If you own a cybersecurity services firm, the question is rarely whether someone wants to buy it. Cybersecurity firms attract one of the deepest and most competitive buyer pools in IT services, and recurring managed-security revenue (MSSP and MDR) commands the biggest premiums, while project-based assessment, penetration testing and staffing work sits lower. This page benchmarks the EV/Revenue and EV/EBITDA (enterprise value, the deal price adjusted for debt and cash) multiples cybersecurity firms change hands at, what drives the number, and who is buying. It is part of our IT services valuation multiples research.
Cybersecurity services firms protect organizations from digital threats. They run managed detection and response (MDR), operate as managed security service providers (MSSPs), and deliver penetration testing, incident response (IR), governance, risk and compliance (GRC) and vCISO advisory work. The best of them combine a 24/7 security operations center, proprietary tooling and certified specialists into a service that clients cannot easily switch away from.
That stickiness is why the sector commands some of the highest multiples in IT services. Contracted MDR and MSSP revenue renews each year and carries strong margins, so buyers pay a premium for it over one-off project fees. A firm running its own 24/7 SOC on top of a large managed-security book sits at the top of the range, while assessment and staffing shops with little recurring revenue sit near the bottom.
Across disclosed acquisitions from 2015 to 2025, cybersecurity firms sold at a median of 2.1x revenue and 12.8x EBITDA. The quartile range around those medians is wide, and the sections below show what moves a business toward the top of it.
How much do cybersecurity firms sell for
Enterprise-value multiples for disclosed cybersecurity acquisitions between 2015 and 2025. The median is the typical outcome, and the quartile range shows the spread. At the median, a cybersecurity firm with $5 million of EBITDA would be worth about $64 million.
| Multiple | Deals (n) | 1st Quartile | Median | 3rd Quartile | Median deal size |
|---|---|---|---|---|---|
| EV/Revenue | 64 | 1.1x | 2.1x | 3.4x | $40M |
| EV/EBITDA | 38 | 8.3x | 12.8x | 23.1x | $42M |
Source: Mergermarket and the Aventis Advisors deal database. Disclosed enterprise-value multiples only, 2015 to 2025. Figures are directional where the disclosed sample is small.
How to read the table: the first quartile (Q1) is the multiple a quarter of the way up the distribution, the median is the midpoint, and the third quartile (Q3) is three quarters of the way up. Half of all deals fall between Q1 and Q3, so the wider that range, the more valuations vary within the sector, and the more growth, margins and recurring revenue decide where a business lands.
What drives a cybersecurity valuation
Within the sector the gap between the first and third quartile is large, and that spread is not random. A short list of factors explains most of why one business clears the top quartile while another lands at the bottom.
Recurring MSSP and MDR revenue is the strongest lever. Contracted managed detection and response and managed security service revenue is valued far more highly than one-off project fees, because buyers pay for predictable, renewing income. A book of managed-security contracts that renews each year is worth a multiple of assessment or penetration-testing work that has to be re-won on every engagement.
Proprietary tooling and intellectual property separate a firm from commodity delivery. Owned detection platforms, threat-intelligence feeds, automation and playbooks lift the multiple, because they improve margin and reduce reliance on individual consultants, whereas resold third-party licenses and generalist staffing do the opposite.
Certified talent and security clearances are a scarce asset that buyers cannot easily hire at speed. A team carrying recognized certifications, and where relevant government clearances, commands a premium, because it lets an acquirer win regulated and public-sector work that would otherwise be closed to it.
A regulated, compliance-driven client base raises value. Clients in financial services, healthcare, defense and critical infrastructure buy security because rules require it, so their spend is durable and less cyclical. A base weighted to these sectors de-risks the revenue and supports a higher multiple.
A 24/7 SOC and threat-intelligence capability is what strategic buyers most often pay up for. A genuine round-the-clock security operations center, with mature incident-response and threat-hunting capability, is expensive to build and hard to replicate, so acquiring one is frequently cheaper than building it.
Recent cybersecurity deals
Accenture bought CyberCX of Australia for about A$1 billion (roughly $650M) in 2025, its largest cybersecurity acquisition. Orange bought the Netherlands’ SecureLink for €515M (about $576M) in 2019, then the largest cybersecurity services deal in Europe. Thales acquired the Australian cyber firm Tesserent for about A$176M in 2023, and Atos bought the managed-detection provider Paladion Networks in 2020 at an undisclosed valuation. Accenture Federal Services also acquired Novetta for about $1.5bn in 2021, though that business sits closer to national-security and mission analytics than commercial cybersecurity. Most private deals close at undisclosed valuations, so the disclosed sample skews slightly toward larger transactions and listed buyers.
Who is buying cybersecurity firms
Cybersecurity attracts one of the deepest and most competitive buyer pools in IT services, which favors sellers. Global consultancies, telco security arms and defense primes buy capability and talent, specialist MSSP roll-ups and regional consolidators such as Integrity360, Allurity, Swiss IT Security and Cyderes, formerly Herjavec Group, pay up for recurring managed-security revenue, and private-equity platforms back consolidators through bolt-on acquisitions. For the full ranking, see who is buying cybersecurity services firms, and for the wider sector our IT services valuation multiples report.
Methodology
The figures cover disclosed acquisitions of cybersecurity services businesses worldwide between 2015 and 2025, sourced from Mergermarket and the Aventis Advisors deal database of more than 125,000 transactions. Every figure is an enterprise-value multiple, computed on a like-for-like basis so it reflects the value of the whole business rather than the headline price. We report the median and quartiles rather than a single average, which a handful of premium deals would distort.
Thinking about selling your cybersecurity business?
Aventis Advisors advises IT services and security founders on M&A. We help you benchmark the business, identify the realistic buyers, and run a competitive process to secure the best price. Talk to our team.
Related reading
- IT services valuation multiples, the wider benchmark across every subsector.
- Who is buying cybersecurity firms, the most active acquirers and private equity investors.
- MSP Valuation Multiples and Cloud Services Valuation Multiples.
- How to sell an IT services business.
- Strategic vs financial buyers and M&A in IT services.

