top of page

The CIA Backed Investor Hunting for the Next Cybersecurity Breakthrough

11 hours ago
11 min read

Inside Katie Gray’s view of cybersecurity, venture capital, and the increasingly blurred line between Silicon Valley innovation and national security


The Investor Behind America’s Cyber Front Line


There was a time when national security technology was mostly imagined as something built inside government laboratories, military research programs, or the sprawling engineering divisions of major defense contractors. Silicon Valley occupied another world entirely, populated by entrepreneurs chasing consumers, enterprise customers, and venture capital. Those worlds still operate differently, but the boundary between them is disappearing. Artificial intelligence, cybersecurity, cloud computing, autonomous systems, satellites, semiconductors, and advanced software now sit at the center of both commercial competition and national security. Increasingly, the technologies that may determine how well a country protects itself are being invented inside startups.


That changing relationship was at the center of a recent Silicon Valley Unplugged conversation with Katie Gray, Senior Partner at IQT, the organization better known by its original name, In Q Tel. Gray has spent years looking at emerging cybersecurity companies through an unusual lens. A conventional venture capitalist might ask whether a company has a large market, exceptional founders, and the potential to become a billion dollar business. Gray has to consider another question at the same time: could this technology someday matter to national security?


In-Q-Tel

That question makes IQT one of the more unusual organizations in the technology industry. It operates inside the world of startups and venture investing, but its purpose reaches far beyond financial return. It was created to help the United States intelligence and national security communities find technologies emerging from the commercial sector, especially technologies developing so quickly that traditional government procurement could struggle to keep pace.

For Gray, cybersecurity is where that relationship becomes particularly urgent. The digital systems that power modern life are becoming more capable, more interconnected, and more difficult to defend. Artificial intelligence is accelerating that transformation. Attackers increasingly have access to tools that can search for vulnerabilities, automate reconnaissance, generate malicious code, and scale operations with less human effort. Defenders are responding with their own artificial intelligence systems. The result may be a cybersecurity environment in which machines increasingly attack, investigate, and defend other machines, while humans supervise a contest unfolding at speeds no human security team could match.


Why the CIA Went Shopping in Silicon Valley


The story of IQT begins in 1999, when the Central Intelligence Agency confronted a problem that would become increasingly familiar across government. Some of the most important advances in information technology were no longer coming primarily from government research programs. They were coming from commercial technology companies, many of them small, venture backed, and moving at Silicon Valley speed.


CIA

Government acquisition was not built for that environment. A startup might develop a new technology, raise several rounds of capital, enter a market, and completely redesign its product before a conventional procurement process had finished evaluating the first version. The CIA needed a way to engage with emerging companies much earlier.


The solution was unconventional. Rather than build another internal government technology office, the intelligence community helped create an independent nonprofit investment organization that could operate inside the commercial technology ecosystem. The organization soon became known as In Q Tel. It opened a Silicon Valley presence and began building relationships with founders, venture investors, researchers, and technology companies.


The idea was simple but radical. If the government could not always invent the technology it needed, it should become better at discovering the people who were inventing it. Over time, that mission expanded. IQT began working with more government partners and moved into technology areas far beyond its original emphasis on information technology. Today its interests span cybersecurity, artificial intelligence, space, biotechnology, advanced computing, microelectronics, quantum technology, energy, and other strategic fields.


This evolution reflects a much larger change in the meaning of national security. A generation ago, the phrase might have brought to mind weapons systems, intelligence satellites, and military hardware. Today it also includes software supply chains, cloud infrastructure, semiconductor manufacturing, communications networks, industrial systems, biotechnology, and data. A vulnerability in any of these areas can become a national vulnerability.


A Venture Firm That Is Not Quite a Venture Firm


IQT looks familiar enough from the outside. It evaluates startups, meets founders, studies markets, and makes investments. Yet its model differs from a traditional venture firm because financial performance is not the only objective. The larger purpose is to identify commercially promising technologies that could also solve problems faced by government agencies.


That dual requirement matters. A company that depends entirely on one government customer can struggle to grow. IQT therefore has an incentive to find technologies that have strong commercial markets as well as national security applications. The strongest candidates are often companies that would have become successful businesses even without government demand.


The organization can also work with companies to adapt existing commercial technologies for government missions. A product designed for Fortune 500 enterprises may be extremely capable, but an intelligence agency or national security organization may need different security controls, deployment models, data handling capabilities, or operating environments. IQT can help connect those requirements with the company developing the technology.


