M&A Deals & Comps
A record of cybersecurity M&A transactions, updated as new deals are announced. It supports comparable-transaction analysis and reads on sub-segment consolidation velocity.
See Precedent-Transaction Methodology for how the raw deal record becomes a precedent comp set: the screen, input normalization, the adjustment stack (control / scarcity / synergy / structure), and common ways precedent comps are misused.
H1 2026 M&A activity (mid-year market review)
The first half of 2026 set a record for deal count: 219 cybersecurity M&A transactions — +1% YoY on count but ~31% above the rolling three-year average — on pace for ~438 for the full year, the highest annual count on record and ~11% above 2025's record. Disclosed value rose ~45% YoY to $9.1B across 36 disclosed deals (vs ~$6.3B in H1 2025) — still well below 2025's mega-deal-driven peak, but with June the marquee month (39 deals, $4.9B, the strongest of the year). (The "+45% YoY" figure is disclosed value; the deal count was roughly flat YoY.) Strategics dominated: ~88% of deployed M&A capital and 126 of the deals; PEs completed 93. There were 19 $100M+ deals, with a median disclosed deal value of ~$90M. (Wall Street research Mid-Year 2026 Review, via GlobeNewswire, published Jul 1 2026.)
- The defining deal: Accenture's ~$4.175B acquisition of Dragos + NetRise + runZero (announced Jun 18 2026) — an assembled xOT platform (OT/ICS detection, software-supply-chain visibility, asset discovery, network intel) that "broke the dam" on $1B+ cyber M&A in 2026. Large public platforms — Palo Alto, Check Point, CrowdStrike, Akamai, Cisco — moved aggressively to fill gaps across AI Security, Identity, Data Security, and OT/ICS.
- Most active M&A sectors: Security Services (82 deals), Risk & Compliance (32), Identity & Access (13), Security Operations (6). Human-led Security Services remains the most active category, while AI Security entered the M&A arena (29 AI-security M&A transactions; 129 SaaS-security).
- Capital "land grab": ~$86B deployed in cybersecurity since June 2025 (M&A + financing combined).
Q2 2026 bank read (Wall Street research quarterly + Wall Street research June)
Two investment-bank updates dated 30 June 2026 corroborate the H1 pace and add the June-specific deals.
Wall Street research — private-market deal activity, Q2 2026: 67 cyber M&A transactions in the quarter — "in line with previous quarters despite wider tech-market volatility." The public-exit window stayed shut: 0 cyber IPOs and 0 take-privates in Q2 (LTM: 1 IPO, 2 take-privates). Consolidation is running almost entirely through private M&A, not public issuance — which keeps sell-side sponsors dependent on strategic and PE buyers rather than an IPO alternative. (One leading mid-market advisor also ranks #1 for global mid-market TMT M&A on an LTM-to-Mar-2026 basis at 73 transactions.)
Wall Street research — named/described June 2026 transactions (the report blanks the logos; figures and business descriptions are verbatim; likely identities cross-referenced to the separately-reported June financing leaders):
| June 2026 deal | Value | What it is | Likely identity |
|---|---|---|---|
| Acquisition | $4.25B | OT security platform — asset discovery, firmware/software-supply-chain analysis, OT threat detection across IT/OT | Accenture–Dragos/runZero/NetRise (matches the ~$4.18B xOT deal in the table below) |
| Series G at $12.0B valuation | $600M | Data security posture management (DSPM) — discovers/classifies sensitive data across cloud, quantifies exposure | Cyera (named a June leader in the H1 review) |
| Series C at $3.0B valuation | $260M | AI-native sovereign cybersecurity — autonomous detection/response across national-scale infrastructure | DREAM (named a June leader) |
| Series F at $1.6B valuation | $200M | AI-native observability + security analytics — logs/metrics/traces across distributed systems | Coralogix (named a June leader) |
The research also lists a €200M and a second $200M acquisition (undisclosed targets) plus a spread of early-stage rounds ($100M Seed, $100M Series B, €60M Series C, $66M Seed, $64M / $60M Series A). See Venture Capital for the financing read.
Wall Street research 1H 2026 read (advisor mid-year review)
A third mid-year source — Wall Street research's 1H 2026 review (Pitchbook + proprietary DB, as of 30 Jun 2026) — counts 205 cyber M&A deals YTD (+24% YoY) on $22.3B of disclosed/estimated volume (−47% YoY — the decline largely optical: 1H 2025 included Google–Wiz at $32B). The dollar figure runs well above the earlier "$9.1B disclosed" mid-year read because the review includes estimated values and adjacent/insurance and SPAC deals — notably Zurich Insurance–Beazley $11.0B (cyber insurance) and a $3.0B SPAC/reverse merger. Same direction, wider net; the methodology differs by source.
- Buyer mix: Strategic 64% / PE 36% — strategics still drive the market, but "active but disciplined": a higher bar on product relevance, platform fit, and execution, producing a more polarized market of big-platform moves plus targeted tuck-ins.
- New named 1H deals to add to the record: CrowdStrike–SGNL ($637M, Jan 8; identity/authorization) and CrowdStrike–Seraphic Security ($379M, Jan 13; enterprise browser) — CrowdStrike buying into identity and browser security in-house. Plus undisclosed targets at $675M (Feb 2) and $375M (Jan 15).
- Most active M&A sectors (the research count): Security Services 76 (Consulting 53 + MSSP 23) · Risk & Compliance 27 · AI Security 19 · Identity & Access 15 · Data Security 15 · AppSec 11 · Network/Infra 10 · SecOps/IR/TI 9. Human-led services still lead on count; AI Security is now a top-three category.
- Decade context: 2022–2026 YTD strategic M&A totals $263.7B (+59% vs the prior five years), even as annual volume swung from $88.4B (2023) to $16.5B (2025) to $22.3B (2026 YTD) — the sector consolidates in waves, and 2026 is re-accelerating off a soft 2025.
(Source: Wall Street research, "Mid-Year Cybersecurity Market Review, 1H 2026," as of 30 Jun 2026. The research figures include estimates and should be treated as approximate.)
1H 2026 detail (bank research)
Wall Street research — 1H26 detail:
- Quarterly split: Q1'26 99 deals / $13.8B · Q2'26 106 deals / $8.5B — Q2 set a quarterly deal-count record; 1H deal counts have surpassed 2021's prior peak. Full-year context: 2023: 271 deals/$48.5B · 2024: 280/$53.3B · 2025: 339/$84.1B.
- Disclosure and size: only 29 of 205 deals had disclosed/estimated values (85% undisclosed); median disclosed deal value $115M. Since 2023: average EV $1.3B, median $180M.
- Pricing discipline: median 8.8x EV/LTM revenue for SaaS-focused cyber M&A in the current "Disciplined Growth / AI-Era" period (vs 6.8x in the 2022–24 correction, 8.6x pandemic peak); ~34% of deals clear at ≤5.0x EV/LTM Rev; 15x+ multiples are generally paid only by cash-rich strategics.
- Buyer league: PE was buyer in 74 of 205 deals (36%); Cisco is the most active strategic acquirer since 2023 with 15 security acquisitions (incl. Splunk, Robust Intelligence, Isovalent, WideField, Galileo). 131 strategic deals through June puts 2026 on pace for the highest strategic acquisition count ever (vs 190 in all of 2025). 2023–1H26 deal mix: strategics 653 deals / $165.7B (60% count, 80% volume); PE 443 / $42.2B.
Bank M&A multiple benchmarks:
- Wall Street research LTM Jun-26 M&A multiples (EV/LTM Rev): strategic buyers 16.8x · financial buyers 5.0x · overall median 10.0x (Wall Street research, June 2026) — the strategic-over-financial spread at its widest; see 12.
- Wall Street precedent-transaction marks (all EV/NTM Rev): PANW–CyberArk 15.3x · ServiceNow–Armis 22.8x · Google–Wiz 16.0x · Akamai–LayerX 20.5x · Proofpoint–Hornetsecurity 11.3x (Wall Street research, 6/29/26). Basis note: the transaction log below carries Hornetsecurity at ~9x ARR — the research's 11.3x is NTM revenue; a different denominator, not a conflict.
Methodology note — reconciling the mid-year deal counts. Three trackers, three counts, each internally consistent: one Wall Street review counts 219 deals / $9.1B disclosed (published Jul 1 2026; widest inclusion net, disclosed-value-only), a second counts 205 deals / $22.3B (as of 6/30/26; Pitchbook + proprietary DB; includes estimated values plus insurance/SPAC deals — Zurich–Beazley $11.0B and a $3.0B SPAC account for most of the dollar gap), and a news-based deal tracker counts ~190 (mid-June cut-off, announced deals only). For June alone, SecurityWeek's monthly roundup counts 37 announced deals (SecurityWeek, Jul 13 2026) against the Wall Street review's 39 — the same inclusion-criteria spread at monthly grain; the bulk of the gap is small MSP/consultancy tuck-ins that individual trackers catch or miss at the margin. The spread reflects deal-inclusion criteria (services/insurance/SPAC in or out; announced vs completed) and count dates, not disagreement about direction — all three show a record-count, price-disciplined 1H. The counts are source-specific and are not directly comparable across trackers. The same applies to per-deal values across sources: CrowdStrike–SGNL $740M (company PR) vs $637M (a Wall Street review); Seraphic ~$400M (press) vs $379M (a Wall Street review); Accenture–Dragos/runZero/NetRise ~$4.18B (press) vs $4.2B vs $4.25B (Wall Street research) — the log keeps primary-source figures as canonical and attributes advisor figures separately.
(Sources: Wall Street research, "Cyber Security: Quarterly Update Q2 2026"; Wall Street research, "Cybersecurity Monthly Review, June 2026," both 30 Jun 2026. Named private-round identities are inferred from matching descriptions to the H1 review's stated June leaders and are unconfirmed.)
2025 in numbers
- Deal count: ~400–426 cybersecurity M&A deals announced (SecurityWeek: 426).
- Disclosed value: ~$84–96B total; eight deals >$1B accounting for ~$75B.
- 9-month software-sector subset (Kroll): 234 deals / $63.3B.
- Theme: mega-cap platform consolidation (Google–Wiz, Palo Alto–CyberArk) alongside a long tail of services/tuck-in deals.
2026 YTD pace (SecurityWeek M&A tracker)
- Jan–Jul 2026: 231 announced deals across SecurityWeek's seven monthly roundups — Jan 34 · Feb 42 · Mar 38 · Apr 33 · May 26 · Jun 37 · Jul 21 (July per SecurityWeek's July 2026 roundup, published Aug 13 2026; June per SecurityWeek's June 2026 roundup). July's 21 is the lightest month of the year on this tracker — a summer lull after June's 37-deal peak rather than a trend break; the annualized pace (~396) runs a touch below 2025's full-year record of 426 by the same tracker. The July roundup's named strategic deals (BofA–MDSec, Barracuda–Evo, Cribl–CardinalOps, CrowdStrike–XM Cyber IP, Cyera–Oasis, Infoblox–Kentik, Okta–Permiso, Palo Alto–Embrace, Qualcomm–SAM, Keyfactor–Cofide) are all captured in the transaction log below. The June long tail beyond the deals logged below is dominated by MSP/MSSP and IT-services tuck-ins (Claranet–Six Degrees, Nexus IT–TecServ, Nordlo–Nethouse, Cegeka–3Point, efex–onPlatinum, Stryve–BITS, Woven–Insignis), federal-mission services (Valiant–BreakPoint Labs), graph/data infrastructure (Neo4j–GraphAware), security training (Mthree–CAPSLOCK), and a quantum-technology SPAC (EigenQ–Silicon Valley Acquisition Corp.).
- Dominant theme: platform vendors buying AI / agentic security specialists in-house (Akamai–LayerX, Torq–Jit, SecurityScorecard–Driftnet, SailPoint–Entro) and asset-centric OT/IoT consolidation (Accenture–Dragos/runZero/NetRise vs. ServiceNow–Armis).
