Cybersecurity M&A: what is happening now?

In our cybersecurity market deck, you will find everything you need to understand the market
SUMMARY
Cybersecurity M&A: what is happening now? The market is in a real platform consolidation cycle, not just a normal run of scattered acquisitions.
The clearest pattern is acceleration. The tracked primary deal count doubled from 14 deals in the previous 12 months to 28 in the latest 12 months, while disclosed or reported value rose from about $43.3B to $82.7B.
The market is not being carried only by Google / Wiz or Palo Alto / CyberArk. Those are the headline peaks, but the same acceleration appears in mid-sized deals across AI security, identity, browser security, data security, MDR, telemetry, OT security and exposure management.
Buyers are paying up again, but not equally across the market. The richest prices are going to assets that can become control points inside larger security platforms: cloud security, identity, asset visibility, observability, OT security and AI-era data control.
AI security is now one of the main acquisition logics in cybersecurity. It does not show up only in pure AI security startups; it is also reshaping deals in identity, data security, browser security, SIEM, app security, cloud security and exposure management.
Identity has moved back to the center, but in a different way. Buyers are no longer only protecting employee login; they are trying to secure humans, machines, service accounts and AI agents across apps, data and cloud environments.
Cloud security remains a heavyweight category because Google / Wiz is the largest deal in the dataset. But the market has moved beyond a pure CNAPP story into a broader AI-era enterprise security stack.
Data security is suddenly more urgent because AI makes old governance problems feel operational and immediate. Enterprises now need to know where sensitive data sits, who can touch it, and what AI tools or agents can do with it.
Browser security is small but newly serious. Akamai / LayerX and CrowdStrike / Seraphic show that large buyers now see the browser session as a missing control point for SaaS, GenAI and agentic workflows.
Private equity is still present, especially in take-privates like Darktrace and Jamf, but strategic buyers are setting the pace. Google, Palo Alto Networks, ServiceNow, CrowdStrike, Zscaler, Accenture, Veeam, Proofpoint and others are buying because product gaps need to close quickly.
The practical conclusion is blunt: cybersecurity is still crowded, but it is not fragmenting endlessly. The largest platforms are buying the missing pieces, and that makes life harder for mid-sized standalone vendors unless they own a very sharp category position.

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market
What are all the latest deals and acquisitions in cybersecurity M&A?
When we look at all the M&A deals in cybersecurity over the last 24 months, the market is clearly in a heavy consolidation phase, with the largest buyers moving across cloud security, identity, AI security, data security, exposure management, OT security, browser security and MDR.
| Date | Target | Acquirer | Value | Strategic rationale | Status and additional comment |
|---|---|---|---|---|---|
| Jun 2026 | Dragos majority stake + runZero + NetRise | Accenture | ~$4.175B | Build a larger OT cybersecurity platform across threat detection, exposure management, device security and software supply chain risk | Announced / pending. Expected close by Sep 2026. Combined businesses expected to generate about $208M ARR |
| May 2026 | LayerX | Akamai | ~$205M | Extend Zero Trust into the browser, especially for SaaS, GenAI apps and AI agents | Announced / pending. Expected Q3 2026 |
| May 2026 | Symmetry Systems | Zscaler | Undisclosed | Improve data visibility and control when AI agents access enterprise data | Announced / pending |
| Apr 2026 | Quarkslab | Airbus | Undisclosed | Strengthen advanced cyber research and sovereign defense cyber capabilities | Announced / pending |
| Apr 2026 | Ryft | Cyera | Undisclosed | Broaden Cyera’s data security platform with AI and data workflow capabilities | Announced / pending |
| Apr 2026 | Portkey | Palo Alto Networks | Undisclosed | Add AI application and agent security into Palo Alto’s platform | Announced / pending |
| Apr 2026 | Armis | ServiceNow | $7.75B | Combine asset visibility, exposure management and cyber risk workflows | Closed. Largest acquisition in ServiceNow’s history |
