Cybersecurity firm Deepwatch has laid off between 60 and 80 employees, representing a significant portion of its workforce, as part of a strategic restructuring to prioritize investments in artificial intelligence and automation. The company cited the need to accelerate its AI initiatives as the primary reason for the job cuts, reflecting a broader industry trend where cybersecurity vendors are increasingly leveraging advanced technologies for threat detection and response. This move follows a period of rapid growth and substantial funding, but also comes amid ongoing challenges in maintaining profitability and operational efficiency.
The layoffs at Deepwatch are part of a wider pattern in the cybersecurity sector, with other firms such as Axonius also announcing substantial staff reductions to sharpen their focus on AI-driven solutions. Deepwatch's CEO emphasized the company's commitment to evolving its business model to stay competitive in a rapidly changing threat landscape. While these changes are intended to enhance technological capabilities, they have raised concerns about the impact on the cybersecurity workforce and the long-term implications for talent retention in the industry.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
In November 2025, Axonius reduced its workforce by just under 100 employees, about 11% of staff. The company said the layoffs were intended to sharpen its focus and position the business for future growth despite recent expansion and funding.
In November 2025, Deepwatch laid off an estimated 60 to 80 employees, a double-digit share of its roughly 250-person workforce. The company said the cuts were part of a strategic realignment to accelerate investment in AI and automation amid financial and market challenges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.