Cybersecurity buyers use 39 September deals to fill AI and OT gaps
SecurityWeek counted 39 cybersecurity M&A deals in September, with buyers using acquisitions to add OT visibility, AI-security controls, offensive-testing scale, sovereign-technology work and compliance reach.

SecurityWeek counted 39 cybersecurity merger and acquisition announcements in September, showing a buyer market focused on filling product gaps across operational technology, AI security, managed detection and compliance.
The monthly list was not dominated by one mega-deal; instead, it showed larger platforms and specialist providers using takeovers to add narrower functions quickly.
The September activity lands against a heavier consolidation backdrop.
SecurityWeek's annual M&A tracking listed more than 420 acquisitions announced in 2025, and the latest roundup suggests that security vendors are still using acquisitions as a shortcut to sector access, technical depth and new automation features.
Dragos was one of the clearest examples of capability stacking.
Its completed purchases of NetRise and runZero added firmware intelligence for exposed devices, software supply-chain visibility, asset inventory, exposure analysis and external attack-surface mapping.
The company positioned those additions beside its existing operational-technology asset visibility and threat-detection products.
The Dragos transactions also connect with Accenture's $4.1 billion OT cybersecurity initiative announced in June.
That context matters because industrial and critical-infrastructure security is becoming a platform race: buyers want visibility into devices, vulnerabilities and software dependencies before an incident moves through operational environments.
IBM added a different kind of reach through Logiq Consulting, a UK cybersecurity consultancy with defense, government and critical-infrastructure customers.
The acquisition gives IBM more capacity around secure digital transformation and sovereign technology work in Britain, where customer relationships and sector credentials can be as valuable as a standalone tool.
AI-era data controls drove another group of deals.
Kiteworks bought Bonfy.AI to strengthen policy enforcement for sensitive data moving between people and AI agents.
Palo Alto Networks acquired Console, a natural-language workflow platform for agentic security operations, in a transaction valued at $500 million in cash and stock.
Console is intended to add more automation for investigation and remediation inside Cortex.
Testing providers also moved toward scale.
NetSPI and Synack agreed to combine into a KKR-backed offensive-security business with revenue above $200 million.
Their merged model brings human penetration-testing expertise together with agentic AI, aiming to support more continuous testing rather than episodic assessments.
Upwind used M&A to extend cloud and AI risk coverage.
Its all-equity purchase of Israeli startup Aegis was valued at $30 million, and Aegis' founders are set to run Upwind AI Security Labs.
The new unit will work on defenses against attacks that use AI systems or target AI-driven environments.
Several smaller transactions rounded out the pattern by adding geography, compliance coverage or managed-service depth.
A-LIGN acquired Sydney-based AssurePoint for IRAP assessment work and Australian market entry, then bought Pathfynder for penetration testing, red teaming and incident response.
Pistachio picked up Hugin.io intellectual property for a compliance-management product planned for 2027.
Quantum eMotion agreed to buy Plurilock Security for about C$33.8 million, or $23.6 million, while Quorum Cyber moved to acquire Ontinue for a Microsoft-first agentic security operations center.
Together, the 39 September deals show cybersecurity buyers seeking discrete technical modules, regulated-market access and AI-ready operating models instead of waiting for internal roadmaps to deliver every piece.




















