The ongoing AI explosion and recent growth of agentic AI usage have created a security landscape with new and evolving risks. Enterprises are deploying AI agents within their networks at a rapid pace, outstripping any previously existing framework in place for tracking what these agents can access. They are often over-permissioned, under-monitored, and unsecured.
Traditional identity and access management (IAM) capabilities were built around human logins, not the type of machine-to-machine activity that is always on with AI agents. AI security platform provider Cyera cites a nearly 500% increase in non-human identities (NHIs) in use by Fortune 500 companies in the past six months alone, and Gartner predicts that the average Fortune 500 company will be using over 150,000 agents by 2028, a massive increase from less than 15 in 2025. These statistics underline the immense scale of the ungoverned agentic AI gap.
A Security Gap Creating a Market
Human identities are now outnumbered by NHIs inside most large organizations: recent research from the Cloud Security Alliance places the ratio of NHIs to human users in enterprise environments at 45:1, an increase from 17:1 in 2023. In spite of the volume of NHIs with access to sensitive enterprise data and network areas, few tools exist that are built to monitor their behavior and permissions.
This phenomenon led to the 2022 founding of Oasis Security in a specific effort to police the category. The announcement of data security company Cyera’s intent to acquire Oasis is indicative of the value of the company’s offerings. Oasis raised around $75 million in its Seed and Series A rounds and an additional $120 million in a Series B round that valued the company near $700 million. The absence of a dominant governance layer created an opening that was rapidly filled not by traditional IAM players, but by data-security vendors.
Cyera's Acquisition Spree
Fresh off its own $600 million raise at a $12 billion valuation, Cyera has already signaled the desire to buy its way into capabilities adjacent to what Oasis offers. The recent acquisitions of Ryft, Genie Security, and Trail Security preceded the deal with Oasis, with each transaction further extending Cyera’s platform beyond just data discovery. This pattern shows Cyera as a company treating mergers and acquisitions as a core part of its strategy rather than an opportunistic method for supplementing functionality, financed by investor confidence rather than pure profit.
Strategic Benefits Justifying Cost
The timing and billion-dollar valuation of this acquisition are reflective of the importance of what Oasis has to offer among Cyera’s other offerings. In protecting modern enterprise environments, data and identity are inseparable factors, as it means very little to be able to locate sensitive data without visibility and control over which identities can access it.
The price tag on the Cyera-Oasis deal is 50 to 100 times the estimated annual recurring revenue (ARR), higher than Google’s acquisition of Wiz and Okta’s acquisition of Auth0. This signals that investors are pricing and prioritizing NHI governance as the next must-own layer of security. Oasis will remain intact as an independent unit within Cyera, preserving the company’s agentic access management technology while benefiting Cyera’s broader platform.
Impact on the Security Market
Cyera’s acquisition of Oasis is representative of an ongoing, rising trend of mergers and acquisitions in the cybersecurity industry. SecurityWeek’s cybersecurity M&A tracker cites 230 deals to date in 2026, naming the Cyera-Oasis acquisition as the second-largest acquisition of the year, behind only Accenture’s $3.2 billion purchase of a majority stake in Dragos.
The market has also seen moves from other leading companies rivalling this acquisition, including Sailpoint’s purchase of Entro and Cisco’s acquisition of WideField for Splunk’s agentic SOC, confirming a race across the sector to cover this category. Competitors are now facing pressure either to acquire their own NHI capabilities or risk ceding the category entirely to those who do so.
The Bet Hasn't Paid Off Yet
While this and other massive acquisitions signal confidence in a growing category of security, the numbers show that it hasn’t yet seen matching success. Cyera remains unprofitable in spite of having surpassed $150-200 million in ARR, with the company’s acquisition strategy financed on investor capital rather than actual cash flow.
The entire strategic logic of the company’s serial acquisitions depends upon millions of AI agents materializing inside enterprises at a scale that has not yet been reached—such as the growth Gartner has predicted by 2028. If agent adoption stalls or governance requirements prove simpler than anticipated, the premium Cyera has paid for Oasis will become far more difficult to justify.
What This Means for Security Leaders
This acquisition and similar deals force CISOs to treat NHI governance as a near-term budget line, rather than a consideration for the future. Consolidation of capabilities among vendors means that enterprises can expect platform lock-in decisions sooner than their timelines for rolling out AI agents may suggest. Whether Cyera’s bet on Oasis Security turns out to be prescient or premature, the acquisition has already reset what the market considers foundational security infrastructure.