Cybersecurity M&A: what is happening now?

Last updated: 29 June 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity M&A: what is happening now? The market is in a real platform consolidation cycle, not just a normal run of scattered acquisitions.

The clearest pattern is acceleration. The tracked primary deal count doubled from 14 deals in the previous 12 months to 28 in the latest 12 months, while disclosed or reported value rose from about $43.3B to $82.7B.

The market is not being carried only by Google / Wiz or Palo Alto / CyberArk. Those are the headline peaks, but the same acceleration appears in mid-sized deals across AI security, identity, browser security, data security, MDR, telemetry, OT security and exposure management.

Buyers are paying up again, but not equally across the market. The richest prices are going to assets that can become control points inside larger security platforms: cloud security, identity, asset visibility, observability, OT security and AI-era data control.

AI security is now one of the main acquisition logics in cybersecurity. It does not show up only in pure AI security startups; it is also reshaping deals in identity, data security, browser security, SIEM, app security, cloud security and exposure management.

Identity has moved back to the center, but in a different way. Buyers are no longer only protecting employee login; they are trying to secure humans, machines, service accounts and AI agents across apps, data and cloud environments.

Cloud security remains a heavyweight category because Google / Wiz is the largest deal in the dataset. But the market has moved beyond a pure CNAPP story into a broader AI-era enterprise security stack.

Data security is suddenly more urgent because AI makes old governance problems feel operational and immediate. Enterprises now need to know where sensitive data sits, who can touch it, and what AI tools or agents can do with it.

Browser security is small but newly serious. Akamai / LayerX and CrowdStrike / Seraphic show that large buyers now see the browser session as a missing control point for SaaS, GenAI and agentic workflows.

Private equity is still present, especially in take-privates like Darktrace and Jamf, but strategic buyers are setting the pace. Google, Palo Alto Networks, ServiceNow, CrowdStrike, Zscaler, Accenture, Veeam, Proofpoint and others are buying because product gaps need to close quickly.

The practical conclusion is blunt: cybersecurity is still crowded, but it is not fragmenting endlessly. The largest platforms are buying the missing pieces, and that makes life harder for mid-sized standalone vendors unless they own a very sharp category position.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

What are all the latest deals and acquisitions in cybersecurity M&A?

When we look at all the M&A deals in cybersecurity over the last 24 months, the market is clearly in a heavy consolidation phase, with the largest buyers moving across cloud security, identity, AI security, data security, exposure management, OT security, browser security and MDR.

