Who’s buying cybersecurity startups?

Last updated: 25 August 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity startups are being bought by a much wider group than the usual security giants: large security vendors, cloud and enterprise-software companies, private equity firms, PE-backed platforms, infrastructure companies, consultancies and even banks are all active buyers today.

The market is genuinely busy, but the strongest evidence is deal count rather than headline dollar value. With 219 acquisitions in the first half of 2026, cybersecurity is running at a record annualized pace even without another Wiz-sized transaction inflating the total.

Strategic buyers and private equity are playing different games. Corporates still dominate disclosed acquisition spending because they can justify paying for strategic position, product gaps or technology that would take years to build, while PE shows up much more heavily in the middle of the market and in overall deal count.

Palo Alto Networks remains the clearest serial acquirer, but the more important pattern is that it no longer defines the market by itself. CrowdStrike, Fortinet, Check Point, Okta, Cisco, Cyera and several others are all using M&A to move into adjacent security layers.

The buyer universe now extends well outside cybersecurity. Google is using security to strengthen cloud, ServiceNow is tying cyber exposure to workflow and asset management, Qualcomm has bought IoT-security technology, Accenture is building industrial-cyber capability, and Bank of America is even buying specialist security expertise directly.

AI security is already an acquisition market rather than a future theme. The interesting part is how specific the targets have become: agent identities, model testing, runtime protection, permissions, model supply chains and security for autonomous software are now distinct buying themes.

Identity is becoming unusually strategic because the thing being secured is changing. Buyers are preparing for environments where machine and agent identities vastly outnumber employees, which gives identity startups relevance well beyond the current AI-agent hype cycle.

Founders do not need huge revenue to get acquired. Small companies can sell early if the technology is scarce and urgently needed, while the multibillion-dollar exits usually require a much harder combination of scale, growth, customers and category leadership.

Private-market valuation is a weak acquisition floor. Most disclosed cybersecurity deals still happen at fairly ordinary prices, and the venture boom produced several companies whose last funding valuation ended up saying very little about what an acquirer would later pay.

The strongest acquisition targets tend to sit exactly where the technology stack is changing fastest. More cloud creates new data and configuration risk, more AI creates autonomous identities and permissions problems, and more connected industrial equipment creates assets that old IT-security tools were never designed to see.

The practical answer to “Who’s buying cybersecurity startups?” is therefore less about memorizing a list of acquirers and more about understanding where ownership suddenly becomes strategic. If a startup controls an important new security layer, there is now a surprisingly broad set of companies that may eventually decide they need to own it.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Is cybersecurity M&A actually booming right now?

Cybersecurity M&A is running at a record pace right now, and this time the surge is coming from deal volume rather than one or two giant acquisitions.

Momentum Cyber counted 219 cybersecurity acquisitions in the first half of 2026, up slightly from an already busy first half of 2025. At that pace, the industry would finish the year with roughly 438 deals, the highest annual number Momentum Cyber has ever tracked. SecurityWeek's separate database points in the same direction: after recording more than 420 acquisitions in 2025, it counted another 37 in June and 21 in July alone.

The dollar total looks less spectacular than last year's because 2025 contained two exceptional transactions: Google's $32 billion acquisition of Wiz and Palo Alto Networks' roughly $25 billion acquisition of CyberArk. In the first half of 2026, Momentum Cyber recorded only $9.1 billion of disclosed M&A value.

That actually makes the current activity more interesting. Buyers have kept acquiring companies even without mega-deals inflating the total. AI security, identity, industrial cybersecurity, security operations and managed services are all producing transactions at the same time.

So yes, cybersecurity companies are being bought unusually often these days. The boom is broader than the headline numbers from 2025 suggested.

Cybersecurity M&A Deal count
2025 About 400–420+
First half of 2026 219
Current annualized pace About 438

If you want more recent data on this point, please see our latest cybersecurity market report.

Who spends the most money buying cybersecurity startups?

