Yotam Segev, the co-founder and chief executive of Cyera, has a way of reducing security problems to two sentences: knowing your data is not enough if you cannot govern who or what touches it, and knowing your identities is not enough if you do not know what they can see. His company’s $1 billion acquisition of Oasis Security, announced Wednesday, is an attempt to build the product those sentences describe. Cyera, a data security firm, is buying Oasis, a specialist in managing the identities of software agents, and combining the two into a single platform for the age of autonomous AI.
The deal is the latest and largest in a wave of consolidation in identity security, a category that has become the fastest-growing corner of the cybersecurity market. According to people familiar with the matter, Cyera has signed an agreement to acquire Oasis for about $1 billion, and it will integrate Oasis’s technology into its unified identity and data security platform. It is the third acquisition worth $1 billion or more in the identity security sector in 2026, a pace that reflects a straightforward change in the threat environment: the identities under attack are no longer only human.
Oasis Security built its business on that change. Its platform focuses on non-human identities, the service accounts, API keys, OAuth tokens, workload identities and, increasingly, autonomous AI agents that run continuously inside enterprise networks. The company’s Agentic Access Management technology provides visibility into what agents can reach, control over their permissions and enforcement of policy across the systems they touch. In an enterprise that has deployed AI copilots and agentic workflows, and in 2026 most have, these identities outnumber human ones by an order of magnitude.
The technical problem the deal targets is real, and it is growing. Human workers log in, do work and log out; AI agents do none of those things. They chain tool calls across SaaS platforms, spawn sub-agents, hold credentials granted once during a pilot and never reviewed, and touch sensitive data stores at machine speed. There is no login event to gate with multi-factor authentication, no session to terminate, no behavioral baseline anchored to a human workday. An agent’s risk is defined not by where it sits on the network but by what data its credentials can reach, which makes data security and identity security two halves of the same question. Cyera’s argument is that no vendor has answered both halves together until now.
The threat scenarios are already visible in the wild. Indirect prompt injection, in which malicious content inside an email or document steers an agent to retrieve and transmit sensitive data using its own legitimate credentials, has become a recognized attack class. Orphaned and over-privileged agent credentials, tokens with no expiration, scopes granted for a proof of concept and never tightened, are the most common finding in agent security audits. Shadow agents, business units standing up automated workflows without security review, create invisible identities with real data access. Each scenario collapses the boundary between identity compromise and application attack.
The market has noticed. Identity security deals have multiplied as enterprises recognize that the AI agents they deploy are also the attack surface they did not plan for. Cyera itself has been acquisitive, buying the Index Ventures-backed Lightr and the young startup Genie Security in recent months, and it raised a major round weeks before this deal, giving it the balance sheet to keep consolidating. Analysts estimate the non-human identity segment is growing faster than the security market as a whole, and the deal valuations have followed, with acquisition prices in the segment climbing through the year as buyers pay up for the few platforms with mature agent-governance technology. The company’s pitch to customers is that the two halves, knowing the data and knowing the identity, have to be governed from one place, and that the vendors selling them separately are selling yesterday’s problem.
The integration will test that pitch. Data security posture management and identity governance have historically been operated by different teams, bought by different budgets and sold by different vendors, and folding them into one product means forcing two disciplines to share a data model. Cyera’s engineers will have to reconcile how each side inventories the environment, and customers will have to decide whether the combined platform is genuinely better than the sum of its parts or simply a larger bill.
For the industry, the deal is a marker of where security spending is heading. Enterprises are not just deploying more AI; they are deploying AI that acts, and every acting system needs an identity, a permission set and a governance regime. The vendors that control the identity layer of the agentic enterprise will control a growing share of the security market. Cyera’s $1 billion bet says the company intends to be one of them, and that the wave of consolidation in identity security is not close to finished.