Date Target Acquirer Value Strategic rationale Status and additional comment
Jun 2026 Dragos majority stake + runZero + NetRise Accenture ~$4.175B Build a larger OT cybersecurity platform across threat detection, exposure management, device security and software supply chain risk Announced / pending. Expected close by Sep 2026. Combined businesses expected to generate about $208M ARR
May 2026 LayerX Akamai ~$205M Extend Zero Trust into the browser, especially for SaaS, GenAI apps and AI agents Announced / pending. Expected Q3 2026
May 2026 Symmetry Systems Zscaler Undisclosed Improve data visibility and control when AI agents access enterprise data Announced / pending
Apr 2026 Quarkslab Airbus Undisclosed Strengthen advanced cyber research and sovereign defense cyber capabilities Announced / pending
Apr 2026 Ryft Cyera Undisclosed Broaden Cyera’s data security platform with AI and data workflow capabilities Announced / pending
Apr 2026 Portkey Palo Alto Networks Undisclosed Add AI application and agent security into Palo Alto’s platform Announced / pending
Apr 2026 Armis ServiceNow $7.75B Combine asset visibility, exposure management and cyber risk workflows Closed. Largest acquisition in ServiceNow’s history
Mar 2026 Wiz Google / Alphabet $32B Strengthen Google Cloud security across multicloud and AI-era cloud environments Closed. Largest deal in the 24-month cybersecurity M&A dataset
Mar 2026 Veza ServiceNow ~$1B reported Add AI-native identity security across apps, data, cloud and AI agents Closed. Official terms undisclosed
Feb 2026 CyberArk Palo Alto Networks ~$25B Make identity security a core platform pillar for human, machine and agentic identities Closed. One of the defining cybersecurity platform deals
Jan 2026 Jamf Francisco Partners $2.2B Take Apple device management and security vendor private Closed
Jan 2026 Chronosphere Palo Alto Networks $3.35B Connect observability, security operations and agentic remediation Closed
Jan 2026 Seraphic Security CrowdStrike ~$420M reported Turn any browser into a secure enterprise browser Announced
Jan 2026 SGNL CrowdStrike ~$740M reported Add continuous identity and real-time authorization Announced
Dec 2025 Securiti AI Veeam $1.725B Create a trusted data platform for AI, governance, recovery and security Closed
Dec 2025 Hornetsecurity Proofpoint $1.8B Expand Microsoft 365 security, compliance, data protection and security awareness Completed
Nov 2025 SPLX Zscaler Undisclosed Add AI asset discovery, automated red-teaming and AI governance Announced
Nov 2025 UpSight Security Arctic Wolf Undisclosed Strengthen endpoint and ransomware defense with predictive AI and rollback Announced
Nov 2025 Mayhem Security Bugcrowd Undisclosed Combine crowdsourced testing with automated application security testing Announced
Oct 2025 ThreatConnect Dataminr $290M Combine real-time event detection with threat intelligence and agentic AI workflows Announced
Oct 2025 Verosint Imprivata Undisclosed Add AI-powered risk intelligence to healthcare identity security Announced
Sep 2025 Pangea CrowdStrike ~$260M reported Create AI Detection and Response across the AI application lifecycle Announced
Sep 2025 Aim Security Cato Networks ~$300-350M reported Secure AI agents and AI applications inside Cato’s SASE cloud Announced. First acquisition ever for Cato
Sep 2025 Lakera Check Point ~$300M reported Build stronger AI security and create a Global Center of Excellence for AI Security Announced
Sep 2025 SlashNext Varonis $150M Add email and social engineering protection to managed data detection and response Announced
Aug 2025 Onum CrowdStrike ~$290M reported Strengthen Falcon Next-Gen SIEM with real-time telemetry pipeline management Announced
Aug 2025 Mira Security Darktrace Undisclosed Improve network visibility and encrypted traffic analysis Announced
Jul 2025 Red Canary Zscaler ~$675M reported Combine MDR, threat detection and exposure management Completed
Apr 2025 Protect AI Palo Alto Networks ~$650-700M reported Add AI model and AI application protection Announced
Feb 2025 Secureworks Sophos ~$859M Combine Sophos with Taegis MDR / XDR and create a larger MDR provider Closed
Feb 2025 Veriti Check Point Undisclosed Add automated exposure assessment and remediation Announced
Jan 2025 Zilla Security CyberArk ~$175M reported Add identity governance and administration to CyberArk’s platform Announced / completed
Jan 2025 Vulcan Cyber Tenable ~$147M reported Add exposure remediation and vulnerability prioritization workflows Announced / completed
Dec 2024 Recorded Future Mastercard $2.65B Expand threat intelligence and cybersecurity services beyond payments Closed
Dec 2024 Egress KnowBe4 Undisclosed Combine security awareness with adaptive email security Closed / announced
Oct 2024 Darktrace Thoma Bravo ~$5.3B Take AI cybersecurity leader private Closed
Oct 2024 Venafi CyberArk ~$1.54B Expand machine identity security and certificate lifecycle management Closed
Aug 2024 Lacework Fortinet Undisclosed Add CNAPP capabilities to Fortinet’s security platform Closed
Aug 2024 Trustwave LevelBlue Undisclosed Expand MDR, MSSP and security consulting capabilities Announced
Jul 2024 Aberrant 360 Advanced Undisclosed Expand cybersecurity and compliance services Announced
Jul 2024 Banyan Security SonicWall Undisclosed Add Zero Trust Network Access and secure access capabilities Announced

Is cybersecurity M&A still hot right now?

Cybersecurity M&A is still hot, and the last 12 months were materially more active than the 12 months before.

When we look at all the M&A deals in cybersecurity over the last 24 months, the tracked primary deal count moves from 14 deals in the previous 12 months to 28 deals in the latest 12 months. That is a clean 2.0x increase.

The broader market checks point in the same direction: SecurityWeek counted 426 cybersecurity M&A deals in 2025, including 334 pure-play cybersecurity deals, while Momentum Cyber tracked 400 M&A transactions and $96B deployed in 2025.

We also noticed that the buyer list changed in quality. In the latest period, we see Google, Palo Alto Networks, ServiceNow, CrowdStrike, Zscaler, Accenture, Veeam, Proofpoint, Akamai, Check Point and Cato all buying into strategic cyber categories. That tells us this is not a thin market where one or two buyers create the whole story.

