A data security platform has paid roughly $1 billion for non-human identity capability, five times what an established identity vendor paid for a comparable asset six weeks earlier. The strategic logic is valid even if the price appears high. The premium is a bet on the agentic AI narrative, and the integration risk resides with the buyer.
What Happened
On 28 July 2026, Cyera announced that it had signed a letter of intent to acquire Oasis Security. Cyera frames the deal as uniting data security and identity security into a single control point that determines what every human, machine, and AI agent is permitted to see and do.
|
Acquirer |
Cyera (founded 2021; Yotam Segev, CEO). Data security / DSPM. Valued at $12bn following a $600m raise weeks before the announcement. |
|
Target |
Oasis Security (founded 2022; Danny Brickman, CEO). Non-human identity and “agentic access management”. ~$195m raised, including a $120m Series B in March 2026. |
|
Reported value |
~$1bn. Cyera confirmed the headline figure to SecurityWeek. Calcalist reported ~$700m cash with the balance in Cyera shares; the split is not officially disclosed. |
|
Status |
Letter of intent, announced 28 July 2026. Not a closed transaction. Oasis is expected to operate as an independent unit post-close. |
|
Context |
Cyera’s third acquisition of 2026, after Ryft and Genie Security. Second-largest cybersecurity deal of the year to date behind Accenture’s ~$3.2bn majority stake in Dragos. |
A caveat first. This is only a letter of intent so terms have not been formally disclosed. Cyera also states in its announcement that Non-Human Identities (NHIs) inside Fortune 500 organizations grew by nearly 500% in the last six months. That is the acquirer’s own figure, offered without published methodology, and we would not build a business case on it. The trend itself is well documented in our own research: machine and agent identities are outpacing human ones. The specific growth rate is not.
Our Take
The architectural argument for this deal is valid even if the price is too high.
Authorizing an AI agent requires two things that have historically lived in different products and been bought by different teams. You need to know how sensitive a given data asset is, which is what data security posture management does. And you need to know which identity holds the credential reaching for it, who owns that identity, and whether it should still exist, which is what non-human identity management does. Neither discipline can answer the question that actually matters when an agent acts autonomously at machine speed: should this non-human identity be able to read this record right now? Cyera is making a credible claim that the answer requires both halves in one system.
The gap is real, and Cyera is not the only one who has spotted it. Microsoft, Palo Alto Networks and CyberArk are converging on the same control point from different directions, so moving early is defensible.
Where we are more skeptical is the price and the direction of the integration. Asking identity teams to govern machine identity from a data security tool is the hardest thing this deal has to prove.
The Price Is the Story
Six weeks before this announcement, SailPoint agreed to acquire Entro Security, another Israeli NHI specialist, for a reported $200 million. The comparison is instructive.
|
Deal |
Announced |
Reported value |
KuppingerCole rating of target |
|
SailPoint / Entro Security |
18 Jun 2026 |
~$200m |
Product Leader and Innovation Leader, NHIM Leadership Compass 2025 |
|
Cyera / Oasis Security |
28 Jul 2026 |
~$1bn |
Rising Star (Jun 2025); not rated in the NHIM Leadership Compass 2025 |
We want to be careful here, because the two companies were not the same size. Oasis had raised roughly $195 million against Entro’s $24 million and was almost certainly the larger commercial business, so some of the gap reflects genuine scale. But not five times. The rest is being paid for the agentic AI narrative and for strategic fit with a platform story, using the currency of a company valued at $12 billion on more than $150 million of annual recurring revenue: roughly an 80x multiple, on a business that TechCrunch reports is not profitable.
Two further facts bear on the number. Accel and Cyberstarts are investors in both Cyera and Oasis, so this is not a clean arm’s-length price discovery event. And Cyera raised $600 million weeks ago and is now committing a reported $700 million in cash; in effect, the round is funding most of the cash consideration. Neither point makes the deal unwise. Both mean the $1 billion figure should not be treated as an independent market valuation of NHI technology.
Where This Deal Will Be Won or Lost
- Buyer mismatch. Oasis sells to identity and IAM teams. Cyera sells to data security, privacy and compliance functions. The budget holders, procurement cycles and internal champions are all different. It is the most common reason otherwise sensible security acquisitions underperform, and a shared platform diagram does not fix it.
