Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Google completed its acquisition of Mandiant on September 12, 2022, bringing the incident-response and threat-intelligence company into Google Cloud while keeping the Mandiant name. Google had announced the all-cash transaction in March at $23 per share, or approximately $5.4 billion inclusive of Mandiant’s net cash. Alphabet later reported a $6.1 billion total purchase price including cash and debt—a different accounting measure, not a claim that Google paid $6.1 billion in cash.
What Google actually acquired
The buyer was Google LLC, using merger subsidiary Dupin Inc.; the target was Mandiant, Inc. The merger agreement was signed on March 7, 2022, and the companies announced it publicly on March 8. The transaction closed on September 12, 2022, when Mandiant became part of Google Cloud. Mandiant retained its brand, as confirmed in Google’s closing announcement (Google Cloud).
Mandiant was a services- and intelligence-led cybersecurity business, not simply a software codebase. At announcement, company materials described more than 600 consultants, more than 300 intelligence analysts and work responding to thousands of breaches each year. Those figures describe the business at the time of the deal, not verified 2026 staffing.
Why the deal was strategically important
Google Cloud already offered cloud infrastructure, security analytics, zero-trust capabilities and security-operations technology. Mandiant added people and expertise that are difficult to build quickly: frontline incident response, threat intelligence, investigations, readiness consulting, security validation and managed defense.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Cybersecurity Cyber Security Computer Security Date A Hacker Design for Cybersecurity Awareness Lovers
- Date A Hacker We Break Security Not Hearts. For people thinking of Funny Cybersecurity Cyber Security Awareness Gift Ideas
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
Google and Mandiant presented the combination as an end-to-end security operation spanning detection, intelligence, automation, response and validation across cloud, on-premises and multicloud environments. That was management’s strategic objective, not proof that every expected benefit was realized. The announcement itself warned that integration and future opportunities were uncertain (Google and Mandiant announcement).
- For Google Cloud: a recognized incident-response brand and a way to sell human expertise alongside infrastructure and software.
- For Mandiant: access to Google’s scale, telemetry and security analytics.
- For enterprise buyers: a potential path from threat detection to expert-led investigation and remediation.
The FireEye distinction matters
Calling the transaction a purchase of “FireEye” is inaccurate. Mandiant had completed the sale of its FireEye Products business to Trellix in October 2021 for approximately $1.2 billion, subject to specified adjustments and liabilities (Mandiant filing).
Google therefore acquired the post-divestiture Mandiant business: incident response, threat intelligence, consulting, validation, investigation automation and attack-surface-management capabilities. Trellix, not Google, received the former FireEye products operation.
Why the headline says $5.4 billion—and filings say $6.1 billion
| Figure | What it means |
|---|---|
| $23 per share | Google’s announced all-cash consideration for each Mandiant share. |
| Approximately $5.4 billion | The announced transaction value, explicitly inclusive of Mandiant’s net cash (SEC exhibit). |
| $6.1 billion | Alphabet’s later reported total purchase price, including cash and debt, in its September 30, 2022 quarterly filing (Alphabet filing). |
These figures use different transaction concepts. The $6.1 billion figure should not be described as $6.1 billion of cash paid, and the difference does not show that Google and Mandiant disagreed about the deal’s value.
Free tools Windows power users keep installed
One-click scans. No signup required.
What Mandiant’s integration looks like in Google Cloud
After closing, Mandiant capabilities appeared across Google’s security portfolio rather than as one automatically bundled product. Current offerings include:
Rank #2
- Hardcover journal with 240 line-ruled pages (120 sheets)
- Built-in elastic closure and ribbon bookmark
- Includes an expandable inner storage pocket and a pen holder
Google Security Operations and Google Threat Intelligence
Google Security Operations provides enterprise SIEM, SOAR, detection, investigation and analytics. Its Enterprise Plus tier includes applied threat intelligence incorporating Mandiant, VirusTotal and Google sources, plus detections informed by Mandiant research and incident-response activity (Google Security Operations). Google Threat Intelligence combines Google, Mandiant and VirusTotal intelligence; Digital Threat Monitoring is listed as part of Google Threat Intelligence Enterprise and Enterprise+ (Digital Threat Monitoring).
