More consolidation is afoot in the world of cyber security. TechCrunch has learned from sources that Palo Alto Networks is going to be announcing the acquisition of Cider Security for $200 million in cash and a further $100 million in shares. The deal has been rumored for weeks, but we understand that investors have now been informed, and staff is also being looped in on the deal, which will be made official when Palo Alto reports its earnings later today.
Palo Alto has not responded to our request for comment.
Cider Security, based out of Israel, is one of a number of companies that focuses on application security, which includes not just technology to monitor malicious or suspicious activity around live applications in the cloud, but observability of the full ecosystem around those applications, specifically code deployments and other kinds of modifications and updates, covering code, CI/CD and the wider supply chain around those apps.
The company had raised $44 million from investors that included Tiger Global and Glilot Capital Partners — representing a decent exit for them at a time when valuations are seeing a lot of pressure, and many investors (including Tiger) have made drastic mark-downs in some or their holdings.
That’s not to say that prices are buoyant here: one source tells us that Palo Alto may well publicize this as a $200 million cash deal, with the $100 million share part disclosed later in order not to alarm the market.
Palo Alto Networks currently has a market cap of close to $47 billion. Relatively speaking, while it has been hit, like other tech companies, by a dropping share price, it has seen significantly less volatility and decline than some of its more valuable, bigger, consumer-facing counterparts. The company has made a number of acquisitions over the years to expand its reach in the market, but this appears to be the first and only one in 2022 (the two most recent before this are Expanse and BridgeCrew, respectively for $800 million in 2020 and $156 million by 2021).
Palo Alto already has a division that focuses on application security, which was in part formed by way of acquisitions. Evident.io, which it acquired in 2018 for $300 million, forms the basis of its Prisma Cloud business, which is focused on end-to-end application security. Cider will bring Palo Alto a product built from the ground up envisioning more holistic observability and communication between engineers and security teams.
Notably, along with the rumors of this Cider deal, it had been reported that Palo Alto Networks had been eyeing up another application security startup, Apiiro Security; however, reports claim that PA “walked away” due to a much higher price tag of $600 million. Interestingly, Apiiro looks like it is set to go it alone for now: just earlier this month, it announced a $100 million round of funding.
Cloud security, and application security specifically, continue to be hot areas in the enterprise IT world, not least because the high amount of network activity and systems exposure both make the space vulnerable to attacks. It was estimated to be a market worth some $6.2 billion in 2020, and it’s growing fast.
We will update this post as we learn more.