September Cybersecurity Deal Wave Expands OT, AI and Offensive-Security Portfolios

September 2026 saw 39 cybersecurity M&A deals, with Dragos, Palo Alto Networks and IBM expanding OT, AI security and public-sector portfolios.

September Cybersecurity Deal Wave Expands OT, AI and Offensive-Security Portfolios
Vulnerabilities

Illustrative image generated with AI

Reported total does not match the transaction list

Cybersecurity companies announced a broad set of acquisitions, mergers and majority-stake investments in September 2026, spanning operational technology, cloud assessments, offensive testing, data security and managed detection.

A SecurityWeek roundup puts the monthly total at 39 cybersecurity-related M&A deals. However, the transactions presented in the report do not reconcile cleanly with that figure.

The roundup has 11 featured headings and 27 additional entries, producing 38 entries when every heading is counted once. Two featured headings each contain two separate acquisitions: A-LIGN bought AssurePoint and Pathfynder, while Dragos acquired NetRise and runZero. Counting those purchases individually produces 40 transactions.

The source does not explain the difference. There is therefore no basis for deciding whether one transaction was excluded, combined with another or counted under a different methodology.

Deal status also varies. Some purchases are described as completed, while other companies have agreed to merge or acquire a target. Majority-stake investments and an intellectual-property acquisition appear alongside full-company purchases. These distinctions matter because an agreement does not establish that a transaction has closed.

This is a market-activity report, not a cybersecurity incident disclosure. It describes no vulnerability, CVE, threat actor, compromised customer, indicator of compromise or severity rating.

OT and public-sector capabilities drive several acquisitions

Operational technology and critical-infrastructure security feature prominently in the selected transactions.

Spanish managed security provider Aiuken Cybersecurity, part of the Allurity group, acquired 4Elitech, another Spanish company. The target specializes in protecting industrial and critical-infrastructure environments. The stated additions to Aiuken’s services are OT threat detection and industrial incident response.

Dragos completed its acquisitions of NetRise and runZero. According to the reported product descriptions, NetRise provides firmware-level insight into device exposure and software supply chains. runZero adds asset discovery, exposure assessment and attack-surface intelligence.

Dragos said the purchases extend its platform with exposure-management and software-supply-chain security functions that complement its existing OT asset visibility and threat detection. These are the company’s stated capability outcomes; the supplied reporting does not independently evaluate the resulting platform.

SecurityWeek places the Dragos transactions within Accenture’s $4.1 billion OT cybersecurity push, which it says was announced in June. Because no year is supplied for that announcement, it cannot be assigned to a more specific date from the available material.

Government and critical-infrastructure customers are also central to IBM’s acquisition of UK-based Logiq Consulting. The consultancy serves the UK defense, government and critical-infrastructure sectors. IBM’s stated rationale is to expand its secure digital-transformation and sovereign-technology capabilities in the UK.

Canadian quantum-security company Quantum eMotion (QeM) agreed to acquire Plurilock Security for approximately C$33.8 million (US$23.6 million) in cash and stock. Both companies are based in Canada. QeM expects to gain an established cybersecurity revenue base, customer relationships and access to public-sector procurement channels.

Buyers pursue AI security and agentic automation

Several buyers presented artificial intelligence as either a technology to secure or a mechanism for automating security work. The announced capabilities and expected integrations remain company or source descriptions rather than independently demonstrated results.

Palo Alto Networks acquired Console for $500 million in cash. Console is described as an AI-native platform for building agentic workflows through natural-language instructions. Palo Alto Networks plans to use the technology to expand agentic functions within Cortex, including automated investigation and remediation.

Kiteworks announced its acquisition of Bonfy.AI, an AI data-security company. Kiteworks says the target’s technology will extend real-time policy enforcement across sensitive data exchanged and used by people and AI agents.

