The annual penetration test is a snapshot of a system that, by the time the report is delivered, is already obsolete. For a CISO at a bank or an insurance firm, that snapshot is a compliance checkbox, not a real-time view of resilience. SignalFisher, a Swiss cybersecurity company founded in 2020, is building a product to replace that static picture with what it calls a live, intelligent security testing program [SignalFisher, October 2026].
The company's core offering, the Cyber Resilience Shield, is a subscription service that continuously probes an organization's external attack surface. It uses a combination of AI-driven automation and expert-led ethical hacking to find vulnerabilities as they emerge from new code deployments, cloud services, and third-party integrations [The Cyber Resilience Shield - Bug Bounty Switzerland, retrieved 2026]. The bet is that for regulated industries, the compliance need for documented security testing can be met not by a point-in-time audit, but by a constantly updated feed of risk data.
From Bug Bounties to a Scalable Shield
SignalFisher's roots are in the Swiss bug bounty scene, dating back to 2015 under its former name, Bug Bounty Switzerland [SignalFisher, October 2026]. The pivot from a service-oriented bug bounty platform to a "service-as-software" product was a deliberate move to scale. Co-founders Sandro Nafzger (CEO), Florian Badertscher (COO), and Lukas Heppler (CTO) led the transformation, aiming to productize the continuous testing model [Sandro Nafzger - Bug Bounty Switzerland | LinkedIn, retrieved 2026].
Nafzger's background is instructive. He previously ran the bug bounty program at Swiss Post, giving him direct experience with the operational cadence and reporting needs of a large, regulated entity [#18 Wenn Hacker plötzlich geliebt werden - mit Sandro Nafzger, retrieved 2026]. His public speaking, including a keynote at GISEC Global 2026 in Dubai, positions the company's vision within the broader industry shift toward intelligent, continuous security testing [Sandro Nafzger - Bug Bounty Switzerland | LinkedIn, retrieved 2026].
The Technical Wedge: Continuous Learning Over Snapshots
The product's technical differentiation rests on its architecture for continuous learning. Unlike a traditional penetration test that executes a predefined scope over a week, the Cyber Resilience Shield is designed to adapt its testing strategies as an organization's digital footprint changes. The platform claims to cover all asset types and testing methodologies, providing a unified view instead of forcing security teams to stitch together results from fragmented point solutions [Bug Bounty Switzerland becomes SignalFisher, retrieved 2026].
From an infrastructure perspective, the shift is from batch processing to stream processing. The company argues that modern attack surfaces evolve like a livestream, with every new software release or API endpoint creating a potential new vulnerability [A Photo From Yesterday Versus a Livestream, retrieved 2026]. The Shield's value is in mapping that stream in real time, which theoretically offers a more accurate and actionable risk posture than a photo from yesterday.
Funding and the Path to International Scale
In October 2026, SignalFisher announced a CHF 12 million (approximately $13.4 million) Series A financing round to fund international expansion [SignalFisher, October 2026]. The investors named in connection with the business are European growth equity firm Direttissima Growth Partners and listed private equity firm Deutsche Beteiligungs AG (DBAG), both of which focus on mid-market companies [SignalFisher]. This capital is earmarked for scaling the intelligent testing business beyond its Swiss and European base.
The company's target customer profile is clear: regulated enterprises in banking, finance, insurance, government, healthcare, and critical infrastructure [SignalFisher]. These are organizations for whom security testing is both a technical necessity and a regulatory requirement, creating a dual incentive to adopt a more continuous model.
| Co-Founder | Role | Notable Background |
|---|---|---|
| Sandro Nafzger | CEO | Former Head of Bug Bounty Program at Swiss Post; studied business informatics [#18 Wenn Hacker plötzlich geliebt werden, retrieved 2026]. |
| Florian Badertscher | COO | Co-led the company's transformation from service to scalable product [Sandro Nafzger - Bug Bounty Switzerland |
| Lukas Heppler | CTO | Leads the technical architecture for the continuous testing platform [Lukas Heppler - SignalFisher |
The Competitive and Operational Hurdles
SignalFisher is not operating in a vacuum. It lists competitors like GlitchSecure, Yogosha, and YesWeHack, which also blend crowdsourced security testing with platform tools. The company's answer is to focus less on crowdsourcing and more on the integrated, AI-driven program tailored for the compliance and risk reporting needs of large enterprises. Its rebrand from Bug Bounty Switzerland to SignalFisher underscores this shift from a marketplace model to a managed security program [SignalFisher, October 2026].
The most credible risk for SignalFisher is operational scaling. Delivering a truly continuous, expert-led service is people-intensive at its core, even with AI augmentation. The model requires maintaining a high-caliber security research team and ensuring the automated systems do not generate excessive false positives or miss subtle, complex chain vulnerabilities. The sales motion is also untested at a global scale; convincing a multinational bank's CISO to replace a known, auditable annual process with a new continuous subscription requires navigating lengthy procurement and proving tangible ROI beyond compliance.
The Next Twelve Months
The coming year will be a test of execution with the new Series A capital. Key milestones will be landing flagship customers in its target sectors outside the DACH region and demonstrating that the Cyber Resilience Shield can be deployed and managed efficiently for a distributed global enterprise. The company is also hiring, with an open role for a Software Engineer posted in 2026, indicating a build-out of the core platform [Software Engineer @ SignalFisher, retrieved 2026].
Technically, the system's success hinges on its learning feedback loop. The AI components must effectively prioritize findings, correlate vulnerabilities across assets, and adapt testing to new threat intelligence without human intervention for every configuration change. At scale, the platform's architecture must handle the data load from scanning hundreds of thousands of assets for dozens of clients without performance degradation or cost overruns.
The sober assessment is this: the concept of continuous security testing is sound, but the devil is in the sustained execution. SignalFisher's bet is that the regulatory and threat landscape has finally created a market willing to pay for a live feed. If the platform's automation is precise enough and its human experts scalable, it could define a new category. If the operational complexity or cost balloons, it risks becoming just another expensive, managed service. For now, the $13.4 million vote of confidence suggests investors believe the snapshot era is over.
Sources
- [SignalFisher, October 2026] SignalFisher Raises CHF 12 Million to Scale Intelligent Security Testing Internationally
- [SignalFisher, October 2026] Bug Bounty Switzerland becomes SignalFisher
- [The Cyber Resilience Shield - Bug Bounty Switzerland, retrieved 2026] The Cyber Resilience Shield - Bug Bounty Switzerland
- [Bug Bounty Switzerland becomes SignalFisher, retrieved 2026] Bug Bounty Switzerland becomes SignalFisher
- [A Photo From Yesterday Versus a Livestream, retrieved 2026] A Photo From Yesterday Versus a Livestream: With Helvetia Baloise at Insurers’ Day
- [Sandro Nafzger - Bug Bounty Switzerland | LinkedIn, retrieved 2026] Sandro Nafzger - Bug Bounty Switzerland | LinkedIn
- [#18 Wenn Hacker plötzlich geliebt werden, retrieved 2026] #18 Wenn Hacker plötzlich geliebt werden - mit Sandro Nafzger, Leiter des Bug Bounty Programms der Schweizerischen Post - InnoPodcast
- [Lukas Heppler - SignalFisher | LinkedIn, retrieved 2026] Lukas Heppler - SignalFisher | LinkedIn
- [Software Engineer @ SignalFisher, retrieved 2026] Software Engineer @ SignalFisher | https://jobs.ashbyhq.com/bug-bounty-switzerland/c712a9c3-d5cf-492b-ba1f-870bacc61aa3?embed=js