Cybersecurity M&A: Who Is Buying Whom, and Why the Consolidation Is Accelerating
Cybersecurity M&A is on a record pace in 2026, but the mega-deals hide the real story: platforms are buying up identity and AI capabilities while the crowded middle gets starved. Here is who is buying whom, and why.
Every few weeks in 2026, another cybersecurity company disappears into a bigger one. The headlines fixate on the giants: Google closing its $32 billion purchase of Wiz, Palo Alto Networks absorbing CyberArk for around $25 billion. Those numbers are real, and they are also a distraction. They tell you the top of the market is expensive. They tell you almost nothing about what is actually reshaping the field.
The real story is underneath the mega-deals, in the steady drumbeat of $50 million to $400 million acquisitions that reorganize entire categories quarter by quarter. That is where you can see who is buying whom, and why. I spend my time on the buyer side of this market, watching which vendors get shortlisted and which get deleted. The same logic that decides a shortlist decides an acquisition, and in 2026 it is pointing in one direction.
Cybersecurity M&A is accelerating because three forces now point the same way: platforms need to close capability gaps faster than they can build, AI is spawning new categories worth buying, and capital is concentrating around a shrinking set of winners. In 2026 the buyers are the platform incumbents, and identity is the prize.
How big is the 2026 cybersecurity M&A wave?
By any measure, this is a record year. Industry trackers put the first half of 2026 at well over 200 disclosed cybersecurity transactions, with the pace running at the highest deal count ever recorded, per Momentum Cyber's mid-year 2026 review. Disclosed deal value in the first half landed near $9 billion, and that figure excludes the largest strategic acquisitions that closed with undisclosed or separately reported terms.
My own read of the deal flow says the same thing from a narrower vantage point. According to Mandos platform data (August 2026), we tracked 109 cybersecurity acquisitions in 2026 to date, weighted toward the venture-backed deals that matter most to founders and investors. That is roughly one acquisition every two days, in a single dataset that deliberately excludes most of the services and reseller roll-ups. The tempo is not slowing.
The naive read of a record deal count is that the market is healthy and everyone is winning. The sharper read is that a record number of companies are choosing, or being forced, to sell rather than raise. A busy M&A market is not the same as a thriving startup market. It is often the opposite.
Who is buying whom in cybersecurity right now?
The buyers fall into three camps, and each is acquiring for a different reason.
The first camp is the platform incumbents closing gaps. Palo Alto Networks, Cisco, Check Point, Zscaler and Cloudflare are buying to fill holes in their coverage before a customer notices the hole exists. Cisco alone made multiple acquisitions in the first half, including a $400 million deal for non-human identity capability. Check Point closed three acquisitions on a single day in February. These companies are not buying revenue. They are buying the ability to say yes to one more line item in a platform RFP.
The Mandos Brief
Analysis like this, every Monday. Ten minutes.
The second camp is the identity specialists consolidating their own category. Okta, SailPoint, 1Password, Delinea and Silverfort are acquiring smaller identity companies to keep pace with a threat surface that has exploded. Human identity was the last decade's problem. Machine and non-human identity, the credentials that AI agents and automated workflows carry, is this decade's, and the identity leaders are buying their way into it rather than waiting to build.
The third camp is the cross-sector acquirers. Hyperscalers and data platforms like Google, Microsoft and Databricks are buying security and AI-security assets to bolt onto much larger franchises. When a data platform buys a security operations company, it is not entering the security market to compete with pure-plays. It is making its core product safer to sell into the enterprise.
Here is the leaderboard of the biggest disclosed venture-scale deals we tracked this year. Notice how many of them are identity.
Mandos platform data, August 2026
Which cybersecurity categories are consolidating fastest?
Not evenly. The consolidation is concentrated in a handful of categories, and the concentration itself is the signal. When one category absorbs a disproportionate share of the deals, the market is telling you that is where standalone tools can no longer survive on their own.
According to Mandos platform data (August 2026), across the 109 acquisitions we tracked in 2026, identity and access management and network security each accounted for 22 deals. Together that is 44 transactions, roughly 40% of all activity, in just two categories. Data protection, cloud security and application security formed the next tier at around 10 deals each.
