The richest single multiple in this series went to a cybersecurity firm, but the average tells a more useful story
Cybersecurity has moved from a budget line item to a board-level priority. Global spending is on track to surpass $213B in 2025, up from around $140B just five years earlier. Ransomware is still a risk, but its growth is tapering, while phishing and business email compromise, now often AI-enhanced, are rising fast. IBM's 2025 breach report puts the global average cost of a data breach at $4.44M, a slight drop thanks to better AI-powered detection, though the U.S. figure alone hit a record $10.22M.
On the back of that pressure, the sector keeps consolidating. Big platforms like Accenture, Cisco and IBM are making strategic plays, and so is private equity: Cisco's $28B purchase of Splunk and Thoma Bravo's $5.3B acquisition of Darktrace both signal deep conviction in this space.
Why cybersecurity M&A keeps rising
Threat complexity is expanding faster than internal teams can cover. Organisations are under pressure to defend more attack vectors, faster, than their headcount allows.
Regulation is pushing compliance to the front of the buying decision. Frameworks like the EU's NIS2 and Cyber Resilience Act are turning what used to be a technical purchase into a board-level compliance requirement.
AI adoption cuts both ways. Buyers want intelligent detection, automation and real-time response, and they're increasingly willing to acquire that capability rather than build it.
The market is still fragmented. Consolidation lets buyers eliminate overlapping tools and integrate point solutions into more comprehensive platforms, which is exactly what's driving roll-up activity at the mid-market end.
What the multiples tell you
Recent private transactions in cybersecurity show an EV/Gross Revenue range of roughly 1.4x to 5.7x, averaging around 2.6x on a total-consideration basis. That ceiling, 5.7x, is the single highest multiple we've seen across every category in this series, higher than Data & AI Services, ServiceNow, or any platform ecosystem we track. But the average sitting at 2.6x tells the real story: that top-of-range outcome goes to a specific kind of asset (high growth, differentiated technology, often AI-native), not to the typical mid-market MSSP.
There's an interesting wrinkle in the public markets too. Accenture trades at 12.68x EV/EBITDA, while Infosys, a smaller player, trades higher at 16.8x, driven by its expansion into vertical-specific offerings and enterprise AI capability. The usual pattern of "biggest company gets the highest multiple" doesn't hold here. Depth and specialisation are beating sheer scale.
Recent deals worth watching
- Accenture agreed to acquire CyberCX (2025, Australia) for a reported A$1 billion-plus, Accenture's largest-ever cybersecurity acquisition. CyberCX itself was built by rolling up twelve smaller Australian and New Zealand cybersecurity boutiques into one 1,400-person platform, a useful reminder that today's roll-up can become tomorrow's billion-dollar exit.
- SentinelOne acquired PingSafe, a Bengaluru-founded cloud-native application protection startup, in a deal reportedly valued north of $100 million. It's a clean example of a global security platform paying up for AI-native, cloud-specific capability rather than building it internally.
- Bitdefender's back-to-back APAC acquisitions of Horangi Cyber Security (Singapore) and BitShield (Malaysia) show what a deliberate regional roll-up looks like in practice: two bolt-ons, roughly eighteen months apart, each adding local teams and market access rather than just technology.
What this means if you're building a cybersecurity business
Don't anchor your expectations to the ceiling. A 5.7x outcome is real, but it went to an asset with a very specific profile. Most APAC cybersecurity deals land much closer to the 2.6x average, and plenty land below it.
Recurring revenue and hard-to-replicate capability are what move you up that range. Even as broader multiples have cooled from their 2021 highs, buyers are still paying up for sticky managed-services revenue and genuine depth in AI-driven detection, cloud security or Zero Trust, not generic point solutions.
Scale and regional reach matter more than the headlines suggest. Private equity drove roughly half of all $1B+ cybersecurity deals in 2024, but PE's overall share of transaction volume was only around 38%. Most APAC deals are still mid-market and corporate-led. If you're building toward an exit, the realistic buyer is more likely to be a strategic acquirer looking to add regional capability than a financial sponsor building a platform, unless you're already at meaningful scale.
The roll-up path is a legitimate strategy, not just a consolation prize. CyberCX started as twelve smaller businesses before becoming a billion-dollar sale. If you're too small today to attract a top-tier strategic buyer, joining or building a platform may be the more direct route to the outcome you eventually want.
If you want to talk through where your business sits against this range, or what would move you toward the top of it, we're happy to help. Our full breakdown of cybersecurity and IT M&A in APAC, including deal multiples, buyer segmentation, and our READY framework for exit preparation, is available in the whitepaper below.