This is one of the most interesting themes running through Gray’s interview. The difficult part is often not identifying impressive technology. Silicon Valley produces plenty of that. The more difficult task is understanding which technologies solve real operational problems.


National security users may have requirements that commercial founders have never encountered. They may operate in disconnected networks, hostile environments, restricted computing systems, or situations where reliability matters more than convenience. A product that works beautifully inside a corporate data center may need substantial changes before it can perform in those environments.

In this sense, IQT does more than invest capital. It translates between two cultures that speak different languages. Startups think about products, customers, market size, and growth. Government agencies think about missions, threats, resilience, and strategic consequences. IQT sits somewhere in the middle.


Keyhole and the Reinvention of the Map


One of the clearest examples of the IQT model came early in its history with an investment in Keyhole, a company developing a three dimensional visualization platform called EarthViewer. Today, navigating an interactive digital globe seems completely ordinary. Satellite imagery is available on every smartphone. Zooming from a view of the planet down to an individual neighborhood takes seconds. In the early 2000s, however, the experience was extraordinary.


EarthViewer allowed users to navigate huge collections of satellite imagery and geographic data through an intuitive visual interface. For intelligence analysts, this represented much more than a convenient mapping tool. It provided a faster way to understand location, terrain, infrastructure, and events through a visual environment.


The technology quickly demonstrated its national security value. Government users could explore imagery in ways that had previously required much more specialized systems. At the same time, Keyhole was not merely a government contractor. The technology had obvious commercial applications in media, transportation, real estate, travel, and other industries.


Google Earth
Photo courtesy of Alphabet

Google acquired Keyhole in 2004. Its technology became the foundation for Google Earth.

The story is remarkable because it illustrates the basic philosophy behind dual use investing. A technology can simultaneously be useful to intelligence agencies and millions of ordinary consumers. National security innovation does not always arrive in the shape of a missile or military vehicle. Sometimes it arrives as a better interface.


FireEye and the Beginning of a Different Cyber War


A second example came from cybersecurity. IQT invested in FireEye when the company was developing technology designed to detect advanced malware and attacks that conventional security systems could miss. Traditional antivirus tools relied heavily on identifying known malicious signatures. That approach becomes less effective when attackers create new malware specifically designed to evade existing defenses.


FireEye took a different approach. Suspicious activity could be examined inside controlled virtual environments where software behavior could be observed. Rather than asking only whether a piece of code matched something already known to be dangerous, defenders could study what the software actually attempted to do.


That concept became increasingly important as cyberattacks became more sophisticated. Attackers were no longer simply sending obvious viruses across the internet. They were targeting specific organizations, exploiting previously unknown vulnerabilities, moving quietly through networks, and developing techniques designed to avoid detection.


The significance for national security was obvious. Governments, military systems, financial networks, telecommunications companies, energy infrastructure, and intelligence organizations all depended increasingly on software. Protecting software was becoming inseparable from protecting the institutions that depended on it.


Gray’s own career at IQT has unfolded against this transformation. Cybersecurity is no longer merely an information technology concern. It has become part of the architecture of national resilience. A successful attack on a corporate website may be inconvenient. A successful attack on an electrical grid, communications network, transportation system, satellite infrastructure, or defense network can have consequences far beyond the digital world. The cyber domain has effectively become another terrain on which nations compete.


Anduril and the Return of the Defense Startup


A third IQT investment illustrates how far the Silicon Valley and national security relationship has evolved. Anduril Industries emerged as part of a new generation of defense technology companies built much more like Silicon Valley startups than traditional defense contractors. The company develops autonomous systems, sensors, artificial intelligence software, and other technologies for defense and security missions.


Its business model reflects a broader change in the industry. Traditional defense companies often develop technologies in response to detailed government requirements. Newer defense startups increasingly take a different approach. They raise private capital, build products rapidly, iterate independently, and then bring those capabilities to government customers.



This approach is familiar in commercial technology. It is relatively new in defense. The rise of companies such as Anduril demonstrates how much the economics of national security technology have changed. Venture investors who once considered government markets too slow or complicated now view defense technology as one of the most important emerging areas in the startup ecosystem.


The reasons extend well beyond geopolitics. Modern defense increasingly depends on the same technologies driving commercial innovation: artificial intelligence, robotics, computer vision, autonomous systems, cloud computing, cybersecurity, satellite networks, and advanced semiconductors. Silicon Valley no longer sits outside the national security system. In important ways, it has become part of it.


Cybersecurity Enters the Age of Artificial Intelligence


That convergence is particularly visible in cybersecurity. During her Silicon Valley Unplugged conversation, Gray discusses a security environment changing rapidly under the influence of artificial intelligence. The implications go far beyond adding a chatbot to a cybersecurity product.


Artificial intelligence changes the economics of both attack and defense. An attacker once needed people to conduct reconnaissance, study software systems, create convincing phishing messages, search for vulnerabilities, and develop attack strategies. Artificial intelligence can increasingly assist with each of those tasks. It can generate code, summarize technical documentation, inspect systems, adapt messages to specific targets, and automate portions of an operation. That means relatively small groups may eventually achieve capabilities that once required much larger teams.


Cybersecurity Enters the Age of Artificial Intelligence
Photo courtesy of In-Q-Tel

Defenders are gaining similar advantages. Security systems can use artificial intelligence to investigate alerts, classify suspicious activity, analyze enormous volumes of logs, examine code, identify unusual network behavior, and recommend responses. The important question is what happens when both sides automate simultaneously.


Cybersecurity may begin to resemble a contest between agents. An attacking system discovers a vulnerability. A defending system detects unusual behavior. Another defensive agent isolates a device. An attacking agent changes tactics. A security agent analyzes the change and adjusts policy. Much of this interaction could occur before a human operator fully understands what has happened. That possibility changes the basic tempo of cybersecurity.


Human Speed Will Not Be Enough


For decades, cybersecurity has suffered from an overwhelming volume problem. Large organizations generate enormous numbers of security alerts. Analysts must determine which ones represent genuine attacks and which are harmless anomalies.


The problem is not simply detecting suspicious activity. It is deciding what deserves attention.

Artificial intelligence could fundamentally change that process. Instead of human analysts manually reviewing thousands of alerts, autonomous systems could perform the initial investigation, gather evidence, connect related events, and escalate only the cases requiring human judgment. The security operations center of the future may therefore look very different from the one we know today.


Human analysts will not disappear. Their responsibilities will become more strategic. They will determine policy, evaluate ambiguous threats, supervise autonomous systems, authorize consequential responses, and investigate situations where context matters more than pattern recognition. Machines will handle more of the volume.


The reason is unavoidable. If attackers operate at machine speed, defenders eventually must as well.

Waiting several hours for a human analyst to inspect an alert may be unacceptable when an automated adversary can scan thousands of systems, identify an opening, move laterally through a network, and exfiltrate information in minutes. Cyber defense becomes a problem of reaction time.


When AI Writes the Software and AI Attacks It


There is another complication that receives less attention. Artificial intelligence will not only attack and defend software. It will increasingly create software. AI coding tools are already changing how developers work. As those systems improve, the quantity of software produced by organizations could increase dramatically. Applications will be created faster. Internal tools will multiply. Integrations will become easier to generate. Code will change more frequently.


Every new application potentially creates another surface that must be secured. This produces a strange future in which artificial intelligence may write enormous amounts of software, artificial intelligence may search that software for weaknesses, and other artificial intelligence systems may defend it.


The cybersecurity industry will need to adapt to this expanding scale. Security testing may become continuous rather than periodic. Software could be examined automatically while it is being generated. Systems may constantly search themselves for misconfigurations and vulnerabilities. Defensive agents may simulate attacks before adversaries have the opportunity to try them. Cybersecurity, in other words, may shift from something organizations perform on their technology to something embedded continuously inside the technology itself.


The Physical World Becomes Cyber Territory


The most serious implications appear when software connects directly to physical systems. Modern cities depend on digital networks. Power grids, water systems, hospitals, factories, transportation networks, communications infrastructure, and satellites all rely increasingly on software.

This means cyber risk no longer ends at the screen.


A compromised industrial system can interrupt production. A compromised hospital network can delay patient care. A compromised communications network can disrupt emergency services. A compromised satellite can affect navigation, financial transactions, agriculture, logistics, intelligence collection, and military operations. The boundary between cybersecurity and physical security is becoming increasingly artificial.


Future cybersecurity strategies will therefore focus not only on preventing intrusions but also on resilience. The most important question may not be whether an attacker can enter a system. Given enough time and resources, sophisticated attackers may eventually succeed.


