Identity and Access Management · AI Security, Governance and Assurance · Data Security and Protection · Industrial Control Systems

Cybersecurity M&A 2026: Platforms Are Drawing the Map

In four months, cybersecurity platforms closed the two largest deals in industry history and a wave of strategic tuck-ins. The map is being redrawn.

By Tal Eliyahu · · 12 min read

Editorial technical diagram for Cybersecurity M&A 2026: Platforms Are Drawing the Map
A clean acquisition logic map showing Acquirer, Platform Fit, Target, Gap, and Integration as connected parts of the story. CyberBiz

The two largest cybersecurity M&A deals in industry history closed in the same calendar quarter. They will not be the most consequential ones.

Google's $32 billion acquisition of Wiz closed on March 11, 2026, making it the largest cybersecurity exit on record. Eleven days earlier, Palo Alto Networks' $25 billion acquisition of CyberArk had completed regulatory clearance, the largest deal in PANW's history. Together those two closures represent more dollar volume than every cybersecurity M&A deal in 2024 combined.

The closures matter. The closings are not the story.

The story is what the platforms have done in the four months since — and what those moves say about how the cybersecurity industry's map is being redrawn around AI agents.

The two megadeals closed. The story is below them.

Google/Wiz and Palo Alto/CyberArk are book-ends, not bookmarks. Wiz had defined CNAPP. CyberArk had defined PAM. Both were the most successful pure-plays in their categories. Both became platform features.

Workflow diagram for Cybersecurity M&A 2026: Platforms Are Drawing the Map
Workflow view of the control path, market pressure, and buyer impact behind Cybersecurity M&A 2026: Platforms Are Drawing the Map. CyberBiz

Below those two closures, more than a dozen verified cybersecurity M&A deals at $100 million or more have been announced or closed in 2026 through May 9. SecurityWeek's monthly roundups count roughly 147 cybersecurity M&A transactions through April. Q1 2026 produced 108 deals, the second-highest quarterly count in 65 tracked quarters, with six at $100M+ — the densest concentration of large transactions since the 2021-2022 peak.

This is not a slowdown. This is acceleration with a different shape.

Capstone Partners' Q1 update frames the shape with a number: public strategics' deal count is up 33% year over year while PE-backed transactions are down 24%. The corporate platform-fill model has displaced the private-equity buy-and-build model that ran 2020-2024. The buyers writing checks in 2026 are PANW, Google, Cisco, CrowdStrike, ServiceNow, Microsoft, Zscaler, Rapid7, Varonis, Arctic Wolf, and Check Point. The sellers are agentic-stack startups two to four years into their commercial life, often with one to three rounds of strategic capital already on the cap table.

The map is being redrawn. Wiz and CyberArk were former capitals that became districts. The interesting question is not who bought the capitals. It is who is annexing the next towns.

The platforms are drawing the map

The pattern across the 2026 deals is cartographic. Incumbent platforms — PANW, Google, Cisco, CrowdStrike, ServiceNow, Microsoft — are each redrawing the cybersecurity map around themselves, one tuck-in at a time. Every $100M+ deal is a town being annexed into a platform's territory.

Palo Alto Networks has the cleanest example. Beyond CyberArk, PANW completed the $400 million acquisition of Koi Security for *agentic endpoint* — a category PANW itself named — and announced its acquisition of Portkey for AI Gateway. Combined with CyberArk for identity, PANW has filled three of the six agentic-stack layers in five months. We've covered the Portkey deal in detail.

CrowdStrike's pattern is faster and tighter. SGNL ($740M, identity) and Seraphic ($420M, browser) were announced six days apart in mid-January. George Kurtz framed them as a fused control plane: endpoint to browser to cloud, every AI agent a privileged identity, every privileged identity needing continuous authorization.

Cisco bought Astrix Security (~$400M, NHI) on May 4 — analyzed in this companion piece — and added Galileo in April for agentic monitoring inside Splunk. ServiceNow closed its $7.75 billion acquisition of Armis, the largest cyber-physical exit ever.