Landmark transactions (2024–2026)
| Date | Acquirer | Target | Value | Sub-segment | Rationale |
|---|---|---|---|---|---|
| announced Mar 2025, completed Mar 11 2026 | Alphabet/Google | Wiz | announced $32B; accounted consideration $29.5B | Cloud security (CNAPP) | Largest cyber deal ever; ~12-month multi-jurisdiction regulatory review (EC cleared Feb 2026); resets cloud-security comps. Alphabet records the completed transaction at $29,467M after purchase price adjustments and excluding post-combination compensation. (Alphabet 10-Q, Q2 2026; TechCrunch, Mar 11 2026) |
| agreed Jul 2025, closed Feb 11 2026 | Palo Alto Networks | CyberArk | announced $25B; accounted consideration $21.1B ($45.00 cash + 2.2005 PANW sh/share) | Identity / PAM | Platformization into identity; PAM now platform-center (see 03a). Palo Alto records $21,061M — $2,308M cash, $18,488M in 112M shares, $265M of replacement awards — the stock leg valued at closing rather than at announcement. (PANW 10-Q, Q3 FY26) |
| announced Sep 21 2023, completed Mar 18 2024 | Cisco | Splunk | announced $28B; accounted consideration $27.1B ($157.00/sh, all cash) | SIEM / observability | SecOps + data platform; license→ratable-cloud transition a multi-quarter revenue drag (Security rev ~flat YoY in Q3 FY26, reported May 13 2026) even as Splunk ARR/RPO compound — the drag lapped in Q4 FY26 (rep. Aug 12 2026): security $2.2B, +14% YoY, with Splunk cited as a growth contributor. Cisco records $27,090M — $26,950M cash for common stock, $137M of converted equity awards attributable to pre-acquisition services, $3M settling pre-existing relationships — the largest all-cash cyber transaction on record and the control case for the announced-versus-accounted gap. (Cisco 10-K FY2024) See 30a, 23 |
| announced Dec 2025, completed Apr 20 2026 | ServiceNow | Armis | $7.75B | OT/IoT security | Asset visibility into ITSM; >3x ServiceNow's security/risk TAM. Completed per ServiceNow newsroom. See 03h, 15f |
| announced Sep 9 2025, completed Jan 28 2026 | Mitsubishi Electric | Nozomi Networks | ~$1B EV (~$883M for remaining 93%) | OT/IoT/CPS security | Industrial OEM buys the OT asset-graph leader; the first of three major OT-independent exits inside six months (w/ Armis→ServiceNow, Dragos→Accenture). (Mitsubishi Electric / BusinessWire, Jan 28 2026) |
| agreed Jun 16 2026, completed Aug 3 2026 (terms N/D) | Databricks | Panther | undisclosed (Panther ~$1.4B val. at 2021 round) | AI SOC / SIEM-replacement (security lakehouse) | Databricks' 3rd security acquisition; brings Panther's SOC workflows, detection-as-code engine and 100+ integrations onto the Lakewatch agentic-SIEM/security-lakehouse foundation; disrupts legacy SIEM on cost and retention. (Databricks, Aug 3 2026) |
| announced Jun 24 2025 (terms N/D) | Snyk | Invariant Labs | undisclosed | Security FOR AI (agentic-AI / MCP runtime defense) | Adds an agentic-AI attack-research team (MCP vulns, tool-poisoning, runtime "Guardrails" for LLMs/agents; coined "tool poisoning" & "MCP rug pulls") into Snyk's AI Trust Platform + Snyk Labs; developer-security platform extends from AppSec into agentic-AI security. Invariant = ETH Zurich spin-off (Marc Fischer/Beurer-Kellner/Vechev/Tramèr). Early entrant — pre-dates the 2026 agentic-AI-security deal wave (date re-verified vs the Snyk PR's "BOSTON, June 24 2025" dateline; recurs as a Jun-2026 search date-trap). (Snyk, Jun 24 2025) See 03l, 20g |
| 2025 | Palo Alto Networks | Chronosphere | $3.3B | Observability | Adjacent to SecOps |
| 2024 | Mastercard | Recorded Future | $2.65B | Threat intel | Fraud/identity adjacency |
| 2025 | Francisco Partners | Jamf | $2.2B | Apple device mgmt/security | Take-private |
| announced Oct 11 2022, completed Feb 1 2023 | Vista Equity Partners | KnowBe4 | $4.6B ($24.90/sh, ~11% premium) | Security awareness / human-risk mgmt | Take-private; founder-CEO Sjouwerman + KKR + Elephant rolled ~$682M equity — Vista's largest cyber control bet. See 06b, 06f |
| agreed Feb 7 2025, completed Apr 16 2025 | Turn/River Capital | SolarWinds | $4.4B ($18.50/sh, ~35% prem. to 90-day avg) | IT mgmt / observability w/ security exposure | Post-breach reset take-private; "growth-engineering" overhaul off the public clock. See 06f |
| announced Oct 21 2024, closed Feb 3 2025 | Sophos (TB) | Secureworks | ~$859M ($8.50/sh) | MDR / SecOps | Services scale + Taegis platform; removes largest independent MDR; ~28k+ MDR customers. See 04b, 06e |
| announced May 2025, closed Aug 1 2025 | Zscaler | Red Canary | ~$675M | MDR | ~4.8× ~$140M ARR; "agentic AI + human expertise" — SASE platform enters SecOps. See 04b, 04c |
| announced Jul 1 2025, closed Aug 19 2025 | LevelBlue (WillJam; AT&T Cybersecurity carve-out) | Trustwave | undisclosed | MSSP | Forms "world's largest pure-play MSSP"; + Alert Logic managed services (Jan 2026) + Stroz Friedberg. See 04a |
| agreed Dec 15 2024, closed Feb 3 2025 | Arctic Wolf | Cylance (BlackBerry assets) | ~$160M total (~$80M cash at close + ~$40M deferred + ~5.5M shares) | Endpoint / MDR | Owned-telemetry move → Aurora Endpoint Security. See 04b |
| announced Apr 28 2025 (close exp. fiscal Q1 2026) | Palo Alto Networks | Protect AI | ~$650–700M (est.; undisclosed) | AI security (security FOR AI) | Becomes Prisma AIRS; largest security-for-AI deal. See 03l, 20g |
| 2024–26 | Cisco / Palo Alto / SentinelOne / Cato / Check Point / F5 / OpenAI / Anaconda / Fortinet | Robust Intelligence / Protect AI / Prompt Security / Aim Security / Lakera / CalypsoAI / Promptfoo / Enkrypt AI / Virtue AI | Protect AI ~$650–700M (anncd Apr 28 2025); Aim ~$300–350M (anncd Sep 3 2025); Lakera ~$300M (anncd Sep 16 2025, completed Q4 2025); Prompt ~$250M (anncd Aug 5 2025); Robust, CalypsoAI, Promptfoo, Enkrypt and Virtue AI all N/D | AI security (security FOR AI) | Platform land-grab: nine security-for-AI companies absorbed between Aug 2024 and Aug 2026 — roughly one every three months, mostly pre-scale. See 20g |
| announced Mar 9 2026 (intent; terms undisclosed) | OpenAI | Promptfoo | undisclosed | AI security — red-teaming / LLM-&-agent evaluation (security FOR AI) | First frontier-lab acquisition of an independent AI-security pure-play. The labs move from validating security partners (Project Glasswing / Daybreak) to buying the harness outright → folds into OpenAI Frontier. Promptfoo (founded 2024; Ian Webster / Michael D'Angelo) probes models for prompt-injection, jailbreak & data-leakage; ~$23M raised ($18.4M Series A Jul 2025, Insight Partners + a16z, ~$86M post). Bear-case "labs absorb the harness" signal for book Ch 26. (OpenAI · TechCrunch, Mar 9 2026 · SecurityWeek) See 20g |
| announced Feb 2026, completed Apr 14 2026 | Palo Alto Networks | Koi | ~$400M | Agentic endpoint security (AES) | First dedicated agentic-endpoint product among the majors — secures autonomous AI coding agents (Claude Code, OpenClaw) on enterprise endpoints; folds into Prisma AIRS + Cortex XDR. Israeli (Unit 8200 founders); had raised ~$48M at ~$135M — a striking step-up for a 2024-founded co. (PANW IR · Ctech, Apr 14 2026) See 20g, 03l |
| 2025 | Akamai | Noname Security (2024) / API | — | API security | API security expansion |
| announced Jun 18 2026 (close exp. Aug/Sep 2026) | Accenture | Dragos (majority) + runZero + NetRise | ~$4.18B EV (Dragos valued $3.25B) | OT/ICS + asset discovery + firmware | Services giant builds asset-centric xOT platform; answer to ServiceNow–Armis. Combined ~$208M ARR (+53% YoY). (SecurityWeek, Jun 18 2026) |
| 2026 | Infoblox | Axur | undisclosed | External threat / digital risk | AI-powered external threat discovery; preemptive-security expansion |
| announced May 14 2026, completed Jul 2 2026 | Akamai | LayerX | ~$205M | Browser/enterprise security | Browser-layer security; closed within the expected Q3 2026 window |
| announced May 19 2026 | Torq | Jit | undisclosed (~$70M est.) | Agentic SecOps / AppSec context | Agentic-SOC roll-up; AI Context Graph (~30 staff, founder David Melamed join); Jit had raised ~$40M. (SiliconANGLE, May 19 2026) |
| announced & completed May 14 2026 | SecurityScorecard | Driftnet | undisclosed | Threat intel / TPRM / attack-surface | Driftnet's high-fidelity internet-scanning engine into the TITAN AI platform; real-time external/third-party risk |
Announced deal value and accounted consideration are different numbers
The value attached to a transaction in press coverage is the figure struck on the day of announcement. The figure the acquirer records when the deal closes is set months later, under accounting rules, and across the four largest cyber closes for which acquirers disclose it, the recorded figure is lower in every case.
| Transaction | Consideration mix | Announced | Accounted consideration | Difference | Accounted vs announced |
|---|---|---|---|---|---|
| Cisco → Splunk | all cash | $28.00B | $27.09B | $0.91B | −3.25% |
| Alphabet/Google → Wiz | all cash | $32.00B | $29.47B | $2.53B | −7.9% |
| Palo Alto Networks → Chronosphere | mixed | $3.35B | $2.95B | $0.40B | −11.9% |
| Palo Alto Networks → CyberArk | ~88% stock | $25.00B | $21.06B | $3.94B | −15.8% |
Four mechanisms account for the gap, and they are separable. Ordering the table by consideration mix rather than by size sorts it almost exactly by the size of the gap, which is the first evidence that the mix is the dominant variable.
Stock consideration is measured at closing, not at announcement. CyberArk shareholders received $45.00 in cash and 2.2005 Palo Alto shares per share. The cash leg is fixed; the stock leg is not. Palo Alto records $2,308M of cash and $18,488M for 112M shares — the share count fixed by the exchange ratio, the price by the market on Feb 11 2026. An announced value struck in July 2025 therefore embeds the acquirer's share price at signing, and the recorded price embeds it at closing. Where an agreement runs seven months and the consideration is 88% stock, the difference is a market movement rather than a renegotiation.
Cisco–Splunk isolates that mechanism by removing it. Splunk was acquired entirely for cash at $157.00 per share, so no part of the consideration could reprice between signing in September 2023 and closing in March 2024. Cisco records total purchase consideration of $27,090M: $26,950M of cash paid for outstanding common stock, $137M for converted Splunk equity awards attributable to pre-acquisition services, and $3M for settlement of pre-existing relationships. The gap to the announced ~$28B is 3.25% — against 15.8% on the stock-heavy CyberArk transaction, a difference of 12.5 percentage points and a gap roughly 4.8 times larger. An all-cash structure does not close the gap to zero, because the remaining mechanisms operate regardless of currency. Wiz is the check on reading too much into this: it was also all cash and still records a 7.9% gap. The difference between the two all-cash cases is disclosure — Cisco itemises every component of the Splunk consideration, while Alphabet attributes the Wiz difference to purchase price adjustments it does not quantify. Where the components are itemised, the non-currency mechanisms come to about three percent; where they are not, the gap can be more than twice that and its composition is unknown.
Replacement equity awards split between price and future compensation. Palo Alto issued $945M of replacement awards on CyberArk and allocated only the portion earned before the acquisition date — $265M — to purchase consideration; the remaining $680M is post-combination share-based compensation, expensed over the remaining service periods. Chronosphere follows the same pattern: $525M issued, $109M to consideration, $416M to future expense. Retention economics that a headline treats as part of the price are, in the accounts, an operating cost of the years that follow.
Settlement of pre-existing relationships is carved out of the price. Where acquirer and target were already trading with each other, the accounting rules require the effective settlement of that relationship to be accounted for separately from the business combination rather than treated as consideration. Cisco records $3M on this line for Splunk. The amount is immaterial at this scale, but the line matters for a different class of transaction: where a platform acquires an existing OEM partner, reseller or technology supplier, the pre-existing contract can be a material fraction of a smaller deal, and it does not appear in the purchase price.
Purchase price adjustments. Alphabet states the Wiz figure is $29.5B "after purchase price adjustments and excluding post combination compensation arrangements." Neither the size of the adjustments nor the amount of the excluded compensation is disclosed, so for Wiz the composition of the $2.53B gap cannot be decomposed from the filing.
