NetSPI And Synack To Merge, Creating Offensive Cybersecurity Platform With More Than $200 Million In Revenue

NetSPI and Synack have entered into a definitive agreement to merge, creating a combined offensive cybersecurity company with more than $200 million in revenue and a platform that pairs expert security testing with agentic AI.

The transaction will bring together NetSPI’s penetration testing capabilities with Synack’s continuous security validation platform and network of vetted security researchers.

The combined company will serve a customer base that includes major cloud providers, leading U.S. banks, MAMAA companies, Fortune 100 enterprises and U.S. federal agencies.

NetSPI and Synack bring nearly 40 years of combined operating history and more than 13 million hours of real-world offensive security testing experience.

The companies are positioning the combination around a hybrid model that uses AI to accelerate security testing while continuing to rely on human expertise for areas requiring judgment, context and an understanding of attacker behavior.

The combined platform will offer continuous security testing and validation across enterprise attack surfaces, with AI supporting areas such as vulnerability discovery, analysis and validation.

Customers are also expected to gain access to a broader bench of offensive security professionals, expanded service offerings, greater operational scale and additional delivery models.

KKR will support the combined company’s growth strategy, including investments in technology and product development, expansion of its offensive security talent base and further international growth.

The companies said existing customer relationships and service models will continue through the integration, with broader capabilities becoming available over time.

The merger is expected to close in October 2026, subject to regulatory approvals and customary closing conditions.

Piper Sandler is serving as financial advisor to Synack, with Latham & Watkins serving as legal counsel. Gibson Dunn & Crutcher is serving as legal advisor to KKR and NetSPI.

KEY QUOTES:

“AI is transforming security testing, but it’s still experts who find the vulnerabilities that lead to real breaches. Bad actors are unpredictable; you need people who understand context, business logic, and attacker intent to catch them. Our challenge to the market: put our expert + AI team against any fully autonomous platform, on a real target, anytime. Autonomous tools find exploits. Experts armed with AI find the ones that actually breach you.”

Jay Kaplan, CEO of Synack

“Every conversation about this merger started with the same question: What does the customer get out of it? The answer is simple. More coverage, deeper expertise, and faster answers from a partner they already know and trust. On day one, nothing about how customers work with us changes, but what they can access grows significantly.”

Aaron Shilts, CEO of NetSPI

“Offensive security is a large and structurally growing market driven by regulatory requirements, expanding attack surfaces, and increasingly sophisticated threats amplified by AI. The combination of these two companies creates a platform with the scale, technology, and talent to serve the most demanding enterprise and government customers. Given the pace of adversary innovation, customers will be looking for a trusted partner to help maneuver the accelerating velocity of threats and breaches, and we believe there will be no other company in the market with the breadth or depth of offensive security capabilities.”

Ben Pederson, Managing Director on KKR’s Technology Growth Team