21 Cybersecurity Companies Changed Hands in July 2026
From a billion-dollar identity security deal to a bank buying a British consultancy, July was a busy month for cybersecurity acquisitions. Here is what each deal means in plain English.

Key points
- Twenty-one cybersecurity mergers and acquisitions were announced in July 2026, according to SecurityWeek.
- Cyera agreed to acquire Israeli startup Oasis Security in a deal valued at roughly $1 billion.
- CrowdStrike is buying the patents and source code of XM Cyber, which its seller originally purchased for $700 million in 2021.
- Okta signed an agreement to acquire identity-threat detection firm Permiso Security for approximately $200 million.
- Qualcomm acquired IoT security startup SAM Seamless Network for a reported sum exceeding $100 million.
July 2026 brought 21 confirmed deals in the cybersecurity sector. Some were quiet roll-ups. A few were genuinely interesting.
What were the biggest deals?
The standout transaction by dollar value is Cyera's agreement to buy Oasis Security for around $1 billion. We covered that deal in detail on 28 July in "Cyera Buys Oasis Security for $1 Billion to Lock Down AI Agents". Cyera specialises in data security, tracking where sensitive information lives and who can reach it. Oasis handles non-human identity governance, managing the digital credentials that software bots and AI agents use to log into systems. One platform watching over both human employees and the automated tools increasingly doing work on their behalf is the pitch.
CrowdStrike, the large American security firm, is acquiring the patents and source code belonging to XM Cyber, an Israeli company that maps the routes an attacker could take through a corporate network. Schwarz Group, the German retail giant behind Lidl and Kaufland, paid $700 million for XM Cyber in 2021 and is now the seller. CrowdStrike hasn't disclosed what it's paying.
Okta, which handles logins and identity verification for businesses, agreed to buy Permiso Security for roughly $200 million. Our 30 July story on that deal noted that it pushes Okta beyond managing who can log in and into spotting when a legitimate login is being used to do something it shouldn't. Permiso specialises in detecting misuse of digital identities inside cloud environments, covering human accounts, machine accounts and autonomous AI systems acting on a company's behalf.
What else happened?
Several other deals deserve a quick note.
| Deal | What the buyer gains |
|---|---|
| Barracuda acquires Evo Security | Better identity management tools for IT service providers |
| Cribl acquires CardinalOps | Automated security-alert detection for corporate security teams |
| Infoblox acquires Kentik | Real-time network traffic visibility layered onto existing DNS tools |
| Qualcomm acquires SAM Seamless Network | Network security baked into wireless chips used by AT&T and Verizon customers |
| Palo Alto Networks acquires Embrace | Mobile app monitoring added to its security platform |
| Bank of America acquires MDSec | Around 65 UK security consultants, expanding the bank's in-house expertise in northern England |
The Qualcomm deal is worth a moment. SAM's software protects internet-connected devices, from smart thermostats to home routers, collectively called IoT (Internet of Things) devices. Embedding it directly into Qualcomm's wireless chips means security arrives pre-installed before a device ever reaches a customer.
Should ordinary people care?
Most of these deals won't change anything you experience directly, at least not soon. What they signal is where the industry thinks the next big problems are: AI agents acting autonomously, automated software accounts that can be stolen just like human passwords, and connected devices that ship with weak security built in.
Okta users logging into work systems can expect better threat-detection features over the coming year. Owners of routers or smart home devices running on Qualcomm chips may find that future models include protections that currently require a separate subscription.
Consolidation also means fewer independent vendors, concentrating security decisions inside a smaller number of large platforms. Whether that's a good outcome depends entirely on how well those platforms are maintained.
Common questions
Does any of this affect my personal data?
Not directly. These are business-to-business transactions involving tools companies use internally. No customer data is reported to have changed hands as part of any July deal.
Why do banks buy cybersecurity firms?
Large banks face constant attack and heavy regulatory requirements to protect customer data. Buying a consultancy like MDSec brings specialist skills in-house rather than paying an outside firm by the hour.
What is an identity threat, and why does everyone seem to be buying firms that fight them?
An identity threat is when a criminal steals or fakes the credentials that a person or piece of software uses to prove who it is. As more work is done by automated systems and AI tools, there are more credentials to steal. That's what's driving the identity-related acquisitions from Okta and Cyera alike, and it's a pattern our 10 August overview of the forces reshaping cybersecurity in 2026 found running through the whole year's deal activity.



