October 9, 2026

AI Scramble Drives Cybersecurity M&A Boom

Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What’s different: Many of the buyers are not your typical cybersecurity firms.

AI Scramble Drives Cybersecurity M&A Boom

Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What’s different: Many of the buyers are not your typical cybersecurity firms.

Surging demand for native-AI cybersecurity services (and the security capabilities needed to tame agentic AI) has put 2026 on the path to become another record-breaking year for cybersecurity-startup acquisitions.

While the value of financing deals is on track to decline slightly this year — dropping to an annualized 754 funding rounds, from 820 last year — the number of mergers and acquisitions should reach 450 deals, up from 404 transactions last year, according to the latest report from Momentum Cyber, a cybersecurity investment firm. Identity and access management, non-human identity, data security, agentic security, runtime protections, and locking down operational technology are the major categories of interest, according to the firm.

Advances in the use of AI for cybersecurity, such as Anthropic’s Mythos foundational model, and the advent of AI-automated attacks, has given dealmakers a sense of urgency, says Eric McAlpine, founder and CEO of the Austin-based firm.

“We have just never seen a pace like this before,” he says. “A company doesn’t have to be native-agentic, but it will be AI first, and I think that’s what you’re seeing in a lot of these deals nowadays.”

In 2025, M&A deals set records for both volume at 404 deals and value, with companies spending $97 billion to acquire startups. The past two years have also hosted massive deals, including Google’s purchase of Wiz for $32 billion in 2025. This year, however, investors are taking dual approaches to AI: funding early-stage startup to develop AI-native categories, while larger companies are acquiring AI startups to build out capabilities, such as Cyera’s $1 billion buy of Oasis Security and Cisco’s dual acquisitions of Astrix Security and WideField Security.

AI has accelerated the market, sped up the incubation cycle for startups, and made deals move faster — faster even than the cloud and software-as-a-service (SaaS) investment markets, says Zane Lackey, a general partner with venture capital firm Andreessen Horowitz.

“We’re seeing the innovation cycle, the buying cycle, the M&A cycle, all of it just wildly compressed in AI compared with cloud — I mean right now it feels like we are in such early innings of this overall super cycle,” he says. “From the company building side, it is the absolute golden age to be building the company right now or investing in companies right now.”

AI Everywhere in Cybersecurity

At the start of 2026, however, the picture for cybersecurity and AI seemed less rosy.

In early January 2026, SaaS companies saw significant sell-offs in the stock market following fears that AI models could quickly replace their services. Soon after, the stock prices of major cybersecurity companies took a hit following fears that they would also become victims of the so-called “SaaS-pocalypse.” Between Jan. 28 and Feb. 23, 2026, CrowdStrike’s stock plunged 26%, JFrog dropped 42%, Tenable Holdings dropped 20%, and Zscaler dropped 28%.

Those worries were overblown, and most companies have recovered and then some: CrowdStrike is up 127% year to date, JFrog is up 72%, and Tenable is up 68%. Zscaler is still down, off 3% since the start of the year, but has recovered most its losses. Fears of AI-augmented and fully-automated attacks has made cybersecurity capabilities a necessity for companies adopting agentic AI.

At the same time, investments in cybersecurity firms stumbled, but have since recovered, says Momentum Cyber’s McAlpine.

Bar chart showing increase in cybersecurity deals over time.

In Q3 2026, cybersecurity M&A transaction reached a high of 117, putting the year on track to set a record. Source: Momentum Cyber

“Because of the SaaS-pocalypse and the Mythos scare earlier this year, there were a lot of private equity firms that decided to hold onto their portfolio companies that would’ve otherwise hired somebody like me to take them into market — they held off doing that,” he says. “My prediction is in six months from now, we will see a more return to normal and we’ll see the private equity firms seeking a sale of their portfolio companies in a manner and pace that we didn’t see this year.”

AI security acquisitions jumped to 40 deals in the first three quarters, compared to 10 throughout all of last year, according to Momentum Cyber’s data. Yet, the term “AI security” does not capture how integral AI has become for cyber security. In reality, AI is rapidly becoming part of every category, McAlpine says. The company’s taxonomy of a dozen sectors and 62 sub-sectors may end up becoming much simpler, he jokes.

“AI is really blurring the boundaries so quickly that the next version we putting that out probably next year could potentially look like three mega categories: AI for security, security for AI, and everything else,” he says.

A Tale of Two Markets: M&A Versus Financing

Yet, the race to finance companies is not as frenetic as the contest to acquire capabilities, McAlpine says. “In the financing world, we’re just seeing a much more scrutinized view on where VCs and private equity firms are going to place their bets,” he says. “It’s lower overall volume, fewer deals, but larger check sizes.”

Financing is focusing on founders with track records, he says.

Because capabilities and the market is moving so fast, companies are seeing a “seed-to-C funding path,” says McAlpine. “What would’ve traditionally been five years ago, a seed round, a series A, and a B and a C, is now all in one funding package right out of the gate.”

In addition, non-traditional companies are looking at spurring innovation in cybersecurity and AI security. Software-as-a-service companies are focused on securing agentic workloads, while operation-technology firms need control the agents manage fleets of devices. Yet, they all have similar pain points, says Andreessen Horowitz’s Lackey.

“There are three main buckets that make up that pain — the first is attacks, the second is technology change, and the third is compliance,” he says. “We are living through tremendous amounts of the first two right now, and everyone knows that the third one is coming as well.”

McAlpine agrees that the next wave of buyers for cybersecurity may come from outside of traditional cybersecurity firms. He sees the hyperscalers and frontier labs themselves as the future purchasers of a great deal of cybersecurity capability.

“There’s no secret that security is one of the predominant concerns with the frontier,” he says. “They have to figure out AI and cyber, and there’s a lot at stake here.”

Originally published on Dark Reading