Skip to content
← Insights

Why Cyber Roll-Ups Seldom Deliver What They Promise

May 20, 2026 · 5 min read

AI Summary
Generating summary…

Every few years, somebody decides cybersecurity is the next great consolidation play. A fund gets raised, a banker draws up a list of boutique firms, and the acquisitions start landing one after another. The press releases use words like platform and scale and synergy. The investor deck has a chart with an arrow going up and to the right.

And then, two or three years later, the same firms quietly start losing the people who made them worth buying. Clients drift. Numbers slip. The fund moves on to whatever theme is next. I have watched this happen enough times now that the pattern is hard to miss, and yet the playbook keeps getting tried. So before going any further, it is probably worth being clear about what a cyber roll-up actually is, since most people outside the industry have never had a reason to think about it.

What a Cyber Roll-Up Actually Is

It is a strategy used mostly by private equity, but sometimes by larger industry players. The investor buys a series of smaller companies in the same industry and combines them under one corporate roof. The companies being bought are usually boutiques that have done well for themselves but have hit a wall — they cannot grow much further without capital, infrastructure, or a sales engine they do not have. The investor pays a modest price for each one, glues them together, and then either runs the combined business or sells the whole thing to someone else at a much higher multiple than they paid for the parts. The arithmetic of buying small and selling big is the whole game.

In cybersecurity, the targets are usually some mix of managed security providers, incident response shops, penetration testers, governance and compliance consultants, awareness training companies, and small product vendors. The pitch is that clients are tired of dealing with twelve different vendors and would rather have one. The math says that combining back offices saves money. And the eventual buyer will pay more for a bigger, broader platform than they would for any one of the pieces. None of that is unreasonable on its face. The problem is what happens in the middle.

What You Are Actually Buying Walks Out the Door at Five

Cybersecurity firms are not really businesses in the way a software company or a manufacturer is a business. They are small groups of people whose names clients know, whose judgment clients trust, and whose opinions clients are willing to pay a lot of money to hear. When the founder of an incident response shop sells, the clients are not buying a logo. They are buying her phone number and the people she trained.

Earn-outs and retention bonuses can keep those people in their chairs for a year or two. They cannot make them care about the new org chart, the new ticketing system, or the new EVP of Operations who flew in from somewhere to run a process they never asked for. When the lock-up ends, the strongest practitioners are the ones who go first. Usually they start something new. Sometimes they take a chunk of the client list with them, openly or quietly. Either way, the firm that the investor thought they bought is not the firm they own twenty-four months later. The talent is the asset, and the talent has wheels.

Cross-Sell Is the Slide That Always Disappoints

Almost every cyber roll-up I have looked at has a slide showing how much additional revenue is going to come from selling more services to existing clients. The pen testing client will buy managed detection. The compliance client will sign up for the SOC. The IR client will take a retainer. It looks tidy. It almost never happens at the rate the model expects.

There are two reasons. The first is that sophisticated clients deliberately do not buy everything from one provider. They want their offensive testers to be different from their defenders, their auditors to be independent of their implementers, and their advisor to be someone with no skin in the game. Asking them to consolidate after the fact is asking them to give up something they put in place on purpose. The second reason is harder to admit: the people who are excellent at offensive security are usually not the same people who are excellent at GRC, and bundling those services under one banner does not change that. Clients can tell. They start by buying the bundle and end by going back to the specialists.

The Independence Problem

A real piece of what an advisory firm sells, even if it is never written down anywhere, is the fact that the advisor is not also trying to move product. Once a roll-up combines an advisory practice with a tool vendor or an MSSP under the same parent company, that quiet promise is harder to keep. The advice might still be honest. The advisor might genuinely believe the in-house tool is the right call. But the client sitting across the table cannot easily tell, and most of them stop assuming. I have seen advisory practices that were absolute powerhouses as independent firms slowly lose the kind of work that made them powerhouses, not because they got worse but because the market repositioned them. The phone stops ringing for the second opinions. That is the kind of revenue you do not get back.

Integration Is Not the Part of the Slide Anyone Reads

Stitching cybersecurity firms together is harder, slower, and more expensive than the deal model assumes. Every firm comes with its own tools, its own way of writing reports, its own client portal, and its own founder who has strong views about all of it. Standardizing on one approach is the right answer commercially and usually the wrong answer operationally, because the practice with the best methodology is rarely the loudest in the room. Meanwhile the senior people who could be winning new business are sitting in integration meetings. Two years of that, and the firms that did not get acquired have caught up or pulled ahead.

When It Actually Works

Consolidation is not impossible in this industry. I have seen a few that worked. They tend to share the same handful of traits. The acquirer treats the deal as a fifteen-year operating commitment, not a five-year exit story. Founders are kept in real leadership roles and not slowly squeezed out after their earn-outs. The practices are allowed to keep what made them good even when that is annoying for the back office. The integration is paced. Cross-sell numbers are kept honest. And the people writing the cheques understand that the value of the thing they bought lives in human beings, not in the trademark.

Most roll-ups do not run on those terms, because fund timelines do not allow it.

What This Means for the Rest of Us

If your organization buys cybersecurity services and your provider has just been acquired, the most useful question is not what the new parent has announced. It is who is staying, in what role, and for how long. Get an answer in writing if you can. Pay attention over the next twelve to eighteen months. If the people you actually relied on start showing up on LinkedIn somewhere else, you have your answer.

If you run one of these firms and you are looking at an offer, the number on the page is the easy part. What matters is the structure underneath it and the role you will actually have on the other side of the closing. I have watched founders sign deals they regretted within eighteen months and I have watched founders sign deals that turned into the best chapter of their careers. The difference was almost never the price. It was the terms.

And for investors, the dental-practice and HVAC playbooks do not transfer cleanly to a business whose entire asset class is opinionated experts with strong views and a short commute to a competitor. Cybersecurity rewards specialists. It punishes generalists with a parent company logo on their email signature. The strategies that succeed here look more like long-term operating businesses than short-cycle financial plays. Most roll-ups are not built that way, which is why most of them do not work.

Cybersecurity rewards specialists. It punishes generalists with a parent company logo on their email signature. The strategies that succeed here look more like long-term operating businesses than short-cycle financial plays — and most roll-ups are not built that way.

Next Step

Ready to strengthen your organization's resilience?

A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.