NetSPI and Synack merge to build $200m+ offensive security platform

KKR-backed deal unites two penetration testing leaders, embedding agentic AI into a platform serving Fortune 100 firms and US federal agencies.

NetSPI and Synack merge to build $200m+ offensive security platform

NetSPI and Synack, two of the longest-established names in offensive cybersecurity, have announced a definitive agreement to merge, creating a combined entity the companies say will be the largest dedicated offensive security platform in the market. With over $200 million in combined revenue and a client roster spanning the top ten US banks, the MAMAA group, the Fortune 100, and US federal agencies, the deal represents a meaningful consolidation in a sector that has historically been fragmented across specialist boutiques.

KKR, which backs NetSPI, will fund the combined company's next phase, including technology investment, talent acquisition, and international expansion. The transaction is expected to close in October 2026, subject to regulatory approvals.

Expert-plus-AI: a deliberate counter-positioning

The merger's strategic logic is as much about narrative as capability. As autonomous security testing tools proliferate, driven by the same generative AI wave transforming software development, both firms are making a pointed bet that human expertise remains irreplaceable for high-stakes penetration testing. Jay Kaplan, CEO of Synack, set out the challenge directly: "Bad actors are unpredictable; you need people who understand context, business logic, and attacker intent to catch them. Autonomous tools find exploits. Experts armed with AI find the ones that actually breach you."

That positioning is significant. A cluster of well-funded autonomous testing platforms has emerged over the past two years, attracting capital on the premise that AI can replicate red-team workflows at a fraction of the cost. The NetSPI-Synack combination is, in effect, a counter-thesis: that enterprise and government clients, particularly those in regulated industries or with national-security obligations, will pay a premium for validated, expert-led coverage that a fully automated tool cannot credibly provide.

The combined company will bring together roughly 13 million hours of recorded offensive testing experience and a bench of vetted security researchers, including Synack's "Red Team," a globally distributed community founded originally by former NSA operatives. NetSPI, meanwhile, pioneered Penetration Testing as a Service (PTaaS) from Minneapolis and has built deep relationships with large US financial institutions.

Convergence implications: AI, regulation and critical infrastructure

For cross-sector strategists, the deal sits at the intersection of three structural forces. First, the regulatory environment is tightening. Frameworks including SEC cyber-disclosure rules in the US and NIS2 in Europe are pushing boards to demonstrate continuous security assurance rather than annual point-in-time assessments. That shift in compliance posture creates structural demand for the kind of continuous testing the combined platform is designed to deliver.

Second, expanding attack surfaces, accelerated by cloud migration, IoT proliferation, and the rapid deployment of AI systems and LLMs inside enterprise stacks, are outpacing the capacity of any single internal security team to assess. Organisations that have moved fast on AI adoption are now realising they have introduced novel attack vectors that their legacy security vendors have little experience testing.

Third, the role of private equity in cybersecurity consolidation is intensifying. KKR's backing positions the merged entity with capital to pursue further acquisitions at a moment when mid-market offensive security boutiques are weighing their options. The broader cybersecurity M&A market has been active, as platform-scale players seek to offer clients a single trusted partner rather than a patchwork of specialist tools.

Ben Pederson of KKR's Technology Growth team framed the macro case: "Offensive security is a large and structurally growing market driven by regulatory requirements, expanding attack surfaces, and increasingly sophisticated threats amplified by AI."

The second-order question for investors and enterprise buyers alike is whether the expert-plus-AI model can scale without diluting quality. The combined company's ability to maintain its vetted-talent bench while growing internationally will be the critical test of whether the merger thesis holds beyond the deal announcement.