Skip to main content
Private Equity

Private Equity Firms Cybersecurity: Top Firms in 2026

Andre Miller•September 10, 2026
Top Cybersecurity private equity firms in 2026

Key Facts

  • Cybersecurity ranks among the most active investment sectors for PE fund managers. Global cybercrime costs reached $6 trillion in 2021, up from $3 trillion in 2015, sustaining deal flow across all investment stages.
  • Thoma Bravo leads the sector with $181 billion in AUM. Its $12.3 billion take-private of Proofpoint remains the largest cybersecurity buyout transaction on record.
  • Insight Partners manages $89 billion in AUM and is the most active growth equity investor in cybersecurity. Its portfolio includes Darktrace and the $6.2 billion acquisition of Datto.
  • The primary geographic hubs for cybersecurity-focused PE investors are New York, San Francisco, Menlo Park, Boston, and Washington, D.C.
  • Companies increased cybersecurity spending 70% between 2019 and 2023, allocating a median 8% of technology budgets to security. This growth delivers predictable recurring revenue for portfolio companies.
  • The dominant strategies are software buyouts, growth equity, and dedicated venture capital, each targeting different stages of company maturity within the sector.
  • 72% of PE firms across the U.S. and Europe reported a serious cyber incident at a portfolio company in the past three years. Cybersecurity governance has become both an investment thesis and an operational imperative.

Cybersecurity Private Equity: Sector Overview

Private equity investment in cybersecurity operates on two distinct tracks. The first involves firms that deploy capital into cybersecurity companies, acquiring software businesses, backing founders, or consolidating point solutions into platforms. The second involves PE firms managing cyber risk across their own portfolio companies. This guide covers the first track: the buyout firms, growth equity investors, and venture capital funds that actively invest in cybersecurity as a sector.

The market has produced some of the largest software transactions in PE history. Thoma Bravo's $12.3 billion take-private of Proofpoint stands as the defining deal of the software buyout era. The firm assembled a portfolio spanning endpoint security, identity management, and compliance software.

The underlying demand is structural: enterprises increased security budgets 70% in four years. Ransomware costs average $3.4 million per incident at portfolio companies. Regulatory mandates from the SEC, NIST, and GDPR are sustaining that trajectory.

New York and San Francisco anchor the geographic landscape. Insight Partners and Evolution Equity Partners concentrate on growth-stage deals from New York. ForgePoint Capital and NightDragon operate from San Francisco.

Washington, D.C. plays a distinct role through MC2 Security Fund, which benefits from proximity to government and defense cybersecurity demand. Chicago-based Thoma Bravo is the sector's dominant buyout firm by deal volume and AUM. Menlo Park hosts Crosspoint Capital Partners, one of the most concentrated cybersecurity-exclusive PE investors in the country.

Comparing the Leading Security PE Investors

The table below covers the primary private equity and venture capital firms actively investing in cybersecurity companies, spanning leveraged buyouts, growth equity, and venture capital.

Firm Strategy Sector Strength Best Known For HQ
Thoma Bravo Buyout Endpoint, Identity, Compliance Proofpoint $12.3B take-private Chicago
Insight Partners Growth Equity Threat Detection, Cloud Security Datto $6.2B acquisition New York
Evolution Equity Partners Growth Equity AI Security, Cloud Native Dedicated $1.1B cybersecurity fund New York
Ten Eleven Ventures Venture Cross-stage, Global First pure-play cybersecurity VC Multiple Offices
NightDragon Growth Equity Safety, Privacy, Security NightScale value creation platform San Francisco
ForgePoint Capital Venture Infrastructure Security Axonius, Cybereason early backer San Francisco
Crosspoint Capital Partners Buyout/Growth Cybersecurity & Privacy Cybersecurity-exclusive mandate Menlo Park
MC2 Security Fund Growth Equity Defense Tech, Gov Cyber Chertoff Group intelligence network Washington D.C.
Spring Lake Equity Partners Growth Equity SaaS Security, Healthcare IT Later-stage tech specialization Boston

Thoma Bravo and Insight Partners occupy the top tier by AUM and deal scale. The mid-tier comprises dedicated specialists: Evolution Equity, NightDragon, and Crosspoint operate with focused investment theses rather than broad technology mandates. Ten Eleven Ventures and ForgePoint Capital serve the venture end, backing companies well before they reach the scale attractive to buyout funds.

Top Picks by Investment Strategy

Largest AUM: Thoma Bravo ($181 billion). No other PE firm has deployed more capital into cybersecurity software acquisitions, with a portfolio including Proofpoint, SailPoint, Ping Identity, Sophos, LogRhythm, and ConnectWise.

Growth Equity Leader: Insight Partners ($89 billion AUM) is the most active growth equity backer of cybersecurity companies globally. The $6.2 billion acquisition of Datto demonstrates the firm's willingness to write large checks at scale.

Top Dedicated Cybersecurity Fund: Evolution Equity Partners raised a $1.1 billion Fund III exclusively for cybersecurity and AI. Portfolio companies include Arctic Wolf, SecurityScorecard, Snyk, Aqua Security, Carbon Black, and Halcyon.

Strongest Venture Track Record: Ten Eleven Ventures was the first venture capital fund created to invest exclusively in cybersecurity across all stages and geographies. The firm now manages over $1 billion in AUM, including a $600 million third-generation fund.

Best Value Creation Model: NightDragon pairs capital with the NightScale Value Creation Platform, a dedicated operational resource structurally unusual even among specialist funds. The NightDragon Growth I fund totals $750 million.

Most Active in Government Cyber: MC2 Security Fund, backed by The Chertoff Group, brings intelligence community networks and federal sector relationships to its investments. The $205 million acquisition of Trustwave demonstrates the scale of its deal activity.

Rising Specialist: ForgePoint Capital focuses exclusively on early-stage cybersecurity and infrastructure software. Portfolio companies Axonius and Cybereason are two of the sector's most closely watched names.

Firm Profiles: In-Depth Breakdowns

Thoma Bravo

The defining PE investor in cybersecurity software, Thoma Bravo manages $181 billion in AUM and has built the most concentrated cybersecurity buyout portfolio in the industry. The firm's investment thesis centers on acquiring mature security software businesses and applying operational improvements. It then consolidates adjacent point solutions into platforms.

The Proofpoint take-private at $12.3 billion remains the largest cybersecurity transaction in PE history. The portfolio spans identity management (SailPoint, Ping Identity), endpoint protection (Sophos), log management (LogRhythm), IT management (ConnectWise), and AI-driven threat detection (Darktrace). Security software founders with demonstrated EBITDA are the firm's primary counterparties, and no other buyout firm matches its depth of operator relationships across the cybersecurity vendor community.

Insight Partners

Insight Partners brings $89 billion in AUM to growth-stage technology, with cybersecurity representing one of its highest-conviction segments. The firm operates as a growth equity investor and later-stage venture capitalist, writing checks from Series B through pre-IPO. On occasion, it takes controlling positions at scale.

The $6.2 billion acquisition of Datto demonstrates Insight's willingness to own cybersecurity businesses outright. Datto is a managed detection and response and backup platform serving managed service providers. Darktrace, the AI-driven threat detection company, is among the most recognized names in the portfolio, and the firm's ScaleUp program provides go-to-market support well beyond capital. For security companies scaling past $20 million in ARR, Insight Partners is among the most consequential growth equity conversations available.

Evolution Equity Partners

Evolution Equity Partners is the only growth equity firm to have raised a dedicated cybersecurity and AI fund at the $1 billion-plus scale. Its $1.1 billion Evolution Technology Fund III invests in growth-stage companies solving active threat categories: cloud-native security, AI-powered detection, and developer security.

The portfolio includes category leaders across multiple security segments: Arctic Wolf (managed detection and response), SecurityScorecard (cyber risk ratings), Snyk (developer security), and Aqua Security (cloud-native protection). Additional holdings include Halcyon (ransomware resilience), Pentera (automated red teaming), and Protect AI (AI security). The New York base provides proximity to the financial services industry, cybersecurity's most demanding and highest-spending buyer segment. Evolution's sector concentration means its network of operators and potential acquirers is narrower than generalist funds but substantially deeper within cybersecurity itself.

Ten Eleven Ventures

Ten Eleven Ventures was the first venture capital fund created with a mandate to invest exclusively in cybersecurity, operating across all stages and geographies. The firm has grown to over $1 billion in AUM, with its third-generation fund closing at $600 million.

This cross-stage flexibility is structurally unusual. Ten Eleven backs companies from early venture through pre-IPO, maintaining ownership through multiple rounds in the same portfolio company. Notable investments include Barracuda Networks, Ping Identity (subsequently acquired by Thoma Bravo), and Aura, the consumer digital security platform. The global mandate distinguishes Ten Eleven from U.S.-centric peers, with portfolio companies backed across Israel, the U.K., and Europe. LPs seeking concentrated cybersecurity venture exposure with an established multi-fund track record have few peer alternatives.

NightDragon

NightDragon's $750 million NightDragon Growth I fund targets late-stage companies in security, safety, and privacy, a mandate broader than pure cybersecurity software. The firm's NightScale Value Creation Platform is its most structurally distinctive feature. This dedicated operational resource connects portfolio companies to enterprise buyers, strategic advisors, and talent networks.

Portfolio investments include Onapsis (SAP and cloud application security), Mezmo (formerly LogDNA, observability), and IronCircle. The San Francisco base places NightDragon at the intersection of enterprise security buyers and the West Coast technology ecosystem. Late-stage security companies seeking capital and go-to-market acceleration find in NightDragon an investor whose operational platform sets it apart from financial-only GPs.

ForgePoint Capital

ForgePoint Capital occupies the early-stage end of the cybersecurity investment spectrum, investing exclusively in cybersecurity and infrastructure software from San Francisco. Portfolio companies include Axonius, one of the fastest-growing cybersecurity asset management platforms of the past five years. Cybereason, the endpoint detection and response company, is another notable holding.

ForgePoint's exclusive sector focus means partners bring domain expertise that generalist venture funds cannot replicate. This includes detailed knowledge of security buyer procurement cycles, threat category evolution, and acquirer priorities at exit. Seed and Series A founders seeking deep sector fluency consistently identify ForgePoint as among the most respected early-stage specialists in the market.

MC2 Security Fund (Chertoff Group)

The MC2 Security Fund has a distinctive capability: direct ties to U.S. national security and intelligence networks through The Chertoff Group. No other fund on this list matches that access. The fund invests in cybersecurity, defense technology, homeland security, and government services, targeting growth-stage companies with demonstrated traction in government and enterprise markets.

The $205 million acquisition of Trustwave demonstrates willingness to take platform-sized positions in managed security services. Additional investments include ThayerMahan, which raised a $30 million Series C for maritime autonomous systems, and Virtru, the data protection and encryption company. For security companies serving the federal market or defense industrial base, MC2 is the most strategically relevant growth equity partner on this list. Its deal origination and exit pathways are inaccessible to commercially-oriented funds.

Crosspoint Capital Partners

Crosspoint Capital Partners operates from Menlo Park with a mandate restricted entirely to cybersecurity and privacy investments. The firm's sector exclusivity places it among the most concentrated security-focused PE investors on the West Coast. Deal flow orients toward established companies rather than early-stage ventures.

Unlike generalist technology PE funds cycling attention across software verticals, Crosspoint's partners focus entirely on cybersecurity market dynamics, regulatory pressure, and buyer consolidation trends. The Menlo Park location provides proximity to Silicon Valley's largest security vendors and enterprise buyers. These are also the venture-backed companies most likely to become acquisition targets or buyout candidates at scale.

Platform Consolidation and Add-On Strategies

The cybersecurity software market remains fragmented, with hundreds of point solutions competing for enterprise budgets. Buyout funds are accelerating platform acquisitions and add-on strategies to consolidate overlapping capabilities, reducing customer complexity and improving net revenue retention.

Thoma Bravo's assembly of identity management assets across SailPoint and Ping Identity illustrates the roll-up playbook at the largest scale the sector has seen. Buyers pay premium revenue multiples for platforms with high ARR growth and strong cross-sell potential.

AI-Native Security as the Defining Investment Thesis

Generative AI has become the central theme in cybersecurity deal flow. Evolution Equity's Fund III explicitly targets AI security, with portfolio companies including Protect AI and Pentera built around automated detection and adversarial simulation.

Attackers already use AI to accelerate phishing campaigns and automated ransomware negotiations. Industry surveys indicate 52% of PE leaders expect AI adoption to disrupt existing cybersecurity safeguards. Investors are pricing both the threat acceleration and the resulting demand surge for AI-native defensive platforms.

Managed Detection and Response as the Preferred Business Model

Managed detection and response (MDR) has emerged as the service model PE investors favor most within cybersecurity. Recurring revenue, high switching costs, and strong net revenue retention create the financial profile that growth equity and buyout fund managers prize. Insight Partners' $6.2 billion acquisition of Datto reflected confidence in the managed services model for the SMB and mid-market.

Leading MDR providers now serve more than 100 PE firms representing $7 trillion in AUM, illustrating the scale achievable in specialized managed security delivery.

Regulatory Mandates Converting Discretionary Spend to Compliance Budget

SEC cybersecurity disclosure rules now require registered investment advisers (RIAs) and investment companies to adopt cyber policies and maintain 24/7 detection capabilities. Material incidents must be disclosed within four business days. NYDFS regulations impose heightened requirements on New York-regulated entities.

These mandates convert cybersecurity from discretionary spending into compliance expenditure, improving revenue predictability for PE-backed security vendors. Companies increased cybersecurity spending 70% from 2019 to 2023, and regulatory pressure is keeping that trajectory intact.

Cyber Maturity as a Direct Driver of Exit Valuation

Portfolio companies entering a sale process face buyers who conduct red-team exercises, ISO 27001 compliance audits, and SOC 2 assessments as standard diligence. A cyber breach during a holding period can eliminate millions in enterprise value and derail a transaction entirely.

Leading PE sponsors invest in NIST Cybersecurity Framework compliance documentation and cross-portfolio benchmarking to create an audit trail supporting premium exit multiples. Firms that treat cyber maturity as a competitive differentiator consistently report higher buyer confidence during exit processes.

How to Evaluate Cybersecurity PE Firms

Start with investment thesis alignment. Buyout-oriented funds like Thoma Bravo pursue profitable software businesses with EBITDA margins that support leveraged buyout structures. Growth equity investors like Insight Partners and Evolution Equity prioritize ARR growth rate and net revenue retention over near-term profitability.

Venture funds including ForgePoint and Ten Eleven invest on founder quality and category thesis. Matching the fund's preferred financial profile to your company's current metrics determines which conversations are worth having.

Sector depth matters more in cybersecurity than in most software verticals. Security buyers have distinct procurement cycles, compliance requirements, and threat category awareness that generalist investors frequently misunderstand.

Evaluate how many cybersecurity-specific partners the fund employs and whether they have direct experience in your specific threat category. Also assess their exit track record in comparable security software categories. A fund with five dedicated cybersecurity partners will outperform a generalist fund with a single sector analyst in every diligence conversation.

For LPs building exposure to the cybersecurity theme, the key distinction is between diversified funds with cybersecurity allocations and dedicated cybersecurity vehicles. Ten Eleven Ventures and Evolution Equity Fund III offer pure-play sector exposure with concentrated risk.

Insight Partners and Thoma Bravo provide cybersecurity exposure as part of broader technology mandates, with diversification that lowers volatility. IRR implications differ, and so do the portfolio construction requirements for LPs targeting specific cybersecurity sector betas.

Governance quality is an increasingly important evaluation factor at the fund level. A 2025 private funds industry survey found LP questions about cybersecurity governance increased over the past 12 months, with strong protocols now considered must-haves by a significant majority of investors. Funds without documented incident response plans or dedicated cyber operating leadership face a growing disadvantage in LP due diligence.

Which Firm Fits Your Needs?

Cybersecurity founders at Series B and beyond, with $10 million or more in ARR, should prioritize conversations with Evolution Equity Partners and NightDragon. Both firms write growth equity checks specifically for security companies, bring dedicated operational support networks, and have portfolio track records demonstrating deep sector credibility.

Companies at the early venture stage with a defensible technical thesis should target ForgePoint Capital and Ten Eleven Ventures. Both firms have the domain expertise and multi-stage flexibility to support companies from initial product-market fit through growth equity rounds.

Security software businesses with established EBITDA and strong market positions should target Thoma Bravo and Crosspoint Capital Partners as buyout partners. Thoma Bravo's operator network across the security software vendor community is unmatched. Crosspoint's cybersecurity-exclusive mandate makes it the most focused West Coast option for businesses seeking a specialist over a generalist.

LPs and institutional investors allocating to the cybersecurity sector should start with Insight Partners and Ten Eleven Ventures, which offer broad exposure with established fund series and documented track records. For concentrated security venture exposure without generalist technology dilution, Evolution Equity Fund III and ForgePoint Capital provide the narrowest mandates.

Security companies serving the government and defense market should examine MC2 Security Fund first. Its structural advantages in federal deal origination provide exit pathways that commercially-oriented funds cannot replicate.

Methodology

This guide covers private equity firms investing in cybersecurity, drawing on publicly available firm data, fund announcements, portfolio company disclosures, and market research published through 2025. Firm selection prioritized funds with explicit cybersecurity investment mandates, significant portfolio company counts in the sector, or documented landmark transactions in security software.

AUM and fund size figures reflect the most recently published data available for each firm. Market statistics draw on the 2025 S-RM Cyber Incident Insights Report, the QBE North America PE cybersecurity survey, a private funds CFO insights survey, and IBM Cost of Data Breach research. All profiled firms have verifiable deal history or fund documentation in the public record.

Frequently Asked Questions

Dozens of PE firms and venture capital funds now carry explicit cybersecurity investment mandates. The specialist tier includes Ten Eleven Ventures, ForgePoint Capital, Evolution Equity Partners, Crosspoint Capital Partners, and NightDragon. These funds invest exclusively or primarily in cybersecurity. A larger tier of generalist technology investors, including Insight Partners and Thoma Bravo, have built substantial cybersecurity portfolios within broader software mandates. PE industry deal databases track several hundred cybersecurity transactions annually across buyout, growth equity, and venture stages.

Written by

Andre Miller

Business Analyst

Andre Miller is a Business Analyst at ZoomInvestors, covering private equity and venture capital firms across geographies and sectors. His work focuses on deal structures, investor criteria, and the market trends that shape institutional capital flows.

Related Topics

Explore More

Read more articles on our blog

All Articles