CaseStudies.Chat
← Back to the archive
change.archi2017–2019 · tech

OneLogin rebuilt after a data breach — revenue doubled and it raised $100M

After a 2017 breach exposed client data, CEO Brad Brooks rebuilt OneLogin around unified access management — revenue doubled and a $100M round followed.

What was changed

In mid-2017, OneLogin — an access management security company — suffered a serious AWS breach that exposed client data and drove out a number of employees. Brad Brooks, a Microsoft veteran and former chief of marketing, product and engineering at DocuSign, took over as CEO just a few months later. He recalled the choice facing the company: 'Are you going to shut this thing down and sell it or are you going to make a go of it?' The recovery started with short-term wins, because 'the pipeline had completely dried up' — customers hadn't left, but they stopped expanding their use of the product.

About a year later the company launched new 'unified access management' software combining single sign-on and multi-factor authentication that companies can set to their own security requirements. Brooks positioned the differentiator as scope: not just cloud applications but 'access to everything, whether it's walking through the front door to your business in the morning, to your enterprise applications, to your cloud applications' — against giants like Microsoft and rivals like Duo. Okta's well-performing 2017 IPO, he noted, validated the market's size.

Having started in SMB and born-in-the-cloud accounts, OneLogin pivoted to much larger enterprise customers about 18–19 months before the funding. Brooks said the company had 70+ customers paying well above $100,000 in ARR and revenue up 100% year-over-year from Q4 2017 to Q4 2018, partly on upsells. The $100 million growth round was led by new investor Greenspring Associates with CRV and Scale Venture Partners participating, bringing total known funding above $170 million and, by Brooks' run-rate math, at least three years before another raise.

Why it worked

The breach had frozen expansion, so recovery was sequenced around short-term wins rather than a rebrand or a discounting spree.

The product pivot gave the company a differentiated thesis — unified access across physical doors, on-premise apps and cloud apps — instead of competing feature-for-feature with Okta.

Moving upmarket to enterprise accounts raised contract sizes precisely when credibility needed rebuilding.

It raised $100 million while revenue was doubling, buying three years of runway against deep-pocketed security competitors.

What can be applied

A security company can survive its own breach if it converts the crisis into a product thesis: rebuild access management as the umbrella for everything, then chase enterprise contracts.

Aftermath

With the new capital, OneLogin planned to open new offices and pursue private- and public-sector clients, leveraging an already significant European presence. Brooks said the company's run rate meant it would not need to raise again for at least three years.

Sources

  1. OneLogin Solidifies Comeback With $100 Million ↗