Six platforms. Sixteen verified material deals in four months. Each platform is drawing its corner of the same map.

Identity is the fourth pillar

Across the 2026 deal log, one sub-category dominates. Identity.

Nikesh Arora has been explicit about it. PANW's CyberArk close was framed as establishing identity as the *fourth pillar* of platformization, alongside network, cloud, and SecOps. The framing has spread.

CrowdStrike's SGNL acquisition restructures identity from session-time authentication to runtime, continuous authorization across human, non-human, and AI-agent identities. Cisco's Astrix purchase puts non-human identity inventory and lifecycle management inside Cisco Identity Intelligence and Duo. Silverfort's acquisition of Fabrix Security in late April pairs runtime access protection with AI-native decisioning. Delinea's merger with StrongDM, backed by TPG, fuses traditional PAM with developer-first just-in-time runtime authorization.

The structural argument unifying these deals is a thesis about how access fails. Standing privilege is dead. Session-time authentication is too coarse. AI agents act faster than humans can approve, and they act on behalf of humans whose authorizations were never designed to cover an autonomous proxy. The market is converging on runtime, continuous, agent-aware authorization as the new identity control plane.

That convergence has the shape of a category formation. The early agentic-identity startups — Astrix, SGNL, Fabrix, and the StrongDM-Delinea pair — are the supply curve. The platforms are the demand. The category is being defined by acquisition rather than by independent category leadership, which is the inverse of how cloud security got defined in the prior cycle.

For public security companies, the read is straightforward. Identity is now a checklist item. Any platform without an agentic-identity acquisition in the next twelve months will be benchmarked against the platforms that have one. CrowdStrike and Palo Alto Networks have set the standard. The pressure on the rest of the public cohort is structural, not optional.

Six layers, four months

If identity is the fourth pillar, the agentic stack is what gets built on top of it. The 2026 deals fill out six layers of that stack with notable speed.

Identity, covered above. The deepest concentration of capital.

AI Gateway. Palo Alto's Portkey acquisition stakes the routing and policy layer. Every prompt, response, and tool invocation that an agent emits passes through the gateway. That is the chokepoint where inline enforcement lives. PANW is alone in this layer for now; Microsoft, Google, and Cloudflare have gateway-shaped capabilities embedded in their hyperscaler stacks but no acquired specialist. The gap is competitive whitespace through the rest of 2026.

Agentic Endpoint. PANW's $400 million acquisition of Koi Security in February explicitly named *agentic endpoint security* as a new category. Koi targets AI agents and browser-resident AI tools that bypass traditional EDR. The category did not exist as a budget line in 2025. By 2027, expect three to four named entrants and a recognized procurement category.

Agentic Browser. CrowdStrike/Seraphic and Zscaler/SquareX in the same six-week window. Both target the gap between unmanaged browsers and enterprise security. Both turn the browser into the place where agent traffic gets inspected. Island and Talon, the prior-cycle browser-security pure-plays, have to decide whether to consolidate further or hold for a higher offer. They will not get to wait long.

Agent-ready Data. Varonis' $150 million acquisition of AllTrue.ai adds shadow-AI discovery and runtime guardrails. The data-access layer is where the agentic stack may monetize most durably.

Agentic SOC. Rapid7's acquisition of Kenzo Security and Cisco's purchase of Galileo apply agentic AI to security operations workflow. The framing is *machine-speed investigation* — collapsing the dwell time between alert and response. The category overlaps with traditional SOAR and is reshaping it. The next twelve months will produce one or two consolidation events here.

Each layer was a generic capability in 2024. Each layer is a named, platform-owned product surface by mid-2026. Four months.

ServiceNow / Armis is the cyber-physical break-out

The single largest non-PANW, non-Google deal of the window has nothing to do with AI agents.

ServiceNow's $7.75 billion acquisition of Armis brings OT, IoT, and medical-device asset visibility into the Now Platform. ServiceNow says the deal *more than triples* its security and risk TAM. The cyber-physical category — Claroty, Dragos, Nozomi, Armis — has its first true platform exit.