Put simply, cybersecurity M&A is still running hot because multiple strategic buyers are trying to close platform gaps at the same time.

If you want more recent data on this point, please see our latest cybersecurity market report.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Is cybersecurity M&A accelerating now, or are we just noticing the big deals?

Cybersecurity M&A is really accelerating. The big deals make it visible, but they are not the only thing happening.

First, volume: 28 primary deals in the latest 12 months versus 14 before. Second, value: disclosed or reported value in the tracked dataset rises from $43.3B to $82.7B, which is about a 91% increase. Third, breadth: the latest period includes not only mega-deals, but also mid-sized acquisitions in AI security, browser security, identity, telemetry, MDR and data security.

There is also a monthly pattern. In the broader monthly counts captured for July 2025 to May 2026, we see 389 cybersecurity M&A deals across 11 captured months, or roughly 35 deals per month. October 2025 alone had 45 deals, July had 44, February 2026 had 42, and September had 40.

The market is not just being distorted by Google / Wiz or Palo Alto / CyberArk. Those deals are the visible peaks of a much broader acceleration.

Are cybersecurity buyers paying big prices again?

Cybersecurity buyers are paying big prices again, but mostly when the target can become a control point in a larger platform.

The strongest pricing clue is the return of mega-deals. In the previous 12 months, the dataset shows 4 deals above $1B. In the latest 12 months, that number jumps to 9. That is a major change because $1B-plus acquisitions are not normal tuck-ins; they usually mean the buyer sees the target as strategically difficult to replicate.

The multiples tell the same story. ServiceNow / Armis implies about 22.8x ARR using reported ARR above $340M. Palo Alto / Chronosphere implies about 20.9x ARR using reported ARR above $160M. Accenture’s Dragos-runZero-NetRise platform move implies about 20.1x ARR using the reported combined ARR of about $208M. These are not cheap multiples, and they are not being paid for random features. They are being paid for asset visibility, OT security, observability, exposure management and other layers that can anchor a broader security platform.

The smaller deal values create a useful contrast. CrowdStrike / Pangea, Akamai / LayerX, Check Point / Lakera, Cato / Aim Security and Varonis / SlashNext sit in the rough $150M to $420M zone where reported. These are important, but they are capability extensions. The highest prices are going to assets that can reshape the platform, not every attractive security startup.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Is AI security actually driving cybersecurity M&A now?

AI security is now one of the strongest drivers of cybersecurity M&A, and the pattern is much deeper than a few AI-branded deals.

In the dataset, deals with an AI security or AI-era rationale rise from 4 in the previous 12 months to 18 in the latest 12 months. That is a 4.5x increase. But the more interesting part is where AI shows up. It is not contained inside one clean “AI security” bucket. It appears in identity security, data security, browser security, SIEM, telemetry, cloud security, app security and exposure management.

Look at the pattern. CrowdStrike bought Pangea for AI Detection and Response, but it also bought SGNL for identity authorization and Seraphic for browser security. Zscaler bought SPLX for AI asset discovery and red-teaming, then Symmetry Systems for AI-era data access control. Check Point bought Lakera for AI security, while Cato bought Aim Security to secure AI agents inside SASE. Palo Alto bought Protect AI and later Portkey, which shows repeated interest in AI application and model protection.

The stronger interpretation is that AI has become a new acquisition logic across cybersecurity, not just a standalone category. Buyers are asking what happens when employees, developers, SaaS tools and autonomous agents start touching sensitive systems and data at scale. Once we frame it that way, the surge in identity, browser, data and AI app security acquisitions makes much more sense.

Is identity security becoming the center of cybersecurity M&A again?

Identity security is absolutely back at the center of cybersecurity M&A, but the reason has changed.

In the tracked deals, identity-related acquisitions move from 2 in the previous 12 months to 4 in the latest 12 months. On count alone, that is not the largest category. But on strategic importance, it is one of the clearest themes in the dataset. Palo Alto bought CyberArk for about $25B, ServiceNow bought Veza for about $1B reported, CrowdStrike bought SGNL for about $740M reported, and Imprivata bought Verosint to strengthen identity risk intelligence in healthcare.

The important detail is that buyers are no longer thinking only about employee login. CyberArk brings privileged access and machine identity depth. Veza adds identity visibility across apps, data and cloud. SGNL brings real-time authorization. Verosint adds identity risk intelligence for a regulated vertical. Together, these deals point to the same conclusion: identity is becoming the control plane for humans, machines, service accounts and AI agents.

