First Take: Cyera Buys Its Way Into Identity With Planned Acquisition of Oasis Security (KuppingerCole)

Tag: S-2026-07-31-kuppingercole-cyera-oasis-first-take Type: article (independent analyst blog — “First Take” rapid response) Author(s): Jonathan Care, Practice Lead AI, KuppingerCole Analysts AG Date of source: 2026-07-31 (modified 2026-08-03) Date ingested: 2026-09-15 Authority weight: medium — independent analyst house with its own NHI market research (Leadership Compass) and no commercial stake in the deal; but explicitly a rapid, pre-completion take, and several figures it relays (cash/share split, profitability, comparable deal values) are second-hand press reports Raw file: S-2026-07-31-kuppingercole-cyera-oasis-first-take.md

What it claims

Written at the letter-of-intent stage (LOI announced 28 Jul 2026), the piece accepts the architectural logic of a DSPM vendor buying a non-human-identity (NHI) vendor: authorising an AI agent needs both the sensitivity of the data asset (what DSPM knows) and the identity holding the credential, who owns it and whether it should still exist (what NHI management knows); neither discipline alone can answer “should this non-human identity be able to read this record right now?“. It notes Microsoft, Palo Alto Networks and CyberArk converging on the same control point.

Its scepticism is about price and integration direction. The ~$1bn value is about five times SailPoint’s reported ~$200m for Entro Security six weeks earlier, and Oasis was a “Rising Star”, not a rated Leader, in KuppingerCole’s NHIM Leadership Compass 2025; the premium is “a bet on the agentic AI narrative”. Two facts qualify the number: Accel and Cyberstarts invest in both companies, so it is “not a clean arm’s-length price discovery event”, and the cash consideration is largely funded by Cyera’s June $600m raise. It declines to rely on Cyera’s “nearly 500%” NHI-growth statistic (no methodology).

Risks it lists: buyer mismatch (Oasis sells to IAM teams, Cyera to data-security/privacy/compliance functions); the independent-unit hedge (Oasis expected to run separately post-close, deferring the unified control plane the deal is premised on); overlap with Cyera’s existing identity module; a missing substrate (neither company is a secrets/PKI vendor — all nine Overall Leaders in KC’s NHIM Compass are established identity, PAM or secrets vendors); and integration bandwidth (third acquisition of 2026).

Market read: NHI management “is closing as a separate purchase, not as a discipline”; enterprises should choose the platform they will govern identity from; it expects most large enterprises with mature IGA/PAM to keep identity governance anchored in the identity platform rather than a DSPM tool; independent innovation will move to “agent governance and audit”, where EU AI Act rules “have created budget that no acquirer has taken yet”. Buyer risk is dilution: acquired products “tend to lose features as they are folded into a platform”. Recommendations include testing NHI candidates on discovery coverage, ownership attribution for orphaned identities, credential rotation and clean decommissioning, and — for everyone — watching “whether this closes on the announced terms”.

Notable quotes

“The strategic logic is valid even if the price appears high. The premium is a bet on the agentic AI narrative, and the integration risk resides with the buyer.” (standfirst)

“That is the acquirer’s own figure, offered without published methodology, and we would not build a business case on it.” (on the 500% NHI figure)

“NHI management is closing as a separate purchase, not as a discipline.” (What It Means for the Market)

“For organizations that already run mature IGA and PAM programs, governing machine identity from a DSPM tool will be a harder sell internally.” (What It Means for the Market)

“Products bought this quickly tend to lose features as they are folded into a platform, so a shortlist drawn up before the deal will not match what ships.” (What Comes Next)

What’s speculative vs. asserted

  • Asserted, from KC’s own research: Oasis’s “Rising Star” status and non-rating in the NHIM Leadership Compass 2025; the nine Overall Leaders being identity/PAM/secrets vendors; the 18-month platform-absorption pattern (CASB, SOAR, agent threat detection).
  • Relayed from press (second-hand): ~$700m cash / balance in shares (Calcalist); Cyera >$150m ARR and unprofitable (TechCrunch); SailPoint–Entro ~$200m and 1Password–Apono $250–300m (SecurityWeek and others).
  • Speculative / expectations: that Oasis would run as an independent unit post-close; that the deal might not close on announced terms; that most large enterprises will keep identity governance in the identity platform; the “dilution” prediction; that EU AI Act budget is unclaimed by acquirers. The first two are now testable against S-2026-09-03-cyera-oasis-completion — the deal closed at the $1bn headline, and the completion release names a “Cyera Identity” pillar rather than an independent unit.
  • Comparison line (not from source): the piece’s “EU AI Act rules that take effect in August” remark is the author’s; the vault’s EU AI Act page (incl. the AI Omnibus changes) is the reference for the actual timeline and this source should not be read as authoritative on it.

Topics this feeds

  • Cyera — company page; independent counterweight to the vendor release.
  • Agentic Data Access Governance — Tensions entry (integration structure) and Key Point on DSPM/NHI convergence; assurance-relevant test criteria for NHI/agent-access tooling.

Open questions raised

  • Which vaulting / PKI dependencies does the combined Cyera–Oasis platform carry? (KC says buyers should establish this.)
  • Will identity teams accept governing machine identity from a data-security tool — i.e. does the buyer-mismatch risk materialise?
  • Does the acquired Oasis feature set survive platform absorption intact?