| Mar 2026 | Wiz | Google / Alphabet | $32B | Strengthen Google Cloud security across multicloud and AI-era cloud environments | Closed. Largest deal in the 24-month cybersecurity M&A dataset |
| Mar 2026 | Veza | ServiceNow | ~$1B reported | Add AI-native identity security across apps, data, cloud and AI agents | Closed. Official terms undisclosed |
| Feb 2026 | CyberArk | Palo Alto Networks | ~$25B | Make identity security a core platform pillar for human, machine and agentic identities | Closed. One of the defining cybersecurity platform deals |
| Jan 2026 | Jamf | Francisco Partners | $2.2B | Take Apple device management and security vendor private | Closed |
| Jan 2026 | Chronosphere | Palo Alto Networks | $3.35B | Connect observability, security operations and agentic remediation | Closed |
| Jan 2026 | Seraphic Security | CrowdStrike | ~$420M reported | Turn any browser into a secure enterprise browser | Announced |
| Jan 2026 | SGNL | CrowdStrike | ~$740M reported | Add continuous identity and real-time authorization | Announced |
| Dec 2025 | Securiti AI | Veeam | $1.725B | Create a trusted data platform for AI, governance, recovery and security | Closed |
| Dec 2025 | Hornetsecurity | Proofpoint | $1.8B | Expand Microsoft 365 security, compliance, data protection and security awareness | Completed |
| Nov 2025 | SPLX | Zscaler | Undisclosed | Add AI asset discovery, automated red-teaming and AI governance | Announced |
| Nov 2025 | UpSight Security | Arctic Wolf | Undisclosed | Strengthen endpoint and ransomware defense with predictive AI and rollback | Announced |
| Nov 2025 | Mayhem Security | Bugcrowd | Undisclosed | Combine crowdsourced testing with automated application security testing | Announced |
| Oct 2025 | ThreatConnect | Dataminr | $290M | Combine real-time event detection with threat intelligence and agentic AI workflows | Announced |
| Oct 2025 | Verosint | Imprivata | Undisclosed | Add AI-powered risk intelligence to healthcare identity security | Announced |
| Sep 2025 | Pangea | CrowdStrike | ~$260M reported | Create AI Detection and Response across the AI application lifecycle | Announced |
| Sep 2025 | Aim Security | Cato Networks | ~$300-350M reported | Secure AI agents and AI applications inside Cato’s SASE cloud | Announced. First acquisition ever for Cato |
| Sep 2025 | Lakera | Check Point | ~$300M reported | Build stronger AI security and create a Global Center of Excellence for AI Security | Announced |
| Sep 2025 | SlashNext | Varonis | $150M | Add email and social engineering protection to managed data detection and response | Announced |
| Aug 2025 | Onum | CrowdStrike | ~$290M reported | Strengthen Falcon Next-Gen SIEM with real-time telemetry pipeline management | Announced |
| Aug 2025 | Mira Security | Darktrace | Undisclosed | Improve network visibility and encrypted traffic analysis | Announced |
| Jul 2025 | Red Canary | Zscaler | ~$675M reported | Combine MDR, threat detection and exposure management | Completed |
| Apr 2025 | Protect AI | Palo Alto Networks | ~$650-700M reported | Add AI model and AI application protection | Announced |
| Feb 2025 | Secureworks | Sophos | ~$859M | Combine Sophos with Taegis MDR / XDR and create a larger MDR provider | Closed |
| Feb 2025 | Veriti | Check Point | Undisclosed | Add automated exposure assessment and remediation | Announced |
| Jan 2025 | Zilla Security | CyberArk | ~$175M reported | Add identity governance and administration to CyberArk’s platform | Announced / completed |
| Jan 2025 | Vulcan Cyber | Tenable | ~$147M reported | Add exposure remediation and vulnerability prioritization workflows | Announced / completed |
| Dec 2024 | Recorded Future | Mastercard | $2.65B | Expand threat intelligence and cybersecurity services beyond payments | Closed |
| Dec 2024 | Egress | KnowBe4 | Undisclosed | Combine security awareness with adaptive email security | Closed / announced |
| Oct 2024 | Darktrace | Thoma Bravo | ~$5.3B | Take AI cybersecurity leader private | Closed |
| Oct 2024 | Venafi | CyberArk | ~$1.54B | Expand machine identity security and certificate lifecycle management | Closed |
| Aug 2024 | Lacework | Fortinet | Undisclosed | Add CNAPP capabilities to Fortinet’s security platform | Closed |
| Aug 2024 | Trustwave | LevelBlue | Undisclosed | Expand MDR, MSSP and security consulting capabilities | Announced |
| Jul 2024 | Aberrant | 360 Advanced | Undisclosed | Expand cybersecurity and compliance services | Announced |
| Jul 2024 | Banyan Security | SonicWall | Undisclosed | Add Zero Trust Network Access and secure access capabilities | Announced |
Is cybersecurity M&A still hot right now?
