SecurityWeek counted 45 cybersecurity-related M&A announcements in January 2025, but its February 5 roundup visibly names 44 transactions: 12 highlighted deals and 32 others. Treat 45 as SecurityWeek’s reported count, not as a reconciled or independently audited total. The named deals show buyers expanding exposure management, cloud security, identity, backup and recovery, software-supply-chain security, and managed services.
For finance readers, the distinction between a reported valuation and confirmed consideration matters as much as the buyer and target. Several large figures were reported rather than confirmed, and many deal terms were undisclosed. The table below preserves the roundup’s visible transaction list and labels transaction types and announcement status where the available sources establish them.
How to read January’s deal count
SecurityWeek’s February 5, 2025 article says 45 cybersecurity-related M&A deals were announced in January. Its visible list contains 12 highlighted transactions plus 32 additional entries, or 44 named transactions. The article does not reconcile the difference. A missing entry, different counting treatment of a multi-target deal, or another explanation is possible, but none is established by the published list. The count should therefore be attributed to SecurityWeek rather than presented as an independently verified total.
The roundup does not publish a formal inclusion methodology. For the list below, the practical scope is transactions announced from January 1 through January 31, 2025 that SecurityWeek characterized as cybersecurity-related. That includes whole-company purchases, proposed acquisitions, business-unit purchases, platforms, and selected technology or asset deals. It also includes security-adjacent activity such as FinOps, fraud prevention, certificates, and general IT services; those are not all equivalent to buying a cybersecurity vendor.
Recommended Free Tools
#1 Best Overall
The table records announcement status, not whether a transaction eventually closed. “Not stated” means the cited roundup does not establish that field. The source list does not give announcement dates for each of its 44 entries, so dates are included only where the cited primary announcements establish them.
Largest disclosed or reported deal values
The figures below are not a total market valuation. They mix official announced consideration with reported figures, and most transactions in the roundup had no disclosed value.
| Transaction | Value and evidence | Status and qualification |
|---|---|---|
| NinjaOne–Dropsuite | Approximately $252 million, announced by NinjaOne on January 27, 2025. NinjaOne announcement. | At announcement, this was an intended acquisition subject to approvals and customary conditions. NinjaOne later announced completion on June 2, 2025, at approximately $270 million. Completion announcement. |
| Tenable–Vulcan Cyber | Approximately $147 million cash plus $3 million in restricted stock units, according to Tenable’s January 29, 2025 SEC-filed announcement. SEC filing. | Definitive agreement announced; Tenable expected closing in the first quarter of 2025. Tenable announced completion on February 7, 2025. Completion announcement. |
| Chainalysis–Alterya | $150 million, reported by SecurityWeek; the roundup does not establish this as confirmed consideration. | SecurityWeek’s reported figure, not an official value established by a cited primary transaction filing. SecurityWeek roundup. |
| Searchlight Cyber–Assetnote | Approximately AUD 100 million, or about US$62 million, reported by SecurityWeek. | Reported figure, not confirmed purchase price established by a cited primary filing. SecurityWeek roundup. |
| Neqst–WithSecure consulting business | €22.5 million, approximately US$23 million at the conversion stated in SecurityWeek’s roundup. | Business-unit purchase, not a whole-company acquisition. SecurityWeek roundup. |
Do not rank the reported Alterya and Assetnote figures as if they had the same evidentiary status as Tenable’s SEC-filed consideration. Likewise, use NinjaOne’s $252 million figure for the January announcement; the later completion announcement gave a different approximate value.