Strategic companies still spend most of the money in cybersecurity M&A, while private equity accounts for a much bigger share of the actual deal count.

The difference is huge. Momentum Cyber found that strategic buyers represented 92% of disclosed cybersecurity acquisition spending in 2025. Google could pay $32 billion for Wiz because owning one of the leading cloud-security platforms could make Google Cloud itself more competitive. A private equity fund usually needs a much more conventional financial return from the company it buys.

That does not mean private equity is marginal. PE firms completed 165 cybersecurity acquisitions during 2025 and another 89 during the first half of 2026, according to Momentum Cyber. They simply operate much more often in the middle of the market.

Strategic buyers can also pay for something that does not yet show up cleanly in the target's financial statements. They may want a new product category, an engineering team, intellectual property or technology that would take two years to build internally. This is why the largest cybersecurity exits are still more likely to come from a corporate buyer than a financial one.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Is Palo Alto Networks still the biggest cybersecurity buyer?

Palo Alto Networks remains the clearest example of a cybersecurity company that uses acquisitions as a regular way to enter new markets.

The pattern goes back years. Palo Alto Networks bought Bridgecrew to strengthen cloud security for developers, Cider Security for software-supply-chain security, Dig Security for data security and Talon for enterprise-browser technology. It later moved into much larger transactions, including Chronosphere for roughly $3.35 billion and CyberArk for about $25 billion.

The CyberArk deal is especially revealing because Palo Alto Networks did not describe identity as another feature. It made identity security a new core platform alongside network, cloud and security operations. After completing the transaction, the company said CyberArk would help secure human, machine and agentic identities.

Palo Alto Networks has continued buying since then. It completed the acquisition of Koi to secure AI coding agents and other autonomous endpoint tools, and more recently moved to acquire Embrace to add mobile and web observability.

The consistency is what makes Palo Alto Networks unusual. Plenty of cybersecurity companies make acquisitions. Palo Alto Networks repeatedly uses them to jump into categories that have suddenly become strategically important.

CyberArk was the extreme version of that strategy. Most Palo Alto Networks acquisitions are much smaller.

If you want more recent data on this point, please see our latest cybersecurity market report.

Which other cybersecurity companies are buying startups right now?

CrowdStrike, Fortinet, Check Point, Okta and several younger security platforms are all buying cybersecurity startups now, so the market is much broader than Palo Alto Networks alone.

CrowdStrike has been extending Falcon beyond endpoint security for several years. Bionic added application-security capabilities, Flow Security strengthened data protection, Adaptive Shield added SaaS security and SGNL pushed CrowdStrike deeper into identity. More recently, CrowdStrike agreed to acquire intellectual property from XM Cyber so it can add attack-path analysis and exposure management directly to its platform.

Fortinet is also becoming more acquisitive. Lacework expanded its cloud-security business, Next DLP added data protection and Perception Point brought email and collaboration security. Its latest move is Virtue AI, a young company focused on testing and protecting AI models, applications and autonomous agents.

Check Point has followed a similar path with Cyberint, Veriti and Lakera, then added Cyata, Cyclops Security and Rotate. Okta, meanwhile, agreed to acquire Permiso for roughly $200 million to move beyond identity management into continuous identity threat detection.

Even fast-growing private companies are becoming buyers. Cyera, best known for data security, agreed to buy Oasis Security for about $1 billion. Oasis focuses on non-human identities such as service accounts and AI agents. A startup valued in the billions can therefore become an acquirer before it ever reaches the public market.

The current buyer pool is deep enough that a good cybersecurity startup can interest several companies attacking the same problem from different directions.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Are Google, ServiceNow and other non-cyber companies serious cybersecurity buyers?

Large technology companies outside traditional cybersecurity are becoming much more credible buyers when security directly strengthens their main business.

Google is the obvious example. Its $32 billion Wiz acquisition followed its earlier $5.4 billion purchase of Mandiant. Google is clearly willing to spend heavily when security can strengthen Google Cloud rather than simply add another security product.