Cybersecurity M&A is still hot, and the last 12 months were materially more active than the 12 months before.
When we look at all the M&A deals in cybersecurity over the last 24 months, the tracked primary deal count moves from 14 deals in the previous 12 months to 28 deals in the latest 12 months. That is a clean 2.0x increase.
The broader market checks point in the same direction: SecurityWeek counted 426 cybersecurity M&A deals in 2025, including 334 pure-play cybersecurity deals, while Momentum Cyber tracked 400 M&A transactions and $96B deployed in 2025.
We also noticed that the buyer list changed in quality. In the latest period, we see Google, Palo Alto Networks, ServiceNow, CrowdStrike, Zscaler, Accenture, Veeam, Proofpoint, Akamai, Check Point and Cato all buying into strategic cyber categories. That tells us this is not a thin market where one or two buyers create the whole story.
Put simply, cybersecurity M&A is still running hot because multiple strategic buyers are trying to close platform gaps at the same time.
If you want more recent data on this point, please see our latest cybersecurity market report.

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward
Is cybersecurity M&A accelerating now, or are we just noticing the big deals?
Cybersecurity M&A is really accelerating. The big deals make it visible, but they are not the only thing happening.
First, volume: 28 primary deals in the latest 12 months versus 14 before. Second, value: disclosed or reported value in the tracked dataset rises from $43.3B to $82.7B, which is about a 91% increase. Third, breadth: the latest period includes not only mega-deals, but also mid-sized acquisitions in AI security, browser security, identity, telemetry, MDR and data security.
There is also a monthly pattern. In the broader monthly counts captured for July 2025 to May 2026, we see 389 cybersecurity M&A deals across 11 captured months, or roughly 35 deals per month. October 2025 alone had 45 deals, July had 44, February 2026 had 42, and September had 40.
The market is not just being distorted by Google / Wiz or Palo Alto / CyberArk. Those deals are the visible peaks of a much broader acceleration.
Are cybersecurity buyers paying big prices again?
Cybersecurity buyers are paying big prices again, but mostly when the target can become a control point in a larger platform.
The strongest pricing clue is the return of mega-deals. In the previous 12 months, the dataset shows 4 deals above $1B. In the latest 12 months, that number jumps to 9. That is a major change because $1B-plus acquisitions are not normal tuck-ins; they usually mean the buyer sees the target as strategically difficult to replicate.
The multiples tell the same story. ServiceNow / Armis implies about 22.8x ARR using reported ARR above $340M. Palo Alto / Chronosphere implies about 20.9x ARR using reported ARR above $160M. Accenture’s Dragos-runZero-NetRise platform move implies about 20.1x ARR using the reported combined ARR of about $208M. These are not cheap multiples, and they are not being paid for random features. They are being paid for asset visibility, OT security, observability, exposure management and other layers that can anchor a broader security platform.
The smaller deal values create a useful contrast. CrowdStrike / Pangea, Akamai / LayerX, Check Point / Lakera, Cato / Aim Security and Varonis / SlashNext sit in the rough $150M to $420M zone where reported. These are important, but they are capability extensions. The highest prices are going to assets that can reshape the platform, not every attractive security startup.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups
Is AI security actually driving cybersecurity M&A now?
