Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


08:00 AM

Is Bharosa Acquisition Bait?

Authentication specialist may be for sale, but its CEO is not looking to pair up with another security pure-play

Whether authentication specialist Bharosa is just flirting or looking for a more lasting commitment, speculation is afoot about the startup's future.

"I happen to know that they are for sale, they have hired bankers," said an industry analyst, who asked not to be named. "The whole notion of authentication is heating up, particularly around these financial services breaches."

Bharosa is a bit more coy. "I have no comment about being in play," says CEO Jon Fisher, while admitting that his firm has received acquisition overtures. But he does not want to see the company fall "into the wrong hands."

What does he mean by that? "Selling the company to another pure play security vendor is not what I envision," he says. "I don't want to make a wrong move where the technology can't be leveraged around the world."

Bharosa essentially offers two products: "Tracker" verifies the device a user is coming from and assesses the threat the user poses; "Authenticator" is a virtual token to protect sensitive data, such as passwords or PINs. (See Bharosa Launches 3.5 and National City Taps Bharosa.)

"To our knowledge, they are the only pure-play vendor doing strong authentication and fraud detection," said Nick Selby, a senior analyst at The 451 Group, highlighting a recent burst of activity in this space, in a note last week. "The last acquisition was Entrust's acquisition of Business Signatures for $50 million," he noted, adding that RSA also bought security startups PassMark and Cyota. (See Entrust Bags Business Signatures, RSA Snatches Up Competition Passmark, and Add Another Bolt to the Cyber Door.)

The analyst adds that Bharosa's technology could dovetail nicely with any number of large vendors: "It could fit nicely into the portfolios of a number of companies, including Verisign, RSA, IBM, and even, conceivably, Oracle."

Bharosa claims 30 enterprise customers, which include three of the top 10 U.S. banks and five of the country's top 25 credit unions. Notable clients include Wells Fargo, the U.S Air Force, and the Desert Federal Credit Union. (See Banking on Multifactor Authentication.)

CEO Fisher says the 50-employee company, which has racked up $2 million in funding, has been profitable for a year. "We're south of $20 million in annual revenue, but certainly north of $5 million," he adds.

Our anonymous source thinks that even if Bharosa gets bought, it is not likely to involve mega-bucks: "It would be a modest valuation –- if they get taken out for $30 million, they would be dancing in the halls."

For a big-name vendor, a deal of that size would hardly break the bank, according to the analyst. "For a company like EMC, a $20 million acquisition doesn't have to go through a lot of approvals," he says. "Cisco is making all kinds of acquisitions in the security space, so it would not be a stretch for them to buy someone in authentication."

— James Rogers, Senior Editor Byte and Switch

  • Bharosa Inc.
  • Cisco Systems Inc. (Nasdaq: CSCO)
  • EMC Corp. (NYSE: EMC)
  • Entrust Inc.
  • The 451 Group
  • IBM Corp. (NYSE: IBM)
  • RSA Security Inc. (Nasdaq: EMC)
  • VeriSign Inc. (Nasdaq: VRSN)

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Inside the Ransomware Campaigns Targeting Exchange Servers
    Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
    Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
    Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
    Register for Dark Reading Newsletters
    White Papers
    Current Issue
    2021 Top Enterprise IT Trends
    We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
    Flash Poll
    How Enterprises are Developing Secure Applications
    How Enterprises are Developing Secure Applications
    Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    PUBLISHED: 2021-04-16
    The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted workspace configuration.
    PUBLISHED: 2021-04-16
    Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or ...
    PUBLISHED: 2021-04-16
    Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Spring Boot app occurs with a se...
    PUBLISHED: 2021-04-16
    A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions: QTS build 20210202 (and later) QT...
    PUBLISHED: 2021-04-16
    Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request...