<img src="https://ad.doubleclick.net/ddm/activity/src=11631230;type=pagevw0;cat=pw_allpg;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;gdpr=${GDPR};gdpr_consent=${GDPR_CONSENT_755};ord=1;num=1?" width="1" height="1" alt="">

The Coin Has Two Sides: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

Matt Howard
By Matt Howard

TABLE OF CONTENTS

    See Virtru In Action

    Yesterday, Cyera announced the acquisition of Oasis Security for a reported $1 billion. The cybersecurity world is taking note of the valuation — and it should. At an estimated $10–20M in ARR, this deal was priced at 50–100x revenue, topping Google's acquisition of Wiz (46x) and Okta's acquisition of Auth0 (43x).

    But the number isn't the story. The story is the logic behind the number — and what it signals for everyone in this industry.

    Data and Identity Are Two Sides of the Same Coin

    Jason Clark, Head of Strategy at Cyera, put it simply in his announcement: "Data and identity are two sides of the same coin. You cannot secure one without understanding the other."

    He's right. And at Virtru, we've held this conviction — baked into our architecture — for more than a decade.

    Cyera knows where your sensitive data lives. Oasis knows who — and what — can access it. Together they are attempting to build an end-to-end control plane for data security in the age of AI. That is a compelling vision. And the fact that it commanded a $1B price tag is a loud, unambiguous statement about where the market is heading.

    Most breaches don't happen because encryption failed. They happen because access was compromised. With non-human identities — AI agents, API keys, service accounts — now outnumbering human users by a widening margin, securing the intersection of data and identity has never been more critical.

    The Architectural Shift the Industry Has Been Avoiding

    For years, cybersecurity treated identity and data as separate problems. It built separate tooling, separate teams, separate budgets. That worked in a human-centric world where the perimeter was knowable and the actors were mostly human.

    That world is gone.

    In an agentic world — where AI models request data, autonomous workflows cross organizational boundaries, and service accounts outnumber people — the old separation is not just inefficient. It is structurally broken. You cannot govern what an AI agent is allowed to do with data if you don't understand the data. You cannot govern who can touch sensitive information if you don't understand classification, who the data belongs to, and what policies govern it.

    The Cyera/Oasis combination is yet another signal that the next generation of enterprise security will be built at the intersection of data attributes and identity entitlements — not around either one alone.

    Recommended Reading: The Era of AI: Why “Metadata on Data” is Critical Infrastructure

    This Is Terrain We Know Well

    At Virtru, we were not surprised by this deal. We were gratified by it.

    The Trusted Data Format (TDF) — the open standard at the heart of what we do — was built on exactly this conviction. Every piece of data carries its own attributes. Every identity carries entitlements. Policy enforcement happens at their intersection. That is not a product feature. It is an architectural commitment.

    When we integrate the Virtru Platform into DSPM ecosystems — and when we connect to ICAM ecosystems like Microsoft Entra, Ping, Okta, and SailPoint, we are operationalizing the exact thesis this acquisition validates. Data-centric security lives at the intersection of data with attributes and identity with entitlements, enforced via open standards at a uniquely granular level.

    Why This Moment Is Different

    There have been plenty of acquisitions in the security space. Most of them added features. This one is different because it names a premise change.

    For two decades, the security industry has organized itself around the perimeter — or around the identity layer as a proxy for the perimeter. The implicit assumption has been: if you know who someone is and they're inside the boundary, they can be trusted with the data. Access control was the last gate, not a continuous enforcement mechanism.

    That assumption fails catastrophically in three converging ways.

    First, the perimeter dissolved. Data moves to partners, regulators, third parties, cloud environments, and now AI agents. Governance that lives at the edge cannot travel with the data.

    Second, human identity is no longer the dominant access model. The rise of machine identities — service accounts, API tokens, autonomous agents — means that "who is asking" increasingly means "what is asking," and traditional identity governance wasn't designed for that.

    Third, AI has made it possible to interact with sensitive data at unprecedented scale, speed, and autonomy. An AI agent that can read your customer data, synthesize it, and act on it represents an entirely different risk surface than a human analyst doing the same work.

    The old security model — discover, classify, gate, hope — cannot keep pace. The new model must fuse data intelligence with identity intelligence and enforce policy dynamically at the object level.

    What This Means for the Industry

    Jason Clark made an ambitious prediction: over the next decade, Cyera will become one of three defining cybersecurity platforms alongside CrowdStrike and Palo Alto Networks. We'll let time weigh in on that. But the underlying structural thesis — that the future of enterprise security is built around understanding every identity, every piece of data, every AI agent, and every interaction between them — is spot on.

    The practical implications for every organization are real and urgent. Discovery without enforcement is a flashlight, not a defense. Knowing where your sensitive data lives is necessary but not sufficient. You need controls that travel with the data. You need policy that persists beyond the perimeter. You need access governance that understands not just who the user is, but what they're entitled to do with specific data under specific conditions — and enforces that dynamically, in real time, at the data object.

    Our Commitment

    Watching the industry arrive at a conviction we've held for years is energizing. It validates the market. It sharpens the urgency. And it raises the bar for everyone — including us.

    The window is open. The moment is now.

    Virtru is the creator of TDF (Trusted Data Format), the open industry standard for persistent data protection. The Virtru Platform enforces policy and access controls at the intersection of data attributes and identity entitlements — protecting data wherever it moves, with integrations across DSPM and ICAM platforms.

    Matt Howard

    Matt Howard

    A proven executive and entrepreneur with over 25 years experience developing high-growth software companies, Matt serves as Virtru’s CMO and leads all aspects of the company’s go-to-market motion within the data protection and Zero Trust security ecosystems.

    View more posts by Matt Howard

    See Virtru In Action