39 Cybersecurity Deals in One Month: What September 2026 M&A Reveals About the Future of Security

Cybersecurity is no longer a collection of isolated technologies.

Organizations increasingly need security across cloud environments, artificial intelligence, software supply chains, operational technology, identity systems, data platforms, applications, and critical infrastructure.

The cybersecurity M&A activity recorded in September 2026 provides a strong indication of where the industry is heading.

According to SecurityWeek, 39 cybersecurity related merger and acquisition deals were announced during September 2026. The transactions involved areas ranging from penetration testing and compliance to OT security, AI security, cloud security, identity, managed detection and response, and software supply chain protection.

The number itself is significant, but the areas attracting investment are even more important.

The cybersecurity market is moving toward integrated platforms that combine automation, artificial intelligence, continuous monitoring, offensive security, compliance, and specialized expertise.

Cybersecurity M&A Is Becoming a Strategic Security Indicator

Cybersecurity acquisitions are not simply financial transactions.

They often show where security vendors believe customer demand is moving.

The September activity highlights several major themes:

• Artificial intelligence and agentic security
• Cloud and exposure management
• Software supply chain security
• Operational technology security
• Penetration testing and offensive security
• Managed detection and response
• Identity and access management
• Data security and governance
• Compliance and risk management
• Critical infrastructure protection

This convergence reflects a broader change in enterprise cybersecurity.

Organizations are increasingly looking for security capabilities that can work together instead of maintaining disconnected tools for every individual security problem.

OT and Critical Infrastructure Security Continue to Attract Investment

One of the most notable areas of activity involves operational technology and industrial cybersecurity.

Aiuken Cybersecurity acquired 4Elitech, adding capabilities focused on industrial and critical infrastructure security, including OT threat detection and industrial incident response.

Dragos also completed acquisitions involving NetRise and runZero. These additions strengthen capabilities around firmware level device visibility, software supply chain exposure, asset discovery, exposure assessment, and attack surface intelligence.

This direction is important because industrial organizations face a unique combination of cybersecurity and operational risks.

A security incident affecting an enterprise application may result in data loss or business disruption.

An incident affecting an industrial control environment can potentially affect physical operations, production, safety, logistics, and critical services.

Manufacturing, energy, utilities, transportation, maritime organizations, and other critical infrastructure operators therefore need security programs that understand both IT and OT environments.

AI Is Becoming Part of the Security Architecture

Artificial intelligence is another major theme emerging from the September M&A activity.

Palo Alto Networks acquired Console for approximately $500 million in cash. Console provides an AI native platform designed to support agentic workflows using natural language, with the technology expected to strengthen automation capabilities within Palo Alto Networks’ Cortex platform.

Kiteworks also announced the acquisition of Bonfy.AI, with the goal of extending security policy enforcement across data exchanged by both humans and AI agents.

These transactions highlight a fundamental shift.

AI is moving beyond a productivity feature.

It is increasingly becoming part of security operations themselves.

Security teams are exploring AI for:

• Threat investigation
• Alert analysis
• Security orchestration
• Vulnerability prioritization
• Incident response
• Data protection
• Security workflow automation
• Continuous testing
• Threat hunting

However, AI also introduces new risks.

Organizations need to understand what information AI systems can access, what actions AI agents can perform, which applications they can connect to, and how sensitive information is protected.

Agentic AI Creates a New Security Challenge

Traditional software generally follows predefined workflows.

Agentic AI systems can interpret information, make decisions, interact with tools, and perform tasks.

That creates significant opportunities for security automation, but it also introduces new risks.

Organizations deploying AI agents should consider:

• Least privilege access
• Identity controls for AI agents
• Secure API access
• Connector security
• Data loss prevention
• Prompt injection protection
• Activity monitoring
• Human approval for high impact actions
• Audit logging
• Continuous security testing

The acquisition activity surrounding AI security suggests that the industry is preparing for a future in which AI agents become active participants in enterprise environments.

Security architecture will need to evolve accordingly.

Offensive Security Is Becoming More Continuous

Another major development involves offensive security.

NetSPI and Synack agreed to merge, creating an offensive security company with more than $200 million in revenue. Their combined approach is expected to bring human penetration testing expertise together with agentic AI for continuous security testing.

This reflects an important evolution in application security.

Traditional penetration testing often provides a point in time assessment.

Continuous testing aims to identify changes and emerging weaknesses throughout the development and deployment lifecycle.

This does not eliminate the need for experienced security professionals.

