Key Takeaways

  • CrowdStrike agreed to purchase XM Cyber’s technology, patents, and source code from Schwarz Digits while leaving the operating business independent.
  • The move reflects rising consolidation in exposure management and attack path analysis as global cybersecurity spending accelerates.
  • European cloud and regulatory pressures are shaping the expanded CrowdStrike and Schwarz Digits partnership around STACKIT.

CrowdStrike’s latest acquisition agreement has drawn new attention to one of security’s fastest evolving corners. The company signed a deal to acquire XM Cyber’s intellectual property from Schwarz Digits, including its source code, technology assets, and a portfolio of more than 45 patents. XM Cyber itself will remain intact as a standalone business, continuing to serve customers under a long-term licensing arrangement.

The transaction was published July 17, 2026, landing squarely in what analysts describe as a rapid consolidation cycle across exposure management, attack path analytics, and breach simulation. Global cybersecurity spending is expected to exceed $520 billion in 2026, according to Momentum Cyber, and a substantial share of that investment is now flowing toward end-to-end platforms instead of independent tools.

The XM Cyber assets fit neatly into CrowdStrike’s ongoing expansion of its Falcon Exposure Management capabilities. XM Cyber has long been known for its attack path management technology, which models how intruders could pivot inside a network and prioritizes the weaknesses that matter most. These techniques are often mapped against frameworks such as MITRE ATT&CK, which many organizations use as a common reference for adversary behavior. By acquiring the intellectual property, CrowdStrike can weave these capabilities more tightly into its platform rather than rely on integrations or fragmented workflows.

The structure of the transaction reflects an emerging industry trend. Only the IP is changing hands, not the commercial operations, revenue, or customer contracts. While the Schwarz Group purchased XM Cyber outright for $700 million in 2021, Momentum Cyber reported that strategic acquirers, including CrowdStrike and Palo Alto Networks, accounted for more than 90% of cybersecurity deal value in 2025. Many of those deals focused on capabilities that can be embedded into extended detection and response systems or consolidated portfolio offerings.

CrowdStrike’s move is also consistent with predictions from analysts at both Gartner and Forrester. Gartner has projected that more than 60% of organizations will adopt some form of continuous exposure management or attack surface management by 2026. Forrester has forecast that breach and attack simulation features, similar to what XM Cyber pioneered, will be bundled into at least 50% of market-leading XDR platforms by 2027. Those projections help explain why major security vendors are racing to build multi-capability ecosystems that handle everything from preventative modeling to real-time incident response.

Beyond the IP acquisition, CrowdStrike is expanding its strategic partnership with Schwarz Digits. As part of the relationship, the CrowdStrike Falcon platform will be offered on STACKIT, the sovereign cloud created by Schwarz Digits to serve European businesses that want data residency entirely within the European Union. Regulatory momentum is a major factor here. The Cyber Resilience Act and NIS2 are pushing companies to rethink where their data lives and how they demonstrate security controls. For enterprises with operations in Germany, France, or the broader EU, sovereignty has shifted into a board-level operational requirement. STACKIT, paired with Falcon, positions both companies to meet that demand.

The transaction also reflects broader competitive dynamics. Palo Alto Networks continues to deepen its Cortex and attack surface management capabilities, and Tenable has been making its own push into continuous exposure management. These players all operate in slightly different ways, but the direction is similar. Platforms are absorbing specialized technologies so customers can reduce tool sprawl and focus their teams on prioritized risk. The NIST Cybersecurity Framework often serves as a reference in these discussions, especially the Identify and Protect functions, since many exposure management workflows tie directly to those categories.

XM Cyber, for its part, will continue as a standalone company under Schwarz Digits. That means existing customers will see no immediate changes, and over time they may choose to migrate to CrowdStrike’s Falcon platform through programs like Falcon Flex. Long-term licensing models are fairly common when a parent company opts to preserve an acquired business’s commercial autonomy while monetizing its underlying IP.

The rapid acceleration of attacker automation is driving these investments. AI-driven tools allow adversaries to chain vulnerabilities and discover lateral movement paths faster than manual teams can keep up. Exposure management technologies attempt to get ahead of that curve by identifying exploitable scenarios before an attacker does. When combined with breach simulation and attack path modeling, they give security teams a more dynamic understanding of their environment compared to traditional, periodic assessments.

These technology acquisitions reflect a highly active M&A climate. Cybersecurity deal value in 2025 reached an estimated $96 billion to $102 billion across roughly 400 transactions, showing a year-over-year increase of around 270% to 300%. This indicates a marketplace shifting from disparate point products toward integrated security ecosystems. CrowdStrike’s acquisition of XM Cyber’s intellectual property fits into that trajectory. It reinforces a pattern where targeted capabilities, rather than full company purchases, drive strategic moves to improve attack path visibility and exposure reduction as enterprises navigate AI-powered threats and tightening regulatory environments.