Quarterly Report, Q2 2025: Cyber Security Vendor M&A and Funding News
Published by Pinpoint Search Group — the cybersecurity executive search firm that tracks every disclosed vendor funding round and acquisition in the sector.
At a glance
Get the full Q2 2025 dataset — every named company, round, investor, segment, and acquisition.
Highlights and Analysis
In Q2 2025, our team tracked 118 transactions, including 100 funding rounds and 18 M&A events. Disclosed funding totaled $4.18B, a 25% increase over the $3.36B recorded in Q2 2024, while round count held effectively steady (100 vs. 99). Year-to-date funding has now reached $6.41B, a 13% increase over the same period in 2024.
The headline story is the return of late-stage capital. Eight rounds cleared $100M this quarter, with two — ReliaQuest's $500M growth round and Cyera's $500M follow-on — leading the distribution. Cato Networks ($359M growth), Chainguard ($356M Series D+), Persona ($200M Series D+), and Tailscale ($160M Series C) round out the upper band. Together, these eight rounds accounted for more than half of disclosed funding, signaling continued investor preference for vendors with established traction and differentiated platform positioning.
Strategic acquirers remained active alongside venture capital, with 18 M&A events anchored by Proofpoint's $1.8B acquisition of Hornetsecurity and Palo Alto Networks' $700M acquisition of Protect AI — the largest disclosed AI-security acquisition the workbook has tracked. The combination of returning growth capital and active strategic M&A marks Q2 2025 as the quarter where the cyber funding cycle clearly reaccelerated.

Funding Overview
The 100 funding rounds tracked in Q2 2025 highlight a market in which late-stage capital has returned in scale while early-stage formation continues at a steady pace.
Capital concentration at the top was the defining feature. Eight rounds exceeded $100M: ReliaQuest ($500M), Cyera ($500M), Cato Networks ($359M), Chainguard ($356M), Persona ($200M), Tailscale ($160M), Veza ($108M), and Cyberhaven ($100M). Below that band, growth-stage activity remained healthy across Endor Labs ($93M Series B), Exaforce ($75M Series A), Horizon3.ai ($73M Series D+), and Ox Security ($60M Series B). Early-stage activity (56 Seed or Series A rounds) held at 56% of round count, consistent with recent quarters.
What stands out in Q2 2025 is where that capital is clustering. A meaningful portion of investment is concentrating around:
- Data security and data governance, where Cyera's $500M follow-on, Cyberhaven's $100M Series D+, Sentra's $50M Series B, and Zama's $57M Series B reflect growing enterprise demand for data-layer protection and AI-aware data controls
- Identity and access infrastructure, which led the segment mix with 15 transactions, with Persona's $200M Series D+ and Veza's $108M Series D+ anchoring continued late-stage investment in identity platforms
- SASE, network security, and segmentation, where Cato Networks' $359M growth round, Tailscale's $160M Series C, and Zero Networks' $55M Series C signal that network-layer security remains a contested late-stage category
- Application security and software supply chain, where Chainguard's $356M Series D+, Endor Labs' $93M Series B, Ox Security's $60M Series B, and Minimus' $51M Seed reflect persistent buyer demand across pre-production and runtime AppSec
This distribution reflects a market in which investors are placing larger, more selective bets on platforms with clear enterprise traction across data, identity, network security, and AppSec.

Market & Macro Signals
Several structural dynamics are visible in the Q2 2025 transaction record.
First, late-stage capital has returned at meaningful scale. Eight rounds cleared $100M this quarter, including two $500M rounds. Together they represented more than half of disclosed funding, a sharp shift from the late-stage scarcity pattern that defined much of 2023 and the first half of 2024.
Second, AI-security M&A has entered the workbook as a strategic category. Palo Alto Networks' $700M acquisition of Protect AI is the largest disclosed AI-security acquisition tracked in the workbook and signals that incumbent platforms are willing to acquire dedicated AI-defense capabilities rather than build them organically. Snyk's acquisition of Invariant Labs reinforces the same direction at smaller scale.
Third, year-over-year funding accelerated. Disclosed funding of $4.18B is up 25% from Q2 2024 ($3.36B), while round count held essentially flat. The shift reflects increasing deal size at the top of the market rather than broader transaction-count expansion.
Finally, undisclosed M&A continued at high volume. Of the 18 acquisitions, 14 came without disclosed prices, including strategic moves by Zscaler (Red Canary), Tenable (Apex), F5 (Fletch), OneSpan (Nok Nok Labs), Bitdefender (Mesh Security), and Securonix (ThreatQuotient). The breadth of acquirer activity signals continued platform-building across detection/response, identity, AppSec, and email security.

M&A Activity & Strategic Movement
Q2 2025 recorded 18 M&A transactions, with strategic activity concentrated at the top end and across AI-security, email security, and detection/response. The most notable transaction was Proofpoint's acquisition of Hornetsecurity for approximately $1.8B, the quarter's largest deal and a meaningful expansion of email and collaboration security at platform scale.
Additional activity across the quarter reinforces this direction:
- Palo Alto Networks acquired Protect AI ($700M), the largest disclosed AI-security acquisition the workbook has tracked, extending platform reach into AI-defense and model security
- Cellebrite acquired Corellium ($190M), deepening capabilities in mobile-device security research and virtualization
- Check Point acquired Veriti ($100M), reinforcing exposure management and security posture across hybrid environments
- Zscaler, Tenable, F5, OneSpan, Bitdefender, and Securonix each completed targeted acquisitions (Red Canary, Apex, Fletch, Nok Nok Labs, Mesh Security, and ThreatQuotient respectively) to strengthen detection/response, GRC, identity, email security, and threat-intelligence capabilities
- Snyk, Orca Security, Fortra, Collibra, F5, and DNSFilter completed additional platform-building tuck-ins (Invariant Labs, Opus Security, Lookout Cloud Security, Raito BV, Fletch, and Zorus) across AI-security, cloud, DNS, and identity layers
Across these transactions, the strategic pattern is clear: incumbent platforms are pursuing targeted capability expansion across data, AI-security, email, and detection/response — not broad roll-ups. The emergence of AI-security as a disclosed-price M&A category is the quarter's most structurally novel signal.

Looking Ahead
Q2 2025 sets a clear tone for the second half of the year: late-stage capital is back in scale, AI-security is entering the strategic M&A column, and platform consolidation continues across data, identity, and network security.
We expect the following dynamics to continue through the second half of 2025:
- Late-stage capital will continue concentrating on platforms with measurable enterprise traction, particularly in data security, identity, SASE, and AppSec
- AI-security M&A will continue as a strategic category, with incumbent platforms acquiring dedicated AI-defense capabilities to extend coverage rather than build organically
- Strategic consolidation will broaden across email, detection/response, and identity, as acquirers continue filling capability gaps rather than pursuing broad sector roll-ups
From a go-to-market perspective, the implications are increasingly clear. The bar for late-stage capital has risen: investors expect demonstrable traction, differentiated platform positioning, and a credible path to either continued growth or strategic exit. The combination of returning growth capital and active platform consolidation suggests a market in which vendors with clear product-market fit and operational discipline will continue to attract outsized attention from both venture and strategic buyers.
The full Q2 2025 dataset — every named company, round, investor, segment, and acquisition — is in the data feed. Get the full Q2 2025 dataset →
Methodology
Every transaction in this brief was sourced from a primary public report and dedupe-checked against the master Pinpoint funding workbook, which now contains ~2,600 transactions back to May 2020. Funding totals reflect disclosed capital only; acquisition values are included where publicly available.
Each deal is classified against Pinpoint's normalized cybersecurity segment taxonomy — read directly off what the company says they protect and mapped to one of the canonical segments. The taxonomy has been maintained continuously since 2020 and currently covers roughly 55 segments. Identity, Data, Detection / Response, and Threat Intel have been tracked from the first month of the series; AppSec and GRC entered the following month; emergent categories (AI/LLM, Supply Chain, Quantum, Browser) are added when they first appear in vendor positioning. That normalization layer is what makes multi-year, cross-segment comparisons possible against an otherwise inconsistent vocabulary in the broader market.
About Pinpoint Search Group
Cybersecurity innovators work with Pinpoint Search Group to identify, attract, and land professionals that enable maturation, scale, and successful outcomes. As start-ups continue raising millions in funding and established vendors make acquisitions to round out their offerings, Pinpoint Search Group is keeping track.
Get the underlying data
The narrative above is the free version. The paid Pinpoint Cyber Funding Data feed gives you every named transaction, every disclosed investor, every segment classification — exportable, filterable, and updated as the deals close.
