15 Best Cybersecurity M&A Advisors (2026)

Selling a cybersecurity company is not selling software. The buyer is underwriting your detection logic, your research team and your own security posture, and it will send its product organisation to check all three. That changes who should represent you.

ProCloser tracked 96 cybersecurity acquisitions announced in 2026 year to date, and six of them named a sell-side advisor. This guide ranks 15 firms on their cybersecurity record, states what each one publishes and what it does not, and routes you by deal size and sub-sector. Where a firm's claim could not be verified on its own website, the entry says so.

Quick answer. For a cybersecurity company sale in 2026, route by enterprise value. Above roughly $250M: Momentum Cyber, Qatalyst Partners, Houlihan Lokey, Arma Partners for European sellers and Jefferies. Between $50M and $500M: AGC Partners, Piper Sandler for federal cyber services, Woodside Capital Partners, Drake Star for DACH and France, Robert W. Baird for MSSP hybrids, Lincoln International, Canaccord Genuity and Stifel. Between $10M and $100M: Solganick & Co. for cyber consulting and MSSPs, and Capstone Partners for solution providers and resellers. Step down to a regional broker such as Viking Mergers & Acquisitions below $10M. Step up to a bulge bracket above $750M. The routing rule is closed deals in your exact sub-sector, not brand, because only 6 of the 96 cybersecurity acquisitions ProCloser tracked in 2026 publicly named a sell-side advisor.

TL;DR

Five corrections before you read the list. (1) Cybersecurity league tables are noise: only 6 of the 96 cyber acquisitions we tracked in 2026 named a sell-side advisor, so any ranking built on public credit is ranking press-release policy. (2) Stop planning for a private equity auction. Eighty-eight of those 96 deals went to a strategic or a strategic-backed buyer; three were direct sponsor platform purchases. (3) Your buyer list is probably stale. Cribl, Brinqa and Cyera each bought twice in 2026, and none of them is an incumbent. (4) Disclosed prices lie about the middle. Sixteen of 96 disclosed, running from about $3M to $32B, so the "market multiple" you were quoted came from a sample that excludes almost every founder-scale exit. (5) A cybersecurity tab on a bank's website is not a credential. A handful of firms on this list have a named cyber team. Most have a label.

How we verified this list

Four inclusion filters

1. A documented cybersecurity practice on the firm's own website. We fetched every firm's site in August 2026 and required cybersecurity or security to appear as a named sector, sub-sector or team, quoted verbatim in each profile. Where a firm does not name it, we say so in the profile rather than implying otherwise. Stifel is on this page without a cybersecurity label, and its entry states that plainly.

2. Evidence of a real close, not a capability claim. Every firm here has either a named cybersecurity transaction on its own site or a credited sell side in the ProCloser deal index. Firms with a sector page and nothing behind it were cut.

3. A verifiable operating entity. Live website, checkable regulatory status where applicable, and a team page with real people. This filter removed one well-known firm; see exclusions.

4. Relevance to a seller, not to a league table. We ranked on cybersecurity record and fit for a private company sale, which is why a firm with 585 transactions can sit below one with 69.

Cross-referenced against: each firm's own site (fetched August 21, 2026), the ProCloser deal index, FINRA BrokerCheck registration statements where firms publish them, Axial's published lower-middle-market rankings, and Refinitiv technology league table positions where a firm cites them. No firm paid for placement. No firm reviewed its own entry before publication.

The credential behind the numbers. ProCloser maintains a public index of technology and software M&A. It held 1,473 acquisitions announced in 2026 year to date at the time of writing, of which 96 were cybersecurity. Every market statistic on this page comes from that index and is 2026 year to date, public announcements only. You can read the underlying deals at the cybersecurity slice of the index.

What we excluded, and why

  • Union Square Advisors. A well-regarded technology bank that appears on most competing lists. On August 21, 2026 we found unionsquareadvisors.com resolving to a parking page whose only sitemap entry redirects to a GoDaddy for-sale listing for the domain. We could not verify a live firm site, so we left it off rather than recycle it.
  • L40. An M&A advisory firm for founder-led SaaS, technology and AI companies up to $100M ARR, and a firm whose cross-border profile would otherwise suit some security software sellers. It publishes no cybersecurity practice and we found no security transaction we could verify. ProCloser also has a commercial relationship with the firm, so it is excluded rather than ranked.
  • Windsor Drake. Every mandate it takes is on the sell side and it is genuinely good at that, but its published focus is fintech and payments founders with enterprise values between $5M and $300M. No cybersecurity practice, so no place on this page. Disclosure: Windsor Drake is a ProCloser client, and it is excluded anyway.
  • GP Bullhound. Its published sectors are business software and AI, consumer technology and digital services. Cybersecurity is not among them, and its one security-adjacent 2026 deal was on the buy side for Francisco Partners.
  • Hampleton Partners. Lists cybersecurity under "technologies crossing multiple sectors" rather than as one of its seven core sectors. That is honest of them, and it is also a no for this list.
  • Corum Group. Forty years old, 500-plus closed transactions, and no cybersecurity coverage area we could find on its site. Its transaction taxonomy carries a generic "Security" tag only.
  • Evercore and Morgan Stanley. Both run serious technology practices. Neither names cybersecurity as a coverage area on the pages we could fetch, so they appear in the tier-above section rather than as ranked entries.
  • Raymond James. Excluded on process, not on merit. Its site would not load for us on August 21, 2026 across three separate attempts, so we could not verify anything and will not publish unverified claims.

Quick comparison table

FirmDeal size (EV)Cyber sectorsFee modelRegistrationBest for
1. Momentum CyberAvg cyber deal $385MAll cybersecuritySuccess-based, monthly engagement paymentInvestment bank; check BrokerCheckCyber-native process, strategic buyer
2. Qatalyst PartnersLarge-cap; not publishedInfrastructure tech spanning cybersecuritySuccess-basedInvestment bank, SF and London$500M+ and public-company sales
3. Houlihan LokeyMid-market to large-capCyber coverage plus cyber diligence practiceSuccess-based, monthly engagement paymentFull-service investment bankVolume, plus pre-sale diligence defence
4. Arma PartnersLarge-cap average; not publishedInfrastructure software and cybersecuritySuccess-basedFCA regulated; US arm FINRA memberEuropean infrastructure security
5. JefferiesNot publishedCybersecurity named under TMTSuccess-based, plus capital marketsFull-service investment bankDual-track sale and financing
6. AGC Partners$50M to $1B+Cyber and GRC namedSuccess-based, monthly engagement paymentFINRA and SIPC memberUS security software and GRC
7. Piper SandlerNot published"security" in technology coverageSuccess-based, monthly engagement paymentFull-service investment bankFederal and defence cyber services
8. Robert W. BairdMid-market; not publishedIT services, security and infrastructureSuccess-based, monthly engagement paymentFull-service investment bankMSSP and managed IT hybrids
9. Canaccord GenuityNot publishedCybersecurity named sub-sectorSuccess-based, plus capital marketsFull-service capital markets firmCanada, UK and Australia to US
10. StifelNot publishedNone named; one credited 2026 cyber closeSuccess-based, plus capital marketsFull-service investment bankTransatlantic and APAC sellers
11. Woodside Capital PartnersNot publishedSSE, zero trust, endpoint, data, MSSPSuccess-basedNot published; askVenture-scale security product
12. Drake StarNot publishedCybersecurity under Software/SaaSSuccess-basedMulti-jurisdiction; ask per entityDACH and French security software
13. Lincoln InternationalMid-market; not publishedCybersecurity named under technologySuccess-basedGlobal advisory firmSponsor-backed platform buyers
14. Solganick & Co.Lower middle marketCybersecurity is a named sectorSuccess-based, monthly engagement paymentInvestment bank; check BrokerCheckCyber consulting and MSSPs
15. Capstone PartnersMiddle marketNamed cybersecurity banking teamSuccess-based, monthly engagement paymentSubsidiary of Huntington BancsharesSolution providers and special situations

Fee models are the market structures these firms use, not published rate cards. No firm on this page publishes its pricing. See the fee section below for the bands to expect and the four clauses that matter more than the headline number.

Which advisor fits my sub-vertical?

