- What: Cyera acquires Oasis Security to enhance AI agent control and data security
- Impact: A $1 billion deal to integrate AI and identity management into a single platform
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources IDENTITY & ACCESS MANAGEMENT SECURITY CYBERSECURITY OPERATIONS ENDPOINT SECURITY СLOUD SECURITY News, news analysis, and commentary on the latest trends in cybersecurity technology. Cyera's Oasis Security Buy is All About AI Agent Control The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles. Jeffrey Schwartz,Contributing Writer August 14, 2026 4 Min Read SOURCE: PICHETW VIA ALAMNY STOCK PHOTO In a move to add non-human identity (NHI) and AI agent management to its data security platform, Cyera earlier this month announced plans to acquire Oasis Security for approximately $1 billion in cash and stock. The Cyera-Oasis Security deal is the latest in a series of consolidations as companies look to boost their NHI capabilities at a time when organizations must rethink privilege access management (PAM) and identity access management (IAM) to ensure emerging agents don't have unrestricted access. Recent acquisitions include, among others, Cisco's purchase of Astrix, CrowdStrike's buy of SGNL, and Palo Alto Networks' $25 billion acquisition of CyberArk. The Cyera and Oasis combination will converge data and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles, the companies said in a statement. Oasis Security specializes in lifecycle management and security for non-human identities and AI agents — including service accounts, API keys, service principals and other machine identities. Related:USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports "What we've heard consistently from our customers is that data and identity are two sides of the same coin, and that identity is very, very fragmented and very legacy," says Jason Clark, Cyera's chief strategy officer. Ensuring Agents Don't Have Unrestricted Privileges The rise of agents that automate business and technical processes has changed the dynamic for how privileges need to be managed, Clark says. "Humans are over-permissioned — they use 4 percent of their permissions. Agents will use 100 percent, so we need to have the job of reducing that permission envelope," he adds. Expounding on Clark's point, Oasis co-founder and CEO Danny Brickman says agents break the trust model on which legacy IAM/PAM offerings were built, because that model depends on job titles, roles and humans who have to account for their actions — none of which apply to agents. "Agents are not humans," Brickman says. "They act differently, they're greedy, they operate differently. The trust model broke with agents because they're not responsible, they're not accountable, they don't have job titles — so role-based access doesn't exist anymore." Privileged access needs to be reframed to fit the agentic era, as well. "We were basically living in a world in which privileged access was well defined," Brickman says. "Today, if any sensitive information is accessible to a third party, it should be considered privileged access — even though it's not labeled that in the traditional world." Related:Flaws in Passkey Implementation Show Old Attacks Still Work Clark spells out a five-stage model for the combined company: Data discovery, Oasis's identity data, Cyera's understanding of data, authorization based on intent versus action and enforcement when behavior falls outside the norm in real time, with a human in the loop or via audit/forensics. "Identity is the most important control — that's where you control access to any action,” Clark says. “Everything an identity can see and everything it can do is done through identity permissions. Still, we enforce that through hooks at the endpoint, the gateway layer, and the infrastructure layer." Brickman described two types of use cases: near-term traditional processes such as credential rotation, decommissioning stale accounts and data cleanup, versus the agentic scenario, which is fine-grained, real-time enforcement based on an agent's actual intent and the sensitivity of what it touched. "We can stop, right now, immediately, the connection with an identity because we figure out it's accessing data it should not access,” he says. After the deal closes, which the companies expect to happen this quarter, the combined company will focus on supporting identity-side remediation paired with data-side remediation—encryption and cleanup of unused data. Related:Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Longer term, Clark says the plan is to develop a unified data and identity access graph for risk visualization, forensics/incident response and just-in-time authorization for actions of an agent, such as denying permissions mid-session. For example, Clark suggests an agent using stored credentials for research shouldn't retain write access to Workday or Salesforce. A Shared Path for Cyera, Oasis Cyera and Oasis share a similar vision and background. Both companies began with founding teams in Tel Aviv in 2021 and 2022 respectively and now operate with headquarters in New York City and R&D anchored in Israel. Cyera is considerably larger than Oasis, with 1,500 and 150 employees, respectively. Clark estimates that the combined company will have over 2,000 employees by the end of this calendar year. Also aligning both companies is the fact that they have common backers, notably Sequoia Capital, Accel and Cyberstarts. Cyera, which has raised $2 billion in total, raised a $600 million late-stage growth round in June, giving it a market valuation of $12 billion. Oasis raised $120 million in Series B funding in March. "We have many of the same investors, almost the same boards, so we've kind of been close with each other from day one," Clark says. The founders of both companies served together in the IDF. “We met when we were 17 years old, young and stupid, and then we grew up together in the army for many years,” Brickman recalls. “And one day, both of us decided to start different companies. And you know, sometimes when the energy is good, and the combination is perfect, things happen naturally.” About the Author Jeffrey Schwartz Contributing Writer Jeffrey Schwartz is a journalist who has covered information security and all forms of business and enterprise IT, including client computing, data center and cloud infrastructure, and application development for more than 30 years. Jeff is a regular contributor to Channel Futures. Previously, he was editor-in-chief of Redmond magazine and contributed to its sister titles Redmond Channel Partner, Application Development Trends, and Virtualization Review. Earlier, he held editorial roles with CommunicationsWeek, InternetWeek, and VARBusiness. Jeff is based in the New York City suburb of Long Island. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like IDENTITY & ACCESS MANAGEMENT SECURITY Flaws in Passkey Implementation Show Old Attacks Still Work by Arielle Waldman JUL 22, 2026 IDENTITY & ACCESS MANAGEMENT SECURITY Orgs Move to SSO, Passkeys to Solve Bad Password Habits by Nate Nelson NOV 13, 2025 IDENTITY & ACCESS MANAGEMENT SECURITY 1Password Addresses Critical AI Browser Agent Security Gap by Arielle Waldman OCT 10, 2025 IDENTITY & ACCESS MANAGEMENT SECURITY NIST Digital Identity Guidelines Evolve With Threat Landscape by Arielle Waldman AUG 14, 2025 Latest Articles in DR Technology CYBER RISK New Tool Traces AI Videos Back to Their Source AUG 3, 2026 IDENTITY & ACCESS MANAGEMENT SECURITY USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports JUL 31, 2026 APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector JUL 29, 2026 ENDPOINT SECURITY Agentic Browsers Rewind Web Security by 20 Years JUL 27, 2026 Read More DR Technology Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices