21 Deals Reshape Cybersecurity's July 2026
Major acquisitions by Bank of America, CrowdStrike, and Cyera signal continued consolidation in cybersecurity.
The cybersecurity industry's merger and acquisition wave continued in July 2026, with 21 deals announced, according to SecurityWeek. The month's transactions featured several high-profile acquisitions, including Bank of America's move into security consulting and Cyera's $1 billion purchase of a startup focused on machine identities.
Bank of America Expands North
Bank of America announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. MDSec provides technical information security consulting services and employs roughly 65 cybersecurity professionals, according to SecurityWeek. The acquisition expands Bank of America’s presence in northern England.
Identity and Access Deals Heat Up
Barracuda Networks acquired Texas-based Evo Security for an undisclosed amount. The deal expands Barracuda’s BarracudaONE platform by integrating multi-tenant identity, IAM, and PAM capabilities for MSP partners. Okta signed an agreement to acquire Palo Alto-based Permiso Security, reportedly for roughly $200 million, equipping Okta with continuous identity threat detection (ITDR) capabilities to protect human, machine, and autonomous AI identities across cloud environments.
- 21 cybersecurity M&A deals announced in July 2026
- Cyera to acquire Oasis Security in a transaction valued at around $1 billion
- Schwarz Group acquired XM Cyber in 2021 for $700 million
- Qualcomm acquired SAM Seamless Network, reportedly for over $100 million
AI Detection and Data Security Moves
San Francisco-based Cribl acquired Israeli AI detection engineering startup CardinalOps. The acquisition brings automated detection engineering to Cribl’s AI platform to improve threat coverage and lower log management costs for enterprise SOCs. Cribl is establishing a new office in Tel Aviv following the acquisition, according to SecurityWeek.
Exposure Management and IP Acquisitions
Cybersecurity titan CrowdStrike is buying the patents and source code of Israel’s XM Cyber from Schwarz Group for an undisclosed amount. The transaction allows CrowdStrike to integrate exposure management and attack-path analysis directly into its offerings. It’s unclear how much CrowdStrike has paid for the XM Cyber IP, but SecurityWeek notes Schwarz Group acquired XM Cyber in 2021 for $700 million.
Network Intelligence and Observability
Infoblox entered into a definitive agreement to purchase network intelligence and observability platform Kentik for an undisclosed amount. The integration blends Infoblox’s DNS/network context with Kentik’s real-time network traffic visibility to strengthen hybrid cloud cyber resilience. Palo Alto Networks also plans to acquire user-focused mobile and web observability platform Embrace, integrating its mobile observability and real-time user telemetry into its platform to unify mobile experience monitoring and threat visibility.
Hardware-Level Security
Qualcomm acquired Israeli IoT cybersecurity startup SAM Seamless Network, reportedly for over $100 million. The deal embeds SAM’s network security software into Qualcomm’s wireless chipsets and gateways to safeguard communication networks. According to SecurityWeek, SAM customers include US telecom giants AT&T and Verizon.
Other Notable Deals
Additional cybersecurity M&A deals announced in July 2026 include CompassMSP acquiring The Logic Group, CyberNut acquiring Neptune Navigate, Databarracks acquiring Acumen, DataExpert Group acquiring ADO Security, Katalyst acquiring Layer27, Keyfactor's planned acquisition of Cofide, NINJIO acquiring SafeStack, TAC InfoSec's acquisition of Safehouse Technologies, The 20 acquiring Sundance Networks, Veridas acquiring Fourthline, Viatel Technology Group acquiring FullProxy, and Webacy acquiring Trugard Labs.
Why It Matters
For CISOs and IT leaders, this wave of acquisitions suggests a future where integrated platforms may replace point solutions. The deals span identity management, AI-driven detection, network intelligence, and hardware-level security, indicating where vendors see the most pressing needs. As products are absorbed into larger platforms, organizations may face rebranding or sunsetting of tools they rely on, making vendor strategies a key factor in security planning.
Sources
- SecurityWeek Original source
Continue Reading
SCCM Attack Chain Exposes Cost of Weak Trust
XM Cyber researchers chain four SCCM flaws into SYSTEM access for $58, with partial fixes leaving a path open.
Fortinet's Patch Wave Targets Authentication Gaps
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
Google Doc Credentials Leak Serves as a Cautionary Tale
A developer's habit of storing passwords in a shared Google Doc led to a search-indexed exposure of staging credentials.