The cybersecurity landscape is undergoing a profound structural transformation, driven largely by the rapid enterprise adoption of artificial intelligence and automated agents. In a strategic consolidation of high-growth enterprise security startups, data security leader Cyera has announced its acquisition of Oasis Security, a pioneer in non-human identity and agentic access management. This multi-million-dollar union brings together two elite startups that were independently backed from their Series A rounds by venture capital titan Sequoia Capital. By marrying Cyera’s deep visibility into sensitive enterprise data with Oasis’s specialized control over non-human identities, the combined entity aims to establish the definitive security standard for the era of agentic AI.
The transaction underscores a broader realization across boardrooms and Chief Information Security Officer (CISO) suites: traditional cybersecurity paradigms, which were built almost exclusively around human users and static perimeters, are fundamentally ill-equipped for modern, automated digital environments. As organizations race to deploy autonomous AI agents, Large Language Models (LLMs), and complex microservices, the operational attack surface has expanded beyond human control, necessitating an integrated approach to data protection and identity governance.
The Genesis of a Paradigm Shift: Non-Human Identities and Agentic AI
To understand the strategic rationale behind the Cyera-Oasis merger, one must examine the fundamental shift in how digital infrastructure operates. Three years ago, when Danny Brickman and Amit Zimerman founded Oasis Security, enterprise technology was crossing an invisible threshold. Organizations were quietly generating far more machine identities than human ones.
Unlike human users who log in with passwords and multi-factor authentication, non-human identities consist of API keys, service accounts, OAuth tokens, and agent-to-agent credentials. These assets are often invisible to traditional Identity and Access Management (IAM) systems. They frequently operate with high-level administrative permissions, persist indefinitely without rotation, and possess massive blast radiuses if compromised.
With the explosive emergence of generative AI and autonomous agents, this challenge escalated from a niche IAM subcategory into a critical, board-level risk. Modern AI agents do not merely read static documents; they dynamically query databases, execute transactions, communicate with external APIs, and write code. Each of these actions is powered by non-human credentials. Brickman and Zimerman recognized this trajectory early, building Oasis to pioneer "agentic access management"—a framework designed to discover, track, and govern the lifecycle of every machine identity operating within a corporate ecosystem.
Two Halves of the Same Equation: Data Security Meets Identity Governance
While Oasis was tackling the problem from the perspective of credentials and access paths, Cyera approached the digital transformation through the lens of data. Founded by Yotam Segev, Tamar Bar-Ilan, and Yonatan Itai, Cyera set out to answer a deceptively simple yet historically difficult question for enterprises: Where does sensitive data actually live, who has access to it, and what is the genuine business risk?
As generative AI tools and autonomous agents began systematically reading, writing, and manipulating enterprise data repositories, the leadership teams at both Cyera and Oasis arrived at an inevitable conclusion. Securing an AI-driven enterprise cannot be achieved by protecting data in isolation, nor can it be accomplished by managing identities without context. True AI security requires a synchronized approach that simultaneously safeguards the underlying data, maps the identities—both human and non-human—interacting with that data, and governs the autonomous agents executing the logic.
When evaluated side by side, the product portfolios of Cyera and Oasis function as complementary halves of a unified defense mechanism. Industry analysts often compare enterprise security to a high-security bank vault. In this analogy, Cyera acts as the comprehensive inventory system that reveals exactly what is inside the vault and why it matters, while Oasis serves as the biometric and credential verification checkpoint that determines who or what is approaching the door, ensuring that every entity has legitimate authorization to touch the assets.
By combining these capabilities, the merged platform covers the entire lifecycle and traversal path of an AI agent within a corporate network. It provides continuous visibility from the moment an agent queries a sensitive database to the specific credential and permission set utilized to execute the operation.
Shared Heritage and the Israeli Tech Ecosystem
The corporate marriage of Cyera and Oasis is notable not only for its technological synergy but also for its cultural and historical alignment. The founders of both companies share roots in the elite technological units of the Israel Defense Forces (IDF), specifically the prestigious Talpiot leadership program and Unit 8200.
These military intelligence and technological development incubators have served as a prolific incubator for global cybersecurity giants over the past two decades. Prominent firms such as Wiz, Cyera, and Oasis trace their foundational leadership back to this tight-knit community of technical talent. Sequoia Capital, which backed the Series A rounds of both Cyera and Oasis, noted that the conceptual alignment between the two startups felt almost predestined. What began as separate investments in parallel security domains ultimately converged into a single, cohesive solution crafted by engineers who share a common operational ethos and technical pedigree.
Under the leadership of Brickman and Zimerman, Oasis successfully established itself as a category-defining enterprise in non-human identity management in under three years. Despite its rapid ascent from a standing start, the company secured the trust of Fortune 500 enterprises tasked with governing massive fleets of machine identities.
Strategic Execution and Enterprise Go-To-Market Scale
Beyond technical integration, the acquisition solves a primary challenge facing high-growth cybersecurity startups: enterprise distribution and go-to-market (GTM) scale. Building a world-class sales and deployment engine capable of servicing global enterprises typically requires a decade of sustained investment and relationship-building.
Through this transaction, Oasis’s advanced non-human identity and agentic access management technology gains immediate access to Cyera’s established enterprise GTM engine. Cyera has cultivated one of the most powerful and expansive enterprise sales footprints in the modern cybersecurity sector. Integrating the Oasis product suite into this existing sales and deployment pipeline allows the combined organization to deliver comprehensive AI security solutions to enterprise accounts that would have otherwise taken Oasis years to penetrate independently.
Market dynamics dictate an aggressive pace for consolidation. As enterprise adoption of agentic AI accelerates, organizations are increasingly seeking to consolidate their security vendor stack. Enterprises are eager to standardize on unified platforms that can comprehensively address data governance, identity management, and AI agent monitoring simultaneously. By executing this merger, Cyera and Oasis have positioned themselves to capture a dominant market share as the definitive standard for enterprise AI security.
Industry Implications and Future Outlook
The acquisition of Oasis Security by Cyera reflects a broader market maturation regarding artificial intelligence risk management. For several years, enterprise security budgets were heavily allocated toward perimeter defense, network security, and basic endpoint detection. However, the proliferation of large language models, automated microservices, and autonomous software agents has rendered traditional perimeters obsolete.
As enterprises delegate greater operational autonomy to software agents, the potential blast radius of a compromised API key or misconfigured service account grows exponentially. A single compromised non-human identity can grant malicious actors or errant agents unfettered access to petabytes of proprietary customer data, intellectual property, and critical operational infrastructure.
The unification of Cyera and Oasis signals to the market that identity and data security can no longer operate in functional silos. Moving forward, the race to build the ultimate enterprise AI security platform will be won by organizations that can seamlessly correlate data sensitivity with identity behavior in real time.
With Sequoia Capital continuing its backing of the expanded team, the leadership of Cyera and Oasis are poised to embark on their next growth chapter. Armed with an expanded product portfolio, massive enterprise distribution reach, and a unified vision for agentic access management, the combined company enters the market as a formidable force, perfectly timed to meet the complex security demands of the artificial intelligence era.



