CFOtech US - Technology news for CFOs & financial decision-makers
United States
NetSPI & Synack merge to create USD $200m cyber group

NetSPI & Synack merge to create USD $200m cyber group

Fri, 4th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

NetSPI and Synack have agreed to merge, creating a cyber security business with more than USD $200 million in revenue.

The transaction brings together two US groups focused on offensive security testing, including penetration testing and continuous security validation. KKR will back the enlarged company's growth plans, including investment in technology and product development, expansion of its testing workforce and further international growth.

The merged business will combine human-led security testing with agentic AI tools. The companies said customers still need expert judgement to identify weaknesses that automated systems may miss, particularly where context, business logic and attacker behaviour matter.

NetSPI and Synack serve large corporate and government customers. Their client rosters include major cloud providers, large US banks, big technology companies, Fortune 100 companies and federal agencies, according to the companies.

Together, the businesses have nearly 40 years of operating history and more than 13 million hours of offensive security testing experience. Based on the figures disclosed, Synack accounts for nearly 10 million of those hours.

Customer focus

The merged business plans to offer a broader range of services across the offensive security lifecycle. That includes access to a larger pool of vetted testers, continuous testing across a wider attack surface and a mix of delivery models.

Executives presented the tie-up as a response to a changing market, in which companies face more digital assets to defend, tighter regulation and more advanced threats. They also argued that AI will change testing processes, but not replace human specialists.

"AI is transforming security testing, but it's still experts who find the vulnerabilities that lead to real breaches," said Jay Kaplan, Chief Executive Officer, Synack.

"Bad actors are unpredictable; you need people who understand context, business logic and attacker intent to catch them. Our challenge to the market: put our expert + AI team against any fully autonomous platform, on a real target, anytime. Autonomous tools find exploits. Experts armed with AI find the ones that actually breach you," said Kaplan.

This reflects a wider debate in cyber security over how far autonomous systems can take over testing work that has traditionally depended on specialist researchers. Offensive security providers have increasingly added AI tools to speed up discovery, triage and validation, while still relying on human testers for judgement and verification.

Scale and reach

For NetSPI, the merger adds Synack's established researcher network and public-sector presence. For Synack, it adds scale in penetration testing services and a broader base of enterprise clients.

Customers will continue to be supported through the integration process, the companies said. Existing ways of working will remain in place initially, while the range of services available to clients will increase.

"Every conversation about this merger started with the same question: What does the customer get out of it? The answer is simple," said Aaron Shilts, Chief Executive Officer, NetSPI.

"More coverage, deeper expertise and faster answers from a partner they already know and trust. On day one, nothing about how customers work with us changes, but what they can access grows significantly," said Shilts.

Private equity investor KKR is backing the next phase of the combined company, underlining continued investor interest in cyber security businesses, particularly those serving regulated industries and government customers, where demand tends to be more resilient.

Ben Pederson, Managing Director on KKR's Technology Growth team, linked the investment case to structural changes in the market, including broader attack surfaces and the growing use of AI by attackers as well as defenders.

"Offensive security is a large and structurally growing market driven by regulatory requirements, expanding attack surfaces and increasingly sophisticated threats amplified by AI," said Ben Pederson, Managing Director on KKR's Technology Growth team.

"The combination of these two companies creates a platform with the scale, technology and talent to serve the most demanding enterprise and government customers. Given the pace of adversary innovation, customers will be looking for a trusted partner to help manoeuvre through the accelerating pace of threats and breaches, and we believe no other company in the market will match its breadth or depth of offensive security capabilities," said Pederson.

The deal is expected to close in October, subject to customary closing conditions and regulatory approvals.