Cybersecurity's Record M&A Year: What the Wiz, CyberArk, and Dragos Deals Signal for Your Vendor Roadmap

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
Cybersecurity M&A did not just have a busy year in 2026; it had a record one, and the shape of the record matters as much as the size of it. Momentum Cyber's Mid-Year 2026 Review tracked 219 cybersecurity M&A transactions in the first half of 2026 alone, with $9.1 billion in disclosed deal value, and described the pace as on track for the highest deal count Momentum Cyber has ever tracked. That volume was punctuated by three transactions large enough to reshape entire product categories: Google's $32 billion acquisition of Wiz, which closed in March 2026 after roughly a year of regulatory review; Palo Alto Networks' $25 billion acquisition of CyberArk, which closed in February 2026 and which Palo Alto Networks itself called the largest deal in its history; and Accenture's June 2026 agreement to acquire a majority stake in Dragos alongside full acquisitions of runZero and NetRise, a combined transaction valued at approximately $4.175 billion.
This is a different problem than the one covered in most consolidation advice aimed at security teams, which is typically about reducing your own internal tool sprawl, retiring redundant point products, and simplifying your stack. This is the reverse direction: it is what happens on the vendor side of the market, and what a buyer should do when the vendor they already rely on, or the one they are currently evaluating, becomes the acquisition target rather than the acquirer. The rest of this guide works through what actually happened in 2026, why platformization is the throughline connecting these specific deals, what that means concretely for a team currently mid-evaluation or mid-renewal, and what to actually ask for in a contract and in a vendor conversation before you commit.
What actually happened in 2026, by the numbers
Start with the deal-volume data rather than the headline transactions, because it is the broader trend that makes the individual megadeals meaningful rather than one-off outliers. Momentum Cyber's Mid-Year 2026 Review put H1 2026 deal count at 219, with $9.1 billion in disclosed deal value, and characterized the pace as on track for the highest cybersecurity M&A deal count Momentum Cyber has tracked. That is a statement about breadth: a large number of smaller and mid-sized acquisitions happening across the market, not just a handful of large ones.
The breadth is matched by unusual depth at the top end. Google's acquisition of Wiz, a cloud security posture management vendor, closed on March 11, 2026 at a price of $32 billion in an all-cash deal, following an announcement in March 2025 and roughly a year of regulatory review across the US, EU, Australia, Israel, Saudi Arabia, South Africa, and Turkiye. It is Google's largest acquisition in company history. Palo Alto Networks' acquisition of CyberArk, an identity security vendor, closed on February 11, 2026 for a total consideration of $25 billion, structured as $45 in cash plus 2.2005 Palo Alto Networks shares per CyberArk share, a 26 percent premium to CyberArk's unaffected 10-day average share price at announcement. Palo Alto Networks described it as the largest deal in the company's history. In June 2026, Accenture announced it would acquire a majority stake in Dragos, the industrial and OT security vendor, alongside full acquisitions of runZero and NetRise, for a combined enterprise value of approximately $4.175 billion; the deal values Dragos itself at $3.25 billion and was expected to close in the August-to-September 2026 window, subject to regulatory approval. Three category leaders, cloud security, identity security, and OT security, all absorbed into larger platforms within the same calendar year is not a coincidence of timing; it is the same market force showing up three times.
Why platformization is the throughline connecting these deals
The term getting used across 2026 M&A commentary, including CyberDB's analysis of the year's trends, is platformization: the shift from vendors and buyers assembling security capability out of many separate best-of-breed point products toward a smaller number of vendors selling integrated platforms that cover many functions under one contract, one console, and one data model. CyberDB frames the driver plainly, noting that the average enterprise manages dozens of disparate security tools and that this fragmentation is itself a source of risk and operational cost, which gives platform vendors a genuine buyer-side argument for consolidation, not just a sales pitch.
What makes the 2026 megadeals a clean illustration of platformization rather than ordinary tuck-in acquisitions is what each acquirer already had before the deal, and what it was specifically missing. Google Cloud already had a large cloud infrastructure and security business; it did not have a leading cloud security posture management product with Wiz's market position, and it bought that specific gap closed rather than building a competitor from scratch. Palo Alto Networks already had a broad platform spanning network, cloud, and endpoint security; it did not have a leading identity security and privileged access management product, a category CyberArk led, and the acquisition was explicitly framed around identity security for both human users and autonomous AI agents. Accenture already had a large industrial and OT consulting and integration practice; it did not have Dragos's specific OT threat detection product, runZero's asset discovery capability, or NetRise's firmware and software supply chain visibility, and it bought a majority stake in the first and all of the other two to assemble what it called an end-to-end critical-infrastructure security offering in a single move. In every case, the acquirer bought a recognized category leader to complete an existing platform, which is a different and more deliberate move than simply buying market share.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
What this means for a security team evaluating vendors right now
None of this is abstract if you are the customer of a vendor that gets acquired, or if you are currently evaluating one that might be. Three concrete risks show up in a deal like this, and they are worth naming separately rather than treating as one vague worry.
