The Changing Face of Cybersecurity

For as long as I can remember, unlike networking and infrastructure, the cybersecurity playbook was simple: when a new threat appeared, organisations went out and bought a new, best-of-breed tool to fix it. That strategy, however, has collapsed under its own weight.

The Death of the “Point Solution”

I have first hand experience of how tough it is to manage individual tools for email security, secure web gateways, SD-WAN appliances, SIEMs, identity products and so on. I remember a particular scenario where a user had clicked a phishing link in an email. The analysts were straight on it – one of them isolating the machine, and locking the user’s AD account, the other looking at the endpoint security products, and trying to correlate logs in the SIEM. It was slow, clunky and inefficient and although the SecOps team were quick, they relied on loose integrations across products and their own diligence. 

Technology may have moved on now, but in reality most Large Enterprises have on average 45 different security tools (Gartner), creating more blind spots and alert fatigue than fixing problems.

The Rise of Platformisation

Facing the reality of the “swivel-chair” analyst juggling a plethora of disjointed tools, CISOs quickly identified the flaw in the best-of-breed model. Instead of managing dozens of individual point vendors, security leaders increasingly want unified ecosystems—turning to major players that can cover Endpoint, Identity, Cloud, and SASE under a single roof.

The pace of this mindset shift has been remarkable. In 2020, less than 1 in 3 organizations were actively pursuing vendor consolidation. By 2022—accelerated by the remote-work security chaos of the pandemic—that number surged to 75%. Today, nearly two-thirds of enterprises are actively consolidating their stacks, with another 36% planning to follow suit (Gartner).

Moving toward a single platform isn’t without risk—putting more eggs in one vendor’s basket always requires careful trust. So why are CISOs making the leap?

It comes down to three major advantages:

  • Unified Telemetry & Faster Response: Consolidating telemetry into a single pane drastically cuts Mean Time to Resolve (MTTR). Instead of analysts manually stitching together clues, the platform correlates events automatically.
  • Shared Attack Surface Context: A single platform shares threat intelligence across email, network, and endpoint in real time—something nearly impossible to replicate across tens of siloed tools.
  • Commercial Leverage: Concentrating your budget with a primary platform partner dramatically increases your buying power and negotiation leverage, giving you far more value than distributing that same spend across 30 different niche vendors.

How Big Tech Is Buying Its Way to Scale

Let’s look at the numbers. Back in 2020 we saw roughly 190 global cybersecurity M&A deals. Today, we consistently see upwards of 400 deals annually.

It isn’t just the sheer quantity of transactions that has shifted—it’s the eye-watering value of these acquisitions:

  • 2020: Private Equity takes over McAfee ($14bn)
  • 2021: Thoma Bravo acquire Proofpoint ($12.3bn)
  • 2022: Citrix merges to form Cloud Software Group ($16.5bn)
  • 2023: Cisco announces takeover of Splunk ($28bn)
  • 2024: Thoma Bravo acquires Darktrace ($5.2bn)
  • 2025: Google shatters records with it’s acquisition of Wiz ($32bn)
  • 2026: Palo Alto Networks completes its move into identity with Cyberark ($25bn)

These staggering figures are driven by a singular force: platformisation. With the attack surface expanding and threats rising, platform giants with deep pockets are using M&A as a primary engine to stay competitive and plug critical portfolio gaps.

Some of these plays have been massive successes. Palo Alto Networks seamlessly integrated Demisto and Talon to strengthen its operational engine, while CrowdStrike used Humio and Preempt Security to build out logging and identity capabilities. But others have missed the mark entirely—Cisco’s historic struggle with Sourcefire and Symantec’s ill-fated acquisition of Blue Coat proved that simply buying market share isn’t enough.

Great cybersecurity platforms don’t buy companies for their revenue—they buy code to enhance their core offering. When M&A is driven by sales-team bundling rather than engineering integration, the customer pays the price in operational complexity.

AI and Cloud Security Drive the Next Wave

We know the major platforms are buying up smaller, established players and innovative startups—but what specifically is being acquired and integrated right now?

Artificial Intelligence is in the middle of an unprecedented boom. While enterprises rush to leverage LLMs to drive operational efficiency and revenue, securing custom in-house models and managing access to public tools has proved remarkably tough. This has triggered an M&A gold rush, with platforms like Palo Alto Networks, Check Point, and Google acquiring specialized startups to cover this brand-new attack surface.

Recent acquisition activity concentrates heavily around three core AI capabilities:

  1. AI-DSPM to prevent sensitive data/PII leaking into training sets or prompt histories
  2. Agentic AI Protection to stop autonomous AI agents from taking rogue actions or unauthorized commands
  3. Shadow AI discovery to find unapproved AI software and browser extensions being used across a company

Beyond the immediate LLM boom, the next horizon of capital deployment is aggressively targeting two expanding vulnerabilities: Machine Identities and AI Guardrails.

Non-human credentials; API keys, service accounts, certificates all now outnumber human users by an order of magnitude. Cyberark’s purchase of Venafi (before Cyberark itself was acquired by Palo Alto in a $25bn megadeal) proves that platforms are clambering to govern human and machine under a single, unified policy engine.

Meanwhile, AI Guardrail functionality gives platforms the ability to inspect AI prompts inline in real time, stopping risks like prompt injection and data leaks before an LLM processes the request. Palo Alto’s acquisition of Protect AI and F5 acquiring Calypso AI are prime examples of where market leaders see the next battleground.

The reality is that even the major players are unable to build the functionality quick enough to solve the complex problems facing CISO across the globe.

The pattern is clear: wherever the attack surface expands beyond the traditional human-and-laptop boundary, platform giants will use M&A to absorb those defenses into their ecosystem.

What This Means for the Future

So what are the takeaways? 

If you’re a CISO: : Stop buying isolated point solutions. Choose two or three core platform foundations for your enterprise, and only add point solutions if they integrate seamlessly. Even when they do, remember that maintaining that bespoke integration will demand extra time, budget, and operational overhead.

If you’re a startup: Keep building and solving those critical niche problems—but understand that your exit strategy is far less likely to be an independent IPO. Instead, your roadmap is increasingly leaning toward an acquisition by a major platform player.

For everyone else (the TL;DR): The cybersecurity market is no longer a wild west of thousands of fragmented tools—it is settling into an market of mega-platforms. The landscape is no longer defined by who builds the most hyper-focused tool, but by who can build the most deeply integrated platform.

As the market shifts toward AI, agentic workflows, and machine identities, the platforms that truly succeed won’t just be the ones that buy market share. They will be the ones that deliver the engineering integrations required to eliminate the “swivel chair” once and for all.