Arctic Wolf completed its acquisition of BlackBerry’s Cylance endpoint-security assets on February 3, 2025, and launched Aurora Endpoint Security. The announced deal included $160 million in cash, subject to adjustments, plus about 5.5 million Arctic Wolf shares. The acquisition adds endpoint prevention, detection, and response technology to a company already known for managed security operations; it does not mean Arctic Wolf bought all of BlackBerry or that every Cylance product and contract will remain unchanged.
What happened, and when?
Arctic Wolf and BlackBerry announced the agreement on December 16, 2024. It closed on February 3, 2025. At closing, Arctic Wolf introduced Aurora Endpoint Security, integrating Cylance technology into its Aurora Platform.
BlackBerry had acquired Cylance in 2018 for approximately $1.4 billion, according to Axios’s account of that transaction. The 2025 sale was a later transaction for Cylance endpoint-security assets, not a purchase of BlackBerry as a whole.
What did Arctic Wolf buy?
The acquired assets were associated with BlackBerry’s Cylance endpoint-security business: technology and related customer, partner, and employee assets. The capabilities at the center of the deal include endpoint prevention, detection, and response, built around Cylance’s AI- and machine-learning-based protection. Arctic Wolf said the transaction added nearly 400 employees, thousands of customers, and hundreds of partners; those scale figures are the company’s own description of the acquisition’s impact (Arctic Wolf).
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
BlackBerry retained other security businesses, including unified endpoint management, AtHoc, and SecuSUITE. The transaction therefore should not be described as a sale of BlackBerry’s entire security portfolio (acquisition announcement).
What does the $160 million figure mean?
The headline figure refers to announced cash consideration, not the full consideration by itself. Arctic Wolf also agreed to issue approximately 5.5 million of its common shares. The shares are part of the transaction’s economic value, but Arctic Wolf is privately held, so they do not have a publicly quoted market price comparable to listed-company stock.
The announced cash structure included approximately $80 million at closing and approximately $40 million one year later, alongside purchase-price mechanics and adjustments. BlackBerry’s later transaction reporting described approximately $39.1 million in purchase-price adjustments and about $79.8 million in closing cash net of adjustments. These figures reflect different elements of the deal and should not be added or treated as a single all-cash purchase price (BlackBerry transaction filing; announced terms).
What is Aurora Endpoint Security?
Aurora Endpoint Security is Arctic Wolf’s endpoint-security offering, built from Cylance technology and integrated with the Aurora Platform. Arctic Wolf describes the offering as connecting endpoint prevention and detection with its broader security-operations capabilities (product overview).
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →One named managed offering is Aurora Managed Endpoint Defense, described in Arctic Wolf’s documentation as a subscription-based, 24/7-managed XDR service. That is distinct from the endpoint technology itself: the agent and its prevention and detection features are one layer; the Aurora platform and the managed service are operating layers around it (product documentation).
How does the model differ from buying endpoint software alone?
A traditional endpoint purchase may give an organization an agent and console, but the customer still needs people and processes to review alerts, investigate incidents, and decide or carry out response actions. Some organizations add separate MDR, SIEM, SOAR, threat-hunting, or vulnerability tools to fill those roles.
Rank #3
Arctic Wolf’s intended distinction is that endpoint data and response are connected to its Aurora security-operations platform and managed services. The company is selling an operating model as well as endpoint capabilities: a customer may use a broader managed or co-managed security program instead of relying only on its internal team.
That is a service-and-platform distinction, not independent evidence that Aurora’s underlying endpoint technology outperforms CrowdStrike, Microsoft Defender, SentinelOne, or every other competitor. Claims about reduced alert volume or better outcomes should be tested against a buyer’s own workloads, staffing needs, and proof-of-concept results rather than treated as established comparative performance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What should existing Cylance customers check?
The business moved to Arctic Wolf, and service continuity was a stated objective. That does not establish that every legacy Cylance SKU, console, integration, policy, or support process is unchanged. BlackBerry said it would remain a customer and reseller for its large government customers, indicating that at least some existing relationships were expected to continue under Arctic Wolf ownership (BlackBerry statement).
Rank #4
Before renewal or migration, ask Arctic Wolf or the reseller for written answers specific to the deployed product and contract:
- Which product and edition are in use—for example, CylancePROTECT, CylanceOPTICS, CylanceENDPOINT, or another SKU—and is it covered by the acquired business?
- Who is the contract party now, and what changes at renewal, including license conversion, price, or reseller involvement?
- Will the existing console remain supported, or is a new Aurora tenant required?
- Will endpoints need an agent upgrade or reinstall, and can existing policies, exclusions, and integrations be carried over?
- Which team handles support, incident escalation, and remediation, and what authority does the managed service have?
- What data is collected, where is it stored, how long is it retained, and how can it be exported or deleted at termination?
Public announcements do not establish a universal migration schedule across every Cylance product, operating system, edition, or contract. Obtain a product-specific migration and support plan rather than assuming continuity means no operational changes.
