DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Cybersecurity M&A Roundup: 45 Deals Announced in January 2025

SecurityWeek reported 45 cybersecurity-related M&A announcements in January 2025. Its visible roundup names 44 deals, spanning exposure management, cloud security, identity, MDR, resilience, and services.
From TheFinanceBase Team9 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek counted 45 cybersecurity-related M&A announcements in January 2025, but its February 5 roundup visibly names 44 transactions: 12 highlighted deals and 32 others. Treat 45 as SecurityWeek’s reported count, not as a reconciled or independently audited total. The named deals show buyers expanding exposure management, cloud security, identity, backup and recovery, software-supply-chain security, and managed services.

For finance readers, the distinction between a reported valuation and confirmed consideration matters as much as the buyer and target. Several large figures were reported rather than confirmed, and many deal terms were undisclosed. The table below preserves the roundup’s visible transaction list and labels transaction types and announcement status where the available sources establish them.

How to read January’s deal count

SecurityWeek’s February 5, 2025 article says 45 cybersecurity-related M&A deals were announced in January. Its visible list contains 12 highlighted transactions plus 32 additional entries, or 44 named transactions. The article does not reconcile the difference. A missing entry, different counting treatment of a multi-target deal, or another explanation is possible, but none is established by the published list. The count should therefore be attributed to SecurityWeek rather than presented as an independently verified total.

The roundup does not publish a formal inclusion methodology. For the list below, the practical scope is transactions announced from January 1 through January 31, 2025 that SecurityWeek characterized as cybersecurity-related. That includes whole-company purchases, proposed acquisitions, business-unit purchases, platforms, and selected technology or asset deals. It also includes security-adjacent activity such as FinOps, fraud prevention, certificates, and general IT services; those are not all equivalent to buying a cybersecurity vendor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The table records announcement status, not whether a transaction eventually closed. “Not stated” means the cited roundup does not establish that field. The source list does not give announcement dates for each of its 44 entries, so dates are included only where the cited primary announcements establish them.

Largest disclosed or reported deal values

The figures below are not a total market valuation. They mix official announced consideration with reported figures, and most transactions in the roundup had no disclosed value.

Transaction Value and evidence Status and qualification
NinjaOne–Dropsuite Approximately $252 million, announced by NinjaOne on January 27, 2025. NinjaOne announcement. At announcement, this was an intended acquisition subject to approvals and customary conditions. NinjaOne later announced completion on June 2, 2025, at approximately $270 million. Completion announcement.
Tenable–Vulcan Cyber Approximately $147 million cash plus $3 million in restricted stock units, according to Tenable’s January 29, 2025 SEC-filed announcement. SEC filing. Definitive agreement announced; Tenable expected closing in the first quarter of 2025. Tenable announced completion on February 7, 2025. Completion announcement.
Chainalysis–Alterya $150 million, reported by SecurityWeek; the roundup does not establish this as confirmed consideration. SecurityWeek’s reported figure, not an official value established by a cited primary transaction filing. SecurityWeek roundup.
Searchlight Cyber–Assetnote Approximately AUD 100 million, or about US$62 million, reported by SecurityWeek. Reported figure, not confirmed purchase price established by a cited primary filing. SecurityWeek roundup.
Neqst–WithSecure consulting business €22.5 million, approximately US$23 million at the conversion stated in SecurityWeek’s roundup. Business-unit purchase, not a whole-company acquisition. SecurityWeek roundup.

Do not rank the reported Alterya and Assetnote figures as if they had the same evidentiary status as Tenable’s SEC-filed consideration. Likewise, use NinjaOne’s $252 million figure for the January announcement; the later completion announcement gave a different approximate value.

All 44 transactions visibly named in the roundup

The entries preserve the roundup’s names and descriptions. “Announced” means reported as part of January’s announcement dataset; it does not mean the transaction had closed. Values are “not disclosed” unless the cited roundup or primary source provides one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Buyer Target Category or transaction type January announcement status and value
1Password Trelica Access management and SaaS governance; company acquisition Described as acquired; value not disclosed.
Citrix Unicon Secure endpoint operating system and endpoint management; company acquisition Described as a strategic acquisition; value not disclosed.
Chainalysis Alterya Fraud prevention for financial and crypto services; company acquisition Announced; $150 million reported by SecurityWeek, not established as confirmed consideration.
CYE Solvo technology Cloud security, including CSPM and CIEM; technology acquisition Technology acquired; not described as a whole-company purchase. Value not disclosed.
Darktrace Cado Security Cloud investigation, forensics, and incident response; company acquisition proposed Proposed January 9, subject to regulatory approval; expected to complete in February 2025 at announcement. Value not disclosed.
Enigma / Option3 Dellfer Firmware security for automotive and IoT; platform acquisition Platform acquisition announced; value not disclosed.
Fenix24 vArmour Cyber resilience and incident recovery for Argos99 Acquisition announced; vArmour had previously announced shutdown plans. Value not disclosed.
NinjaOne Dropsuite SaaS backup, archiving, recovery, endpoint and data protection; company acquisition Definitive agreement announced January 27; approximately $252 million announced transaction value, subject to approvals and customary conditions.
Neqst WithSecure consulting business Cybersecurity consulting; business-unit purchase Announced; €22.5 million stated value in SecurityWeek’s roundup.
Searchlight Cyber Assetnote Attack-surface management and CTEM; company acquisition Announced; approximately AUD 100 million / US$62 million reported by SecurityWeek.
Tenable Vulcan Cyber Exposure management, prioritization, and remediation; company acquisition Definitive agreement announced January 29; approximately $147 million cash plus $3 million in restricted stock units. Tenable completed the deal February 7.
Veracode Selected Phylum assets Malicious-package analysis and software-supply-chain security; asset acquisition Selected assets acquired; not a whole-company acquisition. Value not disclosed.
Agile Defense IntelliBridge Government technology and services Acquisition listed; transaction type and value not stated in the roundup.
archTIS Direktiv Security-adjacent software Acquisition listed; transaction type and value not stated in the roundup.
AvePoint Ydentic Security-adjacent software and services Acquisition listed; transaction type and value not stated in the roundup.
Bridgepoint Eckoh Security-adjacent communications and payment security Acquisition listed; transaction type and value not stated in the roundup.
Cadence Secure-IC Embedded security and semiconductor security Agreement to acquire listed; value not stated in the roundup.
Case IQ Lextegrity Compliance and investigations software Acquisition listed; transaction type and value not stated in the roundup.
CertifID Paymints.io Fraud prevention and secure real-estate transactions Acquisition listed; transaction type and value not stated in the roundup.
CGI BJSS IT and technology services Acquisition listed; transaction type and value not stated in the roundup.
CHEQ Deduce Identity and fraud prevention Acquisition listed; transaction type and value not stated in the roundup.
CyberMaxx Cybersafe Solutions and onShore Security Managed cybersecurity services; multi-target transaction Acquisitions listed; terms and value not stated in the roundup.
Cymulate CYNC Secure Security validation Acquisition listed; transaction type and value not stated in the roundup.
Cytracom Telivy Security-adjacent managed services and software Acquisition listed; transaction type and value not stated in the roundup.
CyberlinkASP Cosentus Holdings’ MSP division Managed service provider division; business-unit purchase Division acquisition listed; value not stated in the roundup.
Elovade Avangate Security-adjacent software distribution Acquisition listed; transaction type and value not stated in the roundup.
Flexera NetApp’s FinOps business Cloud financial operations; business acquisition adjacent to cybersecurity Agreement to acquire listed; value not stated in the roundup.
Harmonia Maveris Cybersecurity and government services Acquisition listed; transaction type and value not stated in the roundup.
HPN Holdings Cybeta Cybersecurity services Agreement to acquire listed; value not stated in the roundup.
HUB Cyber Security BlackSwan Technologies Data and security software Acquisition listed; transaction type and value not stated in the roundup.
Hook Security Haekka Security awareness and human-risk management Acquisition listed; transaction type and value not stated in the roundup.
Inherent Devensys Cybersecurity services Acquisition listed; transaction type and value not stated in the roundup.
Integrity360 Nclose Cybersecurity services Acquisition listed; transaction type and value not stated in the roundup.
JumpCloud Stack Identity Identity infrastructure Acquisition listed; transaction type and value not stated in the roundup.
Netsurit US Computer Connection Managed IT and security services Acquisition listed; transaction type and value not stated in the roundup.
Patria ILIAS Solutions Defense and security software Acquisition listed; transaction type and value not stated in the roundup.
Quorum Cyber Kivu Consulting Incident response and cybersecurity consulting Acquisition listed; transaction type and value not stated in the roundup.
Rashi Peripherals Satcom Infotech Technology distribution, including security products Acquisition listed; transaction type and value not stated in the roundup.
Sectigo Entrust’s public certificate business Public certificate business; business-unit purchase Business acquisition listed; value not stated in the roundup.
Tersedia Kerberos Cybersecurity company Acquisition listed; transaction type and value not stated in the roundup.
Tidal Cyber Zero-Shot Security Threat-informed defense and security software Acquisition listed; transaction type and value not stated in the roundup.
Valeo Networks Verus Technology Solutions Managed IT and security services Acquisition listed; transaction type and value not stated in the roundup.
WatchGuard ActZero Managed detection and response (MDR) Acquisition announced January 8; deal value not disclosed in the cited announcement.
Xpect Solutions GovDefender Government cybersecurity services Acquisition listed; transaction type and value not stated in the roundup.

The full named list above is drawn from SecurityWeek’s January roundup. For entries without an individual primary announcement URL in the available source set, the table does not claim more about terms, date, or closing status than the roundup establishes.

What the transactions suggest about buyer strategy

Exposure and attack-surface management

Tenable’s Vulcan Cyber agreement paired vulnerability and exposure visibility with prioritization and remediation workflows. Tenable described its aim as consolidating exposure visibility across the security stack and streamlining remediation in its SEC-filed announcement. Searchlight Cyber’s purchase of Assetnote similarly broadened attack-surface capabilities toward continuous threat exposure management. Together, the deals point to buyers seeking to connect finding risk with deciding what to fix, rather than adding another isolated dashboard.

Cloud security, investigation, and identity

CYE’s acquisition of Solvo technology added cloud security posture management (CSPM) and cloud infrastructure entitlement management (CIEM) capabilities. Darktrace’s proposed Cado purchase targeted cloud investigation and forensic response, while 1Password’s Trelica deal expanded access management and SaaS governance. JumpCloud’s Stack Identity acquisition was another identity-infrastructure move. These transactions span prevention, permissions, investigation, and SaaS control rather than one uniform cloud-security product category.

MDR and services capacity

WatchGuard’s ActZero acquisition is a direct example of a product vendor buying managed detection and response capacity. WatchGuard said the deal would expand MDR through AI-assisted threat analysis and response, greater scale, and support for third-party security products. WatchGuard’s announcement did not disclose a purchase value.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other named transactions involved consulting, incident response, government technology, and regional managed-service providers. WithSecure’s consulting business, Kivu Consulting, Nclose, Devensys, Maveris, and multiple MSP or government-services targets illustrate a separate pattern: buyers can acquire delivery teams, customer relationships, and geographic reach as well as software. Those service rollups should not be confused with product-platform acquisitions.

Resilience and data protection

NinjaOne positioned Dropsuite’s backup, archiving, and recovery capabilities alongside endpoint management. Its January announcement described the combination as protection against ransomware and IT incidents. The strategic link is cyber resilience: recovery capability complements prevention and response because an organization also needs usable copies of data and a path back to service after an incident.

Software supply-chain security

Veracode’s purchase of selected Phylum assets concerned malicious-package analysis and software-supply-chain security. The wording matters: the roundup describes an asset acquisition, not Veracode buying the entire Phylum company. This is a targeted capability addition within application security, not evidence that every software-supply-chain deal was a full-company purchase.

Security-adjacent infrastructure

Several entries stretch beyond a narrow definition of cybersecurity. The FinOps business acquired by Flexera, secure endpoint operating systems, fraud and identity products, public certificate operations, and broad IT services may have security relevance, but they do not all represent purchases of security vendors. The breadth helps explain why a roundup’s count depends on its classification rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

January announcements were not all January closings

An M&A roundup organized by announcement month is a record of deal activity, not a list of transactions completed in that month. Darktrace announced a proposed acquisition of Cado Security on January 9, with regulatory approval outstanding and February completion expected at the time. Tenable announced its Vulcan Cyber agreement on January 29 and reported completion on February 7. NinjaOne announced its Dropsuite agreement on January 27, subject to shareholder, court, Australian Foreign Investment Review Board, and customary approvals; it later announced completion on June 2.

These examples show why status verbs should be precise. Use “announced” for the January dataset, “agreed to acquire” for a definitive agreement awaiting conditions, “proposed acquisition” where approval remained outstanding, and “completed” only when a later closing announcement confirms it. “Acquired technology,” “selected assets,” or “business unit” should be used when the target was not the entire company.

Why the values do not add up to a market total

Only a small subset of the named transactions has a value in the cited sources. Even within that subset, the basis varies: Tenable’s terms were disclosed in an SEC filing, NinjaOne reported an approximate transaction value at announcement and a different approximate value at completion, and the Alterya and Assetnote figures were reported by SecurityWeek. The WithSecure consulting business figure concerns a division, not the sale of an entire company.

Accordingly, adding these figures would mix confirmed consideration, approximate announcement values, secondary reporting, currencies, and different transaction scopes. The roundup supports a discussion of selected values, not a reliable aggregate for January cybersecurity M&A.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Context and limits

SecurityWeek separately said it tracked 405 cybersecurity-related M&A transactions announced during 2024. That is a different dataset; without a confirmed common methodology and comparable monthly series, it does not establish that January 2025 represented a particular share of annual activity or a record month. SecurityWeek’s acquisition archive provides that 2024 context.

For January 2025, the most defensible account is specific: SecurityWeek reported 45 announcements, its accessible named list contains 44 entries, and the transactions ranged from full-company acquisitions to proposed deals, divisions, platforms, and selected assets. That distinction is material for anyone using the roundup for market sizing, competitive analysis, or deal comparisons.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.