Sub-verticalSpecialistThe tell
Identity and access (IAM, PAM, non-human identity)Momentum Cyber, Qatalyst, AGC PartnersThe banker names the identity gap at three specific acquirers without checking notes
Cloud and data security (CNAPP, DSPM)Momentum Cyber, Woodside Capital Partners, QatalystThey price off net retention and category position, not revenue multiple comps
MDR, MSSP and managed securityRobert W. Baird, Solganick & Co., Capstone PartnersThey ask about technician utilisation and contract length before they ask about ARR
GRC, compliance and risk softwareAGC Partners, Momentum CyberThey treat GRC as its own category rather than folding it into "software"
Application and offensive security (AppSec, pentest)Woodside Capital Partners, Momentum Cyber, AGC PartnersThey know which exposure-management platforms are buying tuck-ins right now
Network and infrastructure security (DDI, SASE, firewall)Arma Partners, Qatalyst, Woodside Capital PartnersThey have sold to a technology sponsor, not just to strategics
Federal, defence and government cyberPiper Sandler, Woodside Capital PartnersThey ask about contract vehicles and clearances in the first meeting
Cyber consulting and staff augmentationSolganick & Co., Capstone PartnersThey model key-person risk into the range before you do
European security software selling to the USArma Partners, Drake Star, Canaccord GenuityThey can name the US corporate development contact, not just the company
Israeli security vendorsMomentum Cyber, Qatalyst, Woodside Capital PartnersThey raise Innovation Authority grant obligations before diligence does

Tier A: platform and large-cap sellers, roughly $250M and above

Five firms that can run a process where the buyer is a public company, the consideration includes stock and the diligence involves your source code. Ranked on cybersecurity record, not on balance sheet.

1 Momentum Cyber

HeadquartersAustin, Texas (500 West 2nd Street, Suite 1900)
FoundedNot published; the site states "over 20 years" of cybersecurity focus and a counter of 27 years in cyber
TeamJ. Eric McAlpine, founder and CEO. Site counter shows 24 team members. Senior advisors include founders of Solutions Granted, Infocyte and Onspring
Deal sizeNot published as a band. The site reports an average cybersecurity deal value of $385M
SectorsCybersecurity only
Track record"50+ closed Cybersecurity deals to date" on the firm page; the homepage counter shows 69 cyber transactions and 500+ total M&A transactions

Momentum Cyber describes itself as "the only investment banking firm focused exclusively on the Cybersecurity sector", and as far as we can verify that claim holds. Every other firm on this page covers cyber as one line inside a technology practice. The site puts its senior team's collective cybersecurity experience at over 200 years and says the firm is veteran owned and operated. It runs out of Austin, Texas, and hosts its own AIxCYBER event there.

The thing that makes the focus operationally useful is CYBERcloud, the firm's own tracking platform, which it says covers 4,250 or more cybersecurity companies and tens of thousands of investor and executive contacts. That is the machinery behind a buyer list. When a banker can tell you which of six acquirers has an open gap in cloud detection response this quarter, that is not intuition, it is a database plus twenty years of calls. Momentum also publishes the CYBERscape market map, now in version 4.0, and an annual cybersecurity almanac, which is why its taxonomy shows up in other people's decks.

The senior advisor bench is a genuine differentiator and an underrated one. It includes operators the firm previously represented: Michael Crean of Solutions Granted, whose company Momentum sold to SonicWall, Chris Gerritz of Infocyte, sold to Datto, and Greg Martin, whose company JASK went to Sumo Logic. Founders who sold with the firm and then came back as advisors is a strong signal about how the processes went.

Recent closes named on the site: Onspring Technologies strategic capital from Capital IP; Solutions Granted to SonicWall; Infocyte to Datto; JASK to Sumo Logic; Interset to Micro Focus. The site also lists a $250M Series B for an unnamed client and deals with OpenText and Tenex.AI.

Best for: a security product or services company between roughly $50M and $750M of enterprise value where the buyer will be a strategic and the process needs to be narrow, technical and quiet.

Considerations: single-sector focus cuts both ways. There is no equity capital markets desk to pivot to if a sale stalls, no coverage outside security if your business is a hybrid, and a smaller platform for a genuinely global process. The public transaction list also leans toward deals from 2018 to 2023, so ask directly for 2025 and 2026 closes. And the firm's own numbers are inconsistent between pages, 50-plus on one and 69 on another, which is a fair thing to ask about in the first meeting.

2 Qatalyst Partners

HeadquartersSan Francisco (Three Embarcadero Center, Suite 1500), with a London office at 12 Golden Square
FoundedMarch 2008, by Frank Quattrone
TeamFrank Quattrone, executive chairman; George Boutros, chief executive since January 2016; Nadir Shaikh, partner since May 2011, leads infrastructure technology coverage
Deal sizeNot published. Site reports over 255 transactions and more than $950B of transaction volume
SectorsTechnology. Infrastructure technology coverage "spans cybersecurity, observability, networking and other areas"
Track recordSite lists Keyfactor's majority investment from Summit Partners and Silicon Labs' $7.9B agreement to be acquired by Texas Instruments

Qatalyst is the firm technology boards call when the deal is existential. It has no balance sheet, no research franchise and no lending relationship, which is the entire product. The independence argument that every boutique makes is structurally true here, and it is why Qatalyst turns up opposite the largest strategics in software.

On cybersecurity specifically, the coverage sits inside infrastructure technology under Nadir Shaikh, who joined as a partner in 2011. The firm's own site names cybersecurity as part of that remit, alongside observability and networking, which is an honest description of how large-cap security deals get organised: the same buyers, the same product-platform logic. Keyfactor, a certificate lifecycle management business, appears in the current deal list.

Recent closes named on the site: Keyfactor's majority investment from Summit Partners (pending at time of writing) and Silicon Labs' $7.9B agreement to be acquired by Texas Instruments (pending).

Best for: a venture-backed or public security company above roughly $500M of value, especially where the counterparty is a large strategic and the board wants an advisor with nothing else to sell.

Considerations: Qatalyst is not a mid-market option and does not pretend to be. If your enterprise value starts with a two-digit number, this is not your firm. Cybersecurity is also not a standalone practice here, it is a slice of infrastructure technology, so you are buying general large-cap technology excellence rather than security-native domain depth. For a $60M MDR business, Momentum Cyber knows your buyer list better.

3 Houlihan Lokey

HeadquartersLos Angeles, with offices worldwide
FoundedNot published on the pages we fetched
TeamPhil Adams heads global technology; John Lambros is co-head of US technology; Keith Skirbe joined the global technology group covering the cybersecurity sector; Stephen Lee heads the technology and cybersecurity practice inside transaction advisory services
Deal sizeNot published. In practice the technology group runs the full mid-market through large-cap range
SectorsTechnology, with a named cybersecurity coverage seat and a separate cybersecurity diligence practice
Track record"more than 200 financial professionals worldwide" in the technology group; ranked by Refinitiv as the No. 1 investment bank for global technology transactions in 2021 with 124 deals

Houlihan Lokey is the highest-volume mid-market technology bank in the market, and it did something in cybersecurity that most of its peers did not: it hired for the sector twice, publicly. Keith Skirbe joined the global technology group specifically to cover cybersecurity, and separately Stephen Lee was brought in to head a technology and cybersecurity practice inside transaction advisory services, which is the diligence side of the house.

That second hire is the interesting one for sellers. It means the firm sits on both sides of cyber diligence, advising buyers on what to look for and sellers on how to survive it. If you have any doubt about how your own security posture will read to an acquirer's technical team, a bank with a dedicated cybersecurity diligence practice can tell you before the buyer does.

The scale point is real. A group with more than 200 technology professionals runs more processes per year than any boutique on this list, which means more current pricing information and more live buyer conversations. The tradeoff is the usual one at scale: you are one of many mandates, and the seniority of the person who reads your board deck depends on your deal size.

Best for: security businesses from roughly $75M to $1B of enterprise value, and any seller who wants the same firm to pressure-test its own diligence exposure before going out.

Considerations: the No. 1 technology ranking is from 2021 and is a count of all technology deals, not cybersecurity ones, so do not read it as a cyber credential. The firm publishes no cybersecurity deal count. Ask which of the two named cyber seats will be on your deal, because the transaction advisory practice and the coverage banker are different people doing different jobs. And at the smaller end you will be competing for attention with much larger mandates.

4 Arma Partners

HeadquartersLondon. Arma Partners LLP is registered in England and Wales and regulated by the Financial Conduct Authority; US Arma Partners LP is a FINRA member
Founded2003
TeamPaul-Noël Guély leads the firm. Partners include John Meehan, Tom Wells, David Smith, Eric Lawson-Smith, Varun Sunderraman, Jan Helle, Andrew Wheatley, Laura Maddison and Daniel Fugmann. 39 senior bankers
Deal sizeNot published. 366 deals since inception at $224.3B aggregate value implies a large-cap average
SectorsDigital economy, with "Infrastructure Software & Cybersecurity" as a named sector
Track record366 deals and $224.3B since inception; 247 deals and $200.8B since January 2016; 75% cross-border

Arma is the European technology advisory firm that large sponsors call, and it is one of only two firms our 2026 index credits on a cybersecurity sell side alongside a named co-advisor. It advised on EfficientIP's sale to Francisco Partners in June 2026, a French network security business going to a US technology sponsor, which is the exact shape of deal Arma was built for.