That is why identity is showing up in so many different M&A stories. It connects cloud security, data security, SaaS security, healthcare security and AI security.

Identity is not “hot again” in the old IAM sense. It is being rebuilt for a world where non-human and agentic identities matter as much as employees.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Is cloud security still the main cybersecurity M&A battlefield?

Cloud security is still one of the main battlegrounds, but the market has moved beyond pure CNAPP consolidation.

The largest deal in the whole dataset is Google buying Wiz for $32B, so cloud security obviously remains central. Fortinet also bought Lacework in the previous period, which adds another CNAPP signal. Palo Alto’s Protect AI deal also sits close to cloud and AI workload protection, even if its rationale is more AI application and model security than classic CNAPP.

But the deal mix changed after that. In the latest 12 months, the strongest repeated themes are identity, AI security, data security, exposure management, browser security, OT security and security operations. ServiceNow / Armis is about asset and exposure visibility across IT, OT, IoT, medical devices, code and cloud. Veeam / Securiti AI is about trusted data for AI. Accenture / Dragos-runZero-NetRise is about industrial security, not cloud-native app protection.

The conclusion is simple enough: cloud security remains a heavyweight M&A category, but it is no longer the whole story. Cybersecurity M&A has shifted from “secure the cloud” to “secure the AI-era enterprise,” which includes cloud, data, identity, browser sessions, agents, assets and industrial systems.

Is data security suddenly important again?

Data security is moving again because AI turned a slow governance problem into an urgent security problem.

The tracked dataset shows 3 data security / DSPM deals in the latest 12 months versus zero in the previous 12 months. Veeam bought Securiti AI for $1.725B. Zscaler bought Symmetry Systems. Cyera bought Ryft. The count is small, but the direction is very clear because all three deals sit around the same problem: enterprises need to know where sensitive data is, who can access it and what AI systems can do with it.

The Veeam deal is especially useful because it links backup, recovery, governance and security.

That is not a traditional “backup company buys security feature” story. It says cyber resilience and AI data governance are converging. Zscaler and Cyera point to the same underlying issue from another direction: access to sensitive data becomes much harder to control when AI agents, SaaS tools and cloud apps all interact with it.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Are browser security deals becoming real now?

Browser security has become a real cybersecurity M&A theme, even if it is still smaller than cloud or identity.

Two recent deals make the point. Akamai agreed to buy LayerX for around $205M, and CrowdStrike agreed to buy Seraphic Security for around $420M reported. Both targets focus on browser security. That is too specific to dismiss as noise, especially because the buyers are large strategic vendors, not niche acquirers.

The practical reason is obvious once you look at how people now work. Employees spend more and more time inside SaaS apps, collaboration tools and GenAI products, and much of that happens through the browser. Identity tools can decide who gets access. Endpoint tools can secure the device. Network tools can inspect traffic. But the browser session itself is becoming a security surface, especially when users copy data into AI tools, authorize apps or interact with risky web content.

Browser security is moving from “interesting niche” to “missing platform control.”

The deal sizes are not enormous, but the strategic logic is strong. Buyers are preparing for a world where the browser becomes the front door to enterprise AI usage.

Are cybersecurity acquirers buying startups or assembling platforms?

Cybersecurity acquirers are assembling platforms, and the best evidence is the repeat-buyer pattern.

Palo Alto is the clearest case. It bought CyberArk for identity, Chronosphere for observability and agentic remediation, Protect AI for AI model and application protection, and Portkey for AI application security. CrowdStrike bought SGNL, Seraphic, Pangea and Onum across identity, browser security, AI security and telemetry. ServiceNow bought Armis and Veza to pull cyber exposure and identity into security, risk and workflow operations. Zscaler bought Red Canary, SPLX and Symmetry Systems across MDR, AI security and data security.

The acquisitions are not random. Each buyer is filling adjacent gaps around an existing control plane. Palo Alto is pushing platformization. CrowdStrike is extending Falcon beyond endpoint into identity, browser, AI and telemetry. ServiceNow is making cyber operational inside enterprise workflows. Zscaler is adding threat management, AI security and data controls around Zero Trust.

The main cybersecurity M&A story is not startup shopping. It is platform architecture. The leading buyers are deciding which layers they need to own before AI and agentic workflows reshape enterprise security budgets.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Are managed security and MDR still attractive now?

Managed security and MDR are still attractive, but only when they connect to a broader security operating model.