Why did Arctic Wolf want Cylance?
Arctic Wolf’s stated rationale was to add deeper endpoint prevention, detection, and response to its security-operations and MDR foundation. Endpoint telemetry is important to investigating and responding to threats; owning endpoint technology also gives the company more direct control over the agent, roadmap, and integration with Aurora. The deal supports its broader open-XDR platform strategy and creates an opportunity to offer endpoint security alongside other services (Arctic Wolf’s announcement).
Best Value
For customers, combining tools and services could simplify operations, especially where internal security staffing is limited. The trade-off is deeper dependence on one vendor and potentially less transparency about the standalone value of the endpoint component. Buyers should evaluate both the technology and the service commitment.
What changes for BlackBerry?
BlackBerry exited the commercial endpoint-security operating business covered by the sale but retained other security products. It also continued a relationship with Arctic Wolf as a customer, reseller for large government customers, and shareholder. BlackBerry’s statement describes that post-closing relationship and its continuing business focus (BlackBerry).
The difference between BlackBerry’s approximately $1.4 billion 2018 Cylance purchase and the 2025 deal’s announced terms is notable, but it is not by itself a complete measure of financial gain or loss. The later consideration included private-company shares, cash adjustments, and a different transaction scope; the available figures should not be compared as if they represented identical assets and terms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should buyers compare the options?
These offerings have different commercial models. The comparison below is about buying and operating approach, not a ranking of protection quality. Published vendor prices and bundles can change, and the listed CrowdStrike and Microsoft figures were observed on vendor pages on August 16, 2026.
| Option | Commercial model | Best-fit use case | Main caution |
|---|---|---|---|
| Arctic Wolf Aurora Endpoint Security | Sales-led, managed/security-operations-oriented; public per-endpoint pricing was not stated on the reviewed official pages. | Organizations seeking managed or co-managed endpoint defense connected to 24/7 security operations. | Confirm exact packaging, service scope, and total price in a quote. |
| CrowdStrike Falcon | Published per-device tiers plus enterprise options. On CrowdStrike’s pricing page, Falcon Go was listed at $7.99 per device per month, Falcon Pro at $14.99, and Falcon Enterprise at $19.99; annual prices shown were $59.99, $99.99, and $184.99 per device, respectively. The page also advertised a 15-day free trial. | Buyers seeking a dedicated endpoint platform and a more transparent starting price. | Enterprise agreements, device counts, services, and optional modules can change final cost. CrowdStrike pricing |
| Microsoft Defender | Bundled, add-on, standalone, and pay-as-you-go structures. Microsoft listed Microsoft 365 E5 at $60 per user per month paid yearly, or $51.45 for the no-Teams version; Defender Suite was listed at $12 per user per month paid yearly and required qualifying Microsoft 365 or Office 365 E3 and Enterprise Mobility + Security E3 licensing. | Organizations already standardized on Microsoft 365 that want to consolidate security capabilities in that ecosystem. | Check eligibility, existing licenses, configuration work, and operating responsibilities before comparing costs. Microsoft pricing |
For Arctic Wolf, pricing and packaging were not publicly disclosed in the reviewed official pages; prospective customers should request a quote with endpoint counts, service scope, term, and implementation costs. The figures above are vendor-page prices seen August 16, 2026, not a guarantee of current availability or a like-for-like comparison.
What to validate before choosing Aurora
- Coverage: Confirm supported operating systems and endpoint types, plus required prevention, detection, investigation, isolation, and remediation functions.
- Operating model: Establish who monitors alerts, approves containment, carries out remediation, and manages incidents in self-managed, co-managed, or fully managed deployment.
- Integration: Test compatibility with existing SIEM, identity, email, firewall, ticketing, and vulnerability-management systems; ask about APIs and data export.
- Governance: Review data residency and retention, analyst access, regulatory requirements, role-based controls, and termination procedures.
- Endpoint impact: Measure CPU, memory, network, boot-time, and application compatibility effects, including behavior during network loss and protection when endpoints cannot reach the cloud.
- Commercial terms: Confirm per-endpoint or bundled licensing, minimum counts, renewal uplift, migration and professional-service charges, and whether endpoint licensing can be bought independently.
- Response commitments: Define response-time terms, escalation routes, remediation authority, and any contractual warranty or insurance provisions.
A proof of concept should include the organization’s actual applications, endpoint mix, controls, and incident workflows. This is especially important if the purchase is intended to replace only antivirus but the proposed package includes a wider managed-security commitment.
Quick Recap
Who may find the model a poor fit?
- A buyer seeking a simple self-service antivirus or EDR product with transparent online pricing.
- A mature SOC that already has strong endpoint and response workflows and does not need outsourced monitoring.
- An organization whose regulatory or contractual rules restrict third-party analysts from accessing telemetry.
- A buyer dependent on a specific operating-system capability or integration that Arctic Wolf has not confirmed.
- A team that requires complete internal control of triage and remediation but is evaluating a package built around managed operations.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