The number that should get your attention is 75% cross-border. Arma is not a firm that occasionally does an international deal, it is a firm where the international deal is the default, with 32 nationalities and 29 languages on staff. For a European security vendor whose realistic buyer is American, that matters more than any league table position.

Cybersecurity sits inside "Infrastructure Software & Cybersecurity", which tells you how Arma thinks about the category. Its cyber work skews toward infrastructure-adjacent security rather than consumer or services security. If you sell DDI, network security, identity infrastructure or security tooling that a platform sponsor would recognise as infrastructure software, that is the fit.

Recent closes: EfficientIP to Francisco Partners, announced June 16, 2026, with IA Global Capital also credited. The site lists Graphwise to Oakley Capital and Nourish to Hg among August 2026 deals.

Best for: European infrastructure security and security software companies above roughly $100M of enterprise value, selling to US strategics or sponsors.

Considerations: Arma is not a cybersecurity specialist, it is a digital economy specialist with a cyber line, and its deal list is dominated by application software and data businesses. If you are a pure-play security company in the US, a US firm will know your buyer set better. There is also no published minimum, but a firm averaging over $600M per deal since inception is unlikely to take a $30M mandate.

5 Jefferies

HeadquartersNot published on the pages we fetched
FoundedOctober 2, 1962
TeamNot published on the sector pages we fetched
Deal sizeNot published
SectorsTechnology, media and telecom, with "Cybersecurity" named as a focus area
Track recordNot published on the pages we fetched

Jefferies is on this list for one specific reason: it names cybersecurity as a focus area inside its technology, media and telecom coverage, which is more than several larger banks do on their own websites. It is a full-service investment bank with underwriting and financing capability, so it can put alternatives on the table that an advisory-only firm cannot, including a financing route if a sale is not the right answer this year.

The practical case for Jefferies in cybersecurity is scale plus optionality at the upper mid-market. If your board wants to run a dual-track process, testing a sale against a private financing or an eventual public listing, a bank with capital markets capability is a materially different conversation than a pure advisory boutique.

Best for: security companies above roughly $300M of enterprise value where a dual-track sale and financing process is genuinely on the table.

Considerations: this is the thinnest entry on the page in terms of what the firm publishes, and we will say so rather than pad it. Jefferies does not publish cybersecurity deal counts, a named cyber team or a deal-size band on the pages we could fetch. It also did not appear in the six advisor-credited cybersecurity deals in our 2026 index. And a full-service bank carries the conflict question that independents do not: it lends to and underwrites for the same acquirers. Ask for the conflicts list in writing.

Tier B: the core mid-market, roughly $50M to $500M

This is where most cybersecurity founders sell, and where advisor choice moves the number most. Three of the eight firms below were publicly credited on 2026 cybersecurity sell sides in our index, which is three more than almost anybody else.

6 AGC Partners

HeadquartersBoston (99 High Street), with offices in New York, London, Silicon Valley, Los Angeles, Minneapolis, Denver and Chicago
Founded2003
Team70 people, firm owned and run by its partners. Ben Howe and Russ Workman are named in client testimonials on the site
Deal size"Premium outcomes across deal sizes from $50M to $1B+"
Sectors"Whether the technology is AI, Cyber, GRC, or one of 50 verticals we cover"
Track record"Over 585 transactions completed since inception in 2003". Registered as America's Growth Capital, LLC dba AGC Partners, member FINRA and SIPC

AGC is the highest-volume independent technology boutique in the US mid-market, and cybersecurity is one of the few sub-sectors it calls out by name on its own homepage, alongside GRC. That distinction matters: most banks fold governance and compliance software into "software", and pricing a GRC business like a general software business gets you the wrong buyer list.

The firm is partner-owned, which shows up in staffing. AGC's client testimonials name individual bankers over and over, and the same names recur across deals, which is the pattern you want to see. The published band, $50M to $1B and above, is unusually explicit for a boutique, and it tells you honestly whether you are in scope.

On cyber specifically, the site names AGC as advisor to Cyberint on its agreement to be acquired by Check Point, and a client testimonial from Qmulos describes AGC helping it find a growth partner in the cybersecurity software market. AGC also runs a large annual technology conference, which is a buyer-access asset in its own right.

Recent closes named on the site: Cyberint to Check Point; Qmulos growth investment; Buildium strategic investment; Nomadix and GlobalReach to a strategic buyer.

Best for: US security software companies from $50M to $500M of enterprise value, and specifically GRC and compliance vendors who need an advisor that treats the category as its own thing.

Considerations: "50 verticals" is a lot of verticals, and cyber is one of them rather than the whole business. AGC publishes no cybersecurity-specific deal count, so ask for the cyber subset of those 585 transactions. It also did not appear in the six advisor-credited 2026 cybersecurity deals in our index. And below $50M the firm tells you itself that you are out of band.

7 Piper Sandler

Headquarters800 Nicollet Mall, Minneapolis, Minnesota
Founded1895
TeamSteven Schmidt heads technology investment banking; Scott LaRue is global co-head of investment banking and capital markets; Jace Kowalzyk covers technology
Deal sizeNot published. The credited 2026 cyber deals were mid-market services businesses
SectorsTechnology coverage spans "application software, HR technology, vertical market software, infrastructure software, IT / networking, security, storage, internet and digital media, E-commerce, financial technology, tech-enabled services, business and IT services gaming and 3D printing"
Track recordThe only firm credited on two separate cybersecurity sell sides in ProCloser's 2026 index

Piper Sandler earns its place here on evidence rather than marketing. In our index of 96 cybersecurity acquisitions announced in 2026, six named a sell-side advisor, and Piper Sandler is on two of them. Abile Group sold to Valiant Solutions in February 2026 and BreakPoint Labs sold to the same buyer in June 2026, both deals expanding cyber capability for national security missions.

Read what that pattern tells you. The same bank represented two sellers into the same acquirer inside four months. That is not luck, that is a banker who knows a specific consolidator's appetite and is bringing it targets. If your business is federal or defence-facing cyber services, that relationship is worth more to you than any brand name.

The firm itself is a 1895-vintage Minneapolis institution with a broad technology practice. Its published coverage list names "security" as one of thirteen technology areas, which is honest positioning: cyber is a real coverage area, not a dedicated franchise.

Recent closes: BreakPoint Labs to Valiant Solutions, announced June 2, 2026; Abile Group to Valiant Solutions, announced February 17, 2026. Both from the ProCloser index with the announcement links in the sources below.

Best for: federal, defence and government-facing cyber services businesses, and mid-market security companies where the buyer is a services consolidator.

Considerations: Piper Sandler's public evidence in cyber is concentrated in government services, not in security product. If you sell a commercial security platform on ARR, ask specifically for closes in that profile. The firm publishes no cybersecurity deal count, no dedicated cyber team page and no deal-size band. It is also a full-service bank, so run the conflicts question.

8 Robert W. Baird

HeadquartersMilwaukee, Wisconsin
Founded1919
TeamNot published on the technology services page we fetched
Deal sizeNot published. Baird is a mid-market house by design
Sectors"IT Services, Security & Infrastructure" is a named sub-practice; its experience includes "cloud enablement, data and analytics, cyber security, and managed services"
Track recordCredited sell-side advisor on Cyber Advisors' March 2026 sale to Sterling Investment Partners

Baird put security in the name of a sub-practice, which almost no other mid-market bank has done. "IT Services, Security & Infrastructure" is the correct framing for a large part of the cyber market, because the businesses that sell in that band are usually hybrids: managed security wrapped around managed IT, or product revenue attached to a services book.

The 2026 evidence backs it. Baird is the credited sell-side advisor on Cyber Advisors, a cybersecurity and IT services provider, going to Sterling Investment Partners in March 2026. That is one of only three direct sponsor platform purchases in our whole 96-deal cybersecurity set, which tells you Baird can get a sponsor to underwrite a hybrid security services business as a platform rather than a bolt-on. Getting platform pricing instead of bolt-on pricing is worth turns of EBITDA.

Recent closes: Cyber Advisors to Sterling Investment Partners, announced March 19, 2026.

Best for: MSSP and managed IT hybrids from roughly $25M to $250M of enterprise value where the likely buyer is a sponsor building a platform.

Considerations: Baird's cyber positioning is services-shaped. If you are a pure security software company with 85% gross margins, a firm that frames you inside IT services risks anchoring the wrong comparables. Baird publishes no cybersecurity deal count and no named cyber banker on the page we fetched, so ask who owns the sub-sector internally. It is a full-service firm with wealth management and research arms, so the conflicts question applies.

