
Over 215 deals worth $100B+ in H1 2025 signal a shift toward securing AI agents, machine identities, and browser behavior. Visa's $2.4B BioCatch deal leads the charge.
The cybersecurity industry recorded more than 215 mergers and acquisitions in the first half of the year, collectively worth over $100 billion. A deeper look at the deal list shows buyers are concentrating on technology that secures artificial intelligence, machine identities, browser activity, and industrial systems. The shift is a direct response to an expanding attack surface, where threats now target AI agents, cloud applications, APIs, and automated software, not just traditional networks and endpoints.
Visa’s planned $2.4 billion acquisition of BioCatch, announced Aug. 3, is the largest single deal in this wave. BioCatch already serves more than 350 banks across 21 countries, using machine learning to analyze thousands of behavioral, device, and network signals – keystrokes, device handling – to separate legitimate users from fraudsters. The move comes as 42% of banks and non-bank issuers rank fraud and disputes as their biggest or second-biggest platform-related operating cost after employees, according to a report by PYMNTS Intelligence.
Akamai completed its purchase of browser-security company LayerX for roughly $205 million in July. CrowdStrike earlier this year announced a $420 million deal for Seraphic. Both transactions push security controls directly into browsers, a response to the fact that most employees now interact with corporate data through SaaS applications and cloud services rather than software running on managed corporate networks. The browser has become the new perimeter.
AI security is drawing the most attention. Databricks agreed to acquire Panther Labs to build what it calls a security lakehouse. Rubrik bought identity-orchestration provider Strata to help organizations maintain authentication during cyber disruptions. Cisco’s WideField deal, which closed July 31, connects identity and session information with Splunk’s security analytics. The common thread: companies are creating a new population of digital workers – AI agents that can read databases, execute workflows, and communicate with other applications. Those agents need permissions, permissions create identities, and identities create attack surfaces.
What this means for the sector. The M&A wave is a leading indicator of where enterprise security spending is headed. Identity security is evolving from managing employees to managing every entity capable of taking an action inside a company. That includes third-party contractors, APIs, IoT devices, and now AI agents. The report found that 68% of financial institutions increased their fraud-detection budgets year over year, and 46% reported increasingly sophisticated fraud schemes, up from 35% a year earlier.
For cybersecurity vendors, the message is clear: platforms that can correlate identity, behavior, network, and application signals in real time are the most valuable. Standalone tools that address only one vector – endpoint protection, network monitoring, or identity management – are becoming acquisition targets themselves. The companies that are buying now are betting that tomorrow’s most valuable security platforms will not merely identify malicious software. They will understand who or what is acting, what it is trying to do, and whether that behavior should be trusted before the damage occurs, the report said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.