August 6, 2026, 8:34 a.m. (JST)
[Japan] On July 28, 2026, KELA held a press briefing to discuss the progress of ULTRA RED’s business and organizational structure in the Japanese market, as well as global threat trends, the existing strengths of ULTRA RED, and the direction of its evolution as an AI-powered CTEM (Continuous Threat Exposure Management) solution.The company also highlighted the strengths of the AI-Powered CTEM (Continuous Threat Exposure Management), AI Scanner, H1VE, Crimson, and Active Cyber Readiness Dashboard, which are being launched in the Japanese market.On the day of the event, Eran Shtauber, CEO of ULTRA RED, visited Japan to provide an overview of the future development of the company’s external cyber defense platform, centered on AI-Powered CTEM.

Tripling
Business Scale in Three Years Implementing Five Growth Strategies
Under its company structure, the KELA Group consists of three companies—KELA Research & Strategy, UltraRed, and Sling—as well as the regional subsidiary KELA. In Japan and the APAC region, KELA integrates the solutions of all group companies and delivers them to the market.

KELA was founded in 2009 and completed its comprehensive cyber threat intelligence platform in 2015.In 2019, the company established its Japanese subsidiary, launched the proactive cyber defense solution “UltraRed,” and has been offering the monitoring service “Sling” since 2022. This marked the first growth phase, during which the company had just under 20 employees; however, it experienced significant growth by securing government-related business.
The years 2025 and 2026 mark the second growth phase, during which the company launched “C2 Hunting,” an initiative that utilizes AI agents and threat intelligence to proactively detect and investigate threats.Furthermore, the company is strengthening its initiatives utilizing active cyber solutions, such as launching an ACD (Active Cyber Defense) package and an AI-powered CTEM.
Looking ahead, the company aims to triple its business scale over the next three years, through the end of 2028. It cited a 30% year-over-year growth in new orders and an 80% share of renewal contracts as key targets. Mr. Hirokawa expressed his determination to achieve industry-leading growth.He also outlined plans to expand and strengthen the organization, increasing headcount from the current level of 20 to 50 and expanding the partner network from 13 to more than 50 companies. Through these efforts, the company aims to become the leading ACD vendor.
To achieve this, the company will implement five growth strategies. The first is to focus on strategic customers and large-scale projects to establish a track record of success. The second is to scale the partner business while revitalizing existing partners and developing new ones.Third, the company aims to generate demand and increase the number of deals fivefold within one year through marketing, SDRs, and partner collaboration.Fourth, the company will strengthen its organizational capabilities by recruiting and developing top talent. Fifth, it will establish a highly efficient business model as a leading cybersecurity company and seek to expand collaboration with more customers, partners, and industry groups.
The Rules of Cyber Defense Are Being Turned
Upside Down Launching the CTEM Platform Product Suite Leveraging AI
Currently, AI is making cyberattacks faster and less costly, dramatically accelerating their pace. Attackers can now discover and exploit an organization’s threat exposure on an unprecedented scale.Furthermore, new digital assets, identities, and attack surfaces are now being generated more easily. In addition, guidelines from governments and regulatory authorities are reportedly shifting toward continuous cyber resilience.
KELA plans to enhance the AI capabilities of ULTRA RED, Ltd.’s CTEM platform to further advance its automated verification and threat exposure detection capabilities.At the same time, it will launch “H1VE,” which provides deception technology, and “CRIMSON,” which enables fully or semi-automated remediation of detected risks, in the Japanese market.
This evolution will result in an “AI-Powered CTEM” solution that provides end-to-end support—from detecting and analyzing the latest cyber threats to verifying and prioritizing threat exposure, and finally remediating them.“H1VE” provides a deep understanding of attacks and attackers, while “ULTRA RED” identifies and verifies potential threats. Finally, “CRIMSON” executes automated remediation.
“H1VE” understands attackers and safely guides
them away Integrated AI Defense Platform “CRIMSON”
As part of enhanced AI capabilities, the AI Scanner—building on the definitive verification provided by the Vector Scanner—stores information gathered during scans and past verification results to reconstruct application configurations, authentication flows, and hidden paths.The Vector Scanner continuously performs daily scheduled scans for all threats under audit. The AI Scanner accurately guides more detailed investigations, provides feedback on new attack paths, and performs definitive verification.As a result, the system goes beyond simply proving a single vulnerability; the AI infers and explores multi-step vulnerability paths, and ultimately determines the presence or absence of a threat based on evidence collected by the Vector Scanner.
H1VE is a deception platform that enables the easy deployment and centralized management of “decoys”—simulations of real applications and systems—to safely lure actual attackers.It observes attacks on these lures—which are isolated from the customer’s live environment—in real time and transforms the attacker’s IP address, payload, attack methods, C2 infrastructure, and other data into actionable threat intelligence.Furthermore, by integrating the acquired intelligence with ULTRA RED’s CTEM platform, it detects and verifies whether assets within the organization are vulnerable to similar attacks.
CRIMSON is an integrated AI defense platform capable of agentless, AI-driven dynamic automatic recovery. For threat exposures detected and verified by ULTRA RED’s CTEM platform, it executes remediation, correction, and mitigation measures either automatically or following approval by a responsible party.In addition to generating patch code and pull requests in conjunction with code repositories, the platform rapidly reduces risk by applying rules to WAFs and firewalls to block attack vectors when permanent fixes take time to implement. Once applied, the CTEM platform continuously verifies the effectiveness of these measures.
Pricing is to be determined, and the service is scheduled to launch in the second half of 2026.
The company has launched the “Active Cyber Readiness Dashboard” (hereinafter “ACRD”), an active cyber management dashboard announced on March 17.ACRD is a dashboard designed for executives that integrates information across three strategic areas—“Cyber Threat Intelligence” (hereinafter “CTI”), “CTEM,” and “Third-Party Risk Management”—enabling senior management to gain a comprehensive overview of their organization’s cyber risks and the status of countermeasures.





