Cloud-security company Upwind acquired Israeli AI-security startup Aegis in an all-equity deal reportedly valued at $30 million. Aegis’s co-founders are to lead the newly established Upwind AI Security Labs, which will research and develop defenses against AI-driven attacks.

The planned merger of NetSPI and Synack also incorporates an AI strategy. The companies agreed to combine into a KKR-backed offensive-security business described as having more than $200 million in revenue. The proposed model pairs professional penetration testers with agentic AI for continuous security testing.

Neither the revenue figure nor the performance of the planned technical combination is independently verified in the supplied reporting.

Assessment, testing and managed detection portfolios broaden

A-LIGN, a cybersecurity compliance company, completed two acquisitions with distinct geographic and technical effects.

Its purchase of Sydney-based AssurePoint, a cloud-security assessment provider, adds IRAP assessments to A-LIGN’s portfolio and marks the company’s entry into Australia. A-LIGN also acquired Pathfynder, which provides penetration testing, red teaming and incident-response services. The second target will operate as Pathfynder by A-LIGN.

Managed detection is represented by Quorum Cyber’s agreement to acquire Ontinue, an MXDR provider headquartered in Redwood City, California, and Zurich. The planned combination is described as bringing together AI-powered MXDR, cyber resilience and human expertise to create a Microsoft-first agentic SOC.

Oslo-based human-risk-management company Pistachio took a different route, acquiring the intellectual property of Norwegian cyber-risk-management platform Hugin.io. Pistachio plans to use that technology to launch a compliance-management product in 2027. That date concerns a future product plan, not a completed release.

Twenty-seven additional transactions were named without further detail

The roundup also lists the following deals:

  • Act Security acquired Cloud Copilot.
  • AXAITRA acquired Innovate.
  • CBTS acquired Recovery Point Systems.
  • CloudFirst acquired Forvis Mazars’ IT and cyber managed-services practice.
  • Concentrix acquired CastleHill Managed Risk Solutions.
  • CyberMaxx acquired Avertium.
  • Epiq acquired Canopy.
  • Fime acquired Red Alert Labs.
  • Harvey acquired Guardrails AI.
  • InfraVia acquired a majority stake in Nexis.
  • ISMG acquired INE.
  • IT Solutions acquired STACK Cybersecurity.
  • ITC Federal acquired Apriva ISS.
  • Malam Team acquired Foretech Software.
  • Nomios acquired Orbcom.
  • Omada acquired EmpowerID.
  • Project Eleven acquired Riva Labs.
  • Risk X Group acquired Wolfpack Information Risk.
  • S&P Global agreed to acquire OpenZeppelin.
  • SecureSky acquired Soveren.
  • SGS acquired a majority stake in NetSentries.
  • Socure acquired Fravity.
  • Spin.AI acquired DoControl.
  • Surfshark acquired a majority stake in Optery.
  • ThreatBook acquired CyberStrikeAI.
  • TRG acquired Fentron.
  • Tusker acquired Fortress SRM.

The supplied account provides no further financial, product or operational details for these 27 entries. Their names alone do not establish what technologies or market segments the acquired companies represent.

Customers should track deal status and concrete product changes

The transactions could expand portfolios across OT defense, exposure management, software-supply-chain visibility, cloud assessments, penetration testing, MXDR and AI data security. They may also provide access to specialist teams, new markets or public-sector procurement channels.

Those potential effects should not be confused with completed technical integration. An acquisition announcement does not demonstrate that products have already been combined, that agentic functions work at the stated level or that customers have received the promised capabilities.

Organizations using products from the companies involved can monitor subsequent notices for changes to contracts, licensing, support, data handling and product roadmaps. The relevance will depend on whether each transaction closes and how the buyer integrates the acquired assets.

No patches, workarounds or indicators are associated with this roundup because it does not describe an active threat or software flaw.

For broader context, SecurityWeek separately refers to more than 420 acquisitions announced in 2025. That figure concerns a different reporting period and should not be used to resolve the unexplained September 2026 count discrepancy.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →