Deep dive
Company Spotlight: CounterCraft
Alberto Gómez
Founding Partner
August 13, 2025
Min read

Attackers reveal more when they believe nobody is watching

Most security tools observe activity around real systems. That creates a difficult trade off: defenders need enough evidence to understand an attacker, but the longer an intruder remains near a genuine asset, the greater the risk. Alerts also arrive with uneven context, leaving a security team to decide whether a signal is routine noise or the beginning of a targeted operation.

Deception changes the environment. If an attacker interacts with a system, identity or document that has no legitimate user, the signal is immediately meaningful. The defender can observe the adversary’s behaviour in a controlled setting and learn what they are trying to reach before a production system becomes the place where that discovery happens.

Turning deception into threat intelligence

CounterCraft deploys realistic decoys and lures across IT and operational technology environments. These assets are designed to look relevant to an adversary while remaining isolated from the organisation’s critical systems. When someone interacts with them, CounterCraft captures the techniques, tools and movement behind the activity and turns that evidence into specific threat intelligence.

Its platform can support use cases including ransomware, lateral movement, insider threats and targeted intrusion. It also connects with existing security workflows so intelligence gathered through deception can inform investigation and response. The result is a form of threat intelligence generated by the adversary’s own actions inside an environment built by the defender.

Built for organisations with high consequence risks

CounterCraft is headquartered in San Sebastián and operates internationally, with teams and offices serving customers in Europe, the Middle East and Asia. Governments, national security organisations, critical infrastructure operators and large enterprises use the platform, alongside customers in sectors such as financial services, energy, manufacturing and healthcare.

The company has continued to deepen its work with government and defence customers while building commercial partnerships in multiple markets. That breadth reflects a product designed for adversaries who adapt their behaviour and for environments where generic indicators are rarely enough.

Three founders from the cybersecurity front line

David Barroso founded CounterCraft in 2015 and serves as its CEO. He previously helped establish Telefónica’s ElevenPaths cybersecurity business and led cybercrime work at S21sec. The leadership team now also includes Matt Gunston as Chief Financial Officer and Chief Operating Officer, alongside specialists covering product, operations, infrastructure and international sales.

When we invested, and what followed

We first backed CounterCraft in 2016. In 2020, we led a further $5 million round joined by new investors eCAPITAL and Elewit, with participation from existing investors Evolution Equity Partners, ORZA and Wayra. The funding supported product development and expansion with sophisticated enterprise and government customers in Europe, the Middle East and Asia.

Why we backed CounterCraft

CounterCraft gives defenders a way to shape the interaction rather than wait for an attacker to reveal themselves on a real asset. Its advantage comes from the realism of the deception environment, the quality of the behaviour it captures and the team’s ability to turn that behaviour into action. As attacks become faster and more automated, security teams need intelligence that is specific to the adversary in front of them. CounterCraft’s approach sits squarely within Trusted AI Infrastructure: systems that help critical organisations understand and trust what is happening across their digital environments.