money dollars
– Getty Images

The year has already started with a bang for cybersecurity acquisitions. 2025 ended with ServiceNow splashing $7.75 billion on operational security firm Armis, just weeks after buying identity vendor Veza for the reported sum of $1 billion.

It was then Snowflake’s turn to flash the cash, acquiring observability platform Observe, also for a rumored $1 billion.

Arguably, both followed in the footprints of other enterprise vendors suddenly getting an expensive taste for security, with Google Cloud making a $32 billion play for Wiz in early 2025, and backup/recovery vendor Veeam purchasing Securiti AI for $1.7 billion in October.

In the view of Mauricio Sanchez, senior director at Dell’Oro Group, the push is coming from buyers wanting fewer platforms as AI-related expansion of the attack surface makes automation and policy orchestration more valuable than point features.

“Enterprise software is moving deeper into security, where it already owns workflow and data gravity,” Sanchez said. “What matters is converting workflow into enforceable controls. The implication is consolidation around systems of record and systems of action.”

Allie Mellen, cybersecurity author and principal analyst at Forrester, agreed that practitioners are looking to consolidate the number of tools they are using as large security vendors of the Palo Alto ilk continue aggressively pushing a platform approach.

“Large platform companies in the IT space can easily fit a security acquisition into their existing sales channels and make their products stickier in the process. Compound this with AI tools bringing DevOps and security closer together, and there are natural opportunities for consolidation for both the customer and the vendor,” she told SDxCentral.

When asked what’s driving big-ticket security acquisitions such as Observe, Carl Perry, head of analytics at Snowflake, explained it was part of positioning the firm's infrastructure for AI at scale, with the acquisition expanding the Software-as-a-Service provider's presence in what he described as the $51.7 billion IT operations management market.

“As AI agents generate exponentially more data, vertically integrated data and observability platforms become essential to running production AI reliably and economically,” Perry added.

Observability and AI

The Observe deal echoes Google's as-of-yet-closed Wiz win in its bid to bolster cloud security and posture, in this case for Snowflake’s AI Data Cloud.

According to Perry, observability has become a data problem that must scale as its customers run increasingly complex workloads. Sitting alongside Snowflake Trail, a built-in observability offering for Snowflake artifacts, Observe is, in contrast, a full standalone enterprise-wide observability platform, originally built on its parent’s platform, designed to help organizations manage production applications and AI agents to help detect and resolve issues early.

“Observability is a fundamental component of detection and response for AI agents and agentic systems. It’s also an area that many SIEM (Security Information and Event Management) vendors support as a parallel use case,” Forrester's Mellen explained. “Data consolidation is very important to manage costs today, and consolidating data for observability and security in one place can save time and resources.”

“By bringing Observe directly into the Snowflake AI Data Cloud, we will be able to empower our customers to manage enterprise-wide observability across terabytes to petabytes of telemetry using an open, scalable architecture and AI-powered troubleshooting workflows,” Perry claimed.

“AI systems are more dynamic, more distributed, and generate far more telemetry than traditional applications,” he added. “Instead of a single failure, teams are often dealing with chains of decisions across models, data pipelines, and services, which makes cause-and-effect harder to understand and control.”

Snowflake also claimed customers would no longer have to trade scale or visibility for cost.

“Observe reduces monitoring costs by 60-70% while supporting dramatically larger data volumes,” Perry said. “Customers see immediate gains in speed and productivity: unified observability data combined with AI-driven analysis enables teams to identify root causes up to 10 times faster, without learning new tools or workflows.”

As such, like with all tech movements these days, the AI aspect is hard to miss with recent blockbuster enterprise acquisitions. For example, Veeam’s buyout of Securiti AI was driven by the specter of bad data within large language models (LLMs), according to Tim Pfaelzer, Veeam SVP and GM for EMEA at Veeam.

“AI projects and customers fail at a rate of 70 or 80%. Why? Because the data that goes into the LLM is wrong, and it’s wrong because there could be malicious data,” he told SDxCentral. “So how can I make sure that my AI models are actually not corrupted?”

For Pfaelzer, Securiti AI provides Veeam users a single pane of glass into their data across distributed environments, creating what he called a “social graph” of where data currently resides, where it’s moved to, and who accessed it for certain actions.

“Then you can roll back to the right data so that you can be sure that the clean data moves into an LLM. And the second need is staying safe while staying compliant with data regulations. AI also helps in this part, because you can always show you know who touched your data and who has access to which data.”

