NetSPI & Synack to Merge

NetSPI and Synack

The combined company creates the world's largest bench of elite security researchers, paired with the most sophisticated agentic AI pentesting platform in the industry.

Published September 2, 2026
Definitive agreement to merge announced
Expected to close in October 2026
Subject to closing conditions and regulatory approvals
No change to existing customer engagements today
The Category

What Continuous Offensive Security Means

Enterprise attack surfaces expand while software and infrastructure change continuously. Testing an environment once a year describes the environment as it was on the day the scope was agreed, not as it is now.

What it is

A defined surface, under test on an ongoing basis

Continuous offensive security keeps a defined attack surface under expert-led test, validates which findings are genuinely exploitable in the environment as deployed, and tracks how exposure changes over time.

What stays the same

Penetration testing remains the method

The method is not what changes. What changes is cadence, coverage and what happens between engagements, which is where most of the exposure sits.

What is preserved

Point-in-time engagements do not disappear

Specialist assessments, red team exercises and prescribed compliance testing all continue to have a place, and several are specifically required. The question is not whether to keep them, but whether they are the whole of what is needed.

The Combination

Two Complementary Approaches to Offensive Security

NetSPI and Synack have agreed to combine their complementary expertise, technology and approaches to offensive security.

NetSPI

Penetration Testing as a Service, at depth

NetSPI pioneered Penetration Testing as a Service and has built a deep team of offensive security professionals.

Its capabilities span more than 50 penetration testing types, attack surface management, vulnerability prioritization and specialized security services.

Synack

Agentic AI with a vetted researcher community

Synack combines Sara AI Pentesting with the Synack Red Team, a rigorously vetted global community of security researchers.

This model brings together agentic AI, diverse adversarial expertise and a platform designed to provide visibility and control across point-in-time and continuous penetration testing.

Both companies were built around a common principle: organizations need validated findings they can trust, backed by security professionals who understand exploitability, context and business risk.

Why Now

Why NetSPI and Synack Are Combining

Enterprise attack surfaces are expanding while software and infrastructure change continuously. At the same time, AI is increasing the speed and scale at which attackers can operate.

Keeping pace requires more than increasing the volume of automated findings. Organizations need broader testing coverage, greater access to offensive security expertise and faster answers about the vulnerabilities that pose material risk.

Combined Experience

The combination unites two of the industry's deepest benches of security talent with AI-enabled capabilities designed to extend the reach and impact of that expertise.

40 years
Nearly 40 years of combined operating history
13M+ hours
More than 13 million hours of real-world offensive security testing experience

Figures as stated in the merger announcement. Read the press release.

The Shared Vision

AI and Expert Judgment

AI is changing what penetration testing teams can accomplish. Expert judgment decides what the results mean.

What AI adds

AI can operate continuously, expand coverage and accelerate the discovery and analysis of potential vulnerabilities.

What experts decide

Expert judgment remains essential to validating exploitability, understanding business logic and identifying the complex paths an unpredictable attacker might pursue.

Why the two belong together

The shared vision behind this combination is grounded in both capabilities: agentic AI operating at scale and experienced security professionals determining what matters.

That points at a single ambition, easy to state and hard to reach: nothing left to exploit.

For Customers and Partners

What Customers Need to Know

Nothing about how existing customers work with NetSPI or Synack changes today.

During the pre-close period

  • Both companies remain focused on supporting their customers, partners and employees throughout the pre-close period.
  • Customers should continue working with their existing teams, services and platforms.
  • The transaction is expected to close in October 2026. Additional information will be communicated as appropriate following the close.
FAQ

Frequently Asked Questions

What is continuous offensive security?
Continuous offensive security is expert-led offensive testing of a defined attack surface, run on an ongoing basis rather than as isolated engagements, with findings validated for exploitability and posture tracked over time. Penetration testing is the method it uses. Agentic AI provides speed and coverage, and security experts determine which findings represent real, exploitable risk.
Is Synack being acquired?
The companies have announced a definitive agreement to merge. The transaction is subject to customary closing conditions and regulatory approvals.
What happens to my existing contract?
Nothing changes today. Customers should continue working with their existing teams under their current agreements, services and platforms. Contact your account representative with any specific questions.
When is the transaction expected to close?
The transaction is expected to close in October 2026, subject to customary closing conditions and regulatory approvals.
Does this change my testing cadence or scope?
No. Testing cadence, scope, platform access and points of contact remain as they are during the pre-close period.
Who should I contact with questions?
Customers and partners should contact their existing NetSPI or Synack representative. Media inquiries should be directed to the contacts listed in the official press release.
Perspectives

Three Perspectives on the Combination

Published this week by Synack's CEO, CTO and CMO.

Perspective

Autonomy Was Never the Goal

Jay Kaplan, CEO and Co-Founder. The published evidence on what AI agents can and cannot do in offensive security, and why the combination is a bet on expert judgment at AI scale.

Read Jay Kaplan's article
Perspective

The Hard Part Isn't More Experts. It's Routing the Work.

Mark Kuhr, PhD, CTO and Co-Founder. Why scaling offensive security depends on how agents and experts share context, evidence and decisions.

Read Mark Kuhr's article
Next Step

Read the Official Announcement

Full details about the proposed merger, the timeline and what it means for customers and partners.

Explore the Synack Platform