The consequence for comparable-transaction work is direct. A precedent set that reads values off announcements and a set that reads them off acquirer filings are measuring different quantities, and mixing them understates nothing consistently — the error runs from 3% to 16% across these four deals and depends on the stock/cash mix, the quality of the acquirer's disclosure, and the interval to closing. Two corrections follow in this wiki. Wiz at an implied ~$1.20B of ARR prices at ~24.6x on accounted consideration against the ~26.7x long carried on announced value (Valuation by Sub-segment). And Palo Alto's revealed price for acquired ARR — the $1.6B of NGS ARR the company attributes to CyberArk and Chronosphere — is ~15.0x on the accounted figures rather than the ~17.7x the announced values imply, a difference that carries into any sensitivity built on that multiple (Buyer-Universe Matrix).
One announcement discloses the split in advance, which is unusual. NVIDIA's agreement to acquire Hugging Face, announced by the acquirer's chief executive in September 2026, states a price of $12,930,300,000 and separately attributes $1.0B of that total to a retention plan for Hugging Face employees — 7.7% of the announced figure. In the closes above, the equivalent split between purchase consideration and post-combination compensation only became visible in the acquirer's business-combination note months after closing. Whether that $1.0B ultimately falls inside or outside recorded consideration depends on the vesting and service conditions attached to it, which are not public, so no accounted figure can be derived here. The disclosure is nonetheless the cleanest available illustration of the mechanism, and the transaction is a forward test of it. The headline figure carried in coverage, $13B, is itself 0.5% above the stated price. (NVIDIA, Sep 3 2026 · SecurityWeek, Sep 4 2026)
Where each figure is the right one. The announced value is correct for what the parties agreed and for market-signalling questions — it is what reset the cloud-security ceiling in March 2025. The accounted figure is correct for any multiple, any aggregate of deal value, and any argument about what a buyer actually paid. This page carries both for the deals where the filing discloses them, and multiples on this page are computed on the accounted figure where one exists.
Purchase price allocation, where disclosed. Business-combination notes are the only public source for how a cyber megadeal's price divides, and the three largest closes disclose it. Splunk: goodwill $19,301M (71.2% of the price), identified intangibles $10,550M (38.9%), and a set of assumed items large enough to change how the transaction reads — $2,422M of acquired cash and $285M of investments, against $3,344M of assumed convertible notes, $2,523M of deferred tax liabilities and $1,854M of deferred revenue written down to fair value across current and non-current portions. The acquired cash alone is 8.9% of the recorded price, so the net cash outlay was closer to $24.7B than to the $28B headline. Wiz: goodwill $22,705M (77.1% of the price), identified intangibles $8,300M (28.2%), net liabilities assumed $(1,538)M including $660M of acquired cash. Intangibles split into developed technology $3,600M (7-yr life), customer relationships $4,500M (10-yr) and trade names $200M. CyberArk: goodwill $14,802M (70.3%), intangibles $6,279M — of which platform renewals $3,500M carry a 12–14 year life, developed technology $2,537M at 5–7 years, customer contracts $219M at 2 years. The Wiz and CyberArk allocations are preliminary, subject to a measurement period of up to twelve months; the Splunk allocation has passed that period. The concentration in goodwill is consistent across all three at 70% to 77% of the price, and is the accounting expression of what is being bought: a market position and an assembled workforce rather than a separable asset. Splunk is the outlier on the other side of the ledger, carrying identified intangibles at 38.9% of price against 28.2% for Wiz and 29.8% for CyberArk — a platform sold on an installed base of long-lived customer contracts allocates more of the price to assets that can be named. The long-lived "platform renewals" intangible at CyberArk is the more unusual disclosure, and it is a direct statement of what Palo Alto believes it acquired.
Channel & distribution precedents (selected)
The channel is its own consolidation theatre — sponsors take security distributors private and roll up services-attached VARs/SIs and MSP→MSSP platforms. These are recurring, financeable assets that trade on services-attach and recurring mix, not product ARR multiples. See Distribution & Marketplaces and VAR/SI & MSP→MSSP.
| Date | Acquirer | Target | Value | Type | Notes |
|---|---|---|---|---|---|
| block agreed Dec 17 2024; tender closed Feb 28 2025; delisted Euronext Paris Mar 21 2025 | CD&R + Permira | Exclusive Networks | ~€2.2B valuation (66.7% block + tender) | Security-specialist distributor (take-private) | Global cyber distribution taken private off Euronext Paris — distribution as a financeable, recurring toll booth |
| announced Apr 2024, closed 2024 | CD&R | Presidio (from BC Partners) | undisclosed | IT solutions provider / VAR-SI | Presidio's second PE owner in five years; BC Partners retained a minority — serial-PE proof of the services-attach thesis |
| 2024 | Optiv (KKR) | ClearShark | undisclosed | Security VAR/SI (federal add) | The archetype security-VAR roll-up adds a federal practice |
| 2022 | Infinigate (Bridgepoint) | Nuvias | undisclosed | Security distributor (buy-and-build) | Forms a pan-European cyber/cloud distribution champion |
Channel deals trade on recurring/managed mix and services attach, and are structurally distinct from vendor-ARR comps.
2026 transaction log (running, newest first)
The growing precedent set, with implied multiples where derivable. ARR/value figures are as-reported or reported-estimate; undisclosed multiples are shown as N/D.
| Date | Acquirer | Target | Value | Sub-segment | Implied multiple | Notes |
|---|---|---|---|---|---|---|
| Sep 3 2026 (financing) | Upwind (round, not M&A) | $300M Series C | $3.8B post-money (total funding ~$730M) | Cloud security — runtime-first CNAPP built on eBPF kernel telemetry, extending to AI workload security | N/D — ARR not disclosed, so no revenue multiple is derivable | Anchored by returning investors Bessemer Venture Partners and TCV, with Salesforce Ventures, Greylock, Craft Ventures, Cyberstarts, Leaders Fund and Alta Park participating. Upwind (founded 2022; San Francisco, engineering in Israel; CEO Amiram Shachar, whose founding team previously built Spot.io, sold to NetApp for $450M) raised a $250M Series B on Jan 26 2026, also led by Bessemer, which took total funding to $430M; the Series C takes it to ~$730M. At the Series B the company reported 900% YoY revenue growth (a tenfold increase), logo growth of 200%, and headcount from 150 to 300-plus, with named customers including Siemens, Waste Management, Carvana, Roku, Nubank and Peloton. The step-up is given as a range, not a figure: the company disclosed no Series B valuation, and press accounts of it run from ~$1.5B to an implied ~$1.8B, so the move to $3.8B is ≈2.1x–2.5x over just over seven months (220 days). Filed as a capitalisation data point, not a valuation comp — the largest independent financing in the runtime/CWPP lane, where the 03b map otherwise shows scaled assets positioning to sell rather than to scale. See 03b, 07. (BusinessWire, Jan 26 2026 · SiliconANGLE, Sep 3 2026 · SC Media) |
| announced Sep 1 2026 | Palo Alto Networks (NASDAQ: PANW) | Console | undisclosed | AI FOR Security — an AI-native platform for building agentic workflows from natural-language instructions and executing them across enterprise systems | N/D — no consideration disclosed and neither party reports revenue | Announced in the same release as Q4/FY26 results (23). Console's platform takes an operational objective stated in natural language and has AI agents perform the analysis and actions needed to meet it, connecting to identity systems, SaaS applications and security tools to gather context, execute a workflow and record what was done. It is folded into Cortex, extending that platform's agentic capability past security operations into general enterprise workflow; CEO Nikesh Arora frames the acquired capability as customers holding "a direct conversation with data" and building remediation workflows in natural language. Two reads, kept separate. (1) Category: this is the workflow-and-orchestration layer above a detection engine the acquirer already owns — the same shape as Brinqa–PlexTrac and Cribl–Radiant (both Aug 19 2026), making three such prints inside a fortnight and reinforcing that the contested layer in security operations is the one that decides and acts rather than the one that detects. See 04c, 03e. (2) Scope: the stated ambition reaches beyond security into "the broader enterprise agentic transformation," which places a security platform in competition for a workflow-automation budget that is not a security budget — the demand-side counterpart to the infrastructure-vendor encroachment logged at 20g. Terms undisclosed, so the print establishes direction rather than price, and it does not disturb the FY26 acquired-ARR arithmetic on [23]. (SecurityWeek, Sep 1 2026 · Palo Alto Networks, Sep 1 2026) |
| Sep 1 2026 (financing) | AIR Security (round, not M&A) | $50M seed, across two rounds | valuation undisclosed | Security FOR AI — discovery of AI agents running inside an enterprise, continuous vetting of the skills, tools and components those agents load, and blocking of interactions that fail policy | N/D (ARR undisclosed; company emerged from stealth at announcement) | Two seed rounds closed within weeks of each other: an initial $10M led by Sequoia Capital, then $40M led by Greenoaks Capital. Founded by CEO Yair Saban and CTO Niv Hoffman, both Unit 8200 alumni; the company was roughly six months old at launch. Angels include Yinon Costica (co-founder, Wiz), Ofir Erlich (co-founder, Eon), Zach Frankel (president, Cognition), Varun Anand (co-founder, Clay) and former US deputy national security adviser for cyber Anne Neuberger. The product also operates a marketplace of pre-vetted agent skills and add-ons. The structural point is the object being secured: this is a supply-chain control for agent components — the skills, tools and connectors an agent pulls in at run time — rather than a model-layer or prompt-layer guardrail, which places it alongside 03f as much as 20g. A $50M seed for a six-month-old company is a capitalization data point for the security-for-AI cohort, not a valuation one, since no valuation was disclosed. See 20b, 20g. (TechCrunch, Sep 1 2026 · SiliconANGLE, Sep 1 2026) |
| announced Aug 24 2026 | Ampcus Inc. | SmarterD | undisclosed | GRC / IT-and-security data convergence — a platform that consolidates IT, security and compliance data held across separate enterprise systems into a single interface for risk monitoring, workflow automation and analysis | N/D — no consideration disclosed and neither party reports revenue | A services buyer acquiring software, which is the reverse of the direction most of the 2026 tape runs in. Ampcus is a privately held Virginia-based IT, digital-transformation and cybersecurity services firm; SmarterD is placed inside its cybersecurity and risk-management division, the brand is retained, and the platform is to be sold into Ampcus's existing enterprise base with the stated emphasis on regulated industries. SmarterD chief executive Mike Santos steps back from day-to-day operations while the team and technology continue under Ampcus ownership; Salil Sankaran, president of Ampcus Inc., frames the rationale as connecting cybersecurity, compliance and IT operations that enterprises currently manage through separate systems. Structural read: this is the small-end instance of the route treated on 04h — a services firm buying recurring software revenue rather than a platform buying a services business. The scale anchor for the same motion is Accenture's ~$4.175B Dragos/runZero/NetRise assembly at roughly 20× ARR (Jun 18 2026), 67 days earlier. With terms undisclosed, this print establishes direction rather than price. See 04h, 03i, 04-service-providers. (The American Bazaar, Aug 25 2026 · CIO Influence · Ampcus) |