AI security is now one of the strongest drivers of cybersecurity M&A, and the pattern is much deeper than a few AI-branded deals.
In the dataset, deals with an AI security or AI-era rationale rise from 4 in the previous 12 months to 18 in the latest 12 months. That is a 4.5x increase. But the more interesting part is where AI shows up. It is not contained inside one clean “AI security” bucket. It appears in identity security, data security, browser security, SIEM, telemetry, cloud security, app security and exposure management.
Look at the pattern. CrowdStrike bought Pangea for AI Detection and Response, but it also bought SGNL for identity authorization and Seraphic for browser security. Zscaler bought SPLX for AI asset discovery and red-teaming, then Symmetry Systems for AI-era data access control. Check Point bought Lakera for AI security, while Cato bought Aim Security to secure AI agents inside SASE. Palo Alto bought Protect AI and later Portkey, which shows repeated interest in AI application and model protection.
The stronger interpretation is that AI has become a new acquisition logic across cybersecurity, not just a standalone category. Buyers are asking what happens when employees, developers, SaaS tools and autonomous agents start touching sensitive systems and data at scale. Once we frame it that way, the surge in identity, browser, data and AI app security acquisitions makes much more sense.
Is identity security becoming the center of cybersecurity M&A again?
Identity security is absolutely back at the center of cybersecurity M&A, but the reason has changed.
In the tracked deals, identity-related acquisitions move from 2 in the previous 12 months to 4 in the latest 12 months. On count alone, that is not the largest category. But on strategic importance, it is one of the clearest themes in the dataset. Palo Alto bought CyberArk for about $25B, ServiceNow bought Veza for about $1B reported, CrowdStrike bought SGNL for about $740M reported, and Imprivata bought Verosint to strengthen identity risk intelligence in healthcare.
The important detail is that buyers are no longer thinking only about employee login. CyberArk brings privileged access and machine identity depth. Veza adds identity visibility across apps, data and cloud. SGNL brings real-time authorization. Verosint adds identity risk intelligence for a regulated vertical. Together, these deals point to the same conclusion: identity is becoming the control plane for humans, machines, service accounts and AI agents.
That is why identity is showing up in so many different M&A stories. It connects cloud security, data security, SaaS security, healthcare security and AI security.
Identity is not “hot again” in the old IAM sense. It is being rebuilt for a world where non-human and agentic identities matter as much as employees.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity
Is cloud security still the main cybersecurity M&A battlefield?
Cloud security is still one of the main battlegrounds, but the market has moved beyond pure CNAPP consolidation.
The largest deal in the whole dataset is Google buying Wiz for $32B, so cloud security obviously remains central. Fortinet also bought Lacework in the previous period, which adds another CNAPP signal. Palo Alto’s Protect AI deal also sits close to cloud and AI workload protection, even if its rationale is more AI application and model security than classic CNAPP.
But the deal mix changed after that. In the latest 12 months, the strongest repeated themes are identity, AI security, data security, exposure management, browser security, OT security and security operations. ServiceNow / Armis is about asset and exposure visibility across IT, OT, IoT, medical devices, code and cloud. Veeam / Securiti AI is about trusted data for AI. Accenture / Dragos-runZero-NetRise is about industrial security, not cloud-native app protection.
The conclusion is simple enough: cloud security remains a heavyweight M&A category, but it is no longer the whole story. Cybersecurity M&A has shifted from “secure the cloud” to “secure the AI-era enterprise,” which includes cloud, data, identity, browser sessions, agents, assets and industrial systems.
Is data security suddenly important again?
Data security is moving again because AI turned a slow governance problem into an urgent security problem.
The tracked dataset shows 3 data security / DSPM deals in the latest 12 months versus zero in the previous 12 months. Veeam bought Securiti AI for $1.725B. Zscaler bought Symmetry Systems. Cyera bought Ryft. The count is small, but the direction is very clear because all three deals sit around the same problem: enterprises need to know where sensitive data is, who can access it and what AI systems can do with it.