Mandos platform data, August 2026
The category label alone hides the more interesting pattern. Inside those identity deals, the recurring target is not classic single sign-on or password management. It is non-human identity: Cyera buying Oasis Security, Cisco buying Astrix, SailPoint buying Entro, 1Password buying Apono. Four separate buyers, one thesis, that the credentials machines and AI agents carry are the next identity perimeter, and it is cheaper to buy that capability than to build it in time.
The second pattern cutting across categories is AI security getting absorbed rather than scaled. Standalone AI-security startups are being tucked into network, data and operations platforms almost as fast as they are founded. That tells you something uncomfortable for founders in the space: the market currently values AI security as a feature of a larger platform, not yet as a category a customer will buy on its own. You can cross-check how crowded these categories have become against the roughly 9,000 products indexed in the CybersecTools directory and the live deal view at mandos.io/data, where the gap between category breadth and buyer attention is widest.
Why is cybersecurity consolidation accelerating?
Consolidation waves are usually driven by one force. This one is driven by three, and they reinforce each other, which is why it is not slowing down.
The first is coverage pressure. Enterprise buyers are actively trying to reduce the number of security vendors they manage. Every platform incumbent knows this, so each is racing to become the vendor that survives the cut. The fastest way to add a capability a consolidating buyer will demand is to acquire the company that already has it. As the law firm Herbert Smith Freehills Kramer noted in its 2026 global M&A report, platform consolidation is the defining theme of the year, a shift from buying point tools to aggressive platform roll-up.
The second is the AI shift creating new categories faster than any single vendor can build. Every new attack surface AI opens, model security, agent identity, prompt and data governance, becomes a category someone has to cover. Incumbents cannot build all of them in parallel, so they buy the early leaders. That is why AI-native startups are being acquired at seed and Series A stage, long before they would traditionally exit.
The third is capital concentration. Funding in 2026 has stacked heavily into a small cohort of category leaders, leaving strong mid-stage companies in crowded categories unable to raise their next round at a flat or up valuation. A company that cannot raise and cannot reach profitability has one realistic exit, and acquirers know it. That dynamic prices a lot of good companies into the buy column.
What gets a cybersecurity startup acquired instead of shut down?
This is the question founders should actually care about, because the difference between a clean acquisition and a quiet acqui-hire is enormous, and it is mostly decided before the banker gets involved.
Having a great product is not what separates the two outcomes. In a market this crowded, a great product is the default. What separates them is legibility: whether an acquirer can look at your company and instantly understand what capability it is buying, where that capability slots into its platform, and why the buyer's customers will care. A muddy category story turns a real technology into a cheap team purchase.
Mandos platform data, August 2026
I see the same failure on the buyer side of a normal sales cycle. A genuinely differentiated product describes itself in generic terms, the buyer's thirty-second scan files it next to five cheaper tools, and it never reaches the shortlist. In an acquisition, the exact same defect shows up as a lower multiple, because the acquirer is buying your position in the buyer's mind, not just your codebase. That is a positioning problem, and it is precisely what a positioning audit is built to catch before it costs you a turn of valuation.
Signal
Gets acquired at a premium
Gets shut down or acqui-hired
Category story
One clear sentence a buyer repeats internally
Needs a diagram and five minutes to explain
Capability fit
Fills a gap the acquirer urgently needs to close
Nice to have, overlaps with what they own
Product state
Clean, documented, integrable in a quarter
Bespoke, tangled, rebuilt post-acquisition
Market position
Reads as a category leader
Reads as a feature of someone else's category
What the buyer pays for
The brand, the book, and the team
The team only
If you are a founder who might sell in the next two years, the work is to move every row of that table from the right column to the left. The clarity that gets you shortlisted by a CISO is the same clarity that gets you a premium from an acquirer, which is why I score both against the same seven dimensions. A strong position is not a marketing nicety in a consolidating market. It is the difference between the two exit columns.
What the consolidation wave means for investors and founders
For investors, the record deal count is not a green light, it is a sorting mechanism. The exit environment is bifurcating with the funding. A small number of category leaders will command strategic premiums, and the long tail of undifferentiated tools will clear at modest strategic prices or not at all. Underwriting the median outcome in a consolidating category is very different from underwriting the top of it. The question that predicts which side a portfolio company lands on is not whether the product is good, it is whether the buyer places it at the center of a category or the edge of someone else's. That is a testable property, and it is where a competitive benchmark earns its keep.
For founders, the map is free strategic intelligence. The categories absorbing the most deals tell you where standalone survival is getting harder, and the target patterns tell you what acquirers actually value. If you sit in a fast-consolidating category, you have two honest options: become the consolidator, or make yourself the most legible acquisition target in the field. Both require the same thing, a position sharp enough that a buyer understands it in one sentence. Drifting in the middle, undifferentiated and unsold, is how good companies end up as acqui-hires. Reading the market honestly and positioning against it is the core of the advisory work I do.
A short checklist for reading any cybersecurity M&A headline
Whether you are allocating capital or deciding how to position your own company, run any acquisition announcement through these five questions before you let it change your thinking.
Separate the mega-deal from the pattern. One $30 billion acquisition sets valuations at the top. The dozens of $50 to $400 million deals below it tell you which categories are actually consolidating.
Name the capability, not the company. Ask what specific capability the buyer just acquired. If several buyers are chasing the same capability, that is the real trend, not any single deal.
Watch the acquirer's category, not just the target's. When a data platform or hyperscaler buys security, the motive is protecting a larger franchise, not entering the security market. Read the intent accordingly.
Track where the volume clusters. Concentration of deals in one or two categories signals that standalone tools there can no longer survive alone. That is where new entrants need a platform strategy from day one.
Ask whether the target was acquired for its brand or its team. A premium deal buys a position in the market. A cheap one buys engineers. The gap between the two is almost always positioning.
Run those five passes and the 2026 M&A wave stops looking like a boom and starts looking like what it is: a sorting event, deciding which companies become platforms, which get absorbed into them, and which quietly disappear. The strategic work, for founders and for the people who fund them, is figuring out which of those three you are on track to be.
Frequently asked questions
How many cybersecurity acquisitions have there been in 2026?
The first half of 2026 set a record pace for cybersecurity M&A, with industry trackers counting well over 200 disclosed transactions and roughly $9 billion in disclosed deal value. Mandos platform data tracked 109 cybersecurity acquisitions in 2026 to date as of early August, a subset that skews toward the venture-backed deals most relevant to founders and investors.
Who are the biggest acquirers in cybersecurity right now?
The most active buyers in 2026 are platform incumbents closing capability gaps: Palo Alto Networks, Cisco, Check Point, Zscaler and Cloudflare on the network and cloud side, and Okta, SailPoint, 1Password and Cyera on the identity and data side. Hyperscalers and cross-sector acquirers like Google, Microsoft and Databricks are also buying aggressively, mostly to absorb AI and data capabilities.
Which cybersecurity categories are consolidating fastest?
Identity and access management and network security are consolidating fastest. According to Mandos platform data from August 2026, those two categories accounted for 44 of 109 tracked 2026 acquisitions, roughly 40% of all deals. Within identity, non-human and machine identity is the single hottest target theme, followed by AI security capabilities being tucked into larger platforms.
Why is cybersecurity M&A accelerating in 2026?
Three forces reinforce each other. Compliance and AI adoption make security spending non-negotiable, so platforms need broad coverage fast. Building every capability in-house is slower than buying it, so incumbents acquire to close gaps. And capital has concentrated around a few winners, leaving strong mid-stage companies cheap enough to buy. The result is aggressive platform roll-up.
What makes a cybersecurity startup an acquisition target instead of a shutdown?
Acquired companies own a capability a platform urgently needs and can articulate it in one clear sentence, with a clean product a buyer can integrate and a category position that reads as a leader rather than a feature. Companies that get shut down or absorbed in cheap acqui-hires usually have real technology but a muddy category story, so buyers value the team but not the brand or the book of business.
The Platform
Track the market this article is describing.
Every cybersecurity vendor, product, funding round and market move — 3,279 companies and 8,525 products, 450+ data points each, updated daily.