The first is integration risk: the product you bought does not necessarily stay the product you bought. A point solution absorbed into a platform is frequently re-architected, rebranded, or merged into an adjacent product line over a period of months to years, and the pace and outcome of that process is controlled by the acquirer, not by you. The second is pricing and support discontinuity risk: contract terms, support tiers, and roadmap priorities set by the acquired company's original leadership are not guaranteed to survive the transition unchanged, and a feature or support commitment that was a selling point before the deal may quietly become a lower priority once its team reports into a much larger organization's product strategy. The third is the strategic question underneath both of the others: whether to deliberately choose a vendor that has already been absorbed into a stable, well-resourced platform, betting on that platform's continuity, or to choose an independent best-of-breed point solution that may perform better today but carries a real chance of being acquired later, on a timeline and by an acquirer you do not get to pick. Both are legitimate strategies. The mistake is not picking one deliberately, and instead treating vendor stability as a given that does not need active management.
Contract language and vendor questions to use on your next renewal
The practical response to this risk is not to avoid vendors that could plausibly be acquired, since in a market moving at this pace that would rule out most of the category leaders worth evaluating. It is to negotiate for visibility and exit options before you sign, and to ask direct questions a serious vendor should be able to answer plainly.
Ask for a change-of-control clause
Negotiate contract language that gives you the right to exit or renegotiate terms if the vendor is acquired, rather than being bound to the full remaining term under whatever the new owner decides to do with pricing or support.
Confirm data portability and export rights in writing
Get an explicit, contractually binding commitment to export your own data and configurations in a usable format, so you are not dependent on an acquirer's goodwill or a shrinking support team to get your data out if you need to leave.
Ask for a minimum post-acquisition support and patching window
Push for a specific number of months of guaranteed support and security patching commitments that would survive an acquisition, rather than accepting a vague continuity assurance with no enforceable timeline attached.
Ask the vendor directly whether they see themselves as a likely acquisition target
A vendor with a genuine, considered answer, and a stated platform direction of its own, is a materially different risk than one that only offers generic reassurance when asked.
Ask what platform strategy the vendor is building toward, if any
A point-solution vendor with a clear, credible platform roadmap of its own is a different bet than one with no stated direction beyond its current single product; both are viable, but you should know which one you are choosing.
Weigh platform lock-in against best-of-breed acquisition risk explicitly
Write down, for this specific renewal, what you lose if your current best-of-breed vendor gets acquired and re-prioritized, versus what you lose in flexibility and multi-vendor negotiating leverage if you instead standardize on an already-platformed vendor; make the tradeoff a documented decision, not a default.
The bottom line
2026 produced the highest cybersecurity M&A deal count Momentum Cyber has tracked, 219 transactions in the first half of the year alone, and the year's three marquee deals, Google's $32 billion acquisition of Wiz, Palo Alto Networks' $25 billion acquisition of CyberArk, and Accenture's roughly $4.175 billion combined acquisition of a majority stake in Dragos plus all of runZero and NetRise, all follow the same pattern: an established platform vendor buying a recognized category leader to close a specific gap, not a generic roll-up of smaller competitors. That pattern, platformization, is the throughline worth tracking, because it tells you the M&A wave is not slowing down and any vendor you rely on today, however dominant in its category, is a plausible acquisition target tomorrow.
The actionable response is not to avoid category-leading vendors out of acquisition anxiety, since that would rule out most of the strongest options in the market. It is to negotiate change-of-control protection, data portability commitments, and minimum post-acquisition support windows into every renewal from here forward, and to ask every vendor a direct, specific question about their own acquisition posture and platform direction before you sign. Whether you ultimately choose an already-platformed vendor for stability or a best-of-breed point solution for capability, make that choice deliberately and in writing, rather than discovering which one you effectively made only after your vendor's name shows up in the next Momentum Cyber report.
Frequently asked questions
Is 2026 actually a record year for cybersecurity M&A, or does it just feel that way?
The deal-count data supports it. Momentum Cyber's Mid-Year 2026 Review tracked 219 cybersecurity M&A transactions in the first half of 2026 alone, with $9.1 billion in disclosed deal value, and characterized the pace as on track for the highest deal count Momentum Cyber has ever tracked for a comparable period. That is a deal-volume claim, not a subjective impression, and it is reinforced by the size of individual 2026 transactions: Google's $32 billion acquisition of Wiz and Palo Alto Networks' $25 billion acquisition of CyberArk are both among the largest cybersecurity deals ever recorded, not just large for the year.
What does platformization actually mean in the context of these deals?
Platformization means a large vendor is deliberately acquiring category-leading products to assemble a single, integrated security platform rather than building each capability internally or leaving buyers to stitch together point products themselves. In the 2026 deals, Google bought Wiz specifically to strengthen Google Cloud's cloud security and multicloud protection story, Palo Alto Networks bought CyberArk specifically to add identity security, including privileged access management for both humans and AI agents, to its existing platform, and Accenture bought a majority stake in Dragos alongside all of runZero and NetRise to build what it explicitly called an end-to-end OT and critical-infrastructure security offering. In each case the acquirer already had an adjacent platform and bought a recognized leader to fill a specific gap in it, rather than buying an undifferentiated smaller competitor.
What happens to a vendor's product roadmap and support after it gets acquired?
It varies by deal and takes time to become clear, which is precisely the risk a buyer has to manage. Google's Wiz acquisition took about a year from announcement to close, clearing regulatory review in the US, EU, Australia, Israel, Saudi Arabia, South Africa, and Turkiye, and a full year of uncertainty is common for deals of this size. Support commitments, pricing, and integration timelines are typically communicated gradually after close rather than spelled out in full on day one, so a buyer with an existing contract with an acquired vendor should proactively ask the acquirer for a specific, dated roadmap and support commitment rather than waiting for one to be volunteered.
Should I choose an already-platformed vendor over a best-of-breed point solution?
There is no universally correct answer; it is a genuine tradeoff between two different risk profiles. An already-platformed vendor (one that has already made its big acquisitions, like Palo Alto Networks post-CyberArk) offers more roadmap stability for that specific platform, since the consolidation risk for those particular products has already played out, but it also means deeper commitment to a single vendor's ecosystem, pricing power, and release cadence. A best-of-breed point solution may offer superior capability in its specific category today, but carries real risk of being acquired later, on a timeline and by an acquirer you do not control. Weigh how replaceable the specific function is against how much switching cost you would take on if the vendor were absorbed into a platform mid-contract.
What contract terms should I actually ask for to protect against my vendor being acquired?
Ask for a change-of-control clause that lets you exit or renegotiate if the vendor is acquired, rather than being locked into the remaining contract term under a new owner. Ask for a defined data portability and export commitment so you are not dependent on the acquirer's goodwill to get your own data out. Ask for a minimum committed support and patching window post-acquisition, ideally tied to a specific number of months rather than a vague continuity promise. None of these are exotic asks; they are standard vendor-risk contract language that becomes far more relevant in a market with this much acquisition activity.
What questions should I ask a vendor directly about their own acquisition and platform strategy?
Ask whether the vendor sees itself as a likely acquisition target or an acquirer over the next 12 to 24 months, and how leadership would answer that in writing, not just in a sales conversation. Ask what platform, if any, the vendor is trying to build toward, since a vendor with a clear platformization roadmap of its own is a different risk profile than one that is a single point product with no stated direction. Ask specifically what contractual protections apply if the vendor is acquired during your contract term. A vendor that answers these plainly and specifically is a better sign than one that deflects to reassurance without specifics.
Sources & references
- Momentum Cyber - Mid-Year 2026 Review: Cybersecurity M&A on Track for Highest Deal Count Ever Tracked
- CyberDB - Cybersecurity M&A Trends in 2026: The Era of Platformization and AI-Native Integration
- Momentum Cyber - Cybersecurity Quarterly Review Q1 2026
- TechCrunch - Google wraps up $32B acquisition of cloud cybersecurity startup Wiz
- Cleary Gottlieb - Google Completes $32 Billion Acquisition of Wiz
- Bloomberg - Palo Alto Networks Reaches $25 Billion Deal for CyberArk
- Industrial Cyber - Palo Alto Networks to acquire CyberArk in $25 billion deal, expanding into identity security
- SecurityWeek - Accenture to Acquire Majority Stake in Dragos, All of runZero, NetRise in $4.1 Billion OT Cybersecurity Push
- Accenture Newsroom - Accenture to Strengthen Critical Infrastructure Defense with End-to-End Cybersecurity Platform
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
