OneLogin rebuilt after a data breach — revenue doubled and it raised $100M
After a 2017 breach exposed client data, CEO Brad Brooks rebuilt OneLogin around unified access management — revenue doubled and a $100M round followed.
What was changed
In mid-2017, OneLogin — an access management security company — suffered a serious AWS breach that exposed client data and drove out a number of employees. Brad Brooks, a Microsoft veteran and former chief of marketing, product and engineering at DocuSign, took over as CEO just a few months later. He recalled the choice facing the company: 'Are you going to shut this thing down and sell it or are you going to make a go of it?' The recovery started with short-term wins, because 'the pipeline had completely dried up' — customers hadn't left, but they stopped expanding their use of the product.
About a year later the company launched new 'unified access management' software combining single sign-on and multi-factor authentication that companies can set to their own security requirements. Brooks positioned the differentiator as scope: not just cloud applications but 'access to everything, whether it's walking through the front door to your business in the morning, to your enterprise applications, to your cloud applications' — against giants like Microsoft and rivals like Duo. Okta's well-performing 2017 IPO, he noted, validated the market's size.
Having started in SMB and born-in-the-cloud accounts, OneLogin pivoted to much larger enterprise customers about 18–19 months before the funding. Brooks said the company had 70+ customers paying well above $100,000 in ARR and revenue up 100% year-over-year from Q4 2017 to Q4 2018, partly on upsells. The $100 million growth round was led by new investor Greenspring Associates with CRV and Scale Venture Partners participating, bringing total known funding above $170 million and, by Brooks' run-rate math, at least three years before another raise.
Why it worked
The breach had frozen expansion, so recovery was sequenced around short-term wins rather than a rebrand or a discounting spree.
The product pivot gave the company a differentiated thesis — unified access across physical doors, on-premise apps and cloud apps — instead of competing feature-for-feature with Okta.
Moving upmarket to enterprise accounts raised contract sizes precisely when credibility needed rebuilding.
It raised $100 million while revenue was doubling, buying three years of runway against deep-pocketed security competitors.
What can be applied
A security company can survive its own breach if it converts the crisis into a product thesis: rebuild access management as the umbrella for everything, then chase enterprise contracts.
Aftermath
With the new capital, OneLogin planned to open new offices and pursue private- and public-sector clients, leveraging an already significant European presence. Brooks said the company's run rate meant it would not need to raise again for at least three years.