ServiceNow has made an equally important move from a different direction. It bought identity-security company Veza and then completed its $7.75 billion acquisition of Armis. Armis discovers and monitors assets across IT networks, factories, medical devices, IoT systems and cloud infrastructure. ServiceNow believes the combination can more than triple the market available to its security and risk business.

Other recent transactions show how far the buyer universe can stretch. Qualcomm acquired Israeli IoT-security startup SAM Seamless Network for a reported figure above $100 million, bringing cybersecurity technology closer to the chips and networking hardware it already sells. Bank of America agreed to acquire British security consultancy MDSec and its roughly 65 cybersecurity specialists. Accenture has made a multibillion-dollar push into industrial cybersecurity around Dragos, runZero and NetRise.

This creates more exit routes for founders. A cybersecurity startup protecting databases might fit a security vendor. A company protecting connected devices could interest a semiconductor company. An industrial-security company could fit a consulting giant. A security product tied tightly to workflow could make sense for ServiceNow.

The buyer no longer has to look like a cybersecurity company.

How much cybersecurity M&A is actually private equity?

Private equity is one of the biggest forces in cybersecurity by deal count, especially once we include acquisitions made by PE-backed cybersecurity companies.

Momentum Cyber counted 165 PE acquisitions in 2025 and another 89 in the first half of 2026. That is far too much activity to treat PE as a secondary buyer category.

Thoma Bravo shows how the model works. It has assembled a cybersecurity portfolio that includes Proofpoint, SailPoint, Sophos, Darktrace, Ping Identity, Imprivata and Exabeam. The firm says those companies represent roughly $62 billion of enterprise value and around $8 billion of combined revenue.

Then the portfolio companies start buying too. Sophos acquired Secureworks for roughly $859 million. Darktrace bought Cado Security and Mira Security. Proofpoint has used acquisitions to expand into areas including email security, data protection and human-centric security.

Francisco Partners uses a comparable model and has backed companies including BeyondTrust while also pursuing larger transactions such as its roughly $2.2 billion Jamf acquisition.

That creates two layers of buyers for founders. A PE fund can buy the company directly, or one of its portfolio companies can acquire it as part of a larger roll-up.

Type of buyer What cybersecurity startups usually offer them
Large security vendor A missing technology or new product category
Cloud or enterprise-software company Security that strengthens its existing platform
Private equity Recurring revenue and consolidation potential
PE-backed cybersecurity company Products, customers or geographic expansion
Services or consulting group Talent, contracts and specialist expertise
Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Which cybersecurity startups are buyers chasing most aggressively?

AI security, identity, data security, cloud security and exposure management are currently attracting some of the strongest strategic interest.

We can see the convergence by following different buyers rather than repeatedly looking at the same company. Cyera is combining data security with non-human identity through its roughly $1 billion Oasis Security acquisition. Okta is adding identity-threat detection through Permiso. CrowdStrike is adding exposure-management technology from XM Cyber. Fortinet just bought Virtue AI for AI runtime protection. Cisco has moved to acquire WideField Security to strengthen agentic security operations around Splunk.

Industrial cybersecurity is also generating unusually large deals. Accenture agreed to invest roughly $4.2 billion across Dragos, runZero and NetRise, with Dragos accounting for most of the value. That puts operational-technology security in the same strategic conversation as cloud, identity and AI rather than leaving it as a small specialist niche.

Security services remain the volume leader. Momentum Cyber recorded 82 services transactions in the first half of 2026, ahead of risk and compliance with 32 and AI security with 29. Those deals are generally smaller, but there are many more potential targets.

The best acquisition categories today tend to sit where enterprise technology is changing fastest. More AI creates more autonomous identities. More cloud infrastructure creates more data and configuration risk. More connected industrial equipment creates more assets that traditional IT-security tools cannot see properly.

Buyers are following those new attack surfaces.