| announced Aug 19 2026 | Brinqa | PlexTrac | undisclosed | Exposure management / offensive-security validation — pen-test reporting, workflow and evidence software; the validation stage of CTEM | N/D — no consideration disclosed and neither party reports revenue, so no multiple, valuation or step-up is derivable | An exposure-management platform acquiring the software penetration testers use to record, prioritize and report findings, placing validation at both ends of the remediation cycle: proving an exposure exploitable before an engineer is assigned, and retesting afterwards to confirm the fix held. Company-reported combined scale is 3,000+ customers across 57 countries, including more than 25% of the Fortune 500; Brinqa describes the result as the largest standalone vendor in unified exposure management, a vendor characterization rather than an independent measurement. Both companies were named in Gartner's inaugural Magic Quadrant for Exposure Assessment Platforms. PlexTrac's products continue to sell standalone; founder Dan DeCloss joins Brinqa's executive leadership team and board of directors to lead the combined offensive-security practice. Structure is the notable feature: the two companies share a sponsor. Insight Partners led Brinqa's $110M growth round (June 2021) and PlexTrac's $70M Series B (February 2022), roughly 4.5 years before this transaction — so the deal consolidates two positions inside one portfolio rather than transferring an asset between unrelated owners, which is why no arm's-length price signal emerges from it. Brinqa (founded Austin, 2009) reported 164% YoY growth in new bookings for 2025 and a 32% increase in new-logo average selling price, with new-logo bookings more than doubling YoY in 2026 — company-reported, unaudited, and not reconcilable to any revenue base. PlexTrac was founded in Boise in 2018. Brinqa was advised by Covington & Burling. Read against the adjacent tape: on Aug 3 2026 Horizon3.ai raised a $250M Series E at a $2B valuation to build autonomous validation as a standalone; 16 days later a validation-tooling vendor exited into an exposure platform instead — two different structures for the same capability layer inside the same month, one funding independence and one ending it. See 03k, 04f. (Brinqa, Aug 19 2026 · SiliconANGLE, Aug 19 2026) |
| announced Aug 19 2026 | Cribl | Radiant Security — technology assets and intellectual property only | undisclosed | AI FOR Security — AI-native SOC: autonomous alert triage, investigation and resolution | N/D | Cribl's second security acquisition of 2026, 36 days after CardinalOps (Jul 14), and structured around technology rather than a company: the transaction covers technology assets and intellectual property from Radiant Security's AI-native SOC product, not the business. Cribl is adapting the technology to run as an application on its telemetry platform, executing investigations directly against data the platform already collects and routes; the stated design point is that triage logic is generated per alert rather than drawn from pre-built playbooks. Radiant Security had raised a $15M Series A led by Next47 in November 2023, roughly 2.8 years before the transaction; Cribl was valued at $3.5B at its last disclosed round (August 2024). Two reads, kept separate. (1) Structure: an asset-and-IP purchase is the second such print in the security tape within about a month — cf. CrowdStrike–XM Cyber (intellectual property only, Jul 16) — and it is the first dated evidence of what an exit looks like at the mid-tier of the venture-funded AI-SOC field catalogued on 04c, where capital has run well ahead of production penetration. Terms were not disclosed, so it establishes structure rather than price. (2) Buyer identity: the acquirer is a telemetry-pipeline vendor, making this the third data-layer buyer to absorb security-operations capability inside roughly two months — after Cisco–WideField into Splunk (announced Jun 19) and Databricks–Panther (closed Aug 3, 16 days earlier). Cribl's stated rationale is that capabilities which once justified a standalone product increasingly make more sense running on a shared telemetry platform than as a separate tool with its own data silo. Further platform additions are stated for CriblCon on Sep 28, 2026. See 04c, 42a, 03e. (Cribl, Aug 19 2026 · SiliconANGLE, Aug 19 2026) |
| Aug 19 2026 (financing) | Prevalent AI (round, not M&A) | $22M growth round | valuation undisclosed | Security data fabric — cleaning, connecting and contextualizing fragmented enterprise security data into a knowledge graph that security teams and AI agents query for context | N/D (ARR undisclosed) | Sole investor Integrity Growth Partners. Founded 2017 in London by former GCHQ and Darktrace leaders (co-founder and CEO Paul Stokes); bootstrapped for nine years before this round, which makes it an unusual profile in a category where the comparable names are venture-funded from seed. Proceeds directed at US expansion, go-to-market, extending the platform beyond cybersecurity, and leadership hires. The positioning sits on the seam between security data pipelines (03e, cf. DataBahn) and the context layer agents need to act — the same problem the agentic-SOC cohort solves from the detection side. (SecurityWeek, Aug 19 2026) |
| announced Aug 18 2026 | Fortinet (NASDAQ: FTNT) | Virtue AI | undisclosed; Fortinet stated the amount paid was immaterial to its business | Security FOR AI — agentic-system red teaming, agent protection and governance, continuous AI validation, real-time runtime guardrails | N/D — no consideration disclosed; Virtue AI had raised $30M in seed and Series A funding in 2025 | The last of the major network-security incumbents to enter security-for-AI by acquisition, and the ninth company absorbed into that category since Aug 2024 (see the cohort table on 20g). Virtue AI's platform runs automated red teaming using more than 100 proprietary attack algorithms across hundreds of attack vectors and risk categories, simulates enterprise scenarios to evaluate agent tool usage, system access and multi-step execution, and at runtime applies guardrails across text, code, audio, video and image while blocking unsafe agent actions before execution and scanning generated code and tools. Fortinet cites agentic red teaming, agent protection and governance, continuous validation and runtime guardrails as the capabilities acquired. The price characterization is the notable term: earlier entries in this cohort cleared $250–700M for pre-scale assets, so a stated-immaterial consideration marks the first platform entry at what appears to be a materially lower clearing price. SecurityWeek's M&A tracker has catalogued more than 240 cyber deals in 2026 to date. See 03l, 20g, 03d. (SecurityWeek, Aug 18 2026 · Virtue AI) |
| Aug 18 2026 (financing) | Xpander (round, not M&A) | $7.5M seed | valuation undisclosed | Agent enablement and governance — a vendor-neutral "universal agent harness" that executes AI agents as portable workloads and renders interfaces on demand | N/D (ARR undisclosed) | Led by Pico Venture Partners, with Emerge Ventures, Samsung Next and Seedil. San Francisco; founded 2024 by former AWS engineers David Twizer (CEO), Moriel Pahima (CTO) and Ran Sheinberg (CPO). Logged here as a market-structure data point rather than a security transaction: the company positions primarily as AI enablement infrastructure and treats governance over agents as a property of the runtime it supplies. Where that framing wins, part of the agent-governance budget is captured by infrastructure vendors before a security vendor is engaged — the counter-position to the specialist cohort on 20g and to the incumbent bundles on 03a. (SecurityWeek, Aug 18 2026) |
| announced Aug 14 2026 | Datavault AI (NASDAQ: DVLT) | CyberCatch Holdings (TSXV: CYBE / OTCQB: CYBHF) | US$94.5M all cash (US$3.53 per share; approximately 26.8M shares) | GRC / continuous-compliance automation — control validation mapped to NIST CSF 2.0, NIST SP 800-171, CMMC, ISO 27001, HIPAA and PCI DSS, plus continuous agentic-AI penetration testing | N/M — consideration is not supported by current revenue | A definitive agreement structured as a court-approved plan of arrangement under the Business Corporations Act (British Columbia), replacing the binding letter of intent of May 1, 2026, which had contemplated an all-stock deal at C$5.11 per CyberCatch share (approximately C$136.8M, roughly 49.9M newly issued Datavault AI shares, leaving CyberCatch holders about 7.52% of the combined equity). The re-cut from stock to cash 105 days later is the notable structural feature: a Nasdaq-listed acquirer that first proposed paying in its own equity ultimately paid cash. Scale context: CyberCatch reported revenue of approximately C$0.23M over the twelve months to April 30, 2026 and C$0.40M in the fiscal year ended July 31, 2025, so no meaningful revenue multiple is derivable — the consideration reflects the patent estate (USPTO 11,297,094, "Automated and Continuous Cybersecurity Assessment with Measurement and Scoring," plus the patent-pending MARS-MABE multi-authority attribute-based encryption acquired in February 2026 and being converted to post-quantum resistance), the regulated-sector customer base across the US defense supply chain, healthcare and financial services, and a platform rationale rather than acquired ARR. Founder, Chairman and CEO Sai Huda (previously founder/CEO of Compliance Coach, acquired by FIS) is to serve as president of the subsidiary from San Diego; the board and advisory board include former DHS Secretary Tom Ridge and former DARPA information-systems director Dr. Marv Langston. Closing is subject to CyberCatch shareholder approval, British Columbia court approval, and TSX Venture Exchange approval. A compliance-automation print landing while the CMMC Phase II transition is suspended (16a) — the near-term certification catalyst is paused, but the continuous-control-validation asset still traded. See 03i, 04f, 16a. (Datavault AI, Aug 14 2026 · BusinessWire · May 1 2026 LOI — Seeking Alpha · revenue — S&P Global Market Intelligence via StockAnalysis) |
| Aug 12 2026 (financing) | Mindgard (round, not M&A) | $30M Series A | valuation undisclosed (total funding ~$42M) | Security FOR AI — automated AI red-teaming, shadow-AI discovery & runtime AI protection | N/D (ARR undisclosed) | Led by Album VC, with Karma Ventures and existing backers .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar; total funding reaches ~$42M. Mindgard (founded 2022, spun out of Lancaster University; HQ London and Boston; CEO James Brear, founder/CTO Dr. Peter Garraghan) runs an automated AI-security and red-teaming platform — shadow-AI discovery, continuous AI red-teaming, and run-time protection across models, agents, and AI applications; it reports uncovering 150-plus publicly disclosed AI security and safety vulnerabilities. Filed Security-for-AI (securing the AI itself), in the AI red-teaming / AI-SPM lane alongside Protect AI→Palo Alto, Lakera→Check Point, and Enkrypt AI→Anaconda. See 20, 03l, 07. (SecurityWeek, Aug 13 2026 · BusinessWire, Aug 12 2026 · FinTech Global) |
| Aug 10 2026 (financing) | Corma (round, not M&A) | $60M seed | valuation undisclosed | AI FOR Security — purpose-built defensive cybersecurity foundation model powering autonomous defense agents | N/D (ARR undisclosed) | Led by Sequoia Capital, with Khosla Ventures and Coatue. Corma (founded 2025; Tel Aviv and San Francisco; ~20 staff in Tel Aviv; co-founder and CEO Alon Pluda) is building what it calls the first frontier defensive cybersecurity AI lab — a foundation model trained specifically on security telemetry (logs, audits, pattern detection) rather than a general-purpose model applied to security, which powers AI agents that operate across an organization's existing security tools as an end-to-end "virtual analyst." A distinct AI-for-Security archetype: rather than embedding copilots in a platform (A-products) or building agents on GPT/Claude/Gemini, Corma is capitalizing a security-specific base model as the substrate for defensive autonomy — and delivering it as agents that do the work of security staff (the software-eats-services thread). Reported early Fortune 100/500 deployments cut threat-response times by more than 94% and expanded coverage roughly 15x; valuation undisclosed. Positioned explicitly against AI-cheapened offense (15). See 20, 07, 04c. (Sequoia, Aug 10 2026 · Fortune · Calcalist/CTech) |
