HP acquires endpoint security startup Bromium from which it has been licensing anti-malware technology since 2017; Bromium has raised $115.8M, per Crunchbase
The PC and printer maker has been licensing Bromium's anti-malware technology since 2017. — HP Inc. says it will bolster …
Context & Ripple Effects
HP's move on Bromium closes a two-year loop: the company has been licensing Bromium's anti-malware technology since 2017, and is now converting that vendor relationship into ownership — a pattern it set earlier with the acquisition of encryption specialist Voltage in 2015. Bromium raised $115.8M per Crunchbase, so this is also an exit for its venture backers rather than a rescue.
The deal slots into a longer HP/HPE buying streak in security: HPE later picked up zero-trust startup Scytale in 2020 and, via its Aruba subsidiary (itself an $3B HP purchase in 2015), reportedly paid $500M for cloud security firm Axis Security in 2023. Security has become a recurring capability HP builds by acquisition rather than in-house.
First-order effects
- HP moves from paying license fees to owning Bromium's anti-malware stack outright, letting it embed the technology directly into its PC endpoint security offering without a third-party dependency.
- Bromium's investors recoup their stake in a company that raised $115.8M, while Bromium's team and roadmap fold into HP Inc.'s security division.
Second-order effects
- Rival PC makers face an HP that can bundle owned, deeply integrated endpoint security into its machines, raising the bar for how much security capability ships by default on business PCs.
- The license-then-buy sequence signals to venture-backed security startups that hardware incumbents like HP and HPE are credible acquirers — a path HPE followed with Scytale and Axis Security.
Third-order effects
- If the pattern holds, endpoint security capability consolidates into device makers themselves, shifting leverage away from standalone anti-malware vendors toward the OEMs who control what ships on the hardware.
- HP's serial security tuck-ins — Voltage, Bromium, and HPE's Scytale and Axis deals — point toward security becoming a structural differentiator in commodity hardware markets rather than a bolt-on product line.
The trend: PC and hardware makers are converting security licensing relationships into owned capability through serial tuck-in acquisitions, making endpoint security a built-in differentiator rather than a third-party add-on.