At a time when the industry is moving toward increasingly autonomous testing models, both companies share the vision that AI reaches its full potential when combined with the judgment and experience of specialized professionals. Integrating the talent of their security teams with AI-based technologies will allow the resulting company to perform more advanced testing, faster and at a larger scale.
The merged company will have over $200 million in revenue and a top-tier client portfolio, including major cloud service providers, banks, MAMAA companies—Meta, Amazon, Microsoft, Apple, and Alphabet—Fortune 100 companies, and government agencies.
Together, NetSPI and Synack bring nearly 40 years of operational experience and more than 13 million hours of offensive security testing in real-world environments. This combination of scale, experience, and capabilities will enable the new company to help organizations address increasingly sophisticated cybersecurity threats.
“AI is transforming security testing, but it’s still experts who detect the vulnerabilities that can lead to real breaches,” says Jay Kaplan, CEO of Synack. “Attackers are unpredictable, and you need professionals who can understand the context, business logic, and intentions of an attacker. Our challenge to the market is simple: pit our AI-powered team of experts against any fully autonomous platform, on a real target, at any time. Autonomous tools find vulnerabilities; experts, with the help of AI, identify those that can actually impact an organization.”.
A comprehensive offensive security platform.
The company resulting from the merger will offer expanded capabilities across the entire offensive security lifecycle, including:
One of the industry's most comprehensive teams of offensive security professionals, enhanced by autonomous AI.
AI specifically developed to accelerate vulnerability discovery, analysis, and validation.
Continuous security testing and validation across the entire attack surface.
A broader service offering with flexible delivery models.
Greater operational scale, efficiency, and the ability to accelerate innovation.
“Every conversation about this merger began with the same question: What does the customer get? The answer is simple: more coverage, greater expertise, and faster responses from a partner they already know and trust,” said Aaron Shilts, CEO of NetSPI. “From day one, nothing will change in how our customers work with us, but the capabilities they can access will increase significantly.”
KKR will support growth and international expansion.
KKR will support the merged company’s growth plan, which includes investments in technology and product development, expanding the offensive security team, and continuing international expansion.
“Offensive security is a broad and structurally growing market, driven by regulatory requirements, expanding attack surfaces, and increasingly sophisticated threats amplified by AI,” explained Ben Pederson, director of KKR’s Technology Growth team. “Combining these two companies creates a platform with the scale, technology, and talent needed to serve the most demanding enterprise and government clients.”
Pederson adds that, given the pace of innovation by adversaries, organizations will increasingly need trusted partners capable of responding to the accelerating speed of threats and security breaches. He believes the new company will possess a breadth and depth of offensive security capabilities that are difficult to match in the market.
The transaction is expected to close in October 2026, subject to customary closing conditions and regulatory approvals.
Piper Sandler is acting as financial advisor to Synack, while Latham & Watkins LLP is providing legal counsel to the company. Gibson, Dunn & Crutcher LLP is acting as legal advisor to KKR and NetSPI.