| announced Aug 6 2026 | AXA XL (property, casualty and specialty division of AXA SA) | S-RM (UK; the remaining shares, AXA XL having already held ~49%) | undisclosed | Cyber consulting and incident response — cyber risk assessment, managed detection and incident response, specialist investigations, geopolitical intelligence, and integrity and reputational due diligence | N/D — no consideration disclosed and neither party reports S-RM revenue, so no multiple, valuation or stake-implied enterprise value is derivable | An insurance carrier acquiring the remainder of a cyber-services firm it already part-owned. The two had worked together for over 15 years, as client and as investor. S-RM was founded in 2005, operates nine offices across six continents and supports clients in more than 140 countries; it is to sit inside AXA XL Risk Advisory, a business unit created for prevention. The economics of the purchase differ from those facing a strategic or sponsor buyer of the same asset. A carrier holds the loss on its own balance sheet, so a claim avoided or shortened accrues to it directly, and it can underwrite a services business partly against claims severity in its own cyber book rather than against the services margin alone — a basis a services acquirer cannot compute. The counter-case sits in the same value chain and runs the other way: Aon, a broker, sold Stroz Friedberg and Elysium Digital to LevelBlue (announced Jun 11 2025, completed Aug 1 2025, approximately 300 professionals, terms undisclosed) while retaining its cyber brokerage, CyQu platform and Cyber Risk Analyzer. A broker earns commission on placement and carries none of the loss. The dividing line is not insurance against security but whether the owner carries the risk — which places carriers (AXA XL here, Travelers–Corvus in 2024) on one side and brokers on the other. A comparable-transaction set for a cyber-services asset that blends carrier buyers with services and advisory buyers therefore mixes two pricing bases. Completion expected by the end of September 2026, subject to regulatory approvals. See 24a, 24, 04e. (AXA XL, Aug 6 2026 · Infosecurity Magazine — August 2026 M&A roundup, Aug 31 2026 · LevelBlue — completion of the Aon consulting acquisition, Aug 1 2025) |
| announced Aug 4 2026 | Anaconda (private; Python / data-science platform) | Enkrypt AI | undisclosed | Security FOR AI — AI red-teaming, runtime guardrails, AI-SPM & compliance automation across the model/agent/MCP lifecycle | N/D (ARR undisclosed) | A non-security-vendor strategic buyer — Anaconda, the enterprise Python and data-science platform — acquiring an AI-security pure-play to secure its own AI build-and-deploy lifecycle, extending platform governance "from a builder's first prompt to the AI-native application running in production." Enkrypt AI provides pre-deployment red-teaming across 300-plus attack categories, runtime guardrails that block jailbreaks and sensitive-data leakage, coverage across the agent and MCP-server stack, and compliance automation that turns the NIST AI Risk Management Framework and the EU AI Act into enforceable guardrails (Enkrypt research reported ~143,000 vulnerabilities across ~268,000 tools on ~25,000 MCP servers, affecting ~73% of servers scanned). A distinct buyer archetype in the Security-for-AI consolidation: not a security platform absorbing AI security as a feature (Protect AI→Palo Alto, Robust Intelligence→Cisco) but an AI/data-science platform internalizing it to make its own AI outputs trustworthy — and a demand data point tied to the Aug 2, 2026 EU AI Act GPAI-enforcement milestone (16b). Terms undisclosed. See 20, 03l, 16b. (Anaconda, Aug 4 2026 · Enkrypt AI · Security Info Watch) |
| announced Aug 3 2026 | Visa (NYSE: V) | BioCatch (Israel / US) | $2.4B cash | Fraud intelligence / behavioral biometrics — behavioral-first, multi-signal fraud detection (account-takeover, scams, mule accounts, application fraud); identity / anti-fraud adjacency | ~13x ARR (~$185M ARR at end-2025) | A payments network acquiring a behavioral-biometrics fraud-intelligence platform from funds advised by Permira and other shareholders — the direct parallel to Mastercard–Recorded Future (~$2.65B, 2024) on the landmark table above (card networks integrating cyber and fraud intelligence upstream of the transaction). BioCatch analyzes thousands of behavioral, device, and network signals (keystrokes, touch gestures, device handling) to distinguish legitimate users from fraudsters in real time; it protects ~1.8 billion devices and ~760 million users across 350-plus banks in 21 countries and analyzes ~19 billion sessions monthly. Implied ~13x on ~$185M ARR (2400 / 185 = 13.0x); for Permira — which took ~60% at a ~$1.3B valuation in September 2024 — the sale marks roughly a 1.85x step-up in the enterprise valuation over ~22 months. Visa frames the demand as AI-enabled: account takeovers and scams that "AI is enabling at unprecedented scale" against a stated >$1T annual global cost — the C-offense demand side driving a strategic, non-vendor buyer. Close expected by the end of Visa's fiscal Q2 2027, subject to regulatory approval. See 03a, 15d. (Visa, Aug 3 2026 · BioCatch PR · CNBC · Bloomberg) |
| announced Aug 3 2026 (closed Jul 31 2026) | Deel (private; HR / payroll / EOR platform) | Clarity (Tel Aviv, Israel) | ~$45–50M (media-reported; cash + Deel shares) | Identity verification / deepfake detection / workforce fraud prevention — AI-for-Security identity, with a C-offense (AI-enabled deepfake & impersonation) demand driver | N/D (ARR undisclosed) | A non-vendor strategic buyer outside the security sector absorbing a deepfake-defense primitive — the same pattern as Visa–BioCatch above, on the workforce/hiring fraud vector rather than the payment rail. Deel (which said it surpassed ~$1.5B ARR in H1 2026) acquires Clarity (co-founders CEO Michael Matias, CTO Ziv Isaiah) in its 15th acquisition and first in Israel; Clarity's engineering team joins to form Deel's first dedicated cybersecurity division. Clarity's identity-verification, deepfake-detection, and fraud-prevention stack extends from pre-hire candidate screening into employee onboarding and day-to-day workforce access — a response to the "fake hire" / deepfake-interview problem (Gartner projects one in four candidate profiles globally could be fraudulent by 2028). Terms undisclosed by Deel; the ~$45–50M figure is media-reported (Calcalist/CTech) and should be treated as an estimate (press-release-vs-media reliability caveat, see 11a). See 03a, 15d. (Deel, Aug 3 2026 · Calcalist/CTech · TechFundingNews · TNW) |
| Aug 4 2026 (financing) | Obsidian Security (round, not M&A) | $85M Series D | ~$1.1B valuation (total funding >$200M) | Security FOR AI — non-human identity & AI-agent runtime governance across third-party SaaS applications | N/D (ARR undisclosed) | Led by Crescent Cove Advisors, with existing backers Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, GV, and Wing participating; total funding surpasses $200M at a first reported unicorn valuation (~$1.1B). Obsidian (Palo Alto, CA; CEO Hasan Imam) discovers and inventories every AI agent, MCP server, and large language model operating inside third-party SaaS applications and governs their runtime behavior — blocking privilege escalation, excessive data access, and policy violations at the point of execution — with new coverage extending to Anthropic Claude Code/Cowork, Microsoft Copilot, Salesforce Agentforce, OpenAI, and n8n. It reports 60 Fortune 500 customers, 100-plus customers spending over $100K a year and 14-plus above $1M. Filed Security-for-AI on the agent-governance/non-human-identity frontier — the same runtime-governance lane as Zenity and Onyx (securing what agents may do and access), distinct from identity issuance (Keyfactor–Cofide, Oak, Neo) and from the AI-for-Security SOC/posture lane (Mate/Discern). The second nine-figure agent-governance round in two days (after Zenity, Aug 3) and the first to price the lane at a unicorn valuation. See 03l, 20, 07. (SecurityWeek, Aug 4 2026 · SiliconANGLE · FinTech Global) |
| Aug 4 2026 (financing) | Oligo Security (round, not M&A) | $60M round | valuation undisclosed (total funding ~$140M; valuation reported more than doubled since Series B) | AI FOR Security — runtime application/cloud & AI-systems protection (application detection & response) | N/D (ARR +300% YoY; absolute ARR undisclosed) | Participants include Ballistic Ventures, Canon Capital, Greenfield Partners, Lightspeed Venture Partners, Red Dot Capital, TLV Partners, and angels; total funding reaches ~$140M. Oligo (founded 2022, Tel Aviv) provides deep runtime visibility and real-time protection across application code, cloud workloads, and AI systems — using code-execution observability to block exploit attempts, prioritize the vulnerabilities that actually execute at runtime, and virtually patch — positioned against the shrinking window between vulnerability disclosure and AI-accelerated exploitation. Recently named AWS's exclusive AI-runtime-security partner for AWS Security Hub Extended and joined Palantir's FedStart program (a FedRAMP High / IL5 path). Filed AI-for-Security (a runtime-protection product raising the ceiling on the security function), with an AI-systems runtime component and a demand tailwind from AI-cheapened offense (15); distinct from the Security-for-AI agent-governance lane. See 03f, 07. (SecurityWeek, Aug 4 2026 · Globes · SiliconANGLE) |
| Aug 3 2026 (financing) | Zenity (round, not M&A) | $125M Series C | valuation undisclosed (total funding ~$185M) | Security FOR AI — AI-agent security & governance (real-time monitoring of agent actions) | N/D (ARR undisclosed) | Led by Norwest, with new investors SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, and Qumra Capital joining existing backers Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital; total funding reaches ~$185M. Zenity (research in Tel Aviv, operations in New York; co-founders Michael Bargury and CEO Ben Kliger; ~230 staff) secures AI agents inside enterprise systems — mapping how agents are embedded, monitoring their actions in real time, and blocking or altering behavior that deviates from an agent's intended purpose or corporate policy, with a stated focus on regulated sectors (financial services, telecom, healthcare, pharma, energy) and Asia-Pacific demand. Filed Security-for-AI on the agent-security/governance frontier — securing the agents, distinct from the AI-for-Security SOC/posture lane (Mate/Discern) and from identity issuance (Neo/Hush/Act/Oak). One of the largest dedicated Security-for-AI rounds to date and the first with strategic corporate backing (SoftBank, Hitachi, LG) tied to enterprise agent adoption — a data point bearing on whether agent governance becomes a durable independent category or is absorbed pre-scale (see 03l). See 20, 07. (Fortune, Aug 3 2026 · SiliconANGLE · BusinessWire) |
| Aug 3 2026 (financing) | Horizon3.ai (round, not M&A) | $250M Series E | $2B valuation (Series D was $100M) | AI FOR Security — autonomous penetration testing / continuous security validation | N/D (ARR growth 120% YoY; absolute ARR undisclosed) | Co-led by returning investors NightDragon and NEA, with seven new and five returning backers; the valuation more than tripled from ~$650M since June 2025. Horizon3.ai (founded 2019) runs NodeZero, autonomous "friendly agent" pentesting that continuously probes a customer's own network with attacker techniques and reports exploitable paths and fixes — reframing point-in-time pen-testing as continuous, machine-speed validation. Reports 7,000+ customers (four Fortune 10) and 120% YoY ARR growth; proceeds earmarked for go-to-market (MSP/telco channels) and R&D. The largest autonomous-pentest/AEV financing to date, filed AI-for-Security (autonomous validation raising the ceiling on the security function), with a demand tailwind from AI-scaled offense (15). See 04f, 07. (SecurityWeek, Aug 3 2026 · TechCrunch · SiliconANGLE) |
| announced Aug 3 2026 (effective Jul 31 2026) | Logicalis US (Datatec) | Loial (New Mexico) | undisclosed | Security services / managed services — security-operations modernization, Splunk / SIEM integration | N/D | Datatec's Logicalis US acquires 100% of Loial, a New Mexico cybersecurity and managed-services provider and Splunk partner serving energy, utilities, government, and healthcare; the deal establishes a permanent Logicalis location in New Mexico and expands its Southwest team. A VAR/integrator adding regional security-operations and SIEM capability — the services-and-channel consolidation pattern (see 05b, 04a). (GlobeNewswire, Aug 3 2026 · IT-Online, Aug 3 2026) |
| announced Jul 30 2026 | Okta (NASDAQ: OKTA) | Permiso Security | undisclosed by Okta (~$200M media-reported — SC Media / CyberScoop) | Identity threat detection & response (ITDR) / identity posture — across human, non-human & agentic identities (Security FOR AI–adjacent) | N/D | Definitive agreement extending Okta beyond identity management into security operations. Permiso — cloud-native ITDR/CIEM that detects and mitigates threats across human, machine and AI-agent identities in multi-cloud (emerged from stealth 2022; co-founders Paul Nguyen and Jason Martin, ex-FireEye; threat-research arm P0 Labs) — will be unified with Okta's identity-posture capabilities into a single ITDR offering and pull Okta into the SOC. The third major non-human/agent-identity consolidation print in a week, after Cyera–Oasis (~$1B, Jul 28) and the Hush/Act funding cluster (Jul 28) — an identity incumbent absorbing agentic-identity detection. Okta did not disclose terms; the ~$200M figure is media-reported and should be treated as an estimate (press-release-vs-media reliability caveat, see 11a). Closed Aug 26 2026, 27 days after announcement and confirmed alongside Okta's Q2 FY27 results; Permiso's runtime detection and identity-posture capabilities fold into the Okta identity security platform and the P0 Labs research team joins Okta's research operation. See 03a, 20b, 23. (SecurityWeek, Jul 30 2026 · SecurityWeek — close confirmed, Aug 27 2026 · Okta PR · CyberScoop) |
