Cybersecurity Leaders Merge to Create Massive Security Testing Platform
Minneapolis, Wednesday, 30 September 2026.
NetSPI and Synack have agreed to merge, creating an offensive cybersecurity giant with over $200 million in revenue by pairing agentic AI with elite human threat researchers.
Merger Announcement and Regulatory Timeline
NetSPI and Synack announced a definitive merger agreement on September 30, 2026, in Redwood City, CA [1]. The strategic combination aims to form the industry’s largest offensive security testing bench by pairing NetSPI’s penetration testing capabilities with Synack’s agentic AI platform [1]. The transaction is expected to close in October 2026, subject to regulatory approvals and customary closing conditions [1][2]. During the pre-close period, existing customers will maintain their current teams and services without immediate changes [1].
Financial Scale and Operational History
The combined entity reports over $200 million in revenue and a combined operating history of nearly 40 years [2]. This operational history includes more than 13 million hours of real-world offensive testing experience across the organizations [2]. Based on the cumulative testing hours and operating history, the average annual testing volume is approximately 325000 hours per year [1][2]. The company serves a client base including Fortune 100 companies, U.S. federal agencies, and MAMAA organizations [2].
Agentic AI and Human Researcher Integration
Synack’s platform utilizes “Sara AI Pentesting,” which combines agentic AI with the Synack Red Team of over 1,500 vetted researchers [3][8]. Agentic AI differs from standard models by operating autonomously to achieve objectives through iterative loops of planning and tool selection [4]. Human researchers retain responsibility for validating exploitability and real-world impact, ensuring accuracy in final reporting [4]. This hybrid model addresses the limitation where autonomous tools find exploits, but experts find the ones that actually breach systems [2].
Market Shift Toward Continuous Validation
Managed Security Service Providers are transitioning from traditional penetration testing to Penetration Testing as a Service to address evolving client environments [5]. This shift prioritizes continuous security validation rather than static reporting [5]. Effective vendor evaluation now requires mapping service capabilities to defined business outcomes like continuous exposure reduction [6]. The merger positions the combined company to serve demanding enterprise and government customers with scaled technology and talent [2].
Sources
- www.einpresswire.com
- www.techdogs.com
- www.synack.com
- www.synack.com
- www.synack.com
- www.synack.com
- www.synack.com
- www.synack.com