Two acquisitions were worth 5.4 times every venture round in cyber security for six months, and the funding figures do not reconcile
Google paid $32bn for Wiz and Palo Alto paid $25bn for CyberArk. Every startup in the sector raised $10.6bn in the same half year. The ratio is invisible until you draw it on one axis.
By Parminder Kumar Sharma · · 7 min read

The cyber security funding coverage this year has been written in the register of a growth story. Solid. Robust. Holding up.
Read the quarters and something else is happening, and the more interesting finding is not in the venture numbers at all.
Where the money actually went
Where the money in cyber actually went
Every venture round raised by every cyber and privacy startup in the first half of 2026, seed to growth, across the entire sector, came to $10.6 billion.
Google's acquisition of Wiz was $32 billion, in cash. Palo Alto Networks buying CyberArk was $25 billion. Both completed this year.
Those two transactions come to $57 billion, which is 5.4 times everything the venture market put into the whole sector in six months.
That ratio is the story, and it is invisible when the numbers are quoted apart. Ten billion and thirty-two billion both read as simply large. On one axis, half a year of funding the entire next generation of security companies is a third of one cheque.
The direction of travel
The venture side is also shrinking.
Q2 2026 brought $4.4 billion in seed through growth-stage financing, which Crunchbase describe as a decline of around 30% from both the prior quarter and the year-ago quarter, with round counts falling by a similar amount. The quarter produced eight rounds of $100 million or more.
Q1 was reported at $4.9 billion across just under 200 rounds, with 13 mega-rounds of $100 million or more, and was described as dipping slightly on a sequential basis while remaining well above year-ago levels.
The three figures do not reconcile
This is worth stopping on, because it is the sort of thing that gets quoted into a board paper.
Three published figures, and what each one covers
| Figure | As published | The problem |
|---|---|---|
| Q1 2026 | $4.9bn, just under 200 rounds, 13 rounds of $100m or more | Described as dipping slightly sequentially, but well above year-ago levels |
| Q2 2026 | $4.4bn, 8 rounds of $100m or more | Described as down around 30% on both the prior quarter and the year before |
| H1 2026 | $10.6bn across all stages | Q1 plus Q2 is $9.3bn. The H1 total is $1.3bn higher |
| The sequential claim | Q1 to Q2 described as a fall of around 30% | $4.9bn to $4.4bn is about 10% |
| The year-ago claim | Q1 well above year-ago, Q2 down 30% on year-ago | Both can be true, but only if the comparison quarters moved sharply |
There are two ordinary explanations and I cannot choose between them from what is published.
The first is population. The H1 figure is described as covering all stages, while the quarterly figures are described as seed through growth-stage. If the H1 number includes late-stage or post-IPO rounds the quarterly cuts exclude, the $1.3 billion gap is definitional rather than an error.
The second is backfill. Crunchbase data is revised upwards as rounds are reported late, so a quarter's total rises for months after the quarter ends. A comparison written in April against a Q1 figure that has since grown will not match the same comparison written in July.
Both are normal and neither is a scandal. What is not safe is treating any single one of these numbers as the state of the market, which is exactly what a headline does.
What the ratio actually means for a buyer
Strip the reporting problems away and the structural picture holds regardless of which venture figure you prefer, because the M&A numbers dwarf all of them.
The money in cyber security is not primarily going into new companies. It is going into buying existing ones, and specifically into buying them at the identity and cloud layers. Google bought cloud security. Palo Alto bought identity.
That has three consequences for anyone who buys security software.
Your renewal conversation changes owner. A tool procured from an independent vendor with a focused roadmap becomes a line in a platform company's bundle. The roadmap gets reprioritised against the acquirer's, and the pricing gets renegotiated against a suite rather than a product.
The consolidation is happening at the layers you least want single-sourced. Identity and cloud posture are where most organisations already have concentration risk. Fewer independent vendors at those layers means the same dependency argument gets harder to answer.
Fewer new entrants are being funded to replace them. Round counts falling by roughly the same proportion as capital, on any of the published cuts, means the replacement pipeline is thinner at the same time the incumbent pool is shrinking through acquisition.
Take this with you
Practical, for the next twelve months
- List the security products in your estate whose vendor has been acquired in the last eighteen months, and check when each contract renews. That list is your exposure to somebody else’s integration roadmap.
- For anything at the identity or cloud posture layer, ask the vendor directly what happens to the standalone SKU. Bundling is the normal outcome and it is better to hear it before renewal than during.
- Do not build a market thesis on one quarterly funding figure. Cite the source, quarter, stage range and read date, because all four move and the published totals do not currently reconcile.
- If you rely on a small independent vendor for something important, ask about their funding position. Round counts are falling alongside capital, which affects the smaller end hardest.
- Treat “AI-enabled” security funding claims with the same care. A majority of recent cyber funding recipients also sit in AI categories, so the two sets overlap heavily and are not independent evidence of anything.
- When a briefing quotes a single large number, look for the ratio. Ten billion and thirty-two billion both read as large until you put them on one axis.
The position
None of this is a crisis narrative. Cyber security remains extremely well capitalised by the standards of almost any other sector, and a company being acquired for $32 billion is not a sign of distress.
The thing worth adjusting is what the funding coverage is understood to be measuring. A story headlined on venture totals describes the pipeline of new companies. It says almost nothing about where capital in the industry is actually moving, which right now is into consolidation at a scale several times larger.
For a practitioner, the consolidation number is the one that shows up in your working life. It arrives as a renewal notice.
Sources
- PrimaryH1 2026 cyber security and privacy startup funding: the 10.6 billion dollar half-year total, the 4.4 billion dollar Q2 figure and the roughly 30 per cent sequential and year-on-year declineCrunchbase Newsaccessed 2026-09-04
- PrimaryQ1 2026 cyber security funding at 4.9 billion dollars across just under 200 rounds with 13 rounds of 100 million or more, described as dipping only slightly on a sequential basisCrunchbase Newsaccessed 2026-09-04
- PrimaryPalo Alto Networks announces agreement to acquire CyberArk, the 25 billion dollar identity security transaction that completed in 2026Palo Alto Networksaccessed 2026-09-04