| announced Jul 30 2026 | Bank of America (NYSE: BAC) | MDSec Consulting (UK) | undisclosed | Security services — offensive / deeply technical security consultancy (red-teaming, adversary simulation, pen-testing) | N/D | A captive / end-user acquisition: a global bank buying a boutique offensive-security consultancy (~65 professionals, Macclesfield, England; co-founder Dominic Chell) to build red-team and technical-security capability in-house, expanding Bank of America's UK cyber operations near its Chester threat-operations center (CISO Kris Fador). Close expected Q4 2026, subject to regulatory approvals. A less common buyer archetype for the deal record — an enterprise consumer of security services vertically integrating a specialist consultancy, taking capacity off the third-party services market rather than a vendor or sponsor consolidating it (see 04). (SecurityWeek, Jul 30 2026 · Bank of America PR) |
| Jul 30 2026 (financing) | Discern Security (round, not M&A) | $13M Series A | valuation undisclosed | AI FOR Security — agentic security-posture / control-optimization ("Agentic Loops") | N/D | Led by cyber specialist Forgepoint Capital (First Rays Ventures, Growth Enjin Partners, Vela Ventures). Founded 2023 (California); the platform continuously evaluates and improves an organization's existing security controls, combining AI agents with human-approved workflows to identify control gaps and prioritize remediation. Filed AI-for-Security (agents running/improving the security function), distinct from the Security-for-AI agentic-identity rounds. See 07, 04c. (SecurityWeek, Jul 30 2026 · PR Newswire) |
| Jul 30 2026 (financing) | DataBahn (round, not M&A) | $40M Series B | valuation undisclosed (total funding ~$59M) | AI FOR Security — agentic security-data control plane / data-pipeline management | N/D | Led by Insight Partners, with Forgepoint Capital, GTM Capital, and S3 Ventures continuing; total funding reaches ~$59M. DataBahn builds an agentic "data control plane" that ingests, filters, enriches, and routes enterprise security and observability telemetry before it reaches the SIEM/SOC — cutting data volume and cost and feeding AI-driven detection. Filed AI-for-Security on the data-infrastructure side: the security data pipeline that feeds the agentic SOC, distinct from the SOC/posture agents (Mate/Discern) and from the Security-for-AI identity lane. See 07, 04c. (SecurityWeek, Jul 30 2026 · PR Newswire) |
| Jul 29 2026 (financing) | Onyx Security (round, not M&A) | $113M Series B | $640M valuation (total funding ~$153M) | Security FOR AI — enterprise "AI control plane" (discovers, monitors & remediates risks from AI agents) | N/D | Led by Bessemer Venture Partners with Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, G Squared. Founded 2024 (Maxim Bar Kogan, Gil Elbaz); reports quadrupling revenue in ~4 months since leaving stealth, Fortune 500 customers, ~80 staff (Israel/US/Canada). The largest AI-agent-governance round of the July cluster — same securing-the-AI-workforce thesis as Neo/Hush/Act, but from the governance/control angle (what agents may do and access) rather than issuing agent identities. See 07, 20g. (SecurityWeek, Jul 29 2026 · CTech · BusinessWire) |
| announced Jul 28 2026 (agreement; LOI reported) | Cyera | Oasis Security (Israel) | ~$1B (reported ~$700M cash, balance in Cyera stock) | Non-human identity (NHI) / AI-agent identity & access governance (Security FOR AI) | N/D (Oasis raised ~$195M total; $120M Series B Mar 19 2026) | Cyera — the data-security/DSPM valuation bellwether (~$12B after its Jun 2026 round) — extends beyond data security into machine- and agent-identity governance, pairing DSPM's map of what sensitive data exists with Oasis's map of which humans, machines, and AI agents can access it. Oasis (founded 2022; CEO Danny Brickman, CPO Amit Zimerman) builds NHI lifecycle management and posture for service accounts, tokens, keys, and AI agents. The largest NHI/agent-identity print to date — roughly 2.5x the Cisco–Astrix intent (~$400M) and ~5x SailPoint–Entro (~$200M), resetting the comp set for the niche and removing one of its largest remaining independents. See 20b, 03g. (SecurityWeek, Jul 28 2026 · TechCrunch) |
| Jul 28 2026 (financing) | Mate Security (round, not M&A) | $35M Series A (total funding beyond $50M) | valuation undisclosed | AI FOR Security — agentic security operations (AI SOC: autonomous detection, investigation & response) | N/D | Led by Canaan Partners with Microsoft's M12, Insight Partners, and Team8. An AI-driven agentic security-operations platform that detects, investigates, and responds to threats with autonomous agents; heading to Black Hat USA. Filed AI-for-Security (agents running the security function), the SOC-side companion to Discern's posture/control lane — distinct from the Security-for-AI agentic-identity cluster (Neo/Hush/Act/Onyx). See 07, 04c. (CTech · Pulse 2.0) |
| announced Jul 27 2026 | The Carlyle Group (NASDAQ: CG) | Secturion Systems | undisclosed | Government / defense — high-speed, NSA-certified hardware encryption for classified data (airborne, maritime, ground systems) | N/D | Carlyle's first investment through its new dedicated middle-market Aerospace, Defense & Government and Industrials platform (reported to be raising up to ~$3B). Secturion (founded 2012, Centerville UT; customers include the US Navy and Boeing) makes high-assurance hardware encryption for defense platforms. Sean Berg — former CEO of Everfox, the government-cyber business carved out of Forcepoint — named CEO; COO Josh Falslev and CTO Derek Owens continue. D.A. Davidson advised Secturion. A sponsor stepping into cyber-adjacent defense hardware rather than the security software/services large-caps usually underwrite — see 06c, 14. (Carlyle, Jul 27 2026 · Washington Technology · GovCon Wire) |
| announced Jul 27 2026 | Keyfactor | Cofide (UK) | undisclosed | Machine / workload & AI-agent identity — SPIFFE-based verified, short-lived workload and agent identities (Security FOR AI–adjacent) | N/D | Keyfactor — the machine-identity / PKI platform (Atlanta and Stockholm; "Trust Control Plane"; backed by Summit Partners, Insight and Sixth Street after its Jul 6 2026 ~$1B growth investment) — acquires Cofide (founder and CEO Matthew Bates), an open-standards workload-and-agent identity platform built on SPIFFE, OAuth and OIDC that issues each software workload and AI agent a unique, short-lived verified identity in place of static, copyable secrets (its "Cofide Connect" solution). Extends the Trust Control Plane from certificates and PKI into cloud-native workload and agentic identity — the issuance side of the same 2026 non-human-identity consolidation wave as Cyera–Oasis (governance, Jul 28) and Okta–Permiso (detection, Jul 30). Terms undisclosed; team and technology join immediately. Reads as the first strategic acquisition off Keyfactor's July growth capital, which was explicitly earmarked in part for M&A (03a). See 20b. (Keyfactor PR, Jul 27 2026 · Pulse 2.0) |
| announced Jul 21 2026 | Palo Alto Networks (NASDAQ: PANW) | Embrace | undisclosed | Observability / digital-experience monitoring — real-user monitoring (RUM) across mobile & web; not a security product | N/D | Adds Embrace's high-fidelity real-user-monitoring across mobile and web to the Palo Alto Networks Observability platform — extending it into Digital Experience Monitoring — announced alongside a new Synthetics capability for proactive application-performance validation. An observability/DEM tuck-in rather than a security acquisition; logged here because it appears in the SecurityWeek July 2026 M&A roundup and because PANW's observability build-out (cf. its 2025 Chronosphere deal) sits adjacent to the Cortex SecOps data platform. Terms undisclosed; close expected in Q1 FY27. (Palo Alto Networks PR, Jul 21 2026 · SecurityWeek) |
| announced Jul 16 2026 | CrowdStrike (NASDAQ: CRWD) | XM Cyber — intellectual property only (from Schwarz Digits) | undisclosed | Exposure management — attack-path visualization / offensive simulation | N/D | Unusual IP-only structure: definitive agreement covers XM Cyber's intellectual property — more than 45 patents plus proprietary source code — with no revenue or customers acquired; XM Cyber continues operating as a standalone Schwarz Digits business under an IP license back from CrowdStrike, and its customers are offered a migration path to the Falcon platform via Falcon Flex. Announced alongside a broader expansion of the CrowdStrike–Schwarz Digits partnership: a multi-year roadmap to deliver the Falcon platform on STACKIT, Schwarz Digits' EU-operated sovereign cloud. Schwarz Group had acquired XM Cyber for ~$700M in 2021; the IP now feeds Falcon Exposure Management. Close expected in the second half of CrowdStrike's fiscal 2027 (Aug 2026–Jan 2027), subject to regulatory approvals. See 03k. (CrowdStrike PR, Jul 16 2026 · CTech · Investing.com) |
| Jul 15 2026 (financing) | Oak (round, not M&A; emerged from stealth) | $60M seed | N/D | Identity — AI-native "Identity Operating System" (human, machine & AI-agent identities) | N/D | Co-led by Accel, Greylock Partners, and CRV, with Hetz Ventures, AlphaDrive Ventures, and strategic angels — one of the largest seed rounds in identity security. Founded Dec 2025 (Tel Aviv + San Francisco) by Shai Morag (CEO; three prior exits totaling ~$500M: Integrity-Project→Mellanox 2014, Secdo→Palo Alto Networks 2018, Ermetic→Tenable 2023) and Tal Marom (CPO). A single AI-native control plane intended to replace the fragmented identity-governance/security stack, governing every identity — human, machine, or AI agent; generally available and deployed at enterprise customers at launch. Extends the mega-seed pattern in agent-era identity (cf. NewCore $66M, Ent $100M) — repeat-founder pedigree pre-loading time-to-trust (07d); see 03a, 20b. (PR Newswire, Jul 15 2026 · TechCrunch · CTech) |
| announced Jul 14 2026 | Cribl | CardinalOps (Israel) | undisclosed | AI FOR Security — agentic detection engineering (threat-coverage assessment, detection-rule validation & gap analysis) | N/D | Cribl — the security/observability data-pipeline platform — acquires CardinalOps, an AI-native detection-engineering startup whose agents map an organization's deployed detections against adversary techniques (MITRE ATT&CK), continuously test whether detection rules fire as intended, and flag broken, noisy, or missing coverage. Folds into Cribl's telemetry collection/routing/storage to position the combined platform as a lower-cost SIEM-modernization path (keep existing tools while cutting data cost); Cribl is opening a Tel Aviv office post-deal. An AI-for-Security detection-engineering print — automating work previously done by SOC/detection engineers (the software-eats-services thread). See 04c, 03. (Cribl, Jul 14 2026 · SiliconANGLE · Dark Reading) |
| Jul 13 2026 (financing) | Valarian (round, not M&A) | $50M Series A (~$70M total raised) | N/D | Sovereign infrastructure / AI-workload control layer (UK) | N/D | Led by NEA — reported as NEA's first defense/dual-use investment in Europe — with Lightbank, XTX Markets, Sequel, LitVC, and angels including Nikesh Arora and Gokul Rajaram. Valarian's ACRA control layer sits atop Kubernetes to govern AI models, agents, and workloads: organizations keep using US hyperscaler clouds while the layer controls what data leaves, who touches it, and when — digital-sovereignty demand (European governments and enterprises seeking control without leaving AWS/Azure) productized as a control plane rather than a sovereign cloud (see 14). (SecurityWeek, Jul 2026 · Fortune, Jul 13 2026) |
| Jul 10 2026 (non-binding LOI) | Data I/O Corporation (NASDAQ: DAIO) | IAR embedded software security assets (from I.A.R. Systems AB / Qt Group, Nasdaq Helsinki: QTCOM) | undisclosed | Embedded / IoT security — secure provisioning, device identity | N/D | Letter of intent, not a definitive agreement — Data I/O proposes to acquire IAR's embedded-security IP and related assets (the Embedded Trust and Secure Deploy platforms, the eSecIP toolchain, certificate-authority and provisioning infrastructure), bringing in-house the technology behind the companies' February 2026 collaboration; the commercial partnership continues. Rationale is explicitly regulatory: the EU Cyber Resilience Act mandates lifecycle security for connected products sold in the EU by December 2027, making security provisioning a compliance requirement for OEMs. IAR acquired the portfolio in 2018; Qt Group is divesting a non-core line to a partner — a carve-out pattern in embedded security. (Data I/O / IAR joint PR, Jul 10 2026, via GlobeNewswire) |
| announced Jul 8 2026 | Infoblox | Kentik | undisclosed | Network observability / network intelligence (into DDI + preemptive security) | N/D (Kentik founded 2014; raised >$100M) | Definitive agreement, subject to regulatory approvals — unites Infoblox's authoritative DNS/DDI and asset visibility with Kentik's multi-cloud network observability to power "AgenticOps" (an AI-driven, infrastructure-centric network + security operations platform). Infoblox's 2nd acquisition of 2026 (Axur, May 5) — networking-data depth as the substrate for agentic operations. (Infoblox PR / GlobeNewswire, Jul 8 2026 · Kentik) |