9 Canaccord Genuity

HeadquartersNot published on the pages we fetched. The firm operates in North America, the UK and Australia
Founded1950, as a small regional broker dealer
TeamSanjay Chadda, co-head of US investment banking and head of US technology, media, marketing and information services; Mark Williams, head of technology advisory for Europe; Myles Hiscock, head of Canadian technology investment banking
Deal sizeNot published
SectorsTechnology, with "Cybersecurity" named as a sub-sector alongside blockchain, crypto, digital advertising and fintech
Track recordNot published as a cybersecurity-specific figure

Canaccord names cybersecurity explicitly as a technology sub-sector and staffs technology leadership in three geographies, which is the useful thing about it. For a security company whose buyer set spans North America and Europe, or a Canadian or UK vendor selling into the US, a firm with named technology heads on both sides of the Atlantic removes a real coordination problem.

The firm is a full-service capital markets business rather than an advisory boutique, so it brings research coverage and equity capital markets capability. In cybersecurity that is most relevant if you are considering a growth financing as an alternative to a sale, or if a listing is a live option.

Best for: cross-border security companies in the $50M to $300M range, particularly Canadian, UK and Australian vendors selling into US strategics.

Considerations: we could not verify a cybersecurity deal count, a named cyber-dedicated banker or a headquarters statement on the pages we fetched, and Canaccord did not appear in the six advisor-credited 2026 cybersecurity deals in our index. A sub-sector label on a website is a starting point, not evidence. Ask for three closed cyber transactions with references before you shortlist.

10 Stifel

HeadquartersSt. Louis, Missouri
Founded1890
TeamChanan Glambosky, head of technology, New York; Ben Tompkins, head of European technology, London; Jason Stack, co-head of mergers and acquisitions, New York
Deal sizeNot published
SectorsTechnology sub-sectors listed are electronics and industrial technology, internet and digital media, media and telecom, software and tech-enabled services. Cybersecurity is not named
Track record"more than 100 professionals working as an integrated team across North America and Europe". Credited alongside Azure Capital on Qoria's February 2026 sale to Aura

Stifel is on this list for an unusual reason: its own technology page does not name cybersecurity, but our 2026 index credits it on a cybersecurity sell side anyway. Qoria, an Australian child digital safety and security business, sold to Aura in February 2026 with Stifel and Azure Capital credited. We would rather include a firm with a documented 2026 cyber close and a thin website than a firm with a cyber tab and no closes.

The practical strength is the transatlantic technology team, over 100 professionals across North America and Europe with named heads in New York and London, and a separate M&A leadership group. For a security company with revenue on both continents, that structure works.

Recent closes: Qoria to Aura, announced February 2, 2026, with Azure Capital also credited.

Best for: security and digital safety companies with cross-Atlantic or Asia-Pacific operations, in the $75M to $400M range.

Considerations: the absence of cybersecurity from Stifel's own sub-sector list is a real signal, not a website oversight, and you should ask about it directly. One credited cyber deal in a year is evidence of capability, not of specialisation. If cyber-native buyer relationships are what you are buying, the specialists above have more of them.

11 Woodside Capital Partners

HeadquartersNo office is labelled headquarters. Offices in Palo Alto (2650 Birch St), San Diego, London (Riverbank House) and New York
Founded"Entrepreneurs and Investors Since 2001"
TeamNot published as a count on the pages we fetched
Deal sizeNot published. Its named cyber deals are venture-scale technology sales
Sectors"AI and Cybersecurity", broken out as AI security and application security, network and infrastructure security, SSE and zero trust, endpoint security, data and cloud security, MSSPs and MSPs
Track recordPublishes a running quarterly cybersecurity sector update, including Q2 2026 and a state of AI security edition

Woodside publishes the most granular cybersecurity taxonomy of any firm on this list. Its sector page does not say "cybersecurity" and stop; it enumerates SSE and zero trust, endpoint, data and cloud security, network and infrastructure, application security and the MSSP and MSP channel. That level of specificity is a tell. Firms that write their sector page this way are the ones whose bankers can hold a conversation about your detection pipeline.

The firm also runs a quarterly cybersecurity sector update, with a Q2 2026 edition live, which means it maintains a current view of comparables and buyer appetite rather than dusting off a deck when a mandate arrives. And its named cyber transactions sit exactly where most founders sell: WootCloud, a zero trust IoT security business, sold to Netskope, and Attila Security, a data security company with US federal customers, sold to ID Technologies.

Recent closes named on the site: WootCloud to Netskope; Attila Security to ID Technologies, backed by The Acacia Group.

Best for: venture-backed security product companies between roughly $20M and $200M of enterprise value, especially in zero trust, endpoint and data security, and federal-facing security product businesses.

Considerations: Woodside publishes no deal count, no team size and no headquarters, which for a firm founded in 2001 is unusually reticent. The named cyber transactions we could verify are not recent, so ask for 2025 and 2026 closes. The firm also covers health tech and imaging alongside security, so confirm which bankers own the cyber vertical and whether they will be on your deal.

12 Drake Star

HeadquartersNot labelled. Offices in New York, London, Paris, Munich, San Francisco, Los Angeles, Berlin and Dubai
FoundedInconsistent on the firm's own site: one release says "since 2003", another says "since 2004"
Team"100+ Senior professionals". Ralf Philipp Hofmann, Kais Baker and Anton Donauer are named on its Avira transactions
Deal sizeNot published. 500+ transactions against $22B+ of deal volume implies a mid-market average
Sectors"100% Tech-focused". Cybersecurity appears as a sub-sector under Software/SaaS, not as a standalone practice
Track record"500+ Transactions", "$22B+ Deal volume"

Drake Star is the strongest European-plus-US technology mid-market option on this page for a security company with a German or French centre of gravity. Eight offices, four of them in continental Europe, and a genuinely tech-only mandate. Its cybersecurity credentials come from the Avira franchise: Drake Star advised Avira on its $180M majority sale to Investcorp Technology Partners in 2020, then advised Avira on its acquisition of BullGuard in 2021, with the same German deal team on both sides.

Advising the same client on a sale and then on an acquisition is a better signal than most league table positions. It means the relationship survived the first deal.

Recent closes named on the site: Avira majority sale to Investcorp Technology Partners, $180M, April 2020; Avira's acquisition of BullGuard, February 2021.

Best for: European security software companies, particularly in the DACH region and France, selling to US or European buyers in the $50M to $300M range.

Considerations: the verifiable cybersecurity deals are five and six years old, and cyber is a bullet under Software/SaaS rather than a practice. There is no standalone cybersecurity page despite the sector appearing in the site navigation, and the firm's own founding year is stated two different ways on two of its own pages. None of that is disqualifying, but it means you should push hard for recent, named, closed cyber transactions before you shortlist.

13 Lincoln International

HeadquartersChicago
FoundedNot published on the pages we fetched
Team"more than 1,400 professionals in more than 30 offices in 14 countries"
Deal sizeNot published. Lincoln is a mid-market house
SectorsTechnology sector focus list names "Cybersecurity" alongside data and analytics, fintech, government technology, industrial software and infrastructure
Track recordNot published as a cybersecurity-specific figure

Lincoln is the largest genuinely mid-market-focused firm on this page, with more than 1,400 people across 14 countries, and it names cybersecurity explicitly in its technology sector focus. The reason to care is sponsor coverage. Lincoln's business is built on relationships with middle-market private equity, and it also runs a valuations and fairness opinion practice, so it knows what sponsors will underwrite and at what price.

In cybersecurity that skill is narrowly but genuinely useful. Only three of the 96 deals in our 2026 cyber index were direct sponsor platform purchases, but eight more went to sponsor-backed strategics. If your likely buyer is a private-equity-owned platform doing a bolt-on, Lincoln knows the sponsor behind it.

Best for: security services and infrastructure businesses from roughly $50M to $400M where the buyer is a sponsor-backed platform, and cross-border mid-market processes.

Considerations: we could not verify a single named cybersecurity transaction on Lincoln's own site, only the sector label. The firm did not appear in the six advisor-credited 2026 cybersecurity deals in our index. In a 1,400-person firm the question that matters is who specifically covers cyber and how many of those deals they have closed. Ask for names and a client list before you shortlist.

Tier C: founder-scale sellers, roughly $10M to $100M

Below $50M the specialist banks thin out fast. These two firms take mandates in the band where most cybersecurity founders sell, and where the advisor's job is more about buyer education than auction dynamics.

