The Category Builder

Shlomo Kramer has built three cybersecurity categories in 32 years — Check Point, Imperva, Cato Networks. The patience trade behind a postponed IPO, the Wiz comparison, and why Israel's repeat-founder economy is the highest-conviction signal in tech.
Shlomo Kramer co-founded Check Point in 1993. Imperva in 2002. Cato Networks in 2015. Three companies. Three cybersecurity categories. One founder.
The third is now valued at over $4.8 billion. In 2024, Cato Networks started working with investment banks on a potential IPO. Those plans were postponed. In summer 2025, the company raised $409 million in private capital at the same valuation instead.
The shorthand reads “delayed IPO.” The shorthand is wrong.
Shlomo Kramer has built three cybersecurity categories in 32 years. Public markets are asking for quarterly results. Those are not the same game.
The Third-Act Founder
Kramer's career is the most consequential operator arc in Israeli cybersecurity.
1993 — Check Point. Kramer co-founded Check Point Software Technologies with Gil Shwed and Marius Nacht. They built the first commercial firewall. Check Point is now a $20+ billion market cap company. Public since 1996.
2002 — Imperva. Kramer co-founded the innovator of the web application firewall — the category that protected web applications at the application layer. Imperva went public in 2011, peaked above $2 billion in market cap, and was taken private by Thoma Bravo in 2018 for $2.1 billion.
2015 — Cato Networks. Founded with Gur Shatz to converge enterprise networking and security in a single cloud platform. Cato built the category that Gartner formally defined as Secure Access Service Edge — SASE — four years after Cato had already shipped it.
Three companies. Three categories that did not exist when Kramer started building them. One founder.
Category Builders vs. Category Participants
Most cybersecurity founders enter existing categories. Kramer creates them.
Check Point built the first commercial firewall. The firewall did not exist as a procurement category before Check Point made it one. Imperva built the first web application firewall. The category did not exist before Imperva. Cato built SASE. Gartner formally defined SASE in 2019, four years after Cato had already shipped the architecture.
Three categories. Three first-movers. One founder.
The distinction matters because it changes what investors are actually buying when they back the company. A category participant competes on execution, pricing, and distribution. A category builder defines the rules everyone else has to operate inside. Different game. Different valuations. Different patience requirements.
Most founders build companies. Kramer builds categories.
That is the through-line. Everything else in this article is evidence for that claim.
Why Nobody Talks About Cato
In a category where the loudest brand usually wins, Cato is the quiet exception.
Kramer rarely speaks at conferences. He gives few interviews. The company's marketing is technical, not personality-driven. There is no founder-CEO press machine. There is no Twitter-thread strategy. There is no podcast tour.
This is not accident. This is design.
Cato bet that institutional buyers — CISOs, CIOs, procurement teams at Fortune 500 enterprises — make decisions based on analyst reports, customer references, and Gartner positioning. Not press density. Not social media followers. Not founder profiles.
The bet was right. Cato was named to the 2026 Fortune Cyber 60 list for a third consecutive year. Gartner has placed Cato in the SASE Leaders quadrant. The company crossed $250 million ARR in 2024 and $300+ million by September 2025 — almost entirely on word-of-mouth and analyst validation.
The communications lesson: for institutional categories, the analyst is the buyer. For founder-led categories, the press is the buyer. Knowing which game you're in is the strategy.
Wiz won by building the loudest brand in cybersecurity before the company had the product to back it. Cato won by building the quietest. Both produced billion-dollar valuations. Different audiences, different mechanics, same outcome.
What Cato Is — In Plain Terms
Traditional enterprise networking and security ran on hardware — branch routers, hardware firewalls, MPLS connections to data centers. When work moved out of offices, that architecture cracked. SASE moves the entire stack to the cloud: SD-WAN networking, secure web gateways, zero-trust network access, cloud access security broker — all delivered as a single platform from a single vendor.
Today the platform connects 3,500+ enterprises across 190 countries with 50,000 connected sites and 1.5 million remote users. ARR: $250 million in 2024 (+46% year-over-year), $300+ million by September 2025, approaching $400 million by mid-2026. Growth above 40%. The SASE market is projected by Gartner to grow at a compound annual rate of 26% over five years, reaching $28.5 billion by 2028.
The company is not yet profitable. The trajectory is.
What Buying Aim Security Signals
In September 2025, Cato expanded its AI capabilities through the $350 million acquisition of Israeli startup Aim Security.
This is not a standard M&A move. This is a category signal.
Three things Aim Security tells the market.
One — Cato believes AI security will be embedded into SASE, not bolted on as a separate category. The acquisition pre-empts the parallel category formation. Cato is moving to absorb AI security into its existing platform before AI security becomes a separate buyer decision and a separate procurement line.
Two — Cato is willing to spend roughly 7% of its valuation on a single capability acquisition. That is a high-conviction move. It says the founder believes the next layer is critical to defending category leadership.
Three — the acquisition is Israeli. Cato keeps the engineering bench in Tel Aviv, where it already is. Integration risk is low. Talent dilution is minimal.
This is Kramer's category-builder pattern: see where the architecture is going, plant the flag early, absorb adjacent emerging categories before they fragment the buyer decision. He did it with the firewall in 1993. He did it with the WAF in 2002. He is doing it with SASE-plus-AI-security in 2025.
The IPO That Wasn't
The postponement is being read as a setback. It is not.
In 2024, Cato engaged investment banks for a possible listing. By the time the window approached, two things had changed.
The sector was shaken after AI company Anthropic unveiled Claude Code Security, a solution designed to integrate cybersecurity protections directly into cloud-based development environments. The announcement triggered a sharp drop in cybersecurity stocks, including industry leaders Palo Alto Networks, CrowdStrike, and Zscaler. Cato would have priced at a discount to its private mark.
At the same time, Cato had options. The company raised $359 million at a valuation of more than $4.8 billion in summer 2025, then extended the round with an additional $50 million, bringing total Series G to $409 million.
The IPO was not postponed because Cato needed money. It was postponed because Cato didn't need public money.
That distinction is everything.
A typical IPO at $4.8 billion would raise $400-500 million for the company, lock up employee and investor equity for 90-180 days, expose the company to quarterly public-market pressure, and trade at a multiple set by the worst-performing cyber name on any given Tuesday.
The private round raised the same money, kept employee equity liquid through secondary participation, avoided lockup, deferred quarterly pressure for 18-24 months, and priced at the valuation the private market would actually pay.
The trade is not “delay the IPO.” The trade is “buy 18-24 months of optionality at no incremental dilution.”
Cato vs. Wiz — Two Playbooks
The Israeli cybersecurity exit story usually gets compressed into one model. Cato and Wiz show there are at least two.
Brand-first vs. category-first. Wiz built brand recognition before product depth. Assaf Rappaport became the public face of cloud security while ARR was still under $50 million. Cato built category leadership first — through analyst relationships and Gartner positioning — and let brand catch up at the exit.
Media-heavy vs. analyst-heavy. Wiz dominated press coverage. Wiz executives were on every podcast, every conference stage, every founder-profile feature. Cato dominated Gartner Magic Quadrants, Forrester Waves, and analyst custom-research reports. Different signal channels. Different buyer audiences.
Fast vs. patient. Wiz exited six years after founding. Cato is eleven years in and still independent. Wiz turned down $23 billion and accepted $32 billion eight months later. Cato turned down public markets and raised private at the same price.
The Wiz playbook is for new categories. The Cato playbook is for established categories. Both work. Both produce multi-billion-dollar valuations. Both create founder windfalls if executed at scale. The choice depends on whether the category is being defined or has been defined.
The Wiz template misapplied to an established category produces noise. The Cato template misapplied to a new category produces obscurity. Founders should know which game they are in.
The Repeat-Founder Economy
Israeli tech increasingly produces second and third companies, not first companies.
Shlomo Kramer: Check Point, Imperva, Cato — three companies, three categories. Assaf Rappaport: Adallom, Wiz — two companies, $32 billion exit. Gil Shwed: Check Point — still running it 33 years after founding, having declined acquisition offers across three decades. Marius Nacht: Check Point co-founder, now anchoring aMoon and backing Israeli healthtech and cybersecurity. Nir Zuk: Check Point alumnus, founder of Palo Alto Networks.
