Key Takeaways
- July 2026 saw 21 announced cybersecurity M&A deals, reflecting continued consolidation across identity, threat detection, network observability, and AI‑driven security.
- Large enterprises (Bank of America, Qualcomm, Palo Alto Networks, CrowdStrike) pursued strategic tuck‑ins to broaden product capabilities and geographic reach.
- Identity‑centric acquisitions dominated, with Barracuda, Okta, and Cyera adding IAM, ITDR, and non‑human identity governance to their platforms.
- Network and observability firms (Infoblox, Cribl) bolstered hybrid‑cloud visibility and automated detection engineering.
- A flurry of smaller‑scale deals highlighted active MSP, cloud‑native, and data‑protection niches, indicating a vibrant ecosystem beyond the mega‑players.
- Overall, the month underscored a shift toward integrated, end‑to‑end security stacks that combine identity, data, network, and AI‑powered threat management.
Paragraph 1 – Major Financial Institution Moves into UK Cybersecurity Consulting
Bank of America announced its intention to acquire UK‑based information security consultancy MDSec Consulting Limited. MDSec employs roughly 65 cybersecurity professionals and delivers technical advisory services, penetration testing, and risk‑management consulting. The acquisition will extend Bank of America’s footprint into northern England, allowing the bank to offer locally sourced expertise to its corporate and institutional clients while strengthening its internal security posture through added consultancy depth.
Paragraph 2 – Barracuda Enhances MSP‑Focused Identity Platform
Barracuda Networks completed the purchase of Texas‑based Evo Security for an undisclosed sum. Evo’s technology adds multi‑tenant identity, identity‑and‑access‑management (IAM), and privileged‑access‑management (PAM) capabilities to Barracuda’s BarracudaONE platform. By integrating these functions, Barracuda aims to give managed‑service‑provider (MSP) partners a unified console for securing customer identities across cloud and on‑premises environments, thereby reducing operational complexity and improving compliance reporting.
Paragraph 3 – Cribl Boosts AI‑Driven Detection Engineering
San Francisco‑based Cribl acquired Israeli AI detection‑engineering startup CardinalOps. The deal brings CardinalOps’ automated detection‑engine creation tools into Cribl’s AI‑powered observability platform, enabling security operations centers (SOCs) to generate and update detection rules at scale with minimal manual effort. Cribl also announced plans to open a new office in Tel Aviv to leverage local talent and accelerate joint product development, aiming to lower log‑management costs while improving threat coverage for enterprise customers.
Paragraph 4 – CrowdStrike Expands Exposure Management via XM Cyber IP
CrowdStrike signed an agreement to acquire the patents and source code of Israel’s XM Cyber from Schwarz Group for an undisclosed amount. Although Schwarz Group purchased XM Cyber in 2021 for roughly $700 million, the financial terms of this IP transfer were not disclosed. The acquisition will let CrowdStrike embed XM Cyber’s exposure‑management and attack‑path‑analysis technologies directly into its Falcon platform, providing customers with continuous visibility into exploitable attack surfaces and prioritized remediation guidance.
Paragraph 5 – Cyera Unifies Data Security with Non‑Human Identity Governance
Cyera, a California/Israel‑based data‑security firm, agreed to acquire Israeli startup Oasis Security in a transaction valued at approximately $1 billion. Oasis specializes in non‑human identity (NHI) governance—managing service accounts, API keys, and machine identities that increasingly drive modern cloud workloads. By combining Cyera’s data‑security posture management with Oasis’s NHI controls, the merged entity aims to protect enterprise AI agents, automated workflows, and the vast proliferation of machine‑to‑machine communications that traditional IAM solutions often overlook.
Paragraph 6 – Infoblox Deepens Network Observability with Kentik
Infoblox entered a definitive agreement to acquire network intelligence and observability platform Kentik for an undisclosed price. Kentik’s real‑time traffic analytics, flow‑based visibility, and custom dashboarding will be fused with Infoblox’s DNS‑centric network context and security offerings. The combined solution is intended to give hybrid‑cloud enterprises a single pane of glass for detecting anomalous traffic, troubleshooting performance issues, and enforcing policy‑based controls across multi‑vendor environments.
