Cyera, the data security platform backed by some of Silicon Valley’s most prominent venture firms, is in advanced negotiations to acquire Oasis Security, a specialist in non-human identity protection, in a transaction valued at approximately one billion dollars, according to a Globes report published this week. The deal, if completed, would rank among the largest cybersecurity acquisitions of 2025 and signal a significant consolidation in the rapidly expanding identity security market.
The transaction would bring together two Israeli-founded companies operating at the intersection of data governance and machine identity management — a segment of the cybersecurity industry that has attracted intense investor interest as enterprises accelerate artificial intelligence adoption. The timing is notable given the broader capital dynamics at play across the sector, with identity security firms drawing increasing attention from both strategic acquirers and private equity as AI-driven threats multiply. Cyera itself was valued at roughly two billion dollars following a funding round earlier this year, meaning an Oasis acquisition at one billion dollars would effectively double the combined enterprise’s footprint in the market.

Oasis Security’s Position in the Non-Human Identity Market
Oasis Security was founded to address one of enterprise security’s most overlooked vulnerabilities: the vast and largely unmanaged population of service accounts, API keys, bots, and automated processes — collectively termed non-human identities — that operate across corporate networks. As organizations deploy more automation and AI agents, the ratio of machine identities to human ones has expanded dramatically, with some industry estimates suggesting that non-human accounts now outnumber human user credentials by a factor of ten to one or more in large enterprises. Oasis built its platform to discover, monitor, and govern these identities in real time, reducing the attack surface that adversaries exploit through stolen tokens and misconfigured service accounts.
The company raised capital from several institutional investors and had established a customer base among Fortune 500 enterprises before entering what sources describe as serious acquisition discussions with Cyera. A one-billion-dollar exit would represent a substantial return for early backers and validate a thesis that non-human identity management deserves to be treated as a standalone security discipline rather than a subset of traditional privileged access management. The deal also illustrates how the definition of identity security is broadening well beyond usernames and passwords, pushing vendors to build or buy capabilities that cover the full spectrum of digital credentials.
Strategic Logic and Market Implications for Cyera
For Cyera, absorbing Oasis would create a more comprehensive platform capable of correlating data exposure risks with identity vulnerabilities — a combination that security teams have long demanded but few vendors have delivered in a single product. Cyera’s existing technology maps where sensitive data resides across cloud environments and classifies it according to regulatory and business risk. Adding Oasis’s non-human identity layer would allow the combined entity to answer not just where critical data sits, but which automated processes and machine accounts can reach it, and whether those pathways are properly secured.

The acquisition talks arrive at a moment when the cybersecurity industry is undergoing meaningful consolidation, as buyers seek to reduce vendor sprawl and platform vendors race to offer unified security architectures. Valuations for identity-focused firms have remained resilient even as broader technology multiples have compressed — a dynamic explored in analysis of valuation pressure facing large-cap technology names. Cyera’s move suggests that well-capitalized growth-stage companies are willing to deploy significant capital to accelerate platform breadth rather than wait for organic development cycles. Should the deal close at the reported figure, it would also serve as a benchmark for pricing non-human identity assets at a time when the category is still maturing and comparables are scarce. Both companies declined to comment publicly, and negotiations could still fall apart or result in revised terms before any agreement is finalized.