All 44 transactions visibly named in the roundup
The entries preserve the roundup’s names and descriptions. “Announced” means reported as part of January’s announcement dataset; it does not mean the transaction had closed. Values are “not disclosed” unless the cited roundup or primary source provides one.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →| Buyer | Target | Category or transaction type | January announcement status and value |
|---|---|---|---|
| 1Password | Trelica | Access management and SaaS governance; company acquisition | Described as acquired; value not disclosed. |
| Citrix | Unicon | Secure endpoint operating system and endpoint management; company acquisition | Described as a strategic acquisition; value not disclosed. |
| Chainalysis | Alterya | Fraud prevention for financial and crypto services; company acquisition | Announced; $150 million reported by SecurityWeek, not established as confirmed consideration. |
| CYE | Solvo technology | Cloud security, including CSPM and CIEM; technology acquisition | Technology acquired; not described as a whole-company purchase. Value not disclosed. |
| Darktrace | Cado Security | Cloud investigation, forensics, and incident response; company acquisition proposed | Proposed January 9, subject to regulatory approval; expected to complete in February 2025 at announcement. Value not disclosed. |
| Enigma / Option3 | Dellfer | Firmware security for automotive and IoT; platform acquisition | Platform acquisition announced; value not disclosed. |
| Fenix24 | vArmour | Cyber resilience and incident recovery for Argos99 | Acquisition announced; vArmour had previously announced shutdown plans. Value not disclosed. |
| NinjaOne | Dropsuite | SaaS backup, archiving, recovery, endpoint and data protection; company acquisition | Definitive agreement announced January 27; approximately $252 million announced transaction value, subject to approvals and customary conditions. |
| Neqst | WithSecure consulting business | Cybersecurity consulting; business-unit purchase | Announced; €22.5 million stated value in SecurityWeek’s roundup. |
| Searchlight Cyber | Assetnote | Attack-surface management and CTEM; company acquisition | Announced; approximately AUD 100 million / US$62 million reported by SecurityWeek. |
| Tenable | Vulcan Cyber | Exposure management, prioritization, and remediation; company acquisition | Definitive agreement announced January 29; approximately $147 million cash plus $3 million in restricted stock units. Tenable completed the deal February 7. |
| Veracode | Selected Phylum assets | Malicious-package analysis and software-supply-chain security; asset acquisition | Selected assets acquired; not a whole-company acquisition. Value not disclosed. |
| Agile Defense | IntelliBridge | Government technology and services | Acquisition listed; transaction type and value not stated in the roundup. |
| archTIS | Direktiv | Security-adjacent software | Acquisition listed; transaction type and value not stated in the roundup. |
| AvePoint | Ydentic | Security-adjacent software and services | Acquisition listed; transaction type and value not stated in the roundup. |
| Bridgepoint | Eckoh | Security-adjacent communications and payment security | Acquisition listed; transaction type and value not stated in the roundup. |
| Cadence | Secure-IC | Embedded security and semiconductor security | Agreement to acquire listed; value not stated in the roundup. |
| Case IQ | Lextegrity | Compliance and investigations software | Acquisition listed; transaction type and value not stated in the roundup. |
| CertifID | Paymints.io | Fraud prevention and secure real-estate transactions | Acquisition listed; transaction type and value not stated in the roundup. |
| CGI | BJSS | IT and technology services | Acquisition listed; transaction type and value not stated in the roundup. |
| CHEQ | Deduce | Identity and fraud prevention | Acquisition listed; transaction type and value not stated in the roundup. |
| CyberMaxx | Cybersafe Solutions and onShore Security | Managed cybersecurity services; multi-target transaction | Acquisitions listed; terms and value not stated in the roundup. |
| Cymulate | CYNC Secure | Security validation | Acquisition listed; transaction type and value not stated in the roundup. |
| Cytracom | Telivy | Security-adjacent managed services and software | Acquisition listed; transaction type and value not stated in the roundup. |
| CyberlinkASP | Cosentus Holdings’ MSP division | Managed service provider division; business-unit purchase | Division acquisition listed; value not stated in the roundup. |
| Elovade | Avangate | Security-adjacent software distribution | Acquisition listed; transaction type and value not stated in the roundup. |
| Flexera | NetApp’s FinOps business | Cloud financial operations; business acquisition adjacent to cybersecurity | Agreement to acquire listed; value not stated in the roundup. |
| Harmonia | Maveris | Cybersecurity and government services | Acquisition listed; transaction type and value not stated in the roundup. |
| HPN Holdings | Cybeta | Cybersecurity services | Agreement to acquire listed; value not stated in the roundup. |
| HUB Cyber Security | BlackSwan Technologies | Data and security software | Acquisition listed; transaction type and value not stated in the roundup. |
| Hook Security | Haekka | Security awareness and human-risk management | Acquisition listed; transaction type and value not stated in the roundup. |
| Inherent | Devensys | Cybersecurity services | Acquisition listed; transaction type and value not stated in the roundup. |
| Integrity360 | Nclose | Cybersecurity services | Acquisition listed; transaction type and value not stated in the roundup. |
| JumpCloud | Stack Identity | Identity infrastructure | Acquisition listed; transaction type and value not stated in the roundup. |
| Netsurit | US Computer Connection | Managed IT and security services | Acquisition listed; transaction type and value not stated in the roundup. |
| Patria | ILIAS Solutions | Defense and security software | Acquisition listed; transaction type and value not stated in the roundup. |
| Quorum Cyber | Kivu Consulting | Incident response and cybersecurity consulting | Acquisition listed; transaction type and value not stated in the roundup. |
| Rashi Peripherals | Satcom Infotech | Technology distribution, including security products | Acquisition listed; transaction type and value not stated in the roundup. |
| Sectigo | Entrust’s public certificate business | Public certificate business; business-unit purchase | Business acquisition listed; value not stated in the roundup. |
| Tersedia | Kerberos | Cybersecurity company | Acquisition listed; transaction type and value not stated in the roundup. |
| Tidal Cyber | Zero-Shot Security | Threat-informed defense and security software | Acquisition listed; transaction type and value not stated in the roundup. |
| Valeo Networks | Verus Technology Solutions | Managed IT and security services | Acquisition listed; transaction type and value not stated in the roundup. |
| WatchGuard | ActZero | Managed detection and response (MDR) | Acquisition announced January 8; deal value not disclosed in the cited announcement. |
| Xpect Solutions | GovDefender | Government cybersecurity services | Acquisition listed; transaction type and value not stated in the roundup. |
The full named list above is drawn from SecurityWeek’s January roundup. For entries without an individual primary announcement URL in the available source set, the table does not claim more about terms, date, or closing status than the roundup establishes.
What the transactions suggest about buyer strategy
Exposure and attack-surface management
Tenable’s Vulcan Cyber agreement paired vulnerability and exposure visibility with prioritization and remediation workflows. Tenable described its aim as consolidating exposure visibility across the security stack and streamlining remediation in its SEC-filed announcement. Searchlight Cyber’s purchase of Assetnote similarly broadened attack-surface capabilities toward continuous threat exposure management. Together, the deals point to buyers seeking to connect finding risk with deciding what to fix, rather than adding another isolated dashboard.
Cloud security, investigation, and identity
CYE’s acquisition of Solvo technology added cloud security posture management (CSPM) and cloud infrastructure entitlement management (CIEM) capabilities. Darktrace’s proposed Cado purchase targeted cloud investigation and forensic response, while 1Password’s Trelica deal expanded access management and SaaS governance. JumpCloud’s Stack Identity acquisition was another identity-infrastructure move. These transactions span prevention, permissions, investigation, and SaaS control rather than one uniform cloud-security product category.
MDR and services capacity
WatchGuard’s ActZero acquisition is a direct example of a product vendor buying managed detection and response capacity. WatchGuard said the deal would expand MDR through AI-assisted threat analysis and response, greater scale, and support for third-party security products. WatchGuard’s announcement did not disclose a purchase value.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsOther named transactions involved consulting, incident response, government technology, and regional managed-service providers. WithSecure’s consulting business, Kivu Consulting, Nclose, Devensys, Maveris, and multiple MSP or government-services targets illustrate a separate pattern: buyers can acquire delivery teams, customer relationships, and geographic reach as well as software. Those service rollups should not be confused with product-platform acquisitions.
Rank #4
Resilience and data protection
NinjaOne positioned Dropsuite’s backup, archiving, and recovery capabilities alongside endpoint management. Its January announcement described the combination as protection against ransomware and IT incidents. The strategic link is cyber resilience: recovery capability complements prevention and response because an organization also needs usable copies of data and a path back to service after an incident.
Software supply-chain security
Veracode’s purchase of selected Phylum assets concerned malicious-package analysis and software-supply-chain security. The wording matters: the roundup describes an asset acquisition, not Veracode buying the entire Phylum company. This is a targeted capability addition within application security, not evidence that every software-supply-chain deal was a full-company purchase.
Security-adjacent infrastructure
Several entries stretch beyond a narrow definition of cybersecurity. The FinOps business acquired by Flexera, secure endpoint operating systems, fraud and identity products, public certificate operations, and broad IT services may have security relevance, but they do not all represent purchases of security vendors. The breadth helps explain why a roundup’s count depends on its classification rules.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
January announcements were not all January closings
An M&A roundup organized by announcement month is a record of deal activity, not a list of transactions completed in that month. Darktrace announced a proposed acquisition of Cado Security on January 9, with regulatory approval outstanding and February completion expected at the time. Tenable announced its Vulcan Cyber agreement on January 29 and reported completion on February 7. NinjaOne announced its Dropsuite agreement on January 27, subject to shareholder, court, Australian Foreign Investment Review Board, and customary approvals; it later announced completion on June 2.
These examples show why status verbs should be precise. Use “announced” for the January dataset, “agreed to acquire” for a definitive agreement awaiting conditions, “proposed acquisition” where approval remained outstanding, and “completed” only when a later closing announcement confirms it. “Acquired technology,” “selected assets,” or “business unit” should be used when the target was not the entire company.
Why the values do not add up to a market total
Only a small subset of the named transactions has a value in the cited sources. Even within that subset, the basis varies: Tenable’s terms were disclosed in an SEC filing, NinjaOne reported an approximate transaction value at announcement and a different approximate value at completion, and the Alterya and Assetnote figures were reported by SecurityWeek. The WithSecure consulting business figure concerns a division, not the sale of an entire company.
Accordingly, adding these figures would mix confirmed consideration, approximate announcement values, secondary reporting, currencies, and different transaction scopes. The roundup supports a discussion of selected values, not a reliable aggregate for January cybersecurity M&A.
Context and limits
SecurityWeek separately said it tracked 405 cybersecurity-related M&A transactions announced during 2024. That is a different dataset; without a confirmed common methodology and comparable monthly series, it does not establish that January 2025 represented a particular share of annual activity or a record month. SecurityWeek’s acquisition archive provides that 2024 context.
For January 2025, the most defensible account is specific: SecurityWeek reported 45 announcements, its accessible named list contains 44 entries, and the transactions ranged from full-company acquisitions to proposed deals, divisions, platforms, and selected assets. That distinction is material for anyone using the roundup for market sizing, competitive analysis, or deal comparisons.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