If you want more recent data on this point, please see our latest cybersecurity market report.

Is AI security really creating a new acquisition market?

AI security has already become a real M&A category, and the latest transactions show buyers are moving from experimentation toward owning specialist technology.

Momentum Cyber counted 29 AI-security acquisitions in the first half of 2026, compared with only 10 during all of 2025 under the narrower definition cited by The Wall Street Journal. Whichever classification we use, the direction is hard to miss.

The buyers are also coming from several parts of the cybersecurity market. Fortinet bought Virtue AI to test and protect autonomous AI systems. Palo Alto Networks acquired Koi to secure coding agents and autonomous tools running on employee endpoints. Cisco moved for WideField Security to improve the identity and credential context available to Splunk's agentic SOC. Earlier acquisitions by F5, Check Point and other vendors had already brought specialist AI-security companies into larger platforms.

The products being acquired are getting more specific too. Buyers are looking beyond generic “AI security” and into agent identities, model testing, runtime protection, AI application security, model supply chains and the permissions given to autonomous software.

Fortinet's latest acquisition is particularly fresh evidence because Virtue AI was founded only in 2024. Buyers clearly do not require every AI-security company to mature into a large standalone vendor before they become interested.

AI security these days looks less like a future M&A theme and more like an active land grab.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Why are identity-security startups suddenly getting bought?

Identity security is getting hotter because companies now need to control access for employees, machines, software and AI agents at the same time.

The scale of machine identity explains much of the urgency. When Palo Alto Networks completed its CyberArk acquisition, it said machine identities already outnumber human identities by more than 80 to one across modern enterprise environments.

Other buyers are attacking the same problem from different angles. Okta's Permiso acquisition gives it technology for detecting compromised identities across cloud environments. Cyera's Oasis deal adds governance for non-human identities to a data-security platform. CrowdStrike's SGNL acquisition adds continuously changing authorization rather than relying entirely on static access rules.

These companies are responding to a practical problem. An autonomous AI agent may need permission to read a database, call an API, send an email or change a production system. Traditional access controls were designed around employees logging into applications, not thousands of pieces of software acting continuously on their behalf.

That makes identity one of the few cybersecurity categories where AI can increase both the number of things being protected and the importance of the protection itself.

Identity-security startups are therefore likely to stay attractive even if some of the current excitement around AI agents cools down.

Do cybersecurity buyers want small startups or proven companies?

Cybersecurity buyers currently want both, but they buy small startups for technology and large companies for market position.

Small acquisitions can happen surprisingly early. Fortinet's purchase of Virtue AI came only around two years after the company was founded. Qualcomm's purchase of SAM brought specialized IoT-security software into its connectivity business. Okta's planned Permiso acquisition gives it a capability it can plug directly into an existing identity platform.

Those deals do not require the target to dominate an entire market.

At the other end, Armis had surpassed $340 million in annual recurring revenue and was still growing by more than 50% when ServiceNow agreed to acquire it. Chronosphere had reached more than $160 million in ARR before its $3.35 billion sale to Palo Alto Networks.

The price rises sharply once the buyer is getting more than technology. A scaled acquisition brings customers, recurring revenue, salespeople, integrations, brand recognition and a position inside a category that would be expensive to recreate.

Founders therefore have two credible exit paths. They can become technically indispensable early, or become commercially difficult to displace later.

The awkward position is somewhere in between: a startup that is no longer cheap, has no unique technology and has not reached enough scale to change the buyer's market position.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Does a cybersecurity startup need huge revenue to get acquired?

Cybersecurity startups can get acquired with relatively little revenue when they have technology a larger buyer urgently wants.

Recent dealmaking makes that clear. Buyers are purchasing narrowly focused companies in agent security, identity detection, observability and exposure management without waiting for all of them to reach hundreds of millions of dollars in sales.

Historically, Palo Alto Networks paid about $156 million for Bridgecrew and roughly $300 million for Cider Security while using both companies to accelerate its move into emerging cloud-security categories. Check Point paid around $93 million for Veriti. Fortinet spent roughly $105 million on Next DLP.

Those are meaningful exits without requiring the target to become the next CrowdStrike first.

The equation changes when a startup wants a multibillion-dollar outcome. Revenue, growth and category leadership become much harder to ignore. Chronosphere's more than $160 million of ARR helped support a $3.35 billion price. Armis' scale helped justify $7.75 billion.

For a smaller company, scarcity can compensate for limited revenue. For a large one, buyers eventually expect both.

Are cybersecurity buyers paying crazy valuations for everything?

Most cybersecurity acquisitions still happen at ordinary prices, despite a handful of spectacular exits.

A longer look at transaction data makes this obvious. Momentum Cyber studied hundreds of disclosed acquisitions between 2020 and 2025 and found that 211 were worth less than $100 million. Only 55 exceeded $1 billion. Among deals where a revenue multiple could be calculated, almost half were completed at five times revenue or less.

Current market data looks similar. Flow Partners estimates that the median cybersecurity M&A transaction over the past 12 months has been around four times revenue. Venture rounds, by comparison, have been happening at much higher revenue multiples.

That difference matters for founders who assume a high private valuation automatically creates a high acquisition floor. It does not.

Lacework is the harshest recent example. The cloud-security company reached an $8.3 billion valuation during the venture boom. Fortinet later acquired it after the company had gone through layoffs and a major reset, and Fortinet's subsequent SEC disclosure recorded roughly $152 million of cash consideration associated with the transaction.

Giant strategic deals can still reach extraordinary prices. They remain exceptions.

A buyer pays a huge premium when it believes the target can change its position in the market. Simply having raised money at a huge valuation does not create that leverage.

Disclosed cybersecurity acquisitions, 2020–2025 Number of deals
Below $100M 211
$100M–$500M 135
$500M–$1B 38
Above $1B 55

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Why do cybersecurity companies buy startups instead of building the technology themselves?

Cybersecurity companies buy startups when a new security problem is moving faster than their internal product teams can realistically catch up.

The industry constantly creates new categories because the underlying technology keeps changing. Cloud computing produced cloud-security specialists. SaaS created new identity and application-security problems. AI agents are now creating entirely new questions around permissions, model behavior and autonomous software.

An incumbent could spend several years building every missing product itself. Acquiring a startup gives it engineers who already understand the problem, working technology, customers, integrations and often a year or two of learning that cannot be reproduced instantly by hiring more developers.

The distribution economics make these deals particularly attractive. A 100-person startup may struggle to sell globally even when its technology is excellent. A company such as CrowdStrike, Fortinet or Check Point can put that product in front of thousands of existing enterprise customers.

This explains why point solutions can still produce good exits even while customers say they want fewer cybersecurity vendors. Consolidation actually gives large platforms another reason to acquire specialists: enterprises want the specialist capability without necessarily wanting another standalone supplier.

For a startup, becoming something customers demand from the big platforms can be enough.

Does Israel still produce an unusual number of cybersecurity acquisition targets?

Israel remains one of the world's most important sources of cybersecurity companies that eventually get acquired, far beyond what we would expect from the country's size.

Recent transactions keep reinforcing that position. Qualcomm's purchase of SAM brought another Israeli cybersecurity startup into a major US technology company. Cyera's acquisition of Oasis connected two companies with strong Israeli roots. Check Point's acquisition history includes Cyberint, Veriti, Cyata and other Israeli-founded businesses. Palo Alto Networks previously acquired Israeli companies including Cider Security, Dig Security and Talon.

Cross-border transactions are common throughout cybersecurity. Recent industry estimates put them at roughly 40% to 45% of deals, meaning founders do not need to build next door to their eventual acquirer.