Instead, automation can help security teams increase coverage while human experts validate findings, understand business context, and assess complex attack paths.

Compliance Is Becoming More Closely Connected to Cybersecurity

September’s M&A activity also demonstrates that compliance and cybersecurity are increasingly converging.

A-LIGN acquired AssurePoint, expanding its cloud security assessment capabilities and adding IRAP assessment capabilities to its portfolio.

A-LIGN also acquired Pathfynder, adding penetration testing, red teaming, and incident response capabilities.

This combination is important for organizations operating in regulated environments.

Compliance cannot be treated as a separate activity performed only before an audit.

Security controls need to operate continuously.

Organizations should be able to demonstrate:

• Effective access controls
• Vulnerability management
• Data protection
• Security monitoring
• Incident response readiness
• Secure development practices
• Cloud security
• Third party risk management
• Security testing
• Evidence of control effectiveness

The convergence of compliance and security services can help organizations move toward more integrated security governance.

Cloud Security Remains a Major Priority

Cloud environments continue to represent a significant portion of enterprise attack surfaces.

Organizations increasingly operate across multiple cloud providers, SaaS platforms, APIs, containers, serverless services, and third party applications.

This complexity makes asset discovery and exposure management essential.

The Dragos acquisition of runZero is one example of the industry’s focus on understanding what assets exist, how they are connected, and where exposure exists.

Organizations cannot protect assets they do not know about.

Effective cloud security therefore requires visibility across:

• Cloud assets
• Internet exposed services
• APIs
• Identities
• Applications
• Containers
• Network infrastructure
• Third party connections
• Software dependencies
• Data stores

Software Supply Chain Security Is Becoming a Board Level Issue

Modern organizations depend heavily on open source software and third party technology.

A single vulnerable or compromised component can potentially affect multiple applications and downstream customers.

The Dragos and NetRise transaction illustrates the growing importance of firmware and software supply chain visibility.

Organizations should consider implementing:

• Software Composition Analysis
• SBOM management
• Dependency monitoring
• Secure software development
• Code integrity controls
• CI/CD security
• Third party risk assessments
• Secrets management
• Vulnerability management
• Continuous monitoring

Software supply chain security is no longer simply a development team responsibility.

It is part of enterprise risk management.

Identity and Access Security Remain Critical

The September transactions also included activity involving identity and access management.

For example, Omada announced its acquisition of EmpowerID, a company focused on identity and access management capabilities.

Identity has become one of the most important security boundaries in modern organizations.

Employees, applications, APIs, service accounts, cloud workloads, and AI agents all require access to systems and data.

Organizations should therefore continuously evaluate:

• Who has access
• What they can access
• Why they need access
• How access is authenticated
• Whether privileges remain appropriate
• Whether unusual activity is detected
• How quickly access can be revoked

Identity security becomes even more important as organizations adopt AI agents and increasingly automated workflows.

Data Security Is Expanding Beyond Human Users

The acquisition of Bonfy.AI by Kiteworks highlights another important trend.

Enterprise data is increasingly accessed and exchanged not only by employees but also by automated systems and AI agents.

This changes the traditional data security model.

Organizations need to understand where sensitive information is going, who or what is accessing it, and whether that activity is authorized.

Security programs should incorporate:

• Data classification
• Data loss prevention
• Encryption
• Access governance
• AI data security
• Third party risk management
• Secure file transfer
• API security
• Data monitoring
• Compliance controls

The objective is to protect sensitive information regardless of whether the request originates from a person, application, or AI agent.

Why This Matters to Different Industries
Financial Services and Banking

Banks, fintech organizations, payment providers, and investment firms operate highly regulated environments containing financial, customer, identity, and transaction data.

The convergence of identity security, AI fraud detection, cloud security, penetration testing, and compliance creates opportunities to strengthen financial cybersecurity programs.

Healthcare and Life Sciences

Healthcare organizations must protect sensitive patient information while operating increasingly complex cloud, application, medical technology, and third party ecosystems.

Security assessments, penetration testing, data governance, vulnerability management, and compliance programs can help reduce exposure.

Manufacturing and Industrial Organizations

Manufacturers face growing risks across IT, OT, connected devices, cloud platforms, industrial control systems, and supply chains.

OT security assessments, network segmentation, vulnerability management, penetration testing, asset discovery, and incident response planning are particularly important.

Government and Public Sector

Government organizations manage sensitive citizen information, critical services, infrastructure, and large technology environments.

Cloud security, identity management, application security, compliance, supply chain security, and continuous monitoring can help strengthen public sector resilience.

Retail and E-commerce

Retail organizations depend on customer facing applications, payment environments, APIs, cloud platforms, identity systems, and third party technology.

Application security, API testing, cloud security, data protection, vulnerability management, and third party risk assessments can help protect these environments.

Technology and SaaS

Technology companies and SaaS providers face concentrated risks because their products may serve thousands or millions of customers.

A vulnerability in a SaaS platform can potentially create significant downstream exposure.

Secure development, cloud security, penetration testing, software supply chain assessments, API security, and continuous monitoring are therefore essential.

Energy, Utilities, Transportation and Critical Infrastructure

Organizations operating critical infrastructure need security programs capable of addressing both cyber and operational consequences.

OT security, asset discovery, network security, incident response, vulnerability assessments, and cyber resilience planning can help reduce the potential impact of disruptive attacks.

What Organizations Should Learn From the M&A Activity

The September cybersecurity M&A landscape offers several broader lessons.

Security Is Converging

Cloud, identity, AI, data, applications, OT, compliance, and threat detection are increasingly interconnected.

AI Will Reshape Security Operations

AI will increasingly support detection, investigation, testing, automation, and response.

However, AI itself must be secured and governed.

Continuous Security Is Becoming the Standard

Organizations cannot rely exclusively on annual penetration tests or periodic audits.

Security needs continuous monitoring and validation.

Specialized Expertise Still Matters

Automation can improve speed and coverage, but experienced security professionals remain essential for complex assessments, risk decisions, incident response, and strategic security planning.

Compliance and Security Must Work Together

Organizations should build security controls that continuously support regulatory and compliance requirements rather than treating compliance as a separate exercise.

Conclusion

The 39 cybersecurity M&A deals announced in September 2026 provide more than a snapshot of investment activity.

They reveal how the cybersecurity industry is evolving.

The strongest themes are clear: artificial intelligence, agentic security, cloud exposure management, software supply chain protection, operational technology security, offensive security, identity, data protection, managed detection, and compliance are increasingly becoming part of a connected cybersecurity ecosystem.

For organizations, this means cybersecurity strategies must evolve beyond individual tools.

Security leaders need visibility across applications, identities, cloud infrastructure, software dependencies, AI systems, data, third parties, and operational environments.

Organizations that combine continuous monitoring, proactive security testing, strong governance, secure development, identity protection, and compliance will be better positioned to manage the increasingly interconnected cyber risk landscape.

The future of cybersecurity will not be defined by one technology.

It will be defined by how effectively organizations connect people, processes, technology, intelligence, and governance to protect the entire digital environment.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations respond to the evolving cybersecurity landscape through AI security assessments, cloud security assessments, vulnerability management, application security testing, API security testing, identity and access management reviews, software supply chain assessments, third party risk assessments, penetration testing, security architecture reviews, threat monitoring, and compliance readiness programs.

For financial services and banking organizations, COE Security helps assess digital banking applications, payment environments, APIs, identity systems, cloud infrastructure, fraud related security controls, and regulatory compliance requirements.

For healthcare and life sciences organizations, we help protect sensitive information through data governance, application security assessments, cloud security reviews, vulnerability management, penetration testing, AI security assessments, and compliance aligned security programs.

For manufacturing and industrial organizations, COE Security helps strengthen IT and OT security through network assessments, penetration testing, vulnerability management, asset visibility, secure architecture reviews, software supply chain assessments, and incident response readiness.

For government and public sector organizations, we help strengthen application security, cloud security, identity controls, data protection, vulnerability management, software supply chain security, and compliance programs.

For retail and e-commerce organizations, COE Security helps secure customer facing applications, APIs, payment systems, cloud platforms, third party services, identity systems, and sensitive customer information.

For technology and SaaS companies, we help assess applications, APIs, cloud environments, software dependencies, CI/CD pipelines, AI enabled systems, identity controls, and third party technology risks.

For energy, utilities, transportation, maritime, and critical infrastructure organizations, COE Security supports network security, OT and industrial cybersecurity assessments, penetration testing, vulnerability management, infrastructure security, incident response planning, and cyber resilience programs.

COE Security also helps organizations evaluate emerging security risks associated with AI agents, cloud transformation, software supply chains, connected technologies, and increasingly automated security operations.

Our goal is to help organizations identify security gaps, reduce cyber risk, strengthen resilience, support compliance, and build security programs that can adapt to an increasingly interconnected digital environment.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.

Click to read our LinkedIn feature article