The more important question is what happens next. Can the network isolate the compromised section? Can essential services continue operating? Can the system restore itself? Can the organization detect the attack before it spreads? Can critical functions survive even when individual components fail?

A perfectly secure system may be impossible. A resilient system is achievable.


National Security Becomes a Startup Problem


This brings Gray’s Silicon Valley Unplugged conversation back to its central idea. The United States government cannot build every technology required for future national security. Neither can large defense contractors. Neither can Silicon Valley startups.


The challenge is too broad. Cybersecurity alone touches almost every modern industry. Artificial intelligence will expand that complexity. Space infrastructure, autonomous systems, biotechnology, semiconductors, energy technology, and quantum computing will create additional strategic dependencies.


The future will therefore depend increasingly on collaboration among organizations that historically operated separately. Government agencies understand national missions and threats. Startups move quickly and experiment aggressively. Universities produce scientific breakthroughs. Venture investors provide capital and help scale companies. Established technology firms provide infrastructure and global reach.



Organizations such as IQT exist because those communities need translators. A founder developing a new cybersecurity technology may initially believe she is simply building a better enterprise product. A national security organization may look at the same technology and see a capability that could protect critical infrastructure or intelligence systems. Neither perspective is wrong. The most important technologies increasingly belong to both worlds.


The Next National Security Company May Not Know It Yet


There is something distinctly Silicon Valley about the idea behind IQT. Somewhere right now, a handful of engineers may be building a product that appears to serve a narrow commercial market. They may be working from a small office, sharing desks, rewriting code late at night, and trying desperately to find their first customers. They may have no idea that the technology they are developing could eventually become strategically important.


Keyhole began with a new way to visualize the Earth and eventually became the foundation of Google Earth.


FireEye developed new methods for finding sophisticated malware and became part of a much larger transformation in cyber defense.


Anduril embraced the startup model for autonomous defense technology and helped accelerate the return of venture capital to national security.


There will be others.


The next important cybersecurity company may currently consist of five engineers and a prototype. The next intelligence platform may begin as a commercial analytics tool. The next critical infrastructure technology may emerge from a startup whose founders have never spoken with anyone in Washington.

That possibility explains why IQT remains such an unusual and important presence inside the technology ecosystem.


It is making a long term bet that national security increasingly depends on finding innovation before everyone realizes how important it is.


Katie Gray’s work places cybersecurity directly inside that mission. As artificial intelligence accelerates software development, cyberattacks, and cyber defense, the struggle to protect digital infrastructure will become faster, more automated, and more closely connected to the physical world.


The cyber front line will not exist in one place. It will run through data centers, factories, satellites, power grids, hospitals, government networks, startups, and the devices people use every day. And some of the technologies that will defend that world are almost certainly being built in Silicon Valley right now.

Comments


Upcoming Events

  • TALENT TAIWAN Silicon Valley Branch Opening Ceremony
    TALENT TAIWAN Silicon Valley Branch Opening Ceremony
    Fri, Sep 25
    TALENT TAIWAN Silicon Valley Branch
    Taiwan is bringing its global talent initiative to Silicon Valley. Join us in Palo Alto for the TALENT TAIWAN Silicon Valley Branch Opening Ceremony, welcoming leaders from government, technology, business, investment, academia, global mobility, media, and the broader Bay Area community.
  • Joy & Sorrow Short Films @ 2026 Human vs. AI Film Premiere
    Joy & Sorrow Short Films @ 2026 Human vs. AI Film Premiere
    Membership Offer
    Sat, Sep 26
    Delancey Street Screening Room
    Experience the highs and lows of Joy & Sorrow through a collection of short films designed to make you laugh, smile, reflect, and maybe even cry. Watch without knowing whether each film was created by a human filmmaker or with AI, and see for yourself which stories move you most.
  • Intensity & Serenity Short Films @ 2026 Human vs. AI Film Premiere
    Intensity & Serenity Short Films @ 2026 Human vs. AI Film Premiere
    Membership Offer
    Sat, Sep 26
    Delancey Street Screening Room
    Experience the powerful contrast between Intensity & Serenity through short films filled with tension, fear, anger, calm, and release. Watch how human filmmakers and AI bring these emotions to life, and decide for yourself which stories affect you most.

More Articles

Get Latest Tech News & Events

Thanks for submitting!

bottom of page