Not all cyber acquisitions are created equal: what to look for to make sense of the M&A noise
In cyber, not everything is what it seems
There is a lot of noise about cybersecurity startup acquisitions. It surely seems like everyone is getting acquired for at least $500M every month, and social media has been amplifying that big time. Companies seemingly get acquired for hundreds of millions before even coming out of stealth. Some of it is real, some of it is kind of real, and some of it is very creative ways to stretch reality; ways that aren’t exactly untrue, but that cannot be taken at face value.
This piece has been sitting in draft for many months, but it’s been pretty hard to write. It’s also a piece that may be painful to read for many folks who are personally familiar with how these things play out, or who have found themselves in one of the less-ideal scenarios I am going to describe. Suffice to say that startups are hard, that most founders and teams are doing the impossible work to make them successful, and that success is hard to intentionally architect because of the millions of factors that come into play.
Lastly, none of what I am talking about here is meant to be about any specific company (unless I use a company as an example, and I will do that sparingly and as gently as possible).
This issue is brought to you by... Maze.
Code security you trust
Legacy SCA and SAST scanners match patterns and bury engineers in noise. That’s why we built Maze Code: AI agents that understand your code and dependencies.
AI agents investigate every finding with context from your code and cloud, close false positives, and catch business logic flaws other tools miss. Then they help you fix what’s left, right in your IDE or coding agent.
Finally, inbox zero for your code and cloud vulnerabilities is possible.
First things first: defining success of a startup exit
How do you define the success of a startup exit? Well, that depends on whom you ask, and rarely will all the people agree:
To CISOs and security teams, an acquisition is successful if it makes the product they are using better, embeds it seamlessly into their existing stack, and makes it much easier to realize the compound value of the broader security tools portfolio.
To founders, an acquisition is successful when the acquiring company allows them to continue executing on their mission with more resources and support than before, and obviously, when the founders make money they think reflects their hard work over the years
To employees, it’s basically the same - an acquisition is successful when the acquiring company allows them to continue executing on their strategy with more resources and support than before, and obviously, when they make money they think reflects their hard work over the years
To investors, an acquisition is successful when it gives them the return multiple that is truly impactful for their fund.
I have missed many factors, but these are some of the core ones. The problem is, every single one of them is so contextual and so multi-dimensional that when you ask people if a specific M&A was successful, you’ll get vastly different answers:
Say, Palo Alto Networks acquires a startup. That can be great news to CISOs who have consolidated on the Palo Alto stack, but if they are more of a Fortinet shop, they will most likely not be very happy.
Or say, a founder makes an X amount of money. Is this what they wanted? Less than they feel their work is worth? Is it all cash, or have they just exchanged their company stock for another company’s stock? Public or private? (In other words, does it have real cash value or just paper value?). Was this specific co-founder looking to sell, or did the other co-founders and investors push them to? Or maybe they would have preferred to sell many years back, but they couldn’t?
Team members are going to have different perspectives as well. Someone who has joined the company as one of the first 10 team members could be making a life-changing amount of money, while someone else, who joined as the team member number 150, may just get enough to pay for a week-long vacation, or a cup of coffee, depending on how lucky they get.
VCs are also rarely aligned. First off, are they getting cash or equity? If cash, at least that goes to their fund and counts as a return; if equity, then again, they are just exchanging the shares of the company they had some influence on and control over for the shares of a company they don’t control anything in. More importantly, what constitutes a great return multiple is also different. With the same acquisition, a Seed-stage VC could be very happy with their 10-25X return, while a B-stage investor could be barely getting their money back at 1X and making nothing. In cyber, this happens more often than people realize.
The number of different scenarios is so vast that it is extremely, extremely rare to ask all the different people “Is the X acquisition successful?” and have all of them say “Yes”. Zscaler, CrowdStrike, Palo Alto Networks - these kinds of generational companies are definitely on that shortlist. Wiz is as well. The vast majority, not so much. Oftentimes, nobody makes money. Sometimes founders & early-stage VCs make something while employees and later-stage VCs make nothing. Sometimes founders also make nothing… The point is, it all varies.
Success in the broadest terms is making everyone happy, but whether or not an acquisition was successful is always a matter of whom you ask.
The hierarchy of cyber acquisitions: what to look for to make sense of the M&A noise
How do you tell if an acquisition is “good”? As we’ve established, there are no solid answers, but that doesn’t mean that there are no rules of thumb. As you can imagine, the part that follows is pretty subjective, so take it or leave it.
Fundamentally, I believe that we can take all the different M&A scenarios and build a pretty simple hierarchy framework that ranks these scenarios from “Great” to “Okay” or “Not great”.
Acquisition by an established public company
The best acquisition is when the security startup is acquired by a large, reputable, established public company, in an all-cash or cash-and-stock transaction, with no crazy vest periods and other clauses.
The first question is: is the company acquiring a business, a product, or the team? Nobody makes these kinds of announcements, but there are signs to look for.
Is the company issuing a press release? Are the acquisition price and announcement transparent? Sometimes, the startup that gets acquired is all about the transaction, but the company that acquired them doesn’t even do a social media post. A lot of the acqui-hire transactions don’t often get a press release issued, and “terms of transaction are not disclosed” is a shorthand for “terms of transaction are not so great that we want to talk about them”. If the acquiring company is keeping the entire team (or most of the team), chances are they see the acquisition as buying the business, but if a big chunk of the team is suddenly announcing how excited they are to “take time off and recharge before the next opportunity”, and if only the founders and engineers are staying, then it’s often an acqusiition to just integrate the product. None of this means “bad”, but it surely means “not successful” for at least some people involved.
Not all public companies in cyber are created equal when it comes to M&A. Some of them are known for making strategic bets and being willing to pay a premium price for top teams and products, while others are taking more of a “Costco approach” to cyber and buying distressed startups with good tech for a low price.
Also, it goes without saying that when getting acquired in a deal with a stock component, it is much better when the company stock is doing well vs. when it is not. With public companies, all kinds of twists and turns are possible, but if the stock is already doing pretty bad, it’s unlikely that the addition of the startup is going to radically improve it.
Random tip: an interesting way to get some sense if the acquisition was on good terms is to look at the LinkedIn trend of the company that just got acquired. You can never tell that an acquisition was good if the team and company metrics were trending upwards, but you can be pretty sure that the acquisition wasn’t great (again, at least for some people) if they were trending downwards.
Acquisition by an established, high-growth private company
Short of getting acquired by a large public company for a lot of cash, I think the second best M&A outcome is getting acquired by an established, high-growth private company. There are, again, so many different nuances, but there are a number of companies that are private, may be PE-owned, and growing aggressively on a path to the IPO or a large M&A. I am not going to call out any specific companies here for obvious reasons, and because I haven’t been tracking any of this for a while.
The simple logic is that when an acquisition happens, you (almost) always want to get cash. Company stock can go up and down, but cash (hopefully) doesn’t, at least not as quickly. Private companies don’t tend to do all-cash acquisitions, so if there is a cash amount, it may be smaller (again, not always but often). When looking at private company acquisitions, the questions are:
Is it cash and stock, or all stock?
How quickly can stock turn into cash (i.e., how soon can the acquirer itself exit?)
Being acquired by a private company comes with a lot of uncertainty. Over the past years, most of the private company IPOs haven’t been fantastic, so there’s always a question of what the stock will be worth when an exit does happen. Also, all the other points I mentioned for public companies still apply:
If the transaction is for an undisclosed amount, it’s rarely “fantastic”.
It is more common for private acquisitions to be product and team (aka acqui-hire)-focused vs. business-focused. This means that it’s more common for private companies to buy startups that aren’t doing that great but that build products they can integrate than it is to buy successful growing companies.
Acquisition by a PE firm
While I am putting the “acquisition by a PE firm” as last on this list, it’s more for ordering reasons than anything else. I don’t think there is that big of a difference between getting acquired by a private company or a PE firm (especially because so many of the cyber companies are PE-owned). To be clear, the difference is there; I just don’t think one is necessarily better or worse than the other.
Here are a few points:
PE firms tend to acquire companies they think can be run more efficiently, or that have the potential to be transformed into much more valuable businesses (by large-scale transformation, bundling a few companies together, etc.). The degree and the format of PE firm involvement in operating the company is something that founders need to be aware of.
Most importantly, because of how the PE model works, PE firms rarely buy early-stage startups (unless they want to bundle their tech with their existing portfolio companies).
Everything else applies similarly to the acquisitions by the private companies: how much cash, how much stock, and how long until that stock is worth something.
A few specific cases and scenarios to be aware of
Acquisitions within the same VC portfolio
Over the past several years, we have started seeing acquisitions within the same VC portfolio. Cyberstarts in particular seems to be execuring this playbook really well where their most successful bets are buying out all the other portfolio companies. We have seen that with Wiz acquiring Dazz, and Cyera acquiring Trail, and as recently as today - Oasis Security.
This is, I think, a pretty new phenomenon. Obviously, VCs would prefer cash acquisitions by large public companies, but if that isn’t happening, it very much makes sense to continue doubling down on the largest winners. I don’t know if we’ll be seeing more of this with other VCs, but Cyberstarts seems to like this, so I suspect more is to come.
Palo Alto Networks acquisitions
Palo Alto Networks has undeniably become the dream home for most startup founders because of its willingness to pay top multiples for the top teams and top products. One of the latest huge successes is Koi, acquired earlier in 2026 for approximately $400 million after 2 or so years. Palo Alto Networks’ high-risk, high-reward bets have paid off handsomely with bets like Demiso, Talon, and Expanse.
What most people forget is that most cyber startup acquisitions aren’t like Palo Alto’s acquisitions. The median acquisition price of a cyber startup is much lower than these top numbers (somewhere between under $100M and $200M if I were to guess, but I don’t have the actual numbers so take that with a grain of salt).
A note on acquisition amounts
The last note I’ll add here has to do with acquisition amounts. Depending on the source, the numbers can be very real or very unreal. Simply put, not everything is what it seems. When an established, reputable company is issuing a press release stating the acquisition amount, these numbers are typically pretty credible. In some cases, they can include earn-outs, meaning that the company will only get that full amount if the acquired startup hits specific goals, but overall there are no concerns.
Things get pretty hairy when we look at media reports.
When you are reading a reputable source like TechCrunch or VentureBeat report on an acquisition, you can be pretty sure the numbers have been independently verified. The majority of the cyber transactions do not make it to TechCrunch news, and the amount of vetting and verification that goes into confirming if the numbers people claim are true varies widely. Some media may inflate M&A transaction prices by as much as 3X-4X (meaning what is reported as $100M can be as little as $25M, what’s reported as $500M can be as low as $100M, and so on.
I am not there to judge what people say, just here to point out that a) not every number you read is real, and b) that the majority of the successful exits aren’t what people think they are.
But then again, the definition of success is dependent on whom you ask.
P.S. To see how cyber has consolidated, check out 20 years of cybersecurity consolidation: how 200 companies became 11


