Cybersecurity Leaders Merge to Create Massive Security Testing Platform

Cybersecurity Leaders Merge to Create Massive Security Testing Platform

2026-10-01 companies

Minneapolis, Wednesday, 30 September 2026.
NetSPI and Synack have agreed to merge, creating an offensive cybersecurity giant with over $200 million in revenue by pairing agentic AI with elite human threat researchers.

Merger Announcement and Regulatory Timeline

NetSPI and Synack announced a definitive merger agreement on September 30, 2026, in Redwood City, CA [1]. The strategic combination aims to form the industry’s largest offensive security testing bench by pairing NetSPI’s penetration testing capabilities with Synack’s agentic AI platform [1]. The transaction is expected to close in October 2026, subject to regulatory approvals and customary closing conditions [1][2]. During the pre-close period, existing customers will maintain their current teams and services without immediate changes [1].

Financial Scale and Operational History

The combined entity reports over $200 million in revenue and a combined operating history of nearly 40 years [2]. This operational history includes more than 13 million hours of real-world offensive testing experience across the organizations [2]. Based on the cumulative testing hours and operating history, the average annual testing volume is approximately 325000 hours per year [1][2]. The company serves a client base including Fortune 100 companies, U.S. federal agencies, and MAMAA organizations [2].

Agentic AI and Human Researcher Integration

Synack’s platform utilizes “Sara AI Pentesting,” which combines agentic AI with the Synack Red Team of over 1,500 vetted researchers [3][8]. Agentic AI differs from standard models by operating autonomously to achieve objectives through iterative loops of planning and tool selection [4]. Human researchers retain responsibility for validating exploitability and real-world impact, ensuring accuracy in final reporting [4]. This hybrid model addresses the limitation where autonomous tools find exploits, but experts find the ones that actually breach systems [2].

Market Shift Toward Continuous Validation

Managed Security Service Providers are transitioning from traditional penetration testing to Penetration Testing as a Service to address evolving client environments [5]. This shift prioritizes continuous security validation rather than static reporting [5]. Effective vendor evaluation now requires mapping service capabilities to defined business outcomes like continuous exposure reduction [6]. The merger positions the combined company to serve demanding enterprise and government customers with scaled technology and talent [2].

Sources


Cybersecurity Corporate Mergers