NetSPI and Synack have agreed to merge, forming a combined offensive cybersecurity company with more than $ 200 million in revenue and roughly 800 employees. This piece covers what each company brought to the category before the merger, why validation data is becoming more valuable than raw testing volume, and what a security buyer should watch for as this kind of consolidation continues.
What Did NetSPI and Synack Each Actually Bring to the Category?
NetSPI built its position around expert-led penetration testing, drawing on internal testing teams and a track record spanning over two decades of engagements across enterprise and government clients. Synack built its position around a different model, a continuous security validation platform combined with a network of vetted independent security researchers, pairing that distributed testing capacity with technology designed to run assessments on an ongoing rather than scheduled basis.
Together, NetSPI + Synack bring nearly 40 years of combined operating history and more than 13 million hours of documented real-world offensive security testing experience, according to the companies' own announcement of the deal, a scale of accumulated testing data that neither company held independently before the agreement.
Why Is Validation Data Becoming the Asset Rather Than the Test?
A single penetration test produces a report. A large, accumulated body of testing data across thousands of engagements and millions of testing hours produces something more valuable to a security vendor: a dataset that can inform how testing itself improves over time, which vulnerability patterns recur across industries, and where automated tools genuinely add value versus where human judgment remains necessary.
This distinction matters for understanding why this specific merger makes strategic sense beyond simply combining two customer bases. Jay Kaplan, Synack's CEO, framed the combination around exactly this dynamic in the companies' announcement, describing a model that pairs autonomous tools for finding exploits with human experts who understand context, business logic, and attacker intent, a framing that positions accumulated data and expertise, not just testing capacity, as the actual competitive asset.
What Does Consolidation Usually Do to Buyer Choice in a Category?
Consolidation in a specialized services category like offensive security testing typically narrows the number of genuinely independent options a buyer can choose between, even when the combined entity offers broader capability than either company did separately. Crunchbase's profile of NetSPI shows a company with substantial independent funding and operating history prior to this agreement, context worth understanding for any buyer trying to evaluate how much genuine independence existed in this part of the market before the announcement.
Healthcare and finance firms are scrambling to meet new 2026 data standards touches on a related pressure shaping this market, since tightening regulatory data standards drive demand toward vendors that can demonstrate scale and accumulated expertise rather than a smaller, more narrowly scoped provider.
What Should a Security Buyer Watch for Next?
Buyers evaluating vendors in this space should watch specifically for how the combined company handles the integration period the companies themselves have described. According to the announcement, existing customer relationships and service models are expected to continue through the integration, with broader combined capabilities becoming available over time rather than immediately on the deal's close, expected in October 2026 subject to regulatory approval.
That gradual timeline matters practically for any buyer currently evaluating either company, since the specific combined capabilities being marketed around the merger may not be fully available to customers on day one, and confirming what's actually accessible immediately versus what's part of a longer integration roadmap is a reasonable question to raise directly with either company during this period.
FAQ
What company brought what capability to the NetSPI-Synack merger?
NetSPI brought expert-led penetration testing built over more than two decades. Synack brought a continuous security validation platform paired with a network of vetted independent researchers, focused on ongoing rather than scheduled assessment.
Why does accumulated testing data matter more than a single test result?
A large accumulated dataset across many engagements reveals patterns, recurring vulnerability types, and where automated versus human judgment adds the most value, insight a single isolated test cannot provide on its own.
Does this merger reduce the number of independent options buyers have in this market?
Consolidation of this kind typically does narrow the number of genuinely independent specialized providers, even as the combined entity offers broader capability, which is a tradeoff worth weighing when evaluating vendor options going forward.
When is the merger expected to close, and what changes for existing customers immediately?
The companies expect the deal to close in October 2026, subject to regulatory approval. According to their announcement, existing customer relationships and service models are expected to continue through the integration period, with broader capabilities becoming available over time.





.png)