Israel has an additional advantage because the acquisition cycle feeds itself. Founders and engineers build security companies, sell them to larger vendors, gain capital and operating experience, then often start or fund another generation of companies. Large American security companies also maintain major engineering operations there, making acquisitions easier to integrate.

The United States remains the industry's biggest commercial market and home to most of its largest buyers. Israel has become something different: an unusually productive factory for potential targets.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

So who is actually buying cybersecurity startups right now?

Cybersecurity startups currently have more credible buyers than almost any other enterprise-software category: security giants, identity vendors, cloud companies, enterprise-software platforms, infrastructure companies, private equity firms and even banks are all acquiring them.

For an early AI-security, cloud-security or exposure-management startup, Palo Alto Networks, CrowdStrike, Fortinet, Check Point and Cisco are obvious names to watch. Identity companies can add Okta and several identity-focused PE platforms to that group. Data-security startups increasingly have companies such as Cyera and Veeam as possible strategic buyers.

Once a company becomes large enough to affect an entire platform, the universe changes. Google, ServiceNow and other enterprise-technology giants can write checks that normal cybersecurity acquirers cannot easily match. Google's Wiz deal showed just how far that logic can go.

Private equity provides another exit route for companies with stronger revenue and more predictable economics. Thoma Bravo and Francisco Partners can buy mature cybersecurity companies directly, while their portfolio companies provide another pool of strategic acquirers underneath them.

The most interesting change lately is the arrival of buyers that would once have looked unusual. Qualcomm bought an IoT-security startup. Bank of America is buying a cybersecurity consultancy. Cyera is spending around $1 billion on another startup. Accenture is spending billions to build industrial-cybersecurity capability.

Cybersecurity M&A has expanded well beyond a handful of giant vendors buying small competitors.

If a startup controls an important new security layer, there is a growing chance that someone elsewhere in the technology stack will eventually decide it needs to own that layer.

If you want more recent data on this point, please see our latest cybersecurity market report.

OUR METHODOLOGY

The question behind “Who’s buying cybersecurity startups?” is easy to answer badly because a few spectacular deals or familiar acquirer names can distort the picture. We broke the market into separate dimensions: overall acquisition activity, buyer mix, strategic versus private-equity behavior, recurring acquisition themes, target maturity, valuation patterns and the rise of buyers from outside traditional cybersecurity.

For each dimension, we prioritized recent announced and completed transactions, disclosed deal values, buyer explanations, target scale and specialist cybersecurity M&A datasets. We looked for convergence across different buyers rather than letting one prolific acquirer or one exceptional transaction define the market. When several independent companies started buying into the same area, we treated that as stronger evidence of strategic demand.

We also kept different kinds of evidence separate. Deal count tells us how broad acquisition activity is, disclosed value shows where the largest checks are being written, buyer statements help explain strategic intent, and revenue or ARR helps distinguish purchases of scarce technology from purchases of established market position. Older deals were used selectively when they helped establish a repeat acquisition pattern or a useful valuation benchmark.

Fast-moving labels such as AI security, agent security, non-human identity and exposure management do not always mean exactly the same thing across datasets. We therefore treated category counts as directional evidence and checked them against the underlying transactions and the strategic rationale given by the buyers.

We prioritized primary company announcements, investor-relations materials, filings and original transaction datasets, then used specialist M&A datasets for aggregate patterns and tier-1 reporting when an important deal value was not disclosed directly by the companies.

Key sources include Momentum Cyber's H1 2026 Cybersecurity Mid-Year Market Review, Momentum Cyber's 2025 Cybersecurity M&A Year-End Report, SecurityWeek's June 2026 M&A roundup, SecurityWeek's July 2026 M&A roundup, Google on the Wiz acquisition, Palo Alto Networks on CyberArk, Fortinet on Virtue AI, Okta on Permiso Security, Cyera on Oasis Security, Accenture on its industrial-cybersecurity transactions, ServiceNow on Armis, Thoma Bravo's cybersecurity portfolio data, and Flow Partners' cybersecurity M&A valuation data.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.