $60 million at the seed stage is an anomaly in the current venture capital climate, where purse strings have tightened significantly. However, for Oak, this capital is viewed as fuel for a rapid, global expansion.

The company is currently in a state of hyper-growth, having already built a team of 50 employees during its quiet phase. Morag has indicated that the company is actively hiring, with a strategic focus on expanding its presence in the United States. The goal is to establish the U.S. as the primary base for the majority of its staff, signaling a clear intent to dominate the North American enterprise market.

The confidence of the investors—specifically Accel—is rooted in long-term relationships. Andrei Brasoveanu, a partner at Accel, had previously backed Morag’s work at Ermetic. "I knew he had it in him to build another company, but this time even bigger and even better," Brasoveanu noted. The investment is not just a bet on the product, but a bet on the founder’s ability to navigate the complex organizational structures required to sell high-end security software to global enterprises.

Official Responses and Strategic Vision

Shai Morag’s vision for Oak is unapologetically ambitious. When asked about the company’s trajectory, his response was direct: "Our vision is to be born as a giant."

The core differentiator, according to Morag, is the move from "operations-based" to "risk-based" security. "Right now, the whole process is too manual," Morag explained. "There is no trigger when an employee logs in from an unusual location." Oak’s platform aims to automate these triggers, effectively pruning unnecessary permissions automatically rather than waiting for a quarterly review.

Tal Marom, serving as the company’s Chief Product Officer, emphasizes that the product was built specifically to address the "democratizing force" of AI. Because AI agents can now perform tasks that were once exclusively human, the definition of an "identity" must expand to include non-human entities. Without a centralized control plane to govern these digital workers, enterprises are effectively leaving the back door open to potential breaches.

Implications for the Cybersecurity Landscape

The implications of Oak’s entry into the market are two-fold:

1. The Death of Manual IAM

If Oak succeeds, the industry standard for IAM will shift permanently toward continuous, automated governance. The era of the "periodic review"—where IT teams spend weeks manually verifying who has access to what—is likely nearing its end. Organizations that fail to adopt real-time, AI-driven identity governance will find themselves increasingly unable to keep pace with the speed of modern threats.

2. Deepening Vendor Competition

The IAM space is notoriously difficult to disrupt due to "vendor lock-in." Once an organization integrates an identity provider (like Okta or Microsoft Entra), switching is a painful and expensive process. Oak is positioning itself not necessarily as a complete rip-and-replace solution for everything, but as a "control plane" that sits atop the stack, providing a layer of intelligence that legacy providers may struggle to replicate.

However, the path forward is not without challenges. Competitors—ranging from established giants to other well-funded startups—are all eyeing the same prize. The race to integrate AI into identity management is now the most critical theater of the cybersecurity war.

Conclusion: "Go Big or Go Home"

For Shai Morag, this is more than just a business venture; it is his final professional act. Having told his wife that he would retire after the acquisition of Ermetic, his decision to dive back into the startup grind speaks to a deep-seated belief that the current identity model is broken and that he possesses the unique experience to fix it.

"I will go big or go home," Morag stated in a recent interview. With a massive war chest, a seasoned founding team, and a product that addresses the most glaring vulnerability in the modern cloud enterprise, Oak is signaling that it is ready for the long fight ahead. In an age where digital identity is the only true perimeter, the company that controls that identity controls the future of corporate security.