The strategic logic is mechanical. Workflow platforms have been pushing toward security and risk for years. ServiceNow already had IT asset management at scale. What it lacked was the cyber-physical layer where the most regulated, most exposed, and most under-monitored assets live. Armis was the cleanest fit available.

The demand-side analogue is the Itron breach we covered last week. Critical-infrastructure operators have an OT visibility crisis the OT-security category has been pitching against for five years. The Armis deal proves the buyer side is now writing $7B+ checks for it. Expect at least one more major cyber-physical deal in the back half of 2026 — Claroty and Dragos are the obvious candidates, and the comparable pricing has just been set.

The numbers, anchored

Aggregate market data anchors the qualitative pattern.

Capstone Partners' Q1 2026 cybersecurity update reports 79 verified strategic transactions in YTD 2026 (down 9% year over year by count, but up sharply in average ticket size: $461 million versus $171 million in YTD 2025). EV/Revenue multiples sit at 4.3x — on par with the eight-year sector average of 4.6x, not the 2021-2022 froth. ION/Mergermarket commentary clusters strategic deal discussions at 6-8x ARR, with 8-10x reserved for the most strategic targets.

The story those numbers tell is selective expansion, not generic frenzy. Multiples have re-anchored from 2021-2022 levels. The Nasdaq CTA Cybersecurity Index is down 14% from its October 2025 peak. The bidders who are paying have decided which categories are worth the pricing — and which are not.

Capstone's own framing, from Tom McConnell: *We are at an inflection point in cybersecurity as AI driven platforms are required to thwart today's sophisticated AI driven threats. This is leading to a broad-based makeover of the industry.* Twenty-seven percent of the M&A advisors Capstone surveyed expect 2026 multiples to rise above 2025. The bidders are not pulling back. They are concentrating.

This is faster than the cloud-security cycle

The closest historical analogue is the 2019-2022 cloud security consolidation. Symantec went to Broadcom in 2019. Carbon Black went to VMware. Bridgecrew went to PANW in 2020. Auth0 went to Okta for $6.5 billion in 2021. Mandiant went to Google for $5.4 billion in 2022. CSPM, CWPP, CIEM, and CASB collapsed into CNAPP — and CNAPP, in turn, eventually got won by Wiz, which Google then bought for $32 billion to close the cycle.

That cycle took roughly four years.

The agentic stack is consolidating in six to nine months.

The compression matters. Two structural forces are driving it. First, AI agents are a new asset class that did not exist in the prior cycles, and the platforms are racing to control how those assets identify themselves, where they communicate, and what they can read and write. Second, the platforms have learned the cycle. Cloud security taught Cisco, PANW, Google, and Microsoft that the cost of being late is paying $25 billion or $32 billion to a category leader. None of them want to repeat the price.

So the platforms are buying earlier, smaller, and faster. The $100M-$700M strategic tuck-ins of 2026 are explicitly designed to prevent the next Wiz from emerging in the agentic stack. We will see whether the strategy works. The interim implication for founders and investors is that the window to build an independent category leader in identity, gateway, endpoint, browser, data, or SOC is shorter than it was in the prior cycle. Probably much shorter.

What to watch through end of 2026

Five signals between now and December will tell us how the rest of the agentic-stack consolidation plays out.

The first is the deal flow at the close. PANW's Portkey closes Q4 FY26. CrowdStrike's SGNL plus Seraphic close Q1 FY27. Cisco's Astrix has not yet closed publicly. The closing pace, plus any regulatory friction in EU or US review, sets the baseline tempo for the next round of announcements.

The second is the PE counter-wave. Capstone reports PE-backed deals down 24% year over year, but the firms are sitting on capital. Thoma Bravo's interest in Commvault is the canary. SailPoint is back in the public market. Sophos is consolidating Secureworks. Expect a meaningful PE counter-wave in H2 2026, particularly in middle-market segments where corporate buyers are not active.