The Check Point family tree alone now contains roughly twenty billion-dollar companies. The Adallom alumni are four billion-dollar founders. Wiz's senior engineers will be tomorrow's founders.
Each successful Israeli cybersecurity company seeds the next two or three. The capital recycles. The talent recycles. The customer relationships recycle. The cluster does not depend on any single exit — it depends on continuous repeat-founder volume.
For investors, the repeat-founder credential is now the highest-conviction signal in Israeli tech. Founders with a meaningful exit behind them raise on premium terms. The next round of Israeli IPOs and acquisitions will be dominated by repeat founders.
Kramer is what that flywheel looks like at maximum compression. Three categories in 32 years. Each company built off the prior network. The same investors who backed Check Point in 1993 backed Cato in 2025.
Three Things To Watch
The next 24 months will tell whether Cato's category-leadership thesis pays off. Three signals to track.
One — ARR trajectory toward $500 million-plus. Cato is approaching $400 million ARR. The next milestone is $500 million by end of 2026. Cross that line at maintained 40%+ growth and the IPO window reopens at a substantially higher valuation. Growth compression below 30% compresses the patience trade with it.
Two — AI-security integration after Aim. The Aim Security acquisition needs to ship. Watch through 2026 for product announcements showing AI-security capabilities natively integrated into the SASE platform. Delivered integration defends category leadership and pre-empts a separate AI-security buyer decision. Stalled integration lets competitors enter the gap.
Three — strategic interest from Microsoft. Microsoft has the Defender-Azure-AD-Entra stack. Cato is the most direct SASE extension Microsoft could acquire. Watch for joint announcements, partner-channel expansions, executive crosses. If Microsoft moves on Cato, the exit window reopens at hyperscaler pricing.
Hit on all three — Cato emerges as the next $10-billion-plus Israeli cyber exit. Miss any two — Cato becomes a midsize private platform that has to find its own path.
The Takeaway
The most credentialed founder in Israeli cybersecurity is also the most patient. Watch what he does, not what he says.
Kramer has done this twice before. Check Point: built, public, $20+ billion. Imperva: built, public, taken private, recovered. Cato: built, postponed, waiting.
Each cycle, the company that emerged was larger than the cycle before. Each cycle, Kramer was earlier in the next layer than the market understood at the time.
Cato is not trying to become Wiz. It is trying to become the next Check Point. That is a bigger ambition. It is also a longer game.
For investors, the read is simple: when this founder waits, wait with him. When this founder moves, the move is already priced.
Optionality is the asset. Patience is how Kramer preserves it.
The market thinks Cato delayed an IPO.
Kramer is betting he delayed a valuation.
FAQ
Who is Shlomo Kramer?
Shlomo Kramer is an Israeli cybersecurity entrepreneur who has co-founded three companies that each created a new cybersecurity category: Check Point Software Technologies (1993, first commercial firewall), Imperva (2002, web application firewall), and Cato Networks (2015, SASE platform).
What is Cato Networks?
Cato Networks is a Tel Aviv-based cybersecurity company that delivers Secure Access Service Edge (SASE) — a cloud-native platform combining networking and security in a single architecture. Cato created the SASE category in 2015, before Gartner formally named it in 2019.
What is Cato Networks' current valuation?
Cato Networks is valued at over $4.8 billion following a $409 million Series G round completed in summer 2025 and extended in October 2025. Total funding raised: approximately $1 billion.
Why was Cato's IPO postponed?
Cato began working with investment banks on a potential IPO in 2024. Plans were postponed after Nasdaq cybersecurity multiples compressed and after Cato raised private capital at the valuation public markets would not bear. The company chose patient capital at the right price over impatient capital at the wrong price.
How big is Cato Networks' business?
Cato serves more than 4,000 enterprises across 190 countries, with 50,000 connected sites and 1.5 million remote users. ARR exceeded $300 million by September 2025, approaching $400 million by mid-2026, growth above 40% year-over-year.