The Veeam deal is especially useful because it links backup, recovery, governance and security.
That is not a traditional “backup company buys security feature” story. It says cyber resilience and AI data governance are converging. Zscaler and Cyera point to the same underlying issue from another direction: access to sensitive data becomes much harder to control when AI agents, SaaS tools and cloud apps all interact with it.

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups
Are browser security deals becoming real now?
Browser security has become a real cybersecurity M&A theme, even if it is still smaller than cloud or identity.
Two recent deals make the point. Akamai agreed to buy LayerX for around $205M, and CrowdStrike agreed to buy Seraphic Security for around $420M reported. Both targets focus on browser security. That is too specific to dismiss as noise, especially because the buyers are large strategic vendors, not niche acquirers.
The practical reason is obvious once you look at how people now work. Employees spend more and more time inside SaaS apps, collaboration tools and GenAI products, and much of that happens through the browser. Identity tools can decide who gets access. Endpoint tools can secure the device. Network tools can inspect traffic. But the browser session itself is becoming a security surface, especially when users copy data into AI tools, authorize apps or interact with risky web content.
Browser security is moving from “interesting niche” to “missing platform control.”
The deal sizes are not enormous, but the strategic logic is strong. Buyers are preparing for a world where the browser becomes the front door to enterprise AI usage.
Are cybersecurity acquirers buying startups or assembling platforms?
Cybersecurity acquirers are assembling platforms, and the best evidence is the repeat-buyer pattern.
Palo Alto is the clearest case. It bought CyberArk for identity, Chronosphere for observability and agentic remediation, Protect AI for AI model and application protection, and Portkey for AI application security. CrowdStrike bought SGNL, Seraphic, Pangea and Onum across identity, browser security, AI security and telemetry. ServiceNow bought Armis and Veza to pull cyber exposure and identity into security, risk and workflow operations. Zscaler bought Red Canary, SPLX and Symmetry Systems across MDR, AI security and data security.
The acquisitions are not random. Each buyer is filling adjacent gaps around an existing control plane. Palo Alto is pushing platformization. CrowdStrike is extending Falcon beyond endpoint into identity, browser, AI and telemetry. ServiceNow is making cyber operational inside enterprise workflows. Zscaler is adding threat management, AI security and data controls around Zero Trust.
The main cybersecurity M&A story is not startup shopping. It is platform architecture. The leading buyers are deciding which layers they need to own before AI and agentic workflows reshape enterprise security budgets.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors
Are managed security and MDR still attractive now?
Managed security and MDR are still attractive, but only when they connect to a broader security operating model.
The dataset shows MDR / SecOps-related deals rising from 1 in the previous 12 months to 3 in the latest 12 months. Sophos bought Secureworks for about $859M to build a larger MDR / XDR provider around Taegis and Sophos. Zscaler bought Red Canary for around $675M reported to connect threat detection, MDR and exposure management. Arctic Wolf bought UpSight Security to strengthen endpoint and ransomware defense with predictive AI and rollback.
It looks like buyers are buying MDR when it brings a platform advantage: threat telemetry, automation, response workflows, exposure context, endpoint rollback or AI-driven operations. That is why Red Canary matters for Zscaler, and why Secureworks matters for Sophos.
MDR is not dead, but plain vanilla MDR is less exciting than MDR connected to automation and platform data. The category still gets acquired, but the best assets are the ones that make the buyer’s broader security engine smarter.
Is OT cybersecurity becoming a bigger M&A target now?
OT cybersecurity is becoming a much bigger M&A target, and Accenture’s move makes that hard to ignore.
The biggest OT signal is Accenture’s June 2026 move: a majority stake in Dragos plus acquisitions of runZero and NetRise, with a combined value around $4.175B. That is not a small consulting bolt-on. It combines OT threat detection, exposure assessment, device security and software supply chain security into one industrial cyber platform. The reported combined ARR of about $208M also suggests this was bought as a serious software and platform asset, not just as a services capability.