- The independent-unit hedge. Oasis is expected to run as a separate unit after close. That protects near-term revenue and customer continuity, but it also defers the unified control plane the deal is premised on. The value thesis and the integration plan are pulling in opposite directions in year one.
- Overlap with what Cyera already shipped. Cyera already offers an identity module covering human and non-human access to data. The company is therefore replacing or deepening something it built rather than filling an empty space, which raises the bar for demonstrating what customers actually get that they did not have before this deal.
- A missing substrate. Our Non-Human Identity Management Leadership Compass named nine Overall Leaders, and every one of them is an established identity, PAM, or secrets vendor: AppViewX, BeyondTrust, CyberArk, Delinea, HashiCorp, Keeper Security, Kron, Microsoft and One Identity. Depth in this market currently correlates strongly with owning the underlying substrate: a credential vault, certificate lifecycle management, or both. Neither Cyera nor Oasis is a secrets management vendor, and prospective buyers should establish exactly which vaulting and PKI dependencies the combined platform carries before treating it as a like-for-like alternative to those nine.
- Integration bandwidth. This is the third acquisition Cyera has announced in 2026. Absorbing three companies in a year while scaling a platform is an execution load that deserves scrutiny from prospective customers, not just from investors.
What It Means for the Market
NHI management is closing as a separate purchase, not as a discipline. The capability still has to be evaluated, but as it moves inside platforms the category needs a wider definition and probably a different name. Entro has gone to SailPoint, Oasis is going to Cyera, and 1Password acquired Apono for a reported $250–300 million. Enterprises evaluating non-human identity in the second half of 2026 should be choosing the platform they want to govern identity from, not a point tool, because that is the decision that will actually persist.
That choice is now contested, which is the more interesting consequence of this deal. The conventional path runs through the identity platform: SailPoint with Entro, CyberArk, Delinea, Microsoft Entra. Cyera is arguing for something less conventional: govern agent access from the data layer outward. For organizations whose principal exposure is sensitive data reachable by agents, that is a coherent proposition. For organizations that already run mature IGA and PAM programs, governing machine identity from a DSPM tool will be a harder sell internally, and we expect most large enterprises to keep identity governance anchored in their identity platform.
What Comes Next
New security categories are usually swallowed by platforms about eighteen months after they become visible. It happened to CASB in 2017, to SOAR in 2018 and 2019, and agent threat detection followed last year, when seven vendors in agentic security were acquired between September 2024 and the end of 2025, five of them in threat detection alone.
NHI management is at the same point now. Companies in these waves acquire rather than build, so the identity platforms that have not moved yet are the ones to watch, along with SentinelOne and CrowdStrike, neither of which has bought fully integrated agent security. Independent innovation moves on with it, most likely to agent governance and audit, where the EU AI Act rules that take effect in August have created budget that no acquirer has taken yet.
For buyers, the risk is dilution. Products bought this quickly tend to lose features as they are folded into a platform, so a shortlist drawn up before the deal will not match what ships. Prospective buyers should test any acquired platform against their own agent workloads and ask which parts of the roadmap survive alongside what the acquirer already sells.
Recommendations
- Oasis customers: take no action yet. This is a letter of intent. At your next renewal, get written roadmap and support commitments, confirm which secrets management dependencies persist, and establish whether your account moves to a Cyera commercial motion.
- Organizations evaluating NHI management solutions: do not price “agentic” branding as capability. Test candidates on discovery coverage across your actual estate, ownership attribution for orphaned identities, credential rotation, and clean decommissioning. These unglamorous capabilities are what separated leaders from entrants in our assessment.
- Existing Cyera customers: ask what the acquisition delivers beyond the identity module you already have, and on what timeline. “Independent unit” and “unified platform” cannot both be true in the first year.
- Vendors and investors in this segment: the window for independent non-human identity exits is narrowing, and this transaction sets an expectation that will be difficult for the next seller to meet. Assume valuation discipline returns.
Everyone: watch whether this closes on the announced terms. A letter of intent at this valuation, between companies sharing investors, in a market repricing AI assets, is not a certainty.
A First Take is a rapid analytical response to a market event, based on publicly available information at the time of writing. It is not a substitute for a full vendor assessment. Deal terms described here are as reported and, where noted, unconfirmed by the parties.