The dataset shows MDR / SecOps-related deals rising from 1 in the previous 12 months to 3 in the latest 12 months. Sophos bought Secureworks for about $859M to build a larger MDR / XDR provider around Taegis and Sophos. Zscaler bought Red Canary for around $675M reported to connect threat detection, MDR and exposure management. Arctic Wolf bought UpSight Security to strengthen endpoint and ransomware defense with predictive AI and rollback.

It looks like buyers are buying MDR when it brings a platform advantage: threat telemetry, automation, response workflows, exposure context, endpoint rollback or AI-driven operations. That is why Red Canary matters for Zscaler, and why Secureworks matters for Sophos.

MDR is not dead, but plain vanilla MDR is less exciting than MDR connected to automation and platform data. The category still gets acquired, but the best assets are the ones that make the buyer’s broader security engine smarter.

Is OT cybersecurity becoming a bigger M&A target now?

OT cybersecurity is becoming a much bigger M&A target, and Accenture’s move makes that hard to ignore.

The biggest OT signal is Accenture’s June 2026 move: a majority stake in Dragos plus acquisitions of runZero and NetRise, with a combined value around $4.175B. That is not a small consulting bolt-on. It combines OT threat detection, exposure assessment, device security and software supply chain security into one industrial cyber platform. The reported combined ARR of about $208M also suggests this was bought as a serious software and platform asset, not just as a services capability.

There are supporting clues around the edges. Airbus buying Quarkslab points to defense and sovereign cyber capability. ServiceNow buying Armis also touches OT, IoT and medical device exposure, not just classic IT assets. These deals tell us buyers are widening their view of cybersecurity from laptops, servers and cloud workloads to factories, utilities, devices, hospitals and connected infrastructure.

OT security is becoming more strategic because the risk is physical. A cloud breach is serious, but an industrial system breach can affect production, energy, transport or public safety.

That gives OT cybersecurity a different urgency, and the M&A data now reflects it.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Are private equity buyers still shaping cybersecurity M&A?

Private equity is still important, but strategic buyers are clearly setting the direction right now.

The previous period had a very visible PE signal with Thoma Bravo taking Darktrace private for around $5.3B. The latest period still includes Francisco Partners taking Jamf private for $2.2B. Those are meaningful transactions, and they show that PE still likes cybersecurity assets with recurring revenue, operational upside and category depth.

But the center of gravity has shifted toward strategic buyers. Google bought Wiz. Palo Alto bought CyberArk and Chronosphere. ServiceNow bought Armis and Veza. CrowdStrike bought SGNL, Seraphic, Pangea and Onum. Zscaler bought Red Canary, SPLX and Symmetry Systems. Accenture made a major OT cyber platform move. Veeam bought Securiti AI. Proofpoint bought Hornetsecurity.

Private equity still participates, but it is not defining the current cycle. Strategic buyers are doing that because they need product depth quickly. Overall, cybersecurity M&A is being shaped less by financial engineering and more by product-market urgency around AI, identity, data, cloud and exposure.

Is the cybersecurity M&A market becoming more concentrated?

Cybersecurity M&A is becoming more concentrated around a small group of platform buyers, even while the total number of deals remains broad.

The repeat-buyer pattern is strong. Palo Alto appears several times. CrowdStrike appears several times. ServiceNow appears multiple times. Zscaler appears multiple times. Check Point appears more than once. These buyers are not just participating in the market; they are actively shaping category boundaries.

The concentration also shows up in disclosed value. A small number of mega-deals explains a very large share of tracked value: Google / Wiz, Palo Alto / CyberArk, ServiceNow / Armis, Accenture / Dragos-runZero-NetRise, Palo Alto / Chronosphere, Jamf / Francisco Partners, Veeam / Securiti AI, Proofpoint / Hornetsecurity and Mastercard / Recorded Future. That means the market has two layers at once: many smaller deals happening in the background, and a few massive transactions redefining the competitive map.

The practical conclusion is that cybersecurity is not fragmenting endlessly anymore. Many categories are still crowded, but the largest platforms are buying the missing pieces. Over time, that should make it harder for mid-sized standalone vendors to stay independent unless they own a very sharp category position.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

So, what is the latest update on cybersecurity M&A now?

Cybersecurity M&A is in a platform consolidation cycle, with the latest 12 months showing more deals, more disclosed value, more mega-deals and a much stronger AI-era acquisition logic.

Check Current status
Deal activity now Cybersecurity M&A accelerated clearly: 28 tracked primary deals in the latest 12 months versus 14 in the previous 12 months. That is a 2.0x increase, which is too large to describe as normal market noise.
Market-wide confirmation The broader market confirms the same direction: SecurityWeek counted 426 cybersecurity M&A deals in 2025, while Momentum Cyber tracked 400 transactions and $96B deployed. So the dataset’s acceleration is consistent with the wider market.
Disclosed value Tracked disclosed / reported value rose from $43.3B to $82.7B. The increase is not only from one deal, because the number of disclosed / reported value rows also rose from 8 to 19.
Mega-deals Deals above $1B increased from 4 to 9. The market is clearly back in mega-deal mode, especially for cloud, identity, exposure, observability, OT security and data security assets.
AI security AI-related rationale jumped from 4 deals to 18. AI is not just creating one new cyber category; it is changing acquisition logic across identity, data, browser, SIEM, app security and cloud.
Identity security Identity is one of the most strategic M&A themes now. Palo Alto / CyberArk, ServiceNow / Veza, CrowdStrike / SGNL and Imprivata / Verosint show buyers securing humans, machines and AI agents.
Data security Data security reappeared strongly, with 3 tracked DSPM / data security deals in the latest period versus zero before. AI adoption is making data visibility and access control much more urgent.
Cloud security Cloud security remains central because Google / Wiz is the largest deal in the dataset. Still, the market has moved beyond a pure CNAPP story into AI-era enterprise security.
Browser security Browser security is now a real acquisition theme. Akamai / LayerX and CrowdStrike / Seraphic show that the browser is becoming a control point for SaaS, GenAI and agentic workflows.
MDR and SecOps MDR remains attractive when it adds automation, threat telemetry, response workflows or exposure context. Plain service scale is less compelling than MDR connected to a broader security platform.
OT cybersecurity OT cybersecurity is becoming more strategic. Accenture’s Dragos-runZero-NetRise move, Airbus / Quarkslab and ServiceNow / Armis all point to cyber expanding into industrial and physical infrastructure risk.
Buyer concentration The market is becoming more concentrated around repeat strategic buyers. Palo Alto, CrowdStrike, ServiceNow, Zscaler, Google and Accenture are not just buying companies; they are shaping platform categories.
Private equity PE is still present, especially in take-privates like Darktrace and Jamf. But strategic buyers are setting the current direction because they need product capabilities quickly.

OUR METHODOLOGY

This analysis tests what is really happening in cybersecurity M&A now. We did not treat it as a headline-driven question, because the market can look hot simply because a few huge deals dominate attention.

We broke the question into clearer analytical dimensions: deal activity, disclosed value, mega-deals, buyer behavior, category mix, AI-era rationale, private equity activity, and platform concentration.

For each dimension, we looked at recent signals first. We used the latest 12 months versus the previous 12 months to separate real acceleration from older cybersecurity M&A momentum, then checked whether the same pattern appeared across deal count, deal value, buyer quality, and strategic rationale.

We also looked beyond the largest transactions. Google / Wiz and Palo Alto / CyberArk are important, but they do not explain the whole market. The stronger pattern is that large strategic buyers are also acquiring across AI security, identity, data security, browser security, MDR, OT security, exposure management, and security operations.

We classified deals by the strategic problem they addressed, not only by the target’s narrow product label. That matters because cybersecurity categories now overlap heavily: AI security touches identity, data, cloud, browser sessions, app security, SIEM, and agentic workflows.

We gave more weight to patterns that repeated across several signals. A category became more convincing when it showed up through deal count, buyer quality, disclosed value, repeat acquisitions, and clear product logic.

Key sources used for this analysis include: Google on the Wiz acquisition, Google Cloud on completing the Wiz acquisition, Palo Alto Networks on the CyberArk acquisition, Palo Alto Networks on completing CyberArk, Palo Alto Networks on Chronosphere, Palo Alto Networks on completing Chronosphere, Palo Alto Networks on Portkey, ServiceNow on Armis, ServiceNow on Veza, Accenture on Dragos, runZero and NetRise, Veeam on Securiti AI, CrowdStrike on Pangea, CrowdStrike on Onum, Zscaler on Red Canary, Cato Networks on Aim Security, Check Point on Lakera, Akamai on LayerX, SecurityWeek’s cybersecurity M&A activity tracker, Momentum Cyber’s 2025 cybersecurity market review, Mastercard on Recorded Future, Thoma Bravo on Darktrace, and Fortinet on Lacework.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog