Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek counted 27 cybersecurity-related merger-and-acquisition announcements in August 2025. Its September 8 roundup gives detailed summaries of 10 transactions and names 17 more, but does not provide equivalent detail for all 27. The announcements span security services, identity, application and AI security, telemetry, and other capabilities; they should not be read as 27 completed acquisitions.

What the August 2025 count includes

SecurityWeek’s roundup reports 27 cybersecurity M&A announcements for August 2025 and describes the total as a significant drop from previous months, without giving a month-to-month comparison figure. The article is a news roundup, not an independently audited deal database. It uses varied wording—such as “acquired,” “announced plans to acquire,” and “announced an agreement to acquire”—so announcement does not necessarily mean a transaction had closed by publication.

For annual context, SecurityWeek says its own analysis counted 405 cybersecurity-related M&A announcements in 2024. That is the publication’s reported figure, rather than an independently validated total. SecurityWeek’s 2024 M&A analysis provides the cited context.

The 10 deals SecurityWeek described in detail

The roundup’s expanded entries show the range of capabilities being combined. They do not establish a formal ranking by transaction size: SecurityWeek calls these its most important deals but does not define a ranking method.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Buyer and target Capability and stated rationale Geography and status wording Terms in the roundup
Accenture / CyberCX CyberCX provides cybersecurity consulting, transformation, and managed security services. Accenture’s stated aim was to bolster its services in Asia Pacific. Australian firm; SecurityWeek says Accenture acquired it. Terms were not officially disclosed. The roundup attributes a valuation above A$1 billion (about US$650 million) to the Australian Financial Review; this is a reported valuation, not an officially disclosed purchase price.
Aikido Security / Trag Trag is an AI tool for automatic pull-request review, issue flagging, and feedback intended to support code quality. Belgium-based buyer and US-based target; the roundup says Aikido acquired Trag. Not stated by SecurityWeek.
CrowdStrike / Onum Onum’s real-time telemetry pipeline technology was described as enhancing CrowdStrike’s Falcon next-generation SIEM. Spain-based target; CrowdStrike announced plans to acquire it. Terms were undisclosed. The roundup says the deal was reportedly valued at $290 million.
Diginex / Findings Findings provides supply-chain risk monitoring and vendor-risk automation. Diginex is described as offering ESG reporting and supply-chain risk management technology. Israeli target; Diginex announced an agreement to acquire it. Up to $305 million in cash and Diginex shares, according to the roundup.
F5 / MantisNet MantisNet specializes in real-time network observability and intelligence, particularly in cloud-native and 5G environments. F5 planned to integrate the capabilities into its Application Delivery and Security Platform to support visibility, automation, and security in cloud-native architectures. SecurityWeek says F5 acquired MantisNet. Not stated by SecurityWeek.
Incode / AuthenticID AuthenticID provides identity verification and fraud detection, including authentication of government-issued identity documents. The combined effort was framed as addressing identity fraud. SecurityWeek says Incode acquired AuthenticID; no target geography is stated in the roundup. Not stated by SecurityWeek.
Invicti / Kondukto Kondukto is an application security posture management platform for coordinating vulnerabilities through the development lifecycle. The roundup says the combination could correlate runtime-validated DAST findings with broader ASPM data. Invicti is described as a web application security testing provider; SecurityWeek says it acquired Kondukto. Not stated by SecurityWeek.
KeyData Cyber / BeyondID BeyondID is a managed identity provider. The purchase was described as expanding KeyData Cyber’s advisory, implementation, and managed-services capabilities. SecurityWeek says KeyData Cyber announced the purchase; no target geography is stated in the roundup. Not stated by SecurityWeek.
Okta / Axiom Security Axiom Security provides privileged access management for cloud and virtual environments. Its technology was to be integrated into Okta Privileged Access. Israel-based target; SecurityWeek says Okta acquired Axiom. The roundup reports an estimated $75–100 million price, not an officially disclosed purchase price.
SentinelOne / Prompt Security Prompt Security is an AI security firm. SentinelOne’s stated aim was to extend its platform to secure workplace use of generative and agentic AI. SecurityWeek says SentinelOne acquired Prompt Security; no target geography is stated in the roundup. The roundup reports an estimated $250 million value, not an officially disclosed purchase price.

The other 17 announcements named

SecurityWeek lists these additional pairings or transactions without comparable summaries of rationale, terms, or status. The names alone do not support conclusions about purchase price, strategic motive, or whether a deal had closed.

  • Bastion Security Group / Seamless Intelligence
  • Bluewave Technology Group / Cactus Technology Solutions
  • Cloud Software Group / Arctera
  • Continuous / Sycorr
  • Cryptic Vector / Caesar Creek Software
  • Cyberlogic / NBConsult
  • ImageSource / Zorse Cyber assets
  • Kerberus / Pocket Universe
  • Lineal / ProFile Discovery
  • NetSpark / Infinite Technology Source
  • Ostra / Blackwell
  • Red Helix / Risk Crew
  • Root / Kosai
  • Scope Technologies / Cloud Codes
  • V2X / QinetiQ Group’s US Federal IT Services business
  • Valeo Networks / SpliceNet
  • Wingmen Solutions / majority stake in Trifork Security

What the roundup’s deal mix suggests—and what it does not

The 10 expanded summaries point to several areas of strategic interest: cybersecurity services in Asia Pacific; developer security and code review; SIEM telemetry; supply-chain and vendor risk; cloud-native network observability; identity verification; application security posture management; managed identity; privileged access; and AI security. These are themes visible in the described transactions, not a measured breakdown of the full set of 27 announcements.

Deal values also cannot be compared as if they were a consistent dataset. Several entries have no terms in the roundup, while the figures it does mention differ in wording and disclosure: an attributed valuation for CyberCX, a reported valuation for Onum, estimates for Axiom Security and Prompt Security, and a stated maximum consideration for Findings. Those distinctions matter more than treating every figure as a confirmed purchase price.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Source and scope

This account follows SecurityWeek’s roundup published September 8, 2025, which reports the August announcements. SecurityWeek’s deal descriptions and count are attributed to that publication; the roundup’s linked contemporaneous announcements and reporting are not independently assessed here. Use the 27 figure as SecurityWeek’s reported count, and consult transaction-specific announcements for later closing status or terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read SecurityWeek’s August 2025 cybersecurity M&A roundup.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.