Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Blog

Cybersecurity M&A Roundup: 44 Deals Announced in July 2025

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

SecurityWeek counted 44 cybersecurity-related M&A announcements in July 2025. The month’s biggest headline was Palo Alto Networks’ proposed, approximately $25 billion acquisition of identity-security company CyberArk. But the list also captures smaller acquisitions, a completed cyber-insurance deal, managed-service consolidation, majority-stake investment and purchases of business units.

These are announcements, not 44 confirmed closings. The roundup’s total is SecurityWeek’s tracked count—not a universal market census—and includes cyber-adjacent businesses such as IT services, consulting and insurance. SecurityWeek published its roundup on August 4, 2025.

What the 44-deal count means

SecurityWeek’s July figure covers transactions announced during July 1–31, 2025, that it classified as cybersecurity-related. The list includes conventional acquisitions, mergers, majority investments and purchases of operating businesses. Some companies are not pure-play security vendors; their work may span IT services, risk management, consulting, compliance or insurance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Each listed transaction or announcement is counted as a deal, but a single announcement can involve multiple targets or components. For example, Concentric AI’s entry names Swift Security and Acante, while Thrive’s names Abacode and Baroan. The count should therefore be read as the publication’s tracking methodology, not as a standardized total for every deal database. SecurityWeek’s later annual report also cautions that announced transactions in its dataset may not ultimately close (methodology note).

Announcement status matters. Zurich said it had successfully acquired BOXX Insurance on July 3, while Commvault announced an intent to acquire Satori Cyber, with closing then expected in August. Palo Alto Networks announced an agreement to buy CyberArk; that was not a July closing. Do not treat every entry below as a completed acquisition.

The nine headline transactions

  1. Axonius–Cynerio: Axonius announced on July 29 that it would acquire medical-device security specialist Cynerio for more than $100 million in cash and stock. The deal extends asset intelligence into connected equipment used in healthcare settings. Axonius announcement.
  2. Commvault–Satori Cyber: On July 24, Commvault announced its intent to acquire Satori, which works on data discovery and classification, access management, LLM monitoring and prompt protection. The rationale joins data protection with controls over how sensitive data is accessed and used, including in AI workflows. The announcement described an intended deal, not a completed July transaction. Commvault announcement.
  3. Darktrace–Mira Security: Darktrace acquired Mira Security, a network-traffic visibility specialist, to strengthen its network-security capabilities. The roundup did not disclose a price.
  4. Leonardo–Axiomatics and SSH: Leonardo acquired Axiomatics, whose work includes zero-trust and policy-based access controls, and sought a 24.55% stake in SSH. The SSH component involved a €20 million share issue. This was a mixed transaction—not a full acquisition of SSH.
  5. LevelBlue–Trustwave: LevelBlue acquired managed-security provider Trustwave, combining MDR capabilities and platform assets with LevelBlue’s cybersecurity and strategic-risk services. The deal reflects a broader push to build scale in managed security.
  6. Orange Cyberdefense–Ensec: Orange Cyberdefense acquired Swiss cybersecurity consulting and managed-services firm Ensec, adding regional capability and services capacity. The roundup did not report a value.
  7. Palo Alto Networks–CyberArk: Palo Alto Networks announced an agreement on July 30 to acquire identity-security company CyberArk in a cash-and-stock transaction valued at approximately $25 billion. The buyer presented the deal as an expansion into identity security, including controls for human and machine identities and privileged access. It was an announced agreement, not a July closing. Palo Alto Networks announcement.
  8. Vanta–Riskey: Vanta acquired Riskey, a third- and fourth-party risk-monitoring company, extending its compliance and risk-management capabilities.
  9. Zurich–BOXX Insurance: Zurich announced on July 3 that it had successfully acquired BOXX, a cyber-insurance and risk-management insurtech serving retail and small-to-medium-sized business customers. Zurich said BOXX would retain its brand and join Zurich Global Ventures. Zurich announcement.

Disclosed deal values—and the limits of the numbers

The two standout disclosed figures in the roundup are the approximately $25 billion CyberArk agreement and Axonius’s purchase of Cynerio for more than $100 million in cash and stock. Leonardo’s SSH investment involved a €20 million share issue; that amount should not be confused with the price paid for Axiomatics or treated as the value of a full SSH acquisition.

Most other terms were not disclosed in the roundup. Because the public figures cover only a few transactions and describe different kinds of consideration, adding them would not produce a meaningful total for July’s deal value. An undisclosed price is not evidence that a transaction was small.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

All 44 transactions in SecurityWeek’s July roundup

The nine headline transactions above plus the 35 additional entries below make up SecurityWeek’s 44. The additional entries are identified as buyer or lead party and target as listed in the roundup. Its abbreviated list does not provide verified closing status, transaction value or detailed category for every item; an announcement’s inclusion alone does not establish that it closed.

Buyer or lead party Target or transaction
Abacus Group Medicus IT
Barnett Waddingham Risk Evolves
Boxxe CAE Technology Services Limited
Bureau Veritas Institute for Cyber Risk
CASE Ragnarok Technologies
Celerity Silverstring Limited
Concentric AI Swift Security and Acante
CompassMSP BlackPoint IT
Data443 Risk Mitigation TacitRed
Deloitte Canada Allevar
Didomi Sourcepoint
Ekco Adapt IT
Evergreen ImageQuest
F12.net AMTRA
FutureRange DigitalWell’s managed-services business
Hg Majority stake in A-LIGN
InCorp Advisory Ken & Co.
Knexus S4
Lansweeper Redjack
Limerston Capital DigitalXRAID
Monad Tarsal
Nautic Partners AccessIT
Parsons Chesapeake Technologies International
PEN America OnlineSOS
Polymath Polymesh
Secur-Serv Arrowhead Technologies
SecurityBridge CyberSafe
Sphinx Enigma
Thrive Abacode and Baroan
Vorboss 40fi and Optimity
WebPros Comet Backup

The full July set spans product companies, service providers, compliance and risk businesses, and other cyber-adjacent operations. The table records the roundup’s names rather than implying that every deal was a purchase of a standalone cybersecurity software company.

What the deal mix says about cybersecurity M&A

Identity is a platform layer, not just a point product

Palo Alto Networks’ CyberArk agreement was the month’s value outlier and a signal of how large platform vendors may seek capabilities beyond their original product boundaries. Identity security addresses access by employees, administrators, applications and machines; privileged-access controls are one important part of that picture. Leonardo’s Axiomatics acquisition and proposed SSH stake also touch policy-based access, privileged access, secure file transfer and encryption-key management, though the SSH investment is not a full buyout.

A strategic fit does not guarantee successful integration or value creation. For customers, the practical questions are whether products remain distinct, how identity data and policies will be handled, and whether road maps or commercial terms change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data protection is meeting data and AI governance

Commvault’s proposed Satori transaction points to an operational problem: organizations need to know what sensitive data they hold, who or what can reach it, and how it is used in AI systems. Satori’s described capabilities—discovery, classification, access management, LLM monitoring and prompt protection—are more specific than the broad label “AI security.” Bringing them alongside data-protection products could create a wider control surface, but the deal announcement alone does not prove how integrated the products will become.

Healthcare and connected-device security have distinct constraints

Cynerio adds security for medical devices and connected clinical environments to Axonius’s asset-intelligence footprint. These environments can include specialized and legacy equipment, where visibility and remediation need to account for clinical uptime and patient safety. That makes healthcare-device security different from a routine software tuck-in: security teams must work with clinical engineering and operations, and any change must fit the environment’s regulatory and operational requirements.

Managed-security providers are seeking scale

LevelBlue–Trustwave sits within a broader set of service-provider and IT-services transactions in the roundup. Consolidation can help providers expand geography, pursue larger contracts, staff round-the-clock security operations, combine MDR with consulting or compliance services, and spread the cost of platforms and automation across a larger customer base. It can also bring integration complexity: customers should check which service desk, monitoring platform, escalation path and contract entity will support them after a deal.

Insurance broadens the meaning of a security deal

Zurich–BOXX is not the same kind of transaction as buying a security software vendor. Cyber insurance combines underwriting and risk transfer with prevention and response services, and it serves customers through a different regulatory and commercial model. Zurich’s stated plan to keep BOXX under its brand illustrates how an insurer may add a specialist offering without immediately retiring its identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Regional and services consolidation remains part of the story

Ensec and the many smaller or less-detailed entries show that July was not only a megadeal month. Acquisitions of consultancies, managed-service businesses and IT providers can be about local market access, staff, customer relationships and delivery capacity as much as proprietary technology. The 44-entry breadth supports a picture of consolidation across several adjacent markets, but it does not establish a record month or a universal industry trend by itself.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What customers, employees and investors should watch

  • For customers: Ask whether the product or service will retain its name, roadmap, support team and contract terms. Confirm renewal, data-handling, hosting and escalation arrangements rather than assuming they remain unchanged.
  • For employees: Leadership, location, reporting lines and investment priorities can change after a transaction. Announcements often do not specify those details, so avoid inferring them from the buyer’s strategic rationale.
  • For investors and deal teams: Separate a platform-scale acquisition from a small capability tuck-in, a control investment from a full buyout, and software purchases from services or insurance transactions. Disclosed deal value is only one dimension; distribution, talent, customer access and integration burden may also matter.
  • For all parties: A cyber due-diligence review should not be reduced to an external security score. Product architecture, breach and incident history, privacy obligations, customer commitments, dependencies and post-merger integration plans all affect risk.

Status perspective

The July roundup is a snapshot of what was announced in that month, not a ledger of final outcomes. Two examples make the distinction clear: Zurich reported the BOXX acquisition as successful on July 3, while Commvault’s July 24 release said it intended to acquire Satori and expected the deal to close in August. Palo Alto Networks’ July agreement to acquire CyberArk was subsequently reported as completed in 2026; the later closing does not change its status as an announced agreement in a July 2025 announcement roundup. Palo Alto Networks’ later closing announcement.

SecurityWeek also reported 405 cybersecurity-related M&A announcements in 2024, providing context for the July list but not a directly comparable monthly benchmark. As with any roundup, inclusion criteria and deal status should be checked before using the count for market sizing or investment analysis.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.