IBM buys Resilient Systems cybersecurity firm focused on incident response, source says for $100M+
Gregory T. Huang / Xconomy :
Context & Ripple Effects
IBM is buying its way deeper into the security stack: weeks after FireEye paid $200M for threat-intelligence firm iSight Partners, IBM reportedly pays $100M+ for Resilient Systems, whose specialty — incident response — is the piece of the workflow that turns alerts into action. The deal slots alongside IBM's existing Guardium data-security franchise.
The pattern held after this purchase: IBM Security went on to acquire risk-management firm Agile 3 Solutions in early 2017, and in 2023 folded cloud data protection startup Polar Security into Guardium itself. Meanwhile insurers like Resilience began bundling ransomware-defense services with policies, showing response capability being sold through new channels.
First-order effects
- IBM Security immediately gains an incident-response platform it can resell alongside its existing security products, moving from selling tools to orchestrating the full breach workflow.
- Resilient Systems' incident-response customers and methodology now sit inside IBM, which must retain the specialist teams whose playbooks are the actual asset it bought.
Second-order effects
- FireEye, having just spent $200M on iSight intelligence, faces a rival pairing threat intel with response orchestration — pushing both toward bundled detection-plus-response offerings rather than point products.
- Cyber insurers like Resilience, which sell policyholders defense services against ransomware, become both a distribution channel and a competitive alternative for the same response capability IBM just acquired.
Third-order effects
- If the acquisition cadence holds — Guardium, Resilient, Agile 3, Polar — enterprise security consolidates around platform vendors that own detection, data protection, and response end-to-end, squeezing standalone incident-response specialists out of direct procurement.
- Response capability shifts from a professional-services engagement to a contractual product feature, the direction 'recoverability as procurement' describes: buyers increasingly demand breach recovery as part of the platform they already run.
The trend: Enterprise cybersecurity is consolidating as large platform vendors acquire incident-response and data-protection specialists to sell breach handling as a bundled product rather than a service.