| announced Jul 8 2026 | Viatel Technology Group (Ireland) | FullProxy (Scotland) | undisclosed | Security services / consultancy (UK & Ireland channel) | N/D | Irish telecom-and-IT group adds a Scottish cybersecurity consultancy to its security practice, extending its presence in Scotland and the wider UK — the European telco/channel services consolidation pattern (see 05b). (CyberWire Business Briefing, Jul 8 2026) |
| announced Jul 7 2026 | Barracuda Networks (KKR) | Evo Security | undisclosed | Identity — IAM + PAM for the MSP channel | N/D | Adds Evo Security's multi-tenant IAM/PAM platform (MFA, SSO, help-desk verification, RADIUS, privileged elevation; founded 2018, Texas) to the BarracudaONE platform, giving it a four-layer identity architecture (access control, SecureEdge ZTNA, Entra ID backup, Managed XDR) for MSPs; Evo's team joins Barracuda. With CyberFOX–Timus (Jun 29), the second MSP-channel security consolidation print in nine days — identity moving into the single-vendor MSP bundle (see 05b, 03j). (Barracuda PR / BusinessWire, Jul 7 2026 · SiliconANGLE) |
| announced Jul 7 2026 | Databarracks (UK) | Acumen (business-continuity consultancy) | undisclosed | Security services — business continuity / operational resilience consulting | N/D | UK data-protection and business-resilience provider adds a specialist BC/resilience consultancy to its managed-services practice — a small services tuck-in in the resilience lane (per the Infosecurity July 2026 M&A roundup; see 04). (Databarracks, Jul 7 2026 · Infosecurity July roundup) |
| Jul 6 2026 (financing) | Keyfactor (round, not M&A) | $1.0B strategic growth investment | valuation undisclosed | Machine / PKI identity — certificate lifecycle, PQC & AI-enterprise identity | N/D | Led by Summit Partners (with continued backing from existing investors); one of the largest cyber growth rounds of 2026. Capital to expand leadership in securing the AI and post-quantum enterprise — certificate lifecycle management, PKI, and machine/workload identity at scale. A late-stage capitalization of the non-human/machine-identity theme driving 2026 M&A (cf. SailPoint–Entro, 1Password–Apono, Cisco–WideField); positions Keyfactor as a scaled independent and eventual strategic asset in PKI + post-quantum crypto (see 03a, 20b). (Keyfactor PR / PR Newswire, Jul 2026) |
| Jul 1 2026 (announced) | Qualcomm (NASDAQ: QCOM) | SAM Seamless Network (Israel) | >$100M (Globes; Calcalist reported >$150M) | Connected-device / IoT / network-edge security (telco CPE) | N/D (SAM raised ~$30M total; last round 2021 at ~$60M val. → implied ~1.7–2.5x on last-round value, not revenue) | Silicon/edge platform absorbs IoT-security — Qualcomm buys SAM's client-side network protection (guards >500M connected devices across ~15M networks; customers incl. AT&T, Verizon, Bezeq, Telenet, Virgin Media) to thicken the security layer under CEO Cristiano Amon's edge-AI-device strategy (on-device AI compute → needs on-device defense). SAM = ~80 staff (Israel + US); founders Sivan Rauscher (CEO) + Shmuel Chafets (Target Global); prior backers Intel Capital, Verizon Ventures, BlackBerry, Blumberg Capital. SAM stays an independent unit. Qualcomm's 2nd small Israeli buy after Autotalks (~$80–90M, 2025). A rare strategic exit for an under-scaled 2016-vintage IoT-security co — reference point for consumer/telco-CPE-security tuck-ins. (Globes, Jul 1 2026 · Calcalist) |
| Jun 30 2026 (announced) | Aikido Security (Belgium) | Root (Root.io) | ~$70–100M (est.; not officially disclosed — SecurityWeek June roundup) | Open-source supply-chain security / AI-agent auto-patching (AI FOR Security) | N/D | Root's swarms of specialized AI agents research, write, test and ship a verified patch in ~15–40 minutes — backported to the exact pinned versions/containers a customer already runs (no upgrade, no migration). Folded into a new Aikido Libraries product; Aikido commits to releasing backported fixes for critical actively-exploited OSS vulns to the community. The clearest print yet that machine-speed patching is an acquirable capability — the remediation leg of the discover→validate→remediate loop consolidating (cf. BOD 26-04 demand pull on 16). (GlobeNewswire, Jun 30 2026 · SiliconANGLE · Help Net Security) |
| Jun 30 2026 (financing) | Eye Security (round, not M&A) | €60M (~$68.5M) Series C | N/D | European MDR/MSSP + integrated cyber insurance (SME/mid-market) | N/D | Led by Sofina (minority stake), with an increased commitment from TIN Capital and continued backing from J.P. Morgan Growth Equity Partners and Bessemer — reported as the largest funding round to date for a Dutch cybersecurity company. Capital for European market expansion, AI-powered capabilities, and team growth; a scaled European mid-market MDR-plus-insurance platform (see 04b, 24). (Eye Security PR, Jun 30 2026 · FinTech Global) |
| announced Jun 29 2026 | CyberFOX | Timus Networks | undisclosed | MSP-channel security — SASE / ZTNA into an identity & access platform | N/D | Both Tampa-based; adds SASE with zero-trust network access, secure web browsing, and adaptive policy enforcement to CyberFOX's MSP-focused identity/access stack — the MSP security stack consolidating toward single-vendor bundles (see 05b). (GlobeNewswire, Jun 29 2026) |
| Jun 29 2026 (completed) | Intrusion Inc. (NASDAQ: INTZ) | VigilAigent (from Tego Cyber Inc.) | undisclosed | AI-native MSSP / agentic managed detection | N/D (adds ~$3.5M ARR) | Micro-cap ($14M mkt-cap) programmatic tuck-in: adds ~$3.5M ARR of multi-year contracts, 80+ resellers, ~1,000 customers. Folds VigilAigent's "The Oracle" agentic-AI engine (~1B events/day) into Intrusion's TraceCop IP-reputation DB (8.5B addresses) → "AI-native" platform. CEO Tony Scott (ex-US federal CIO). An AI-for-Security micro-cap roll-in (cf. Cycurion–Secuvant) — same programmatic-signal / falsifiability caveat: relative to a ~$14M base this is not a small bolt-on, and INTZ carries a going-concern flag, so integration/cross-sell execution is the test. (ACCESS Newswire, Jun 29 2026) |
| Jun 24 (financing) | Runlayer (round, not M&A) | $30M Series A | N/D (~$42M total raised) | Security FOR AI — MCP / AI-agent security & governance | N/D | Led by Felicis w/ Khosla Ventures (Vinod Khosla reportedly sought "every available dollar"). Wraps security, compliance, observability & cost-control around the Model Context Protocol — tool-mapping, human sign-off on sensitive actions, full-session observability; catches prompt injection, tool poisoning, exfiltration, intent drift. Adopters: Gusto, dbt Labs, Instacart, Opendoor. A front-runner in the agent-governance race — textbook future sell-side. See 20, 20b. (PR Newswire, Jun 24 2026 · Fortune) |
| announced Jun 25 2026 (completed) | Incode Technologies | Identiq (Israel) | undisclosed | Identity verification / privacy-enhancing anti-fraud (PETs) | N/D | Adds Identiq's peer-to-peer, zero-data-sharing cryptographic fraud-validation network to Incode's AI identity-verification platform — "privacy by design" fraud prevention without pooling PII. Identity-fraud consolidation adjacent to the IAM M&A wave. (Incode PR, Jun 25 2026 · Infosecurity June roundup) |
| Jun 25 2026 (financing) | Nebulock (round, not M&A) | $25M Series A | $132.5M post-money | Autonomous threat hunting — AI-native "hunt-first" context / behavioral detection engineering | N/D | Series A to bring hunt-first context to the enterprise: an AI platform that surfaces false negatives and turns threat hunts into hardened behavioral detections (multi-threads hypothesis testing; scans telemetry for policy violations, lateral movement, and attacker pre-positioning). Boston-based, founded 2023. An AI-for-Security detection-engineering entrant in the automated-threat-hunting / agentic-SOC race (see 20, 20a). (BusinessWire, Jun 25 2026) |
| Jun 23 (in-play — REPORTED, not a deal) | Blackstone / Thoma Bravo / Vista (preliminary interest) | Varonis (NASDAQ: VRNS) | rumored — N/D | Data security / DSPM | ~3.9x 2027 EV/Rev (current public) | REPORTED preliminary PE takeover interest only — NO formal process/deal confirmed (Bloomberg, Jun 23 2026). VRNS +~14% to ~$37.42 on the report; trades ~3.9x 2027 EV/rev vs ~7.3x scaled-cyber peers; discount dates to Oct 2025 on-prem renewal-rate drop. Live take-private case — see Book Ch 11 |
| announced Jun 22 2026 | Booz Allen Hamilton (NYSE: BAH) | Ultra I&C Mission Solutions (from Cobham Ultra Group) | $720M | Defense technology — mission-critical software, encryption, edge compute | N/D | Definitive agreement; close expected in Booz Allen's fiscal Q2 FY27 (quarter ending Sep 30, 2026), subject to customary conditions. Booz Allen expects strong double-digit revenue growth from the unit with EBITDA margins above 20%; will operate as a wholly owned subsidiary. Defense-services prime buying product-grade encryption/edge-compute — the services-to-product migration in the government lane (see 14, 04). (Booz Allen PR / BusinessWire, Jun 22 2026 · WashingtonExec) |
| announced Jun 22 2026 | F5 (NASDAQ: FFIV) | SurePath AI | undisclosed (SurePath had raised ~$6M) | Security FOR AI — shadow-AI discovery / network-based AI governance | N/D | Announced alongside the launch of the F5 AI Security Platform; SurePath's network-based detection of shadow AI usage (unsanctioned models, agents, and AI tools observed in traffic) becomes the discovery layer of F5's AI-security stack — application-delivery incumbent building an AI-governance product line by acquisition (cf. A10–TrojAI the week prior; the network/ADC tier absorbing AI security). (F5 PR, Jun 22 2026 · GeekWire) |
| Jun 18 | Accenture | Dragos (majority) + runZero + NetRise | ~$4.175B EV | OT/ICS + asset discovery + firmware | ~20x ARR (combined ~$208M ARR, +53% YoY) | Dragos valued $3.25B; remains independent under CEO Robert M. Lee; close Aug–Sep. Competitive answer to ServiceNow–Armis. See 03h |
| Jun 18 | Cisco | WideField Security | undisclosed | Identity lifecycle / non-human identity → Splunk Agentic SOC | N/D | Identity telemetry correlation/normalization feeding Splunk's Agentic SOC (identity, credentials, sessions, blast radius); secures AI-agent / NHI / autonomous workloads. Cisco's 3rd cyber deal of 2026 (after Galileo, Astrix Security) |
| Jun 18 (financing) | Dream (round, not M&A) | ~$260M raise | $3B valuation | Sovereign AI / cyber for governments & critical infrastructure | N/D | Israeli AI-cyber for nation-state/CNI; ~3x step-up from $1B (Feb 2025); led by Bicycle Capital + Group 11. Sovereign-AI demand signal — see 14, 20 |
| announced Jun 16 2026 | Francisco Partners | EfficientIP (Paris) | undisclosed | DDI (DNS / DHCP / IP address management) + DNS security | N/D | PE takes the French DDI/DNS-security specialist from its founders and minority investors TempoCap and Jolt Capital, in partnership with management; CEO Norman Girard stays and the founders reinvest. 1,500+ customers across finance, telecom, energy, and the public sector. A European network-infrastructure-security platform play in the same lane Infoblox (Warburg/portfolio) anchors — DNS-layer security consolidating under sponsor ownership (cf. Infoblox–Kentik, Jul 8). Advisors: Arma Partners + IA Global Capital (sell side), GP Bullhound (buy side). (Francisco Partners PR / BusinessWire, Jun 16 2026 · EfficientIP) |
| Jun 16 (financing) | Ent (Ent.ai; emerged from stealth) | $100M seed | N/D | Workspace / endpoint security — "prevention" (intent-aware, human + AI-agent actions) | N/D | One of the largest seed rounds in cyber history. Founders = RiskIQ co-founders / ex-Microsoft Security Copilot team (Manousos, Dixon). Led by Decibel; Sequoia, Crosspoint, Craft, Shield, Felicis, In-Q-Tel. Pedigree as pre-loaded time-to-trust — see 07d. (Business Wire, Jun 16 2026) |
| announced Jun 9 2026 | Rubrik (NYSE: RBRK) | Strata (Strata.io) | undisclosed | Identity orchestration → identity resilience | N/D | Announced at Rubrik FORWARD 2026 (BusinessWire PR dateline Jun 9; some trade coverage ran Jun 17); Strata's identity-orchestration layer (unifying fragmented IAM across multi-cloud/hybrid without app rewrites) powers a new Identity Continuity capability — automatic failover to a secondary identity provider so authentication keeps running through a cyber incident — plus Identity Roll Forward (restoring identity systems without reintroducing attacker persistence). Rubrik's identity segment reported at >$50M ARR and its fastest-growing line — cyber-resilience vendor buying its way into identity infrastructure. (Rubrik IR PR, Jun 17 2026 · StorageNewsletter, Jun 17 2026) |
| announced Jun 17 2026 | Quest Software (Clearlake Capital) | Anetac | undisclosed | Identity observability — human, non-human & agentic identities | N/D | Extends Quest's Microsoft-ecosystem identity security (Active Directory management/recovery) with Anetac's continuous discovery of identities, access chains, and privilege inheritance across hybrid environments — built for the machine-identity sprawl the vendor cites at up to 82:1 machine-to-human. Anetac: founded 2023, ~40 staff, CEO Timothy Eades (ex-vArmour). PE-backed platform tuck-in in the identity-observability lane (cf. Rubrik–Strata, Jun 9; SailPoint–Entro, Cisco–WideField the same month). (Quest PR / GlobeNewswire, Jun 17 2026 · BankInfoSecurity) |
| Jun 17 (financing; → Jul 20 extension) | Twenty (round, not M&A) | $100M Series B, + $30M Khosla Ventures (Jul 20 2026) | $1.2B valuation (Jul 2026 extension, up from $1B; total ~$168M) | Offensive cyber-warfare (AI end-to-end systems for US military/IC) | N/D | Arlington, VA; CEO Joe Lin. Led by Accel (Friends & Family, Point72 Ventures, Caffeinated); July extension led by Khosla Ventures (Jon Chu). Backers incl. In-Q-Tel, General Catalyst, and Tim Junio (ex-Expanse CEO; Expanse→PANW, $1.25B, 2020) — an In-Q-Tel-funded offensive-cyber unicorn; Pentagon deployment reported Jul 2026; see 14, 14e, 08a |
| Jun 11 (financing) | Cyera (round, not M&A) | $600M raise (some reports ~$300M) | $12B post-money | Data security / DSPM | N/D | Valuation ~2x in ~12mo ($6B Jun'25 → $9B Jan'26 → $12B, >$150M ARR); board includes Frank Slootman (appointed Mar 25 2025, not part of this round); the data-security valuation bellwether. See 03g |
| announced Jun 15, completed Jun 29 2026 | SailPoint | Entro | ~$200M (reported) | Non-human identity (NHI) / secrets / AI-agent security | N/D (Entro raised ~$24M total; $18M Series A led by Dell Technologies Capital) | Feeds SailPoint's Agentic Fabric (launched Mar 2026); deep secrets discovery, machine-identity threat detection. Founded Oct 2022 (Alvas/Shriki). A CVC-funnel print — Dell Tech Capital (strategic CVC) seeds, then SailPoint (TB-backed strategic) buys. See 08a |
| Mar 18 2026 (financing) | XBOW (round, not M&A) | $120M Series C | $1B+ valuation | Autonomous offensive security / AI pentest | N/D | Led by DFJ Growth + Northzone (Sofina, Alkeon, Altimeter, Sequoia); ~$237M total raised. Founder Oege de Moor (ex-GitHub Copilot/CodeQL); agent hit #1 on HackerOne US (Jun 2025). Graduating-class + AI-offense signal — see 20a, 07g. (SecurityWeek, Mar 18 2026) |
| Jun 15 | 1Password (AgileBits) | Apono | ~$250–300M (reported ~$275M) | Identity / JIT access governance — humans, machines & AI agents (NHI) | N/D (Apono ~80 staff, ~50 in Israel) | Extends 1Password from credential security to access governance: just-in-time, policy-scoped, auto-revoked access for every human/machine/AI identity; pairs with the new Credential Broker (private beta). Part of the identity-for-AI-agents wave (cf. SailPoint–Entro, Cisco–Astrix/WideField, CrowdStrike–SGNL). (BusinessWire, Jun 15 2026; SiliconANGLE) |
| Jun 15 | A10 Networks (ATEN) | TrojAI (Canada) | undisclosed | AI security — red-teaming / runtime threat detection for AI models & agents (security FOR AI) | N/D | Adds TrojAI's two-layer AI security (red-teaming probes + runtime threat protection for agentic workflows) to A10 Networks' hardware-based AI firewall; future integration across on-premises, cloud, hybrid environments. Supports sovereign AI security mandate — customer control over AI model/data/agent protection on customer infrastructure. Positioning as a defense-infrastructure vendor upgrading to AI-aware network security. (A10 Networks PR, Jun 15 2026 · Finance.yahoo) |
| Jun 15 (financing) | NewCore (round, not M&A; emerged from stealth) | $66M seed | $300M valuation | Identity security for humans & AI agents (NHI / agentic) | N/D | Led by Cyberstarts; Index Ventures, Evolution Equity. CEO Zohar Alon (founder of Dome9, sold to Check Point); co-founders incl. ex-Unit 8200 research lead + ex-CIO T-Mobile/Telstra. "Split-key" credential architecture; "Agentic Skill" packs for Claude Code / Codex / Cursor. A large seed validating the AI-agent-identity land-grab — see 03a. (TechCrunch, Jun 15 2026; SiliconANGLE) |
| reported May 24 2026 | Cyera | Genie Security | ~$50M (est.; reported) | Endpoint data protection / GenAI data-leak DLP (DSPM extension) | N/D (Genie ~5 months old, ~$3M raised, ~5 staff) | A ~5-month-old endpoint data-protection startup whose real-time DLP targets sensitive-data leakage through GenAI tools (Claude et al.); folded into Cyera's data-security platform, extending DSPM to the endpoint. Fast acqui-hire-scale exit. Date/value reported, not from a primary filing (Calcalist · Times of Israel). See 03g |
| announced Jun 1 2026 | Dragos | Phosphorus | undisclosed | xIoT security & device management (OT/IoT) | N/D | Dragos bought the xIoT specialist 17 days before Accenture took its majority stake (Jun 18) — extending the Dragos Platform to embedded/connected devices ("xOT: the full environment that matters," per CEO Robert M. Lee) and fattening the asset Accenture then acquired alongside runZero + NetRise. Completes the IoT-edge picture in the OT/ICS consolidation (see 03h). (Dragos PR, Jun 1 2026 · Infosecurity June roundup) |
| announced Jun 2 2026 (closed Jun 1) | Vobis Ventures | Optiv — Advisory, Consulting & Transformation (ACT) business (carve-out) | undisclosed | Security services — project-based advisory/consulting | N/D | Optiv divests its project-based ACT services unit (~500 consultants and forward-deployed engineers; 800+ enterprise clients) to technology investor Vobis Ventures, which makes it the foundation of an AI-native cybersecurity services business operating initially as Optiv Consulting, with Vobis as Optiv's exclusive services partner for a year; industry veteran Anup Kumar named CEO. Barclays advised Optiv. A services-sector carve-out print: the largest US pure-play security VAR/integrator shedding lower-margin project consulting to focus on its core — the software-eats-services re-rating showing up in portfolio shape (see 04, 36). (Optiv PR / PR Newswire, Jun 2 2026) |
| Jun 2 2026 (completed) | Cycurion (NASDAQ: CYCU) | Secuvant (Panoptic platform) | undisclosed (merger) | MSSP / continuous threat & vulnerability mgmt | N/D | Small-cap serial tuck-in; pitched as a "higher-margin, recurring-revenue" portfolio expansion. A textbook programmatic-roll-up signal — not proof: for a buyer this size the deal is not small relative to the base, so the falsifiability test (falling integration cost, durable organic growth) bites harder. See 30a. (SEC Form 8-K, Jun 2026) |
| announced May 14 2026, completed Jul 2 2026 | Akamai | LayerX | ~$205M | Secure enterprise browser / AI usage control | N/D | Definitive agreement May 14; completed Jul 2 2026 (~7 weeks sign-to-close, inside the expected Q3 window); extends Zero Trust into the browser; governs GenAI/SaaS-AI usage. (Akamai PR / SecurityWeek · completion PR, Jul 2 2026) |
| announced May 19 2026 | Check Point | Deepchecks (team + IP) | ~$15M (est.; reported $10–20M, undisclosed) | AI evaluation / LLM observability (security FOR AI) | N/D | Acqui-hire of the Israeli AI-evaluation/monitoring startup, announced alongside Check Point's Agentic Network Security Orchestration platform; LLM-output validation feeds autonomous-agent trust. Check Point's 4th Israeli cyber buy of 2026 (after Cyclops, Cyata, the Rotate acqui-hire). See 03l, 20g. (CTech · Security Boulevard) |
| announced May 19 2026 | Torq | Jit | ~$70M (est.; undisclosed) | Agentic AI SOC / context graph | N/D | Org-specific "AI context graph" ("the grounding layer the AI SOC has been missing"; ~30 staff, founder David Melamed; Jit raised ~$40M from Boldstart/Insight/Tiger) for Torq's AI SOC agentic investigations — the post-model harness an operator buys instead of another model. (BusinessWire May 19 2026 · SiliconANGLE) |
| May 14 | SecurityScorecard | Driftnet | undisclosed | Threat intel / TPRM | N/D | Real-time internet discovery into TITAN AI TPRM platform |
| May 6 (announced; rollout 2026–27, subject to approvals) | Allianz Commercial | Coalition (book transfer + equity) | undisclosed (Allianz takes increased equity + board seat) | Cyber insurance (active-insurance MGA) | N/D | Allianz transitions its standalone commercial cyber book to Coalition (the MGA owns pricing/product/loss-control/claims); min 10-yr alignment; carrier "rents the underwriting brain." Landmark carrier↔insurtech convergence — see 24a, 24b. (GlobeNewswire, May 6 2026) |
| May 5 | Infoblox | Axur | undisclosed | External threat / digital risk protection | N/D | Launches DRPS; foundation for CTEM in Infoblox Exposure Management |
| May 4 (intent announced; not yet closed) | Cisco | Astrix Security | ~$400M (reported) | Non-human identity (NHI) / AI-agent identity | N/D (Astrix ~$85M total raised) | "Securing the agentic workforce" — discovery/governance/lifecycle for AI agents & NHIs; Cisco's 2nd cyber deal of 2026. Subject to closing. Resets the NHI comp set (see 20b). (Cisco, May 4 2026) |
| Feb (rep.) | Zscaler | SquareX | undisclosed | Browser security / detection | N/D | Browser-security arms race; extends SSE/Zero Trust into the browser session |
| announced Jan 8 2026, closed Feb 20 2026 | CrowdStrike | SGNL | $627.9M (net of cash acquired; plus $8.9M equity-award value) | Continuous/real-time identity, NHI & AI-agent access | N/D (SGNL ~$30M early round Feb '25; backers incl. Cisco Investments, Microsoft's venture fund) | Real-time grant/revoke of access for human, non-human & AI identities into Falcon; a CVC-funnel exit — two strategic CVCs on the cap table, then a third strategic buys (see 08a). Deal closed within CRWD FQ1 (ended Apr 30 2026); consideration per SEC 10-Q Form filing (May 30 2026). (CrowdStrike, Jan 8 2026; CrowdStrike 10-Q / SEC EDGAR; SecurityWeek) |
| Jan 13 2026 (announced) | CrowdStrike | Seraphic Security | ~$400M (reported; terms undisclosed, predominantly cash + some vesting stock) | Enterprise browser security | N/D | Adds browser-layer protection to Falcon; kicks off the 2026 browser-security M&A wave; CrowdStrike Falcon Fund had backed Seraphic's Jan 2025 Series A — a CVC invest→buy round-trip (see 08a). (CrowdStrike, Jan 13 2026; ~$400M per Calcalist) |
| Dec 8 '25 (close) | Proofpoint (Thoma Bravo) | Hornetsecurity | $1.8B | Email security / M365 / MSP channel | ~9x ARR (~$200M ARR, +20% YoY) | Buys Proofpoint into the SMB/MSP channel; 125k customers via 12k MSPs; the template for SEG incumbents acquiring channel + AI. See 03j |
Strategic-acquirer / buyer-universe matrix
See The Buyer-Universe Matrix: the table below gives the names by sub-segment; 11b classifies the buyer universe by archetype (platform strategic / adjacent-sovereign / large-cap sponsor / roll-up platform / growth equity) and how each underwrites and prices a deal.
Who buys in which sub-segment — the starting point for any sell-side buyer list and any buy-side competitive read. (Strategics shown; PE platforms — Thoma Bravo, Vista, KKR, TPG, Silver Lake, Crosspoint, STG, Francisco — buy scaled assets across all rows via take-private/carve-out.)
| Sub-segment | Most likely strategic acquirers |
|---|---|
| Identity / PAM / machine identity | Palo Alto, CrowdStrike, Microsoft, Okta, SailPoint, Cisco |
| Cloud security (CNAPP/DSPM) | Palo Alto, CrowdStrike, Wiz/Google, Microsoft, Zscaler, Fortinet |
| SecOps / SIEM / XDR | Microsoft, Google, CrowdStrike, Palo Alto, Cisco |
| Endpoint / XDR | Microsoft, CrowdStrike, SentinelOne, Palo Alto, Sophos |
| Network / SASE / SSE | Palo Alto, Fortinet, Cisco, Zscaler, Cloudflare, Check Point |
| AppSec / supply chain | Palo Alto, Snyk, GitLab/GitHub (Microsoft), Checkmarx, Cisco |
| Data security / resilience | Rubrik, Cohesity, Varonis, Microsoft, Zscaler |
| OT / ICS | ServiceNow, Honeywell, Siemens, Dragos, Claroty, Cisco |
| GRC / TPRM | ServiceNow, Vanta, Drata, OneTrust, Mastercard |
| Exposure mgmt / BAS / PTaaS | Tenable, Qualys, Rapid7, CrowdStrike, Cortex/Palo Alto, Microsoft, Google/Wiz, Schwarz (XM Cyber) |
| AI security | Palo Alto, Cisco, CrowdStrike, Wiz/Google, Microsoft, cloud providers |
| Threat intel | Mastercard, Google (Mandiant), CrowdStrike, Recorded Future |
| Email / collaboration | Proofpoint (TB), Mimecast (Permira), Microsoft, Cloudflare, Check Point, Abnormal (acquirer-track) |
| MDR / managed services | Sophos, Zscaler, Arctic Wolf, CrowdStrike, PE roll-up platforms |
Building a comparable-transaction analysis
A comparable-transaction analysis is built in five steps:
- Comp set: same sub-segment, similar size/growth, recent (last 18–24 months).
- Metrics: EV, target revenue/ARR, growth rate, EBITDA (if profitable), strategic vs. financial buyer.
- Multiples: EV/Revenue and EV/ARR (primary in cyber), EV/EBITDA (for services/profitable).
- Adjustments: control premium (strategic > financial), scarcity premium (category leader), growth premium, synergy value.
- Triangulation with public-company trading comps (12) and the weekly Wall Street research.
Updated 2026-09-08 20:44 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.