Paragraph 7 – Okta Adds Continuous Identity Threat Detection
Okta signed an agreement to acquire Palo Alto‑based Permiso Security for roughly $200 million. Permiso provides continuous identity threat detection and response (ITDR) capabilities that monitor credential usage, privilege escalation, and anomalous authentication patterns across human, machine, and autonomous AI identities. The acquisition will enable Okta to extend its identity cloud with proactive threat hunting, automated remediation playbooks, and richer risk‑scoring features, addressing a growing demand for identity‑centric security in cloud‑first enterprises.
Paragraph 8 – Palo Alto Networks Integrates Mobile Observability
Palo Alto Networks announced plans to acquire user‑focused mobile and web observability platform Embrace. Embrace’s SDK‑based telemetry captures real‑time user experience metrics, crash reports, and performance data from mobile and web applications. By folding Embrace into its Cortex XSOAR and Prisma Access suites, Palo Alto intends to give security teams visibility into how threats impact end‑user behavior, enabling faster correlation between security events and application performance degradation.
Paragraph 9 – Qualcomm Embeds IoT Network Security into Chipsets
Qualcomm acquired Israeli IoT cybersecurity startup SAM Seamless Network for reportedly over $100 million. SAM’s network‑security software—featuring micro‑segmentation, device‑level firewalling, and anomaly detection—will be embedded directly into Qualcomm’s wireless chipsets and gateway solutions. The integration aims to secure communication channels for US telecom giants such as AT&T and Verizon, as well as a broad range of industrial IoT deployments, by delivering hardware‑rooted protection that operates before threats reach the software stack.
Paragraph 10 – A Wave of Smaller‑Scale Deals Across MSP, Cloud, and Data Protection
July also featured a flurry of smaller‑scale transactions that underscore activity in niche segments. CompassMSP acquired The Logic Group to broaden its managed‑service portfolio; CyberNut purchased Neptune Navigate for enhanced cloud‑security posture management; Databarracks added Acumen to strengthen its backup‑and‑recovery offerings; DataExpert Group snapped up ADO Security for extended threat‑intelligence capabilities; Katalyst bought Layer27 to augment its container‑security toolbox; Keyfactor agreed to acquire Cofide, tightening its PKI and certificate‑management suite; NINJIO obtained SafeStack to expand its security‑awareness training library; TAC InfoSec secured Safehouse Technologies for improved endpoint‑detect‑and‑response (EDR) tools; The 20 (a venture‑backed consolidator) took over Sundance Networks to boost its SD‑WAN security stack; Veridas acquired Fourthline to deepen its identity‑verification and AML compliance tech; Viatel Technology Group bought FullProxy to enhance its secure‑web‑gateway offerings; and Webacy purchased Trugard Labs to add blockchain‑focused security analytics to its platform. Collectively, these deals highlight vigorous investment in MSP enablement, cloud‑native protection, data‑privacy, and emerging‑technology security.
Paragraph 11 – Trends and Implications of July 2026 Cybersecurity M&A Activity
The month’s deal flow reveals several overarching themes. First, identity remains a hotbed of consolidation, with players seeking to cover the full spectrum—from traditional IAM (Barracuda/Evo, Okta/Permiso) to non‑human and AI‑driven identities (Cyera/Oasis). Second, network observability and AI‑enhanced detection are converging, as seen in the Cribl/CardinalOps and Infoblox/Kentik pairings, reflecting a market demand for real‑time, context‑rich threat insight. Third, large technology incumbents are using M&A to harden their hardware‑software stacks—Qualcomm’s SAM acquisition exemplifies the shift toward embedding security at the silicon level. Finally, the volume of mid‑tier and tuck‑in deals indicates a healthy pipeline of innovation that larger vendors are eager to absorb, suggesting that the cybersecurity ecosystem will continue to evolve toward integrated platforms that combine identity, data, network, and AI capabilities under a single vendor umbrella.
Paragraph 12 – Outlook for the Remainder of 2026 and Beyond
Looking ahead, the momentum observed in July is likely to persist through the rest of 2026, driven by continued pressure on organizations to simplify vendor sprawl while improving coverage against sophisticated, multi‑vector threats. Expect further consolidation in the XDR/SOAR space, as vendors seek to unify detection, investigation, and response workflows. Additionally, regulatory developments around AI accountability and data sovereignty may spark new M&A activity focused on compliance‑automation and privacy‑enhancing technologies. For investors and strategic buyers, the July 2026 landscape underscores that the most attractive targets are those delivering clear, measurable improvements in identity hygiene, observable network behavior, or automated threat detection—capabilities that can be swiftly integrated into broader security platforms to deliver immediate value to end‑customers.