14 Solganick & Co.

HeadquartersDallas area (6860 Dallas Pkwy, Plano, Texas), with a Los Angeles office in Century City
Founded2009
TeamAaron Solganick, chief executive and founder. Senior team includes David Johnson, Frank Grant, Jason Chan, Mark Zides and Gaylen Tasker, plus Ramesh Menon, hired in March 2026 to cover technology services
Deal sizeNot published as a band. Axial ranked the firm number two for lower middle market software banks in 2020 and top ten investment banks in Q1 2025
SectorsCybersecurity is one of six named industry sectors, alongside AI and data analytics, software, technology services and IT consulting, healthcare technology and education technology
Track record"more than $20 billion in M&A transactions to date". Publishes a recurring Cybersecurity Services M&A Market Update

Solganick is the lower-middle-market specialist on this list, and its cybersecurity work is concentrated where the volume sits: cyber consulting and managed security service providers. It publishes a Cybersecurity Services M&A Market Update covering exactly that segment, most recently for Q4 2025 and early 2026, and it folds cybersecurity services and MSSPs into its broader technology services reporting.

Two things distinguish it in this band. First, it names its competitors on its own website, listing Houlihan Lokey, Capstone Partners, Canaccord Genuity and a dozen others. Firms that do that tend to be honest about where they fit. Second, its client testimonials are attributed to named executives at named companies, which is rarer than it should be.

The Axial rankings are worth reading precisely. Number two for lower middle market software banks in 2020, top ten in Q1 2025, top software investment banks in 2022. Those are real third-party marks in the segment Solganick works in, not global league tables borrowed from a different market.

Best for: cybersecurity consulting firms, MSSPs and security-attached IT services businesses from roughly $10M to $75M of enterprise value, particularly in Texas and the western US.

Considerations: Solganick's centre of gravity is IT and technology services, not security product. If you sell a security platform on ARR to enterprise buyers, a product-focused firm will frame you better. The firm publishes no cybersecurity-specific deal count, and the $20B figure covers the team's careers rather than the firm's cyber work. It also did not appear in the six advisor-credited 2026 cybersecurity deals in our index.

15 Capstone Partners

HeadquartersBoston, with offices across the US
FoundedNot published as a year. "For over 20 years, the firm has been a trusted advisor to leading middle market companies"
Team"175+ professionals across the U.S.". Tom McConnell led the IOvations sale
Deal sizeNot published. Middle market by design
SectorsRuns a named "Cybersecurity Investment Banking Team", separate from its general technology, media and telecom group
Track recordA subsidiary of Huntington Bancshares (NASDAQ: HBAN)

Capstone is one of the few firms on this page with a cybersecurity team that has its own name. Its transaction write-ups refer to the "Capstone Partners Cybersecurity and Special Situations Investment Banking Teams" and to a "Cybersecurity Investment Banking Team", which is a level of internal specialisation most middle-market banks do not bother with.

The 2026 evidence is the interesting part, and it proves the disclosure problem this whole page is built around. Capstone advised IOvations, a Burlington, Massachusetts cybersecurity solutions provider founded in 2004 by Jim Sacco, on its April 2026 sale to Alchemy Technology Group, a portfolio company of Avance Investment Management. That deal is in our 2026 index. Our index records no sell-side advisor for it, because the announcement we captured did not name one. The advisor credit exists only on the advisor's own website. Multiply that by ninety and you understand why cybersecurity league tables are worthless.

Being a subsidiary of Huntington Bancshares gives Capstone balance sheet access a boutique does not have, which matters if a recapitalisation or a debt-financed management buyout is a realistic alternative to a sale.

Recent closes named on the site: IOvations to Alchemy Technology Group, April 2026; Covail to GoSecure, January 2022.

Best for: cybersecurity solution providers, resellers and services businesses from roughly $10M to $100M of enterprise value, and sellers who need a special situations option alongside a straight sale.

Considerations: bank ownership introduces exactly the conflict independents market against, so ask how the Huntington relationship is walled off from your buyer list. Capstone publishes no cybersecurity deal count and no founding year. The verified cyber transactions are solution-provider and services businesses, so if you sell security software on ARR, test the firm on product comparables before you engage.

What 2026 cybersecurity deals show

Everything in this section comes from the ProCloser deal index: 96 cybersecurity acquisitions announced between January 6 and August 19, 2026. It is 2026 year to date, public announcements only, and it captures technology and software transactions rather than the whole security economy. Deals that were never announced are not in it, which is most of the small ones.

96
Cybersecurity acquisitions tracked, Jan 2 to Aug 19, 2026
6
That publicly credited a sell-side advisor
16
That disclosed a price

Finding 1: cybersecurity is a strategic-buyer market, not a sponsor market

Of the 96 tracked deals, 43 were bought by a public company and 42 by a private strategic acquirer. Eight were bought by a strategic that is itself private-equity backed. Only three were a direct sponsor platform purchase. That is 88 out of 96 landing with an operating company.

Compare that to the IT services and managed services slice of the same index, where 38 of 159 tracked 2026 deals went to a sponsor or a sponsor-backed buyer. In cyber the equivalent figure is 11 of 96. If your advisor's pitch is built around a private equity auction, ask why, because in cyber the money is coming from product companies that want your technology inside their platform by the next release cycle. That changes the whole shape of a process: fewer bidders, deeper technical diligence, more of the value sitting in retention packages for the engineering team.

Finding 2: the consolidators repeat, and the buyer list has moved down-market

Palo Alto Networks appears three times in the 96, more than any other acquirer: Portkey (April 30), Koi (February 17) and CyberArk, which it announced on February 11 in an SEC exhibit rather than a press release. Seven other acquirers appear twice each: Cribl, Brinqa, Cyera, Zscaler, Databricks, Logicalis US and Valiant Solutions.

Read that second list again. Cribl, Brinqa and Cyera are venture-backed scale-ups, not incumbents, and they are buying. Cyera paid a reported $1B for Oasis Security on July 28 and roughly $50M for Genie Security on May 24. Cribl bought CardinalOps in July at a reported $100M and Radiant Security in August. The set of credible buyers for a $20M to $80M security company in 2026 includes companies that were themselves startups three years ago, and a banker whose buyer list stops at the public incumbents will miss half the room.

Finding 3: almost nobody discloses, and the disclosed numbers lie about the middle

Sixteen of 96 disclosed a price. Those 16 run from about $0.5M to $32B, with a median around $200M. Do not treat $200M as the market midpoint. It is the midpoint of the deals large enough that somebody had a disclosure obligation or a marketing reason to publish. The 80 undisclosed deals are where most founder exits happen, and they are invisible in every league table you will be shown.

The largest disclosed cybersecurity acquisition in the index is Google completing its $32B purchase of Wiz on March 11, 2026. Behind it: ServiceNow and Armis at $7.75B on August 18, Accenture and Dragos at $4.17B on June 19, and Visa and BioCatch at $2.4B on August 3.

Finding 4: 26 of 96 crossed a border, and Israel is the second-largest source of targets

Twenty-six of the 96 tracked deals were cross-border, and eight of those were specifically US to Europe or Europe to US. Where the target's country is recorded, the United States leads with 21 and Israel is second with 10, ahead of the United Kingdom at 7, Canada at 6 and France at 4. If you are an Israeli security vendor, your realistic buyer is American and your advisor needs a US strategic-development network, not a local one.

Three deals worth studying

EfficientIP sold to Francisco Partners, June 16, 2026

Credited sell-side advisors: Arma Partners and IA Global Capital. A French DDI and network security vendor sold to a US technology-focused sponsor. This is one of only three sponsor platform purchases in the whole 96, and it is the only one in the index that names a European tech boutique on the sell side. What it proves: for a European security business selling into the US sponsor universe, the advisor's job is buyer access across an ocean, not local relationships. Announcement.

Valiant Solutions bought BreakPoint Labs and Abile Group, both with Piper Sandler on the sell side

Abile Group closed February 17, 2026 and BreakPoint Labs June 2, 2026. Same buyer, a Bluestone portfolio company, twice inside four months, with the same bank representing the seller both times. Federal cyber services is a roll-up, the roll-up has a named acquirer, and one bank is sitting on the seller side of it. What it proves: in government-facing cyber services, sub-sector relationships beat brand. BreakPoint Labs announcement and Abile Group announcement.

Cyber Advisors sold to Sterling Investment Partners, March 19, 2026

Credited sell-side advisor: Baird. A cybersecurity and IT services provider going to a sponsor as a platform. What it proves: the hybrid MSSP plus managed IT profile gets valued on services economics, and it is the one part of cyber where sponsors still buy platforms. If that is your business, you are being priced off recurring margin and technician utilisation, not off ARR. Announcement.

The honest caveat on advisor credit. Six of 96 cybersecurity deals named a sell-side advisor. The firms credited were Piper Sandler (twice), Arma Partners, IA Global Capital, Baird, Azure Capital, Stifel and Viking Mergers & Acquisitions. That is not a league table and we refuse to present it as one. A six-deal sample tells you those firms did work in 2026. It cannot tell you who is most active, because 90 deals kept their bankers anonymous. Anyone who ranks cybersecurity advisors off public credits is ranking press-release policy.

