Five cybersecurity startups. A panel of CISOs, investors, marketing and revenue leaders. And a chance to prove that what they've built can solve a problem security practitioners actually care about.
That's the idea behind LaunchPad, the startup competition making its debut at CYBR.SEC.CON 2026 in Houston Sept. 15-16.
As we outlined when we introduced the five finalists, LaunchPad is designed to give promising early-stage cybersecurity companies something they don't always get: direct exposure to the people who buy, use, evaluate, fund and help bring security products to market.
Full LaunchPad coverage:

Full CYBR.SEC.CON coverage:

The five finalists will pitch their companies during CYBR.SEC.CON, where they'll be evaluated on the problem they're solving, the strength of the technology, market opportunity, differentiation and their ability to turn an idea into a sustainable cybersecurity business.
But a pitch can only tell you so much.
So ahead of CYBR.SEC.CON, CYBR.SEC.Media is profiling each of the five LaunchPad finalists individually. We're asking the founders what problem pushed them to build their companies, who they're building for, what separates their approach from what's already on the market and what success looks like from the perspective of the security practitioner.
Next up is MokN, where Co-Founder Antoine Coudoux is focused on a familiar cybersecurity problem with a less familiar blind spot: stolen credentials that attackers are already using but defenders don't yet know have been compromised.
Dark-web monitoring has become a standard piece of many organizations' credential-security programs. When stolen usernames and passwords appear in criminal marketplaces, dumps or other underground sources, defenders can identify the affected accounts and take action.
MokN's premise is that by then, security teams may already be late.
Attackers don't necessarily publish or sell every credential they steal. Some are more valuable when used directly. That creates a window between the initial compromise and the credential appearing on the dark web — assuming it ever appears there at all.
MokN is trying to operate inside that window.
Coudoux describes the approach as effectively “phishing the phishers.” Rather than waiting for compromised credentials to surface somewhere defenders can see them, the platform is designed to collect intelligence from attackers as they validate and attempt to use stolen accounts.
That can give SOC teams an earlier warning that an account has been compromised while also providing intelligence about the infrastructure, tactics and threat actors behind the activity.
And MokN doesn't plan to stop at passwords. The company's longer-term ambition is to expand its approach to session tokens, stolen cookies and other identity-based attack vectors as credential and identity attacks continue to evolve.
Here's our Q&A with MokN Co-Founder Antoine Coudoux:
What problem did you see in the market that convinced you this company needed to exist?
Antoine Coudoux: The idea came from a real-world security incident. Attackers used freshly compromised credentials that had never appeared on the dark web, which meant there was no way for traditional monitoring tools to detect the compromise before the credentials were actively used.
We realized there was a blind spot between the moment credentials are stolen and the moment they eventually appear on the dark web — if they ever appear there at all. During that window, attackers are often already using the credentials.
The only way to gain visibility into that activity was to turn the tables on attackers and collect intelligence directly from them. That led us to develop a platform that effectively “phishes the phishers,” allowing organizations to identify compromised credentials, understand who is being targeted and gain visibility into active threat actors before attacks progress.
Who is the ideal customer for your solution?
Antoine Coudoux: Credential theft impacts every industry, but we typically see the greatest value in organizations with thousands of employees because a larger workforce creates a larger attack surface.
That said, the use case is relevant for organizations of many sizes. We have customers with only a few hundred employees who still benefit significantly from the platform.
Our primary users are security operations teams. They are already investigating credential theft and account compromise alerts. We integrate into their existing security stack and provide additional visibility that complements the monitoring and response capabilities they already have in place.
What makes your approach fundamentally different from other security vendors?
Antoine Coudoux: Most organizations address credential theft through dark-web monitoring or identity protection tools.
The problem is that dark-web monitoring only identifies credentials after attackers decide to disclose or sell them. Many credentials are never published because attackers can derive greater value from using them directly.
Our approach focuses on the gap between compromise and disclosure. We identify stolen credentials while attackers are actively validating and using them rather than waiting for those credentials to eventually surface elsewhere.
That earlier visibility allows organizations to respond before attackers can leverage the stolen accounts to gain access or expand an intrusion.
Can you share a customer story that captures the value of what you're doing?
Antoine Coudoux: One customer is a large global retailer operating in dozens of countries.
Over a weekend, we detected an attack campaign targeting approximately 40 executive and VIP accounts. A significant portion of those credentials were still valid, while others appeared to be older credentials that attackers had retained after previous compromises.
The attackers attempted to validate and use all of those accounts within a short period of time. We blocked the attempts and captured valuable intelligence about the threat actors and their tactics.
That information became actionable threat intelligence for the customer. They were able to enrich their CTI environment, investigate related activity and determine whether the same infrastructure or accounts had been used elsewhere within the organization.
What is the biggest misconception buyers have about the problem you're solving?
Antoine Coudoux: The most common misconception is that dark-web monitoring fully addresses credential compromise.
Many organizations believe they already have visibility into stolen credentials because they subscribe to dark-web monitoring services. In reality, those services only see credentials that attackers choose to disclose.
A significant amount of compromised credential activity never reaches the dark web. Organizations may therefore have visibility into only a fraction of their actual exposure.
A major part of our job is helping security teams understand the size of that blind spot.
What has been the hardest challenge in building the company?
Antoine Coudoux: The biggest challenge has been expanding into new markets.
In France, where we started, we now benefit from customer references and word-of-mouth recommendations. Security leaders talk to one another, which helps generate awareness and adoption.
When entering a new market such as the United States, however, we essentially start over. We need to educate buyers about the concept, introduce a category they may not have encountered before and establish credibility from scratch.
That process requires significant outreach, education and relationship building.
If we were having this conversation a year from now, what milestone would tell you the company is succeeding?
Antoine Coudoux: Success would mean establishing the United States as our primary market.
Today, Europe remains our largest market, but the U.S. represents our biggest growth opportunity.
At the same time, we want to evolve beyond credential recovery into a broader identity protection platform. That includes protecting session tokens, stolen cookies and additional identity-based attack vectors while expanding into external fraud use cases.
If we successfully execute both of those goals, we will consider the year a success.
Why is now the right time for this company and solution to exist?
Antoine Coudoux: Credential theft has existed for decades, so in many ways this solution should have existed long ago.
What makes today different is the ability to move faster and build more efficiently. AI has accelerated everything from product development and interface design to marketing and execution.
The underlying problem is not new, but the tools available today make it possible to innovate and scale solutions much more quickly than would have been possible just a few years ago.
What does success look like for the security practitioner using your product every day?
Antoine Coudoux: Success means stopping attacks at the earliest possible stage.
By identifying compromised credentials during the reconnaissance and preparation phases, security teams can prevent attacks before they become incidents. Automated response capabilities reduce the time analysts spend investigating and recovering from compromises.
The platform also provides rich threat intelligence that can be used to improve firewall policies, enhance monitoring, strengthen phishing-awareness programs and enrich broader security operations.
Ultimately, success means preventing attacks rather than spending time recovering from them.

