Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
SecurityWeek reported 27 cybersecurity-related M&A announcements in March 2024. Its published list, however, appears to enumerate 26 individual transactions when grouped acquisitions are counted target by target. The roundup spans company purchases, managed-service acquisitions and a business-unit deal; most terms were undisclosed, and an announcement does not necessarily mean a transaction had closed.
This is a historical roundup of announcements made during March 1–31, 2024, not a list of deals confirmed as closed during that month. The source is SecurityWeek’s April 2, 2024 roundup. Its coverage is global and includes companies whose work is cybersecurity-focused as well as adjacent IT, cloud-networking and managed-services businesses.
Why the headline says 27 but the list appears to show 26
Counting each target company separately, the article’s highlighted section contains 15 transactions: 13 listed buyer entries, with AUCloud’s purchases of PCG Cyber, Venn IT and Arado counted as three. The “other deals” section adds 11, including two separate targets—Accurate Computer Solutions and Blue Cactus Consulting—acquired by The 20 MSP. That makes 26 visible transactions.
SecurityWeek’s headline says 27. The published list does not identify a twenty-seventh transaction, so the difference cannot be resolved from that article alone. It may reflect an omitted item or a different counting convention; it should not be silently treated as either a confirmed 27-item list or a definitive correction to 26.
#1 Best Overall
Largest reported deal values
Most buyers did not disclose financial terms. Among the figures cited in the roundup, media reports put Zscaler’s acquisition of Avalor at about $350 million, CrowdStrike’s purchase of Flow Security at $200 million, and GitLab’s acquisition of Oxeye at $30 million to $40 million. Cycode–Bearer was reported at approximately $10 million. These are reported figures, not amounts consistently confirmed by the buyers. AUCloud’s three deals were listed at $10 million for PCG Cyber and approximately $4 million each for Venn IT and Arado.
Those figures do not establish the month’s largest deal with certainty: consideration for most transactions was not reported. Nor should they be added together to produce a definitive March total. The source does not provide values for most entries, and the status and provenance of reported figures vary.
March 2024 deal list
The table below follows the visible list in the SecurityWeek roundup. It counts targets separately and distinguishes the StackPath transaction, which involved its web application and API protection business, from a whole-company acquisition. The source does not provide a consistent announcement date, jurisdiction, legal form, or closing status for every entry; where it does not establish those details, they are not inferred here.
| Buyer | Target | Capability or business | Value in roundup | Transaction note |
|---|---|---|---|---|
| Airbus Defence and Space | Infodas | Cybersecurity and IT solutions | Not disclosed | Company acquisition announcement |
| AUCloud | PCG Cyber | Australian government cybersecurity consultancy | $10 million | Counted separately from AUCloud’s other two acquisitions |
| AUCloud | Venn IT | Managed services | Approximately $4 million | Separate target |
| AUCloud | Arado | Managed services | Approximately $4 million | Separate target |
| BlueCyber | ISMAC | Log management, detection and response, and compliance | Not disclosed | Company acquisition announcement |
| CrowdStrike | Flow Security | Cloud data runtime security | Reported at $200 million | Reported value; not identified as buyer-confirmed in the roundup |
| Cloudflare | Nefeli Networks | Multicloud networking technology | Not disclosed | Technology acquisition; the roundup links it to Magic Cloud Networking |
| Cycode | Bearer | Application security, including SAST, API discovery and data-leak protection | Reported at approximately $10 million | Reported value |
| F5 | Heyhack | Automated reconnaissance and penetration testing | Not disclosed | Company acquisition announcement |
| Flare | Foretrace | Threat intelligence and exposure management | Not disclosed | Company acquisition announcement |
| Cyber Security Associates / FluidOne | SureCloud Cyber Services | Penetration testing and cyber-risk consulting | Not disclosed | Service-business transaction |
| GitLab | Oxeye | Application security, software composition analysis and compliance | Reported at $30–40 million | Reported range |
| Hornetsecurity Group | Vade | Email security | Not disclosed | Company acquisition announcement |
| JumpCloud | Resmo | IT asset management and SaaS security | Not disclosed | Company acquisition announcement |
| Zscaler | Avalor | Risk management and security data platform | Reported at $350 million | Reported value; not identified as buyer-confirmed in the roundup |
| Air IT | SCS Technology Solutions | Managed IT and cybersecurity services | Not disclosed | Company acquisition announcement |
| American Technology Services | Cyber Defense International | Cybersecurity services | Not disclosed | Company acquisition announcement |
| Ark Technology Consultants | 5S Technologies | Technology and managed services | Not disclosed | Company acquisition announcement |
| ByteBridge | SecureLake | Cybersecurity and technology services | Not disclosed | Company acquisition announcement |
| Bridewell | Arculus Cyber Security | Cybersecurity services | Not disclosed | Company acquisition announcement |
| Exclusive Networks | NEXTGEN Group | Technology distribution and channel business | Not disclosed | Company acquisition announcement |
| Fscom | FMConsult | Cybersecurity consulting | Not disclosed | Company acquisition announcement |
| Gcore | StackPath’s WAAP business | Web application and API protection | Not disclosed | Business or product portfolio, not clearly a whole-company purchase |
| SHI International | Moot | Technology and cybersecurity capability | Not disclosed | Company acquisition announcement |
| Synopsys | Intrinsic ID | Embedded and hardware security technology | Not disclosed | Company acquisition announcement |
| The 20 MSP | Accurate Computer Solutions | Managed IT services | Not disclosed | Counted separately from Blue Cactus Consulting |
| The 20 MSP | Blue Cactus Consulting | IT and cybersecurity consulting | Not disclosed | Separate target |
What the activity covered
- Cloud and data security: CrowdStrike–Flow Security and Cloudflare–Nefeli Networks broadened capabilities around cloud data protection and multicloud networking.
- Application security and DevSecOps: Cycode–Bearer and GitLab–Oxeye added application-security functions, while F5–Heyhack brought automated testing capabilities.
- Exposure and risk management: Flare–Foretrace and Zscaler–Avalor addressed threat intelligence, exposure or risk data. The roundup characterized Flare–Foretrace as believed to be among the first deals in threat exposure management; that is a qualified characterization, not a settled industry-wide count.
- Email and web protection: Hornetsecurity–Vade involved email security, while Gcore acquired StackPath’s WAAP business rather than clearly buying the entire company.
- Managed services and consulting: AUCloud, Air IT, Bridewell, FluidOne and The 20 MSP were among buyers adding service businesses. The list also includes consulting and managed-IT firms whose work may extend beyond cybersecurity.
- Embedded security and distribution: Synopsys–Intrinsic ID concerned hardware and embedded-security technology; Exclusive Networks–NEXTGEN Group involved distribution and channel expansion.
The mix suggests buyers were adding products, technology and service capacity across several parts of the security market, rather than concentrating solely on one specialty. Platform expansion, geographic reach and managed-services scale are plausible strategic readings of the list, not proof that integrations succeeded or that the acquisitions produced particular financial results.
Rank #3
How to read this roundup
“Announced” is the key word. A deal announced in March may close later, require approvals, cover only selected assets, or change before completion. The roundup’s inclusion of an announcement does not by itself confirm closing, employee retention, product continuity or final consideration. Its visible list also mixes whole-company acquisitions, service-business purchases and an asset or product-business transaction.
Likewise, “not disclosed” means the roundup did not provide a value; it does not mean the transaction had no consideration. Reported prices and ranges should remain labeled as reported unless a buyer or seller confirms them. The source’s broader observation that cybersecurity deal volume and disclosed value were down from 2023 should be read as that article’s analysis, not as a complete market forecast or a conclusion about all of 2024.
Rank #4
For investors and operators, the practical signal is breadth, not a clean valuation benchmark: strategic buyers were pursuing cloud, application, exposure, email, networking, embedded-security and services capabilities. The 26-versus-27 count and the many undisclosed terms make precise totals and comparisons unreliable without a separately verified transaction dataset.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