The third is the second wave of cyber-physical deals. ServiceNow/Armis is the trigger. Claroty, Dragos, and Nozomi are the obvious next candidates. The comparable pricing has been set; the buyers are circling.

The fourth is browser security normalization. With CrowdStrike (Seraphic) and Zscaler (SquareX) both shipping in 2026, every other XDR or SASE vendor needs an answer. Island and Talon are the obvious targets.

The fifth is the consolidation event in agentic SOC. Rapid7 has Kenzo. Cisco has Galileo. Check Point has Cyata. The category will not support five independent entrants. Pick a winner; the rest get bought.

Cybersecurity M&A in 2026 is not a wave. It is a relocation. The map is being redrawn faster than any prior cycle, and the platforms drawing it have decided which categories are worth annexing.

Wiz won CNAPP. CyberArk won PAM. They both got bought.

The startups winning the next category have nine months — maybe twelve — to follow. Some will. Most will be acquired before they finish. A few will become the next platforms drawing the next map.

The question for the rest of us is which corner of the 2026 cybersecurity map we plan to own when the ink dries.

Frequently asked questions

What are the most material cybersecurity M&A deals of 2026 so far?
The two megadeals closed in Q1: Google's $32 billion acquisition of Wiz (the largest cybersecurity exit on record) and Palo Alto Networks' $25 billion close on CyberArk. Below those, the more telling pattern is the wave of $100M-$700M strategic tuck-ins filling the agentic stack: CrowdStrike's SGNL ($740M) and Seraphic ($420M), Palo Alto's Koi ($400M) and Portkey (reported ~$700M), Cisco's Astrix (~$400M), Varonis' AllTrue.ai ($150M), and ServiceNow's $7.75 billion acquisition of Armis for the cyber-physical layer.
What is the agentic stack the 2026 deals are building?
The agentic stack is the six-layer architecture cybersecurity platforms are racing to control before AI agents become standard enterprise software. The layers are identity (CyberArk, SGNL, Astrix, Fabrix), AI gateway (Portkey), agentic endpoint (Koi), agentic browser (Seraphic, SquareX), agent-ready data (Ryft, AllTrue.ai), and agentic SOC (Kenzo, Galileo). Palo Alto Networks alone has bought into four of the six layers in 2026. CrowdStrike covered identity and browser in two weeks. The compression speed is the story.
How does 2026 compare to prior cybersecurity M&A cycles?
The closest analogue is the 2019-2022 cloud security consolidation, which collapsed CSPM, CWPP, CIEM, and CASB into the CNAPP category that platforms (and Wiz) eventually owned. That cycle took roughly four years. The agentic stack is consolidating in six to nine months. Capstone Partners reports public strategics' deal count is up 33% year over year while PE-backed transactions are down 24% — corporate platform-fill has displaced the PE buy-and-build model that ran 2020-2024.
What should cybersecurity founders take from the 2026 M&A pattern?
The startup question has changed. It is no longer *what category am I building?* — it is *which platform's map do I want to be on?* Founders building in identity, gateway, endpoint, browser, data, or SOC layers are competing on a shorter clock than the cloud-security generation faced. Defensibility comes from technical depth, customer concentration in regulated sectors, and being early to a primitive that platforms haven't yet named. The categories platforms have already named — agentic endpoint, AI gateway, agent-ready data — are functionally closed for new entrants. Adjacent primitives platforms haven't named yet are where the next defensible bets sit.

Sources

  1. Google completes acquisition of Wiz — Google
  2. Palo Alto Networks completes acquisition of CyberArk — Palo Alto Networks
  3. CrowdStrike to acquire SGNL — CrowdStrike
  4. ServiceNow completes Armis acquisition — ServiceNow
  5. Capstone Partners Q1 2026 Cybersecurity Market Update — Capstone Partners
  6. Cybersecurity M&A stalls after 2025 surge as AI resets valuations — ION Analytics / Mergermarket
  7. Q1 2026 cybersecurity M&A consolidation analysis — Tech Insider