The honest tier below this band

If your security business does under roughly $10M of enterprise value, most of the firms above will pass on the mandate, and the ones that say yes will staff it badly. Here is what is available to you, named.

Regional business brokers. Our index credits Viking Mergers & Acquisitions on the January 13, 2026 sale of Beyond Secure to NuView, a managed IT and cybersecurity platform. That is a real, closed cybersecurity transaction run by a Southeast US business brokerage. Brokers of this type work on a listing model, price off owner earnings rather than ARR, and generally run a smaller buyer list. For a $3M revenue MSSP with owner-operator economics, that is the correct tool.

Deal marketplaces. Axial, and to a lesser degree BizBuySell at the very small end, will put a confidential profile in front of a wide sponsor and search-fund audience. You are self-serving the process. The tradeoff is that a marketplace creates reach, not tension, and tension is where the price lives.

MSP-specialist brokers. A whole cottage industry now sells managed service providers with a security attachment. They know the buyer set well, they run fast processes and their fee expectations are modest. They are also, in our experience reading these deals, weak on product security valuation, so if a real share of your revenue is your own software rather than resold licences, you are leaving multiple on the table.

The failure mode at this level is not fraud, it is mismatch. A broker prices your recurring revenue like a services book. If your recurring revenue is a product, you want somebody in the tiers above, even if the fee looks uncomfortable next to the broker's.

The honest tier above this band

Goldman Sachs, J.P. Morgan, Morgan Stanley, Bank of America and Citi all run technology M&A groups that cover security. They are excellent, and for most cybersecurity founders reading this they are the wrong call. Three specific reasons.

Fee thresholds. A bulge-bracket technology group is built to earn seven- and eight-figure fees. A $60M sale does not clear that bar, so either the mandate is declined or it is accepted and then staffed by people three levels below the person who pitched you. The second outcome is worse than the first.

Conflicts you cannot see. These banks lend to, research, underwrite and advise the same strategics that would buy you. That is not an accusation, it is structure. Independent advisory firms exist because some sellers want a representative with nothing else on the table. Evercore built a whole franchise on exactly that pitch, and Qatalyst has never had a balance sheet to conflict with.

Process design. A large bank's default is a broad two-round auction. In cybersecurity, where the real bidder set for a specialist product may be six companies and two of them are competitors you cannot show your customer list to, a broad auction leaks and burns leverage. Momentum Cyber, AGC Partners and Arma Partners all run narrower, more surgical processes because that is what the buyer universe demands.

The exception is genuine. Above roughly $750M of enterprise value, and certainly for any public-company sale, you want a bulge bracket or an elite independent in the chair. Palo Alto Networks acquiring CyberArk in February 2026 is not a mandate for a boutique. Neither was Google and Wiz. If that is your scale, stop reading lists like this one and call three banks.

What cybersecurity businesses trade for in 2026

Two warnings before the table. First, only 16 of the 96 cybersecurity deals we tracked in 2026 disclosed a price, so nobody, including us, has a clean private multiple set for this sector. Second, the ranges below are indicative planning anchors drawn from disclosed transactions, public comparables and our own EBITDA multiples by industry and deal-index valuation benchmarks. They are not appraisals and your business will land where its retention, growth and buyer set put it.

Sub-sectorIndicative 2026 rangePriced offWhere the number comes from
Identity and access security6x to 12x ARRARR, net retentionHighest-demand category in our index; 21 of 96 tracked deals touch identity
Cloud and data security (CNAPP, DSPM)6x to 15x ARRARR, growth rateWiz and Oasis Security set the ceiling; most deals here stay undisclosed
Exposure management and offensive security4x to 9x ARRARR, logo count14 of 96 tracked deals; heavy tuck-in activity from Brinqa and Cribl
GRC and compliance software4x to 8x ARRARR, renewal rate14 of 96 tracked deals; sticky revenue, slower growth
MDR, MSSP and managed security8x to 14x EBITDAEBITDA, contract lengthServices economics; see EBITDA multiples by industry
Cyber consulting and staff augmentation5x to 9x EBITDAEBITDA, utilisationPeople-dependent; discounts for key-person risk
Federal and defence cyber services9x to 14x EBITDAEBITDA, contract backlogContract vehicles and clearances carry a premium; Valiant Solutions bought twice in 2026
Security hardware and appliances1.5x to 3x revenueRevenue, gross marginHardware gross margin caps the multiple

The single largest swing factor is not your category, it is whether your revenue survives the buyer's diligence on net retention. A security product with 95% gross retention and expansion inside the base gets the top of its band. The same product with two customers at 40% of revenue gets the bottom, or an earnout.

What do these advisors charge in 2026?

No firm on this page publishes a rate card, and any page that claims to quote one is guessing. What follows is the structure the market uses and the bands we see quoted to sellers, presented as ranges you should expect to negotiate rather than prices you should expect to be given.

Deal size (EV) Monthly engagement payment Success fee Approx total on a clean close
Under $10M $0 to $5,000 6 to 10 percent $400k to $900k
$10M to $50M $10,000 to $25,000 3 to 6 percent $900k to $2.5M
$50M to $200M $25,000 to $50,000 1.5 to 3 percent $1.5M to $5M
$200M to $750M $50,000 to $100,000 0.75 to 1.5 percent $3M to $10M
Over $750M Negotiated or waived 0.4 to 1 percent $6M and up

Four things matter more than the headline percentage.

  • Whether the monthly payment credits against the close. Most credible firms credit it in full. If yours does not, you are paying twice for the same work.
  • Where the tail starts. A tiered scale that steps up on incremental value above a threshold aligns the advisor with the last dollar. A flat percentage does not. Ask for the step-up, and ask for it to start slightly above your realistic base case.
  • What counts as consideration. Earnouts, rollover equity and retention pools for your engineers are all negotiable inclusions. In cybersecurity, retention packages are large, so this clause is worth real money.
  • The tail period. Twelve months is normal, twenty-four is aggressive, and the buyer list attached to the tail should be a named schedule rather than "any party contacted".

For a fuller treatment of how these structures differ between brokers and advisors, see our guide to business broker and M&A advisor fees.

The frames we use in this guide

Five lenses do most of the work when you are picking a cybersecurity advisor. We named them so you can argue with them.

1. The Disclosure Blind Spot

Rule: the public record covers a fraction of cybersecurity M&A, so any ranking built on it is measuring press releases. Number: 6 of 96 tracked 2026 cybersecurity deals credited a sell-side advisor, and 16 disclosed a price. How to act: ignore public league tables for this sector entirely. Ask each firm, under NDA, for its last five closed cybersecurity mandates including the undisclosed ones, and ask for two seller references you can call.

2. The Strategic Gravity Rule

Rule: cybersecurity value flows to operating companies, not sponsors, so the advisor's product-strategy relationships matter more than its sponsor coverage. Number: 88 of 96 tracked 2026 deals went to a strategic or a strategic-backed buyer; only 3 were a direct sponsor platform purchase. How to act: in the pitch meeting, ask which corporate development leaders at your six most likely acquirers the banker has spoken to this quarter. Vague answers are the answer.

3. The Scale-Up Buyer Shift

Rule: the credible acquirer list now includes venture-backed companies that were startups three years ago, and most buyer lists have not caught up. Number: Cribl, Brinqa and Cyera each made two acquisitions in our 2026 index, matching or beating most public incumbents. How to act: when you review a draft buyer list, count how many names raised a round in the last 24 months. If the answer is zero, the list is stale.

4. The Sub-Sector Tell

Rule: cybersecurity is not one market, and the right advisor for identity security is rarely the right advisor for federal cyber services. Number: our 2026 index splits roughly into 21 identity-adjacent deals, 15 in managed security, 14 in exposure and offensive security and 14 in GRC. How to act: make each firm name three closed deals inside your exact sub-sector. Adjacent is not the same.

5. The Retention Discount

Rule: in security, the buyer is underwriting your engineering team as much as your product, so anything that threatens key-person continuity is priced as risk. How to act: before you go to market, fix the two structural things buyers always find. Get your research and detection leads onto retention agreements, and get customer contracts assignable without consent. Both are cheap now and expensive in diligence.

How to verify an advisor is legit and unconflicted

Do this before the second meeting. It takes twenty minutes.

