Empty security operations centre with monitors glowing blue

Mandate profile

Cybersecurity and MSSP buyer profile

Buyer profile: a strategic cybersecurity group acquiring managed security providers and security SaaS with recurring contracts and certified teams.

MDR, SOC-as-a-service, identity, email security, GRC and vulnerability management businesses are all in scope.

Mandate profile

Why strategic groups buy security businesses.

Reference
AQ-0482
Sector
SaaS & software
Region
UK, Ireland, Europe, North America
Last reviewed

Security budgets keep growing while skilled people stay scarce. Strategic cybersecurity groups are buying managed security providers and specialist software to gain certified teams, recurring contracts and products they can sell across a wider client base.

This profile covers managed security and SOC providers, MDR, identity and access management, vulnerability and exposure management, email and cloud security, and governance, risk and compliance software. Businesses with recurring managed-service contracts and accreditations such as CREST, ISO 27001 or Cyber Essentials are the core focus.

Buyers here keep the team and the client relationships and add products from the wider group. Strong recurring revenue and certified analysts drive value.

Acquisition criteria

What this buyer is looking for.

Trust and talent are the assets. Five factors guide the search.

  • Recurring contracts

    Managed-service or subscription agreements, typically multi-year.

  • Certified people

    Analysts, engineers and testers with recognised certifications.

  • Regulated clients

    Financial services, healthcare, public sector or critical infrastructure.

  • Accreditations

    ISO 27001, CREST, Cyber Essentials Plus, SOC 2 or equivalent.

  • Own IP or playbooks

    Platforms, detections or processes your team built.

  • AQ-0482 sits alongside more buyer profiles on the board.

    Browse all mandates

Target financial profile

The numbers this buyer type works to.

Typical ranges for this profile. Businesses outside a range are still assessed on their overall strength.

Revenue
US$3M–US$40M a year
Recurring share
Majority managed or subscription revenue
Gross margin
Healthy and stable
Accreditations
CREST, ISO 27001, SOC 2 or similar
Typical valuation basis
Multiple of EBITDA or recurring revenue
Consideration
Cash with earn-out or rollover

Deal structure and terms

  • Structure

    Agreed per deal: full acquisition, majority stake or carve-out.

  • Team

    SOC analysts and engineers retained with incentives.

  • Client continuity

    Existing contracts and service levels kept unchanged.

  • Cross-sell

    Group products added to the client base after completion.

What makes a relevant business

Security clients renew because it works.

What stands out is a security partner clients would not dream of switching.

All of these are welcome

  • Services, SaaS or a mix
  • Profitable or near profitable
  • Founder-led or PE-backed
  • Specialist or broad offering
  • Any of the listed regions
  • High gross retention

    Clients renewing year after year.

  • Framework places

    Positions on public-sector frameworks.

  • Incident record

    Calm, effective response when it mattered.

  • Cross-sell potential

    Room to add services across the client base.

Market drivers

What keeps demand strong in cybersecurity software and managed security.

  • Regulation

    NIS2, DORA and sector rules push demand for managed security.

  • Skills shortage

    Firms outsource security they cannot staff.

  • Platform consolidation

    Clients want fewer, broader security partners.

FAQ

Common questions.

What does this mandate profile describe?

It sets out what a strategic cybersecurity group looks for in an acquisition: the target profile, deal size, structure and regions shown above.

What is Acquiry’s role?

Acquiry works on the buy side. Profiles like this one set out the criteria acquirers in this segment use to assess targets.

Will security-cleared staff be affected?

Clearances and client obligations are respected throughout; the buyer is acquiring that capability.

Are penetration-testing firms in scope?

Yes, especially those with recurring testing programmes.

Are pure software vendors in scope?

Yes. Security software fits alongside managed service providers.

Is penetration testing revenue considered?

Yes, alongside recurring managed services, which are weighted more heavily.

Do public-sector contracts fit?

Yes. Government and regulated-sector clients are a strength.