There are supporting clues around the edges. Airbus buying Quarkslab points to defense and sovereign cyber capability. ServiceNow buying Armis also touches OT, IoT and medical device exposure, not just classic IT assets. These deals tell us buyers are widening their view of cybersecurity from laptops, servers and cloud workloads to factories, utilities, devices, hospitals and connected infrastructure.
OT security is becoming more strategic because the risk is physical. A cloud breach is serious, but an industrial system breach can affect production, energy, transport or public safety.
That gives OT cybersecurity a different urgency, and the M&A data now reflects it.

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market
Are private equity buyers still shaping cybersecurity M&A?
Private equity is still important, but strategic buyers are clearly setting the direction right now.
The previous period had a very visible PE signal with Thoma Bravo taking Darktrace private for around $5.3B. The latest period still includes Francisco Partners taking Jamf private for $2.2B. Those are meaningful transactions, and they show that PE still likes cybersecurity assets with recurring revenue, operational upside and category depth.
But the center of gravity has shifted toward strategic buyers. Google bought Wiz. Palo Alto bought CyberArk and Chronosphere. ServiceNow bought Armis and Veza. CrowdStrike bought SGNL, Seraphic, Pangea and Onum. Zscaler bought Red Canary, SPLX and Symmetry Systems. Accenture made a major OT cyber platform move. Veeam bought Securiti AI. Proofpoint bought Hornetsecurity.
Private equity still participates, but it is not defining the current cycle. Strategic buyers are doing that because they need product depth quickly. Overall, cybersecurity M&A is being shaped less by financial engineering and more by product-market urgency around AI, identity, data, cloud and exposure.
Is the cybersecurity M&A market becoming more concentrated?
Cybersecurity M&A is becoming more concentrated around a small group of platform buyers, even while the total number of deals remains broad.
The repeat-buyer pattern is strong. Palo Alto appears several times. CrowdStrike appears several times. ServiceNow appears multiple times. Zscaler appears multiple times. Check Point appears more than once. These buyers are not just participating in the market; they are actively shaping category boundaries.
The concentration also shows up in disclosed value. A small number of mega-deals explains a very large share of tracked value: Google / Wiz, Palo Alto / CyberArk, ServiceNow / Armis, Accenture / Dragos-runZero-NetRise, Palo Alto / Chronosphere, Jamf / Francisco Partners, Veeam / Securiti AI, Proofpoint / Hornetsecurity and Mastercard / Recorded Future. That means the market has two layers at once: many smaller deals happening in the background, and a few massive transactions redefining the competitive map.
The practical conclusion is that cybersecurity is not fragmenting endlessly anymore. Many categories are still crowded, but the largest platforms are buying the missing pieces. Over time, that should make it harder for mid-sized standalone vendors to stay independent unless they own a very sharp category position.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time
So, what is the latest update on cybersecurity M&A now?
Cybersecurity M&A is in a platform consolidation cycle, with the latest 12 months showing more deals, more disclosed value, more mega-deals and a much stronger AI-era acquisition logic.