  1. Check FINRA BrokerCheck. Search the firm name at brokercheck.finra.org. You are looking for the broker-dealer entity, its CRD number, its registration status and any disclosure events. Arma Partners, for example, states on its own site that US Arma Partners LP is a FINRA member and links to BrokerCheck. Firms that are proud of the record link to it.
  2. Understand who is not registered, and why that can be fine. Since the SEC's M&A broker exemption under Section 15(b)(13) took effect, some legitimate advisory firms operate without broker-dealer registration on qualifying private-company sales. That is a lawful structure, not a red flag, but you should ask the firm to state plainly which structure it uses and, if unregistered, how it handles any securities consideration in your deal.
  3. Ask who signs your engagement. The entity on the agreement should be the entity you diligenced. Some groups pitch under a brand and contract through a different licensed entity.
  4. Ask for the conflicts list in writing. Specifically: does the firm have a buy-side relationship with any name on your draft buyer list, does it hold equity in any competitor, and has it represented any likely acquirer in the last two years.
  5. Call two references you chose. Not the two the firm offers. Ask for the full client list in your sub-sector from the last three years and pick from it.
  6. Check who runs the deal day to day. Get the names of the day-to-day team in the engagement letter. In cybersecurity this matters more than usual, because the technical narrative is written by the deal team and reviewed by the buyer's product organisation.

The traps in a "best cybersecurity advisor" list

Including, where it applies, this one.

  • Pay-to-play rankings. Several of the pages ranking for this query are directories that charge for placement or run on affiliate arrangements. Check whether the page discloses. If there is no disclosure line, assume there is something to disclose.
  • League tables that measure the wrong thing. Global deal value ranks banks by the size of transactions they touch anywhere, which sorts for balance sheet, not for cybersecurity competence at your scale.
  • Stale entries. Firms merge, get bought and shut down. We removed one well-known technology bank from our own draft of this list after finding its domain parked for sale, and a recycled list will carry a dead firm for years.
  • Sector claims with no closes behind them. A "cybersecurity" tab on a website costs nothing. A named, dated, closed cybersecurity transaction is the only evidence that matters.
  • Counting our own credit correctly. ProCloser tracks deals; we do not advise on them, and we are not neutral about our own matching service. Read the disclosure at the bottom of this page and weigh everything here accordingly.

Where ProCloser fits

Two sentences of scope, so you know what you are reading. ProCloser is not an M&A advisor, does not run sale processes and does not take a success fee on any transaction. We maintain a public index of technology and software M&A, which is where every number on this page comes from, and we operate a matching service that introduces sellers to advisory firms, some of which appear above.

That last clause is a conflict and you should treat it as one. Read the disclosure at the bottom. Then do the diligence in the verification section yourself, because the only opinion that should decide your mandate is the one you formed after calling references.

Want a shortlist instead of a list?

Tell us your sub-sector, revenue and target timeline and we will introduce you to advisory firms that have closed cybersecurity deals in your band. No cost to sellers.

Get matched to an advisor

The bottom line

The routing rule, one more time, because it is the only part of this page you need to remember.

Under $10M of enterprise value: a regional broker or an MSP-focused specialist. Viking Mergers & Acquisitions closed a cybersecurity sale in our 2026 index, so the tier is real, and a full sell-side bank will not take the mandate anyway.

$10M to $75M: Solganick & Co. for services and software hybrids, Capstone Partners for services roll-ins, Woodside Capital Partners for venture-backed security product. This is the band where advisor choice moves the outcome most, because your buyer set is knowable and small and somebody has to know it.

$75M to $500M: Momentum Cyber first, then AGC Partners, Drake Star and Arma Partners for European sellers. Piper Sandler and Baird if your business is a services or federal profile. This is the specialists' band.

$500M and up: Qatalyst Partners, Jefferies, Houlihan Lokey and the bulge brackets. Above roughly $750M the specialisation argument stops winning and execution capability starts.

Cut across all of that with one test. Whoever you hire has to name three closed cybersecurity transactions in your sub-sector, and give you sellers to call. Six of the 96 cybersecurity deals we tracked in 2026 named an advisor publicly, so you are not going to find that record on a website. Ask for it under NDA.

Frequently asked questions

I run an MDR business doing $12M ARR with 40% of revenue from one MSP channel partner. Which advisor should I call first?

Call a services-literate mid-market firm before you call a product bank. At $12M ARR with that concentration profile, your realistic buyer set is other managed security providers, IT services roll-ups and the sponsors behind them, which is the buyer universe Solganick and Capstone Partners work in daily. Baird belongs on the list too, because it was the credited sell-side advisor when Cyber Advisors, a cybersecurity and IT services provider, sold to Sterling Investment Partners in March 2026. Before any of them, deal with the concentration. One partner at 40% of revenue is the single biggest discount you are carrying, and no banker can talk a buyer out of it during diligence. Buyers will model the loss of that partner and price the downside. Spend two quarters diversifying, or at minimum get that relationship onto a multi-year contract with assignment rights and a termination notice period measured in quarters, not weeks. If you cannot fix it before you go to market, expect the structure to absorb the risk instead: a portion of consideration in an earnout tied to that partner's revenue holding for 12 to 24 months post-close. That is not a failure, it is the honest price of the risk. What you should refuse is a process that pretends the concentration is not there, because the buyer finds it in week three of diligence and the renegotiation happens from a much weaker position than if you had priced it in from the start.

My identity security startup has $6M ARR growing 90% a year. Everyone tells me to wait. Should I?

Probably, but not for the reason you are being given. The usual advice is to wait for scale. The better question is whether waiting improves your position in the buyer's roadmap. Identity is the most contested category in our 2026 index; 21 of the 96 cybersecurity acquisitions we tracked touched identity, access or non-human identity. That means buyers are actively filling gaps now, and a gap that is open today may be closed by an acquisition next quarter, after which you are a competitor rather than a fill. So the calculus is not "more ARR equals more money", it is "will the two or three companies who need what I have still need it in 18 months". At $6M ARR growing 90%, you are already inside the band where a strategic will pay for the technology and the team. Palo Alto Networks acquired Portkey in April 2026 and Koi in February. Okta bought Permiso Security in July at a reported $200M. SailPoint bought Entro in June at a reported $200M. None of those were large revenue businesses. Get a conversation started with an advisor now, understand your realistic range, and make the wait a decision rather than a default. If the answer comes back that two buyers are already circling the category, waiting is expensive.

We are a 60-person GRC software company at $9M ARR with flat growth. Is anyone buying?

Yes, but you will be priced as a renewal book, not as a growth asset. GRC and compliance software accounted for roughly 14 of the 96 cybersecurity deals in our 2026 index, which is real volume, and the buyers tend to be platform consolidators adding a module rather than sponsors underwriting growth. Flat growth at $9M ARR with sticky renewals is a legitimate acquisition target for that buyer type. What it is not is a competitive auction, and you should be sceptical of any advisor who promises one. Your value drivers are gross retention, the depth of the framework coverage you have built and how much of your revenue renews without a sales conversation. Fix your reporting on those three before you go out. On the advisor question: at this size a specialist software boutique will serve you better than a broad mid-market bank, because the pitch has to be about the asset's durability and the cost the buyer avoids by not building it. Realistic outcome is a mid-single-digit ARR multiple with a meaningful part of consideration tied to retention. If you want the upper end, the lever is not growth spend, it is proving that the renewal base is contractual and assignable.

Is Momentum Cyber genuinely better than a big bank, or is that just marketing?

For most cybersecurity sellers under $500M, the specialisation is real and it matters. Momentum Cyber's site describes it as the only investment banking firm focused exclusively on the cybersecurity sector, with over 200 years of collective cybersecurity experience across its senior team and a track record it puts at 50 or more closed cybersecurity deals. It publishes the CYBERscape market map and a cybersecurity almanac, and it runs its own tracking platform. Those are the artefacts of a firm that lives in one sector rather than covering it. The practical benefit is not the research, it is the buyer list. A firm that tracks thousands of cybersecurity companies knows which product gaps are open at which acquirer right now, and that determines who gets the call and how the story is framed. The honest counterweight: a single-sector firm has a smaller balance sheet, no equity capital markets alternative if a sale stalls and, by definition, fewer relationships outside security. If your business is half cybersecurity and half something else, that focus becomes a limitation. And above roughly $750M of enterprise value, the bulge brackets and elite independents bring cross-border execution and public-company machinery that a specialist boutique does not.

I got an unsolicited offer of $45M from a strategic. Do I still need an advisor?

Yes, and this is the situation where an advisor pays for itself most reliably. An unsolicited offer tells you one buyer wants you at a price they set. It tells you nothing about the market. The entire job of a sell-side process is converting one bidder into three, and the presence of a credible second bidder is worth far more than any negotiating tactic. There is a second, less discussed reason. A pre-emptive offer usually arrives with a short exclusivity demand attached, and once you are in exclusivity your leverage is gone. Sophisticated acquirers know this. They are not being unfair, they are being good at their job. An advisor's first move is almost always to decline exclusivity and run a compressed process, six to ten weeks rather than six months, against a targeted list. On a $45M offer, moving the headline number by 15 percent pays for a full sell-side mandate several times over, and that is before you count the terms below the headline: escrow size, earnout construction, working capital peg and the retention pool that gets carved out of your consideration rather than the buyer's. Founders routinely give away more in those clauses than in the price. One caveat: if the offer is genuinely strategic and time-sensitive, say a competitive process the buyer is running internally, tell the advisor that up front so the process is designed around it.

