Big data analytics service Splunk says it will acquire security automation platform Phantom Cyber for $350M in cash and stock; Phantom has raised $22M
Big data-crunching platform Splunk has announced plans to acquire Phantom Cyber Corporation ("Phantom"), a security automation and orchestration platform …
Context & Ripple Effects
This is the second act in Splunk's build-out from log-search tool into a full security operations platform: three years after paying $190M for machine-learning detection startup Caspida, it is now buying the automation layer that acts on those alerts, with Caspida supplying the 'detect' half and Phantom Cyber the 'respond' half. The price — roughly sixteen times Phantom's $22M raised — signals Splunk is paying for capability and team, not for revenue scale.
The move also fits a wider consolidation arc in security analytics: SentinelOne later paired its AI detection with logging via its $155M Scalyr acquisition, and Splunk kept adding adjacent data layers with SignalFx and Flowmill before Cisco ultimately moved to acquire Splunk itself.
First-order effects
- Splunk's customers get alert triage and response orchestration natively inside the Splunk platform, removing the need to integrate a separate SOAR vendor alongside their SIEM.
- Phantom's backers turn a $22M investment into a share of a $350M cash-and-stock exit, one of the stronger multiples among Splunk's security acquisitions.
Second-order effects
- Rival SIEM and endpoint vendors face pressure to bundle their own automation-and-response layer rather than leave customers to stitch one on — the same bundling logic that drove SentinelOne to buy Scalyr for its data pipeline.
- Standalone SOAR startups lose their most natural acquirer as a buyer, pushing them toward the remaining platform vendors or toward competing directly against a now-embedded Phantom inside Splunk deals.
Third-order effects
- Serial capability tuck-ins made Splunk a complete enough security platform to become a target itself — the endgame being Cisco's roughly $28B agreement to buy Splunk, which folds this whole stack into a networking giant's portfolio.
- If the pattern holds, security operations consolidates around a few data-platform owners that span detection, analytics, and automated response, shrinking the market for point-tool SOAR and forcing regulators' attention onto concentration in security infrastructure.
The trend: Security analytics platforms are assembling full detect-to-respond stacks through serial capability acquisitions, a consolidation wave that eventually made Splunk itself Cisco's target.