Mandiant Threat Defense and Managed Defense
Mandiant Threat Defense combines expert threat hunting, investigation and rapid response with Google SecOps workflows (Mandiant Threat Defense). Mandiant Managed Defense is a 24/7 detection, investigation, response and threat-hunting service that Google says can support a customer’s existing technology stack (Managed Defense).
Google has also documented support for CrowdStrike and SentinelOne environments (Google Cloud interoperability announcement). That means using Mandiant services does not inherently require an organization to replace every non-Google security product.
Incident response and retainers
Mandiant Incident Response Services cover active-breach response, attack analysis, crisis management, containment, remediation, compromise assessments and preparedness. They are human-led services for serious incidents, not a substitute for routine alert monitoring.
A Mandiant Retainer provides pre-negotiated access to responders and consultants through prepaid units, discounted hourly rates and contractual terms. Google describes a two-hour response time for calling on experts; that is not a promise that an incident will be resolved within two hours. Unused capacity may be redirected to readiness work such as tabletop exercises, penetration testing or training.
Rank #3
Security Validation
Mandiant Security Validation performs breach-and-attack simulation, attack emulation and control testing. Google describes sales-led pricing based on a platform (“director”) plus deployed “actors.” It tests whether defenses work; it does not replace endpoint protection, identity security, a SIEM or incident response.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What customers should—and should not—assume
- Mandiant services can support hybrid, on-premises and multicloud environments; customers are not automatically required to become Google Cloud-only users.
- Acquisition did not make every Mandiant service free or included with a Google Cloud account. Product and services pricing is generally enterprise, sales-led pricing.
- Mandiant Threat Defense or Managed Defense is not the same as buying a standalone endpoint agent.
- A retainer is a preparedness and access arrangement, not an insurance policy or a guaranteed incident-resolution time.
- Product names and packaging can change as Google consolidates Mandiant, Chronicle, VirusTotal and related capabilities under broader security brands.
Competitive and operational trade-offs
The combination strengthened Google Cloud’s bid to compete in enterprise security, but buyers still need to examine practical trade-offs:
- Integration risk: a services-led incident-response organization must fit a hyperscale provider’s products, sales process and operating culture.
- Independence concerns: some customers may question perceived conflicts when a Google-owned provider investigates an incident involving Google technology.
- Multicloud proof: stated interoperability should be checked against the exact endpoints, cloud services, data-handling rules and contractual coverage required.
- Commercial complexity: Google Security Operations, managed defense and consulting services are not interchangeable products and commonly require a tailored quote.
Reasonable alternatives include Microsoft Defender XDR and Sentinel for Microsoft-standardized estates; CrowdStrike Falcon for endpoint- and identity-centered programs; Palo Alto Networks Cortex for customers invested in its network, endpoint and cloud portfolio; and SentinelOne Singularity for endpoint and XDR programs. No one option is universally superior. A serious evaluation should score existing-stack fit, endpoint and identity coverage, SIEM/SOAR needs, multicloud support, threat-hunting depth, incident-response terms, data residency, minimum commitments and migration effort.
Deal timeline
- October 8, 2021: Mandiant completed the sale of FireEye Products to Trellix for approximately $1.2 billion, subject to stated adjustments and liabilities.
- March 7, 2022: Mandiant entered the merger agreement with Google LLC and Dupin Inc. (SEC filing).
- March 8, 2022: The $23-per-share, approximately $5.4 billion announcement was made.
- September 12, 2022: The acquisition closed; Mandiant joined Google Cloud and retained its brand.
- September 30, 2022: Alphabet reported the $6.1 billion purchase price including cash and debt.
What the acquisition did not mean
- It was not a March 2022 closing; March was the announcement and agreement period.
- It was not Google’s purchase of all historic FireEye products.
- It did not make Mandiant services automatically included in Google Cloud.
- It did not force every Mandiant customer to migrate to Google Cloud.
- It did not, by itself, prove better security outcomes for customers; those depend on implementation, coverage, contracts and adoption.
The Bottom Line
Google’s Mandiant deal was completed on September 12, 2022. The announced price was approximately $5.4 billion inclusive of net cash, while Alphabet later reported a $6.1 billion purchase price including cash and debt. Strategically, Google bought incident-response, intelligence and security-services capability—not the entire former FireEye product business—to make Google Cloud a more credible enterprise-security platform. Its practical value depends on product integration, multicloud coverage, commercial terms and customer fit.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




