ActiScan

Industry News

The Great Email-Security Roll-Up: What Proofpoint's $1.8B Hornetsecurity Deal Signals for MSPs

September 17, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Technician's desk with two screens, one showing an acquisition headline and the other domain DNS records

Cybersecurity acquisitions rarely make headlines outside of trade press, but Proofpoint's completed purchase of Hornetsecurity is different. At $1.8 billion, it is one of the largest email-security transactions in years, and unlike most enterprise-focused deals, this one was built almost entirely around the managed service provider channel. That choice of target says more about where the market is heading than the price tag does.

The deal signals that email security is consolidating into fewer, broader platforms built specifically for MSPs rather than sold direct to enterprises. For MSPs, it means a familiar point product can become a division inside a much larger company almost overnight, with new pricing, support paths, and roadmap priorities set by leadership that never worked with your clients directly.

What Exactly Did Proofpoint Buy?

Proofpoint acquired Hornetsecurity's entire business, anchored by its 365 Total Protection platform, which bundles email security, backup, compliance tooling, access controls, and security awareness training into a single multi-tenant console built for MSPs. According to Proofpoint's own completion announcement, Hornetsecurity brought a partner base serving more than 125,000 customers through over 12,000 MSPs and channel partners, concentrated heavily in Europe.

Hornetsecurity was not a distressed seller. Reporting on the closed transaction noted that the company was generating close to $200 million in annual recurring revenue and growing at 20 percent year over year at the time of the deal, a detail that matters because it shows Proofpoint paid a premium for a healthy, MSP-native business rather than picking up a struggling competitor at a discount, as Techzine's coverage of the closing laid out. Notably, early market estimates when the deal was first announced pegged the price closer to $1 billion, and the final figure came in substantially higher once the transaction closed.

Hornetsecurity founder and CEO Daniel Hofmann did not exit after the sale. He now leads Proofpoint's newly created MSP Platform business unit, which suggests Proofpoint is treating the MSP channel as a distinