Funding/M&A

Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius.

Cisco on Thursday announced an agreement to acquire identity lifecycle security company WideField Security to strengthen the capabilities of Splunk’s Agentic SOC. 

No financial details have been publicly disclosed. WideField raised more than $11 million in Series A funding last year. 

WideField has developed technology that enables organizations to discover human and non-human identities, map exposures across accounts and roles, and assess hygiene gaps. 

The company’s platform also enables users to detect misconfigurations in authentication policies and weak authentication paths, providing live session monitoring for real-time threat detection, and AI-powered behavioral analytics.

By integrating this into Splunk’s Agentic SOC and Cisco’s broader data fabric, the acquisition brings deeper identity and session intelligence into threat investigations, adding critical details around credentials, active sessions, and potential impact radius. 

This helps security teams better understand context for both human and AI-driven activity, and organizations gain the visibility needed to run autonomous AI systems securely at scale.

Advertisement. Scroll to continue reading.

This is Cisco’s third cybersecurity-related M&A deal of 2026, after Galileo and Astrix Security.

Cisco’s announcement came on the same day Accenture revealed a major OT cybersecurity push via acquisitions totaling $4.1 billion. The professional services giant is taking a majority stake in Dragos and fully acquiring runZero and NetRise.

SecurityWeek’s M&A tracker has cataloged approximately 190 deals to date in 2026.  

Related: SailPoint to Acquire Entro in Reported $200 Million Deal

Related: Cybersecurity M&A Roundup: 26 Deals Announced in May 2026

Related: 1Password Acquires Apono in Reported $250M-$300M Deal

Related Content

Vulnerabilities

CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.

Funding/M&A

The deal values industrial cybersecurity giant Dragos at $3.25 billion, and runZero and NetRise will operate under Dragos.

Vulnerabilities

Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.

Network Security

Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.

Funding/M&A

Israel-based Entro specializes in non-human identity and credential security solutions, and it will enable SailPoint to enhance its products.

Funding/M&A

Apono specializes in just-in-time access governance technology for humans, machines, and AI agents.

Network Security

Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.

Vulnerabilities

The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version