| Check | Current status |
|---|---|
| Deal activity now | Cybersecurity M&A accelerated clearly: 28 tracked primary deals in the latest 12 months versus 14 in the previous 12 months. That is a 2.0x increase, which is too large to describe as normal market noise. |
| Market-wide confirmation | The broader market confirms the same direction: SecurityWeek counted 426 cybersecurity M&A deals in 2025, while Momentum Cyber tracked 400 transactions and $96B deployed. So the dataset’s acceleration is consistent with the wider market. |
| Disclosed value | Tracked disclosed / reported value rose from $43.3B to $82.7B. The increase is not only from one deal, because the number of disclosed / reported value rows also rose from 8 to 19. |
| Mega-deals | Deals above $1B increased from 4 to 9. The market is clearly back in mega-deal mode, especially for cloud, identity, exposure, observability, OT security and data security assets. |
| AI security | AI-related rationale jumped from 4 deals to 18. AI is not just creating one new cyber category; it is changing acquisition logic across identity, data, browser, SIEM, app security and cloud. |
| Identity security | Identity is one of the most strategic M&A themes now. Palo Alto / CyberArk, ServiceNow / Veza, CrowdStrike / SGNL and Imprivata / Verosint show buyers securing humans, machines and AI agents. |
| Data security | Data security reappeared strongly, with 3 tracked DSPM / data security deals in the latest period versus zero before. AI adoption is making data visibility and access control much more urgent. |
| Cloud security | Cloud security remains central because Google / Wiz is the largest deal in the dataset. Still, the market has moved beyond a pure CNAPP story into AI-era enterprise security. |
| Browser security | Browser security is now a real acquisition theme. Akamai / LayerX and CrowdStrike / Seraphic show that the browser is becoming a control point for SaaS, GenAI and agentic workflows. |
| MDR and SecOps | MDR remains attractive when it adds automation, threat telemetry, response workflows or exposure context. Plain service scale is less compelling than MDR connected to a broader security platform. |
| OT cybersecurity | OT cybersecurity is becoming more strategic. Accenture’s Dragos-runZero-NetRise move, Airbus / Quarkslab and ServiceNow / Armis all point to cyber expanding into industrial and physical infrastructure risk. |
| Buyer concentration | The market is becoming more concentrated around repeat strategic buyers. Palo Alto, CrowdStrike, ServiceNow, Zscaler, Google and Accenture are not just buying companies; they are shaping platform categories. |
| Private equity | PE is still present, especially in take-privates like Darktrace and Jamf. But strategic buyers are setting the current direction because they need product capabilities quickly. |
OUR METHODOLOGY
This analysis tests what is really happening in cybersecurity M&A now. We did not treat it as a headline-driven question, because the market can look hot simply because a few huge deals dominate attention.
We broke the question into clearer analytical dimensions: deal activity, disclosed value, mega-deals, buyer behavior, category mix, AI-era rationale, private equity activity, and platform concentration.
For each dimension, we looked at recent signals first. We used the latest 12 months versus the previous 12 months to separate real acceleration from older cybersecurity M&A momentum, then checked whether the same pattern appeared across deal count, deal value, buyer quality, and strategic rationale.
We also looked beyond the largest transactions. Google / Wiz and Palo Alto / CyberArk are important, but they do not explain the whole market. The stronger pattern is that large strategic buyers are also acquiring across AI security, identity, data security, browser security, MDR, OT security, exposure management, and security operations.
We classified deals by the strategic problem they addressed, not only by the target’s narrow product label. That matters because cybersecurity categories now overlap heavily: AI security touches identity, data, cloud, browser sessions, app security, SIEM, and agentic workflows.
We gave more weight to patterns that repeated across several signals. A category became more convincing when it showed up through deal count, buyer quality, disclosed value, repeat acquisitions, and clear product logic.
Key sources used for this analysis include: Google on the Wiz acquisition, Google Cloud on completing the Wiz acquisition, Palo Alto Networks on the CyberArk acquisition, Palo Alto Networks on completing CyberArk, Palo Alto Networks on Chronosphere, Palo Alto Networks on completing Chronosphere, Palo Alto Networks on Portkey, ServiceNow on Armis, ServiceNow on Veza, Accenture on Dragos, runZero and NetRise, Veeam on Securiti AI, CrowdStrike on Pangea, CrowdStrike on Onum, Zscaler on Red Canary, Cato Networks on Aim Security, Check Point on Lakera, Akamai on LayerX, SecurityWeek’s cybersecurity M&A activity tracker, Momentum Cyber’s 2025 cybersecurity market review, Mastercard on Recorded Future, Thoma Bravo on Darktrace, and Fortinet on Lacework.

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize
Related blog posts
- How strong is fundraising in the cybersecurity market right now?
- The startups that have raised the most funding in cybersecurity
Who is the author of this content?
NEW MARKET PITCH TEAM
We track new markets so founders and investors can move fasterWe build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.