How long does a cybersecurity sale take from engagement to close?

Five to nine months for a normal process, and cybersecurity sits at the longer end of that band. Preparation and materials take four to eight weeks, and in security it is usually longer because the technical narrative has to survive review by the buyer's product and research teams, not just its finance team. Outreach and first-round indications run six to ten weeks. Management meetings and negotiating a letter of intent add four to six weeks. Confirmatory diligence through to close is eight to fourteen weeks. Two things extend cybersecurity timelines specifically. First, security diligence on a security company is unusually deep; expect code review, an examination of your own security posture and questions about any incident in your history. Second, if you sell into government or regulated industries, contract novation and clearance transfers add time that nobody can compress. Deals with a foreign acquirer and US federal customers can add a regulatory review on top. Plan for nine months, and start the preparation work three to six months before you plan to engage anyone, because the fixes that raise your price the most are the ones that need time: retention agreements, assignable contracts and clean audited or reviewed financials.

Should I use a cybersecurity specialist or my existing corporate finance relationship?

Specialist, unless your existing relationship has closed security deals. The test is not whether the firm is good, it is whether the firm can name three closed cybersecurity transactions in your specific sub-sector. Generalist mid-market banks price security companies off the frameworks they know, which usually means EBITDA and comparable services businesses. That is correct for an MSSP and badly wrong for a product company with 85% gross margins and expansion revenue. The reverse mistake is also common: a product-focused technology bank running a managed security services sale as if it were software, promising an ARR multiple the buyer universe will never pay. There is one legitimate reason to keep your existing relationship in the room. If that firm has been advising you for years and knows your board, your cap table and your shareholders' actual objectives, that context has value. The usual resolution is to run the process with a specialist and keep the incumbent involved in a defined, smaller role. What you should not do is award the mandate on relationship alone and then discover in month four that the banker has no idea who runs corporate development at your three most likely acquirers.

We are an Israeli security vendor with $15M ARR. Do we need a US bank?

You need US buyer access, which is not quite the same thing. Israel is the second-largest source of cybersecurity targets in our 2026 index, with 10 of the 96 tracked deals, behind only the United States at 21. Almost all of those targets were bought by American acquirers. So the requirement is a firm whose corporate development relationships are in Santa Clara, Austin and Boston, whoever holds the passport. In practice that points you at either a US technology bank with real security coverage or a specialist with a US network, and it usually rules out a purely local advisor. There are structural items to handle early. Get your intellectual property ownership documented cleanly, particularly anything developed under Israel Innovation Authority grants, because grant repayment and technology transfer restrictions surprise buyers late and cost time. Get employment agreements and assignment of inventions in order for every engineer. If you sell to US federal or defence customers, expect regulatory review to add months. On process design, a narrow list of six to ten genuine strategic acquirers usually beats a broad auction, because at $15M ARR you are being bought for a capability and the number of companies that need that specific capability is small.

Only 6 of your 96 tracked deals named an advisor. Why should I trust any ranking built on that?

You should not, and we did not build one. That is the point of publishing the number. Six of 96 tracked 2026 cybersecurity acquisitions publicly credited a sell-side advisor, and 16 disclosed a price, so the public record covers a small and non-random slice of what happened. Non-random matters more than small: deals get publicised when a buyer wants a market signal or a regulator requires it, which biases the visible set toward large, strategic and public-company transactions. Any ranking assembled from those credits would be a ranking of press-release policy. So this list is built on what firms document about their own practice, which sub-sectors they name, which deals they publish, what deal-size band they say they work in and where their partners came from, cross-referenced against the deals we can see. That is a weaker method than a real league table and we would rather say so than dress it up. It also tells you how to run your own diligence. Ask each firm, under NDA, for its last five closed cybersecurity mandates including the ones that never made the press, with seller references attached. The firms with a genuine record will hand it over.

My cyber consulting firm bills $8M a year with 25 consultants. Is that even sellable?

Sellable, yes. Valuable in the way you are hoping, probably not. A people-based cyber consulting business at $8M of revenue is bought for its client relationships, its certifications and its consultants, all three of which can walk. Expect a mid-single-digit multiple of EBITDA rather than anything resembling a software multiple, and expect a significant portion of the consideration to be contingent on you staying and on revenue holding. The buyers are IT services consolidators, MSSPs building a professional services arm and the occasional sponsor-backed platform. Our 2026 index shows that market is active: Logicalis US made two acquisitions, and Valiant Solutions bought two federal cyber services businesses, both with Piper Sandler credited on the sell side. What raises your number: recurring or repeatable engagements rather than project work, documented methodology that survives the departure of any individual, cleared or certified staff if you serve government, and a second-tier leadership team that clients already know. What lowers it: your name on the door, a top client above 25% of revenue and consultants without non-solicits. Fix what you can in the 12 months before you go out. This is the segment where preparation moves the number most.

What is a realistic multiple for a $25M ARR cloud security platform in 2026?

Somewhere between 6x and 15x ARR, and the spread is not noise, it is the whole negotiation. The high end of that band belongs to companies with strong net revenue retention, a category the buyer has publicly said it needs and at least two credible acquirers in the room. The low end belongs to companies with flat expansion, a crowded category and one interested party. Our 2026 index does not settle this for you, because only 16 of 96 cybersecurity deals disclosed a price, and the ones that did skew large. What the index does show is the ceiling and where it comes from: Google completed its $32B acquisition of Wiz in March 2026, and Cyera agreed to buy Oasis Security for a reported $1B in July. Both were bought for category position, not for current revenue. Practically, three things move you within the band. Net revenue retention above 115% is worth several turns on its own. Being one of the two or three named options in your category is worth more than growth rate. And the shape of the buyer set matters, because a category where four platforms all have the same gap creates a real auction, while a category with one logical buyer creates a negotiation. Get a specialist to map that buyer set before you anchor on any number, including ours.

Should I sell to a private equity firm or a strategic acquirer?

In cybersecurity the question mostly answers itself, because the sponsors are not there in volume. Of the 96 cybersecurity acquisitions we tracked in 2026, only three were a direct private equity platform purchase and eight more went to a sponsor-backed strategic. Eighty-eight of 96 landed with an operating company. Compare that to the IT services slice of the same index, where 38 of 159 tracked deals went to a sponsor or a sponsor-backed buyer, against 11 of 96 in cyber. So if you run a security product business, plan for a strategic outcome and treat sponsor interest as a useful pricing floor rather than the expected result. If you run managed security or cyber services, the sponsor path is genuinely open and often better, because a platform sponsor will pay for a business it can build on and will let you keep running it. The tradeoffs are the familiar ones. A strategic pays more for capability, integrates your product and typically ends your independence within a year. A sponsor pays for cash flow, keeps the brand and gives you a second bite through rollover equity, but loads the balance sheet with debt and expects a defined exit in four to six years. Decide which outcome you want before the process starts, because the buyer list gets built around that answer.

Sources

Every firm fact on this page was taken from a page we fetched on August 21, 2026. Firm names are in plain text in the body; the verification links are here.

Firm sources

Excluded firms, verification sources

  • Union Square Advisors: sitemap and the /lander redirect to a GoDaddy for-sale listing, checked August 21, 2026
  • Windsor Drake: homepage, published focus on fintech and payments founders
  • GP Bullhound: homepage sector list
  • Hampleton Partners: sector list
  • Corum Group: about

Deal sources cited on this page

Disclosure

ProCloser.ai operates a deal-matching network that includes some of the firms named on this page, and L40 and Windsor Drake are ProCloser clients. ProCloser is not an M&A advisor, does not provide investment advice and does not receive a success fee on any transaction described here. No firm paid for placement on this page and no firm reviewed its own entry before publication. Verify any advisor's registration and disciplinary history on FINRA BrokerCheck at brokercheck.finra.org before you engage. Deal-size bands, valuation ranges and fee ranges on this page are indicative market observations, not quotes, appraisals or offers. Nothing here is investment, legal or tax advice.

About the author

Tania Kozar writes ProCloser's advisor research and maintains the editorial standards behind the ProCloser deal index, a public record of technology and software M&A that held 1,473 acquisitions announced in 2026 at the time of writing. She built this guide by fetching every named firm's website in August 2026, cross-referencing the claims against tracked transactions and cutting the firms that could not be verified. Corrections and additions are welcome through the contact page; if you are a firm named here and something is wrong, we will fix it and date the change.

Selling a cybersecurity company? Get matched to advisors with closes in your sub-sector. Free. Get Matched →