Cybersecurity M&A trends point to AI identities, browsers and connected devices
Cybersecurity deal activity is targeting AI identities, cloud work and industrial devices, offering a map of where buyers see growing risk.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
Cybersecurity M&A trends are increasingly centred on AI-agent identities, browser and cloud-application controls, connected devices and broader asset visibility. SecurityWeek counted 26 cybersecurity-related deals announced in May 2026, while Solganick recorded 76 transactions through February in its narrower cybersecurity-services coverage, evidence of sustained activity across different parts of the market.
The transactions do not establish which threat will prove most damaging. They do show where strategic buyers are seeking capabilities as corporate systems extend beyond managed networks to software agents, web applications and operational technology.
What do cybersecurity M&A trends say about the next attack surface?
They indicate buyer concern about identities and activity across a wider set of systems. AI agents can access data, execute workflows, write code and communicate with applications. Those permissions create non-human identities that organisations must discover, govern and monitor, according to PYMNTS.
SecurityWeek reported that Cisco announced an intended acquisition of Astrix Security, estimated at $400 million, to add non-human identity management capabilities. Zscaler also announced its intent to acquire Symmetry Systems, whose access-graph technology is intended to map identities and data access. Both remain announced transactions rather than evidence of deployed results.
Where buyers are placing their bets
- AI and machine identities: Cisco's planned Astrix transaction and Zscaler's proposed Symmetry deal target visibility and controls for autonomous software actors and their access to enterprise data, SecurityWeek reported.
- Browser and cloud work: Akamai agreed in May to buy LayerX for about $205 million, according to SecurityWeek, and PYMNTS reported the acquisition was completed in July. The technology is designed to provide controls across browsers, applications and development environments, where employees increasingly use SaaS and cloud services.
- Connected industrial equipment: Dragos acquired Phosphorus to strengthen security and management of connected devices in critical infrastructure and operational networks, SecurityWeek reported. This marks operational technology as a distinct area of acquisition interest.
- Asset and attack-surface visibility: Solganick reported that Arctic Wolf announced an acquisition of Sevco Security in February to add attack-surface-management capabilities. Such tools are designed to identify exposed assets and reduce risk across an organisation's technology estate.
- Fraud and behavioural signals: PYMNTS reported Visa's planned $2.4 billion acquisition of BioCatch, whose tools analyse application, behavioural, device and network signals. The reported rationale reflects a push to combine signals that have often been held in separate security and fraud systems.
For financial institutions, the overlap between cyber controls and fraud prevention is becoming more visible. PYMNTS cited a study with Visa DPS in which 42% of bank and non-bank issuers ranked fraud and disputes as their largest or second-largest platform operating cost after employees.
Deal flow is therefore best read as a record of buyer priorities, rather than a forecast of attacks or proof that acquired products will work as intended. The available reporting does not establish the effectiveness of these tools after integration, nor does it determine which category will become the most consequential security risk.
This story draws on original reporting from PYMNTS.