Identity issues

AI also likely gilded identity vendor Veza in the eyes of ServiceNow. Identity management solutions have been booming lately due to the rise in AI agents, spurring buys from security vendors such as the Palo Alto Networks/CyberArk mega-deal and CrowdStrike’s $740 million purchase of identity management firm SGNL.

For ServiceNow, Veza offers the IT service management (ITSM) giant an identity security solution aimed at enterprises operating in the cloud suffering from a current lack of insight into access permissions for their data. Like with Securiti AI, central to the platform is a metadata graph, but one that organizes identities and their relationships to data instead of purely data itself. This mapping covers various systems and applications, complemented by a generative AI interface adding intent-driven search and natural-language explainability for ServiceNow users.

Like most enterprise vendors, ServiceNow offers its own AI agents for ITSM automation, as powered by Nvidia’s Llama Nemotron AI models. The firm also bought agentic platform Moveworks for approximately $2.85 billion last year, adding to earlier AI-driven acquisitions such as Logik.ai, Element AI, and Cuein AI.

With such an AI-centric and white-collar-driven portfolio, ServiceNow’s next move in buying Armis may have raised some eyebrows – but there is method to the madness.

Founded in Israel in 2015, the Palo Alto-based Armis secures operational technology (OT) and Internet of Things (IoT) environments, with its flagship Centrix platform monitoring connected devices on a network, ranging across IT, OT, IoT, and even Internet of Medical Things (IoMT) settings.

While ServiceNow declined to comment on the deal’s significance for its users, Dell’Oro’s Sanchez saw the Veza and Armis deals as complementary, describing asset intelligence as a piece of the identity puzzle.

“It complements identity rather than replaces it,” he added. “You cannot enforce identity, segmentation, or response if you do not know what is on the network, especially across IT, OT, and IoT.”

Operational safety can be life and death

Ultimately, Sanchez argued, what matters to buyers is coverage and data quality, implying Cyber Asset Attack Surface Management (CAASM) and External Attack Surface Management (EASM) are converging with IoT security needs.

The analyst added asset management would be a “hot” security theme in 2026, reflected by government advice from authorities such as the U.K.’s National Cyber Security Centre, which recently published principles to help organizations manage OT system security. According to Benny Lakunishok, CEO and co-founder at Zero Networks, such advice is not a nice-to-have but crucial for natural infrastructure.

“In OT environments supporting energy, water, transport, and manufacturing, attackers often abuse trusted access that already exists - an approach seen in incidents affecting fuel pipelines, power grids, and water utilities,” Lakunishok told SDxCentral.

From a business perspective, the now-hot theme was arguably kicked off by Mitsubishi Electric when it set its sights on Armis rival Nozomi Networks. While not an enterprise software player, the Japanese giant is neither a security vendor, and prior to Nozomi, had never bought a cybersecurity player in its 105-year history.

The Japanese giant's purchase of the OT vendor was announced last September and completed last month with no financial details disclosed, though analyst reports placed the deal around the $880 million mark.

With the deal, Mitsubishi Electric is able to build on its own in-house OT security solutions, such as its multi-factor authentication YubiKey tool, while utilizing embedded AI/ML capabilities across Nozomi’s platform, such as deep asset intelligence and anomaly detection to risk scoring, prioritization, and natural-language investigation workflows.

With its enterprise touch, Mitsubishi is also aiming to use Nozomi to augment industrial customers who are still mainly stuck in the past when it comes to security.

According to a Nozomi spokesperson, many industrial environments run decades-old technology never designed with security in mind, making it harder to detect and defend against modern-day attacks.

“There, PCs and other IT devices in OT environments are susceptible to IT attacks that can bleed into OT environments, further expanding the attack surface. In short, attackers have more advanced tools to gain access to systems that were already difficult to protect, significantly increasing the cyberthreat in the OT/IoT space.”

Common attacks in the space include denial of service, adversary-in-the-middle, where a malicious actor acts as a middle man between two parties and intercepts sensitive information, and remote system discovery, where attackers use one compromised device to identify other potential entry points to a system.

Echoing Lakunishok, Nozomi said such security issues can lead to not just physical damage and safety risks for industrial operations, but also economic impact and cascading failures across the interconnected infrastructure.

"Especially toward critical infrastructure like water treatment facilities or the power grid, attacks on OT systems can be the difference between life and death," Nozomi’s representative said, adding: "AI has exacerbated an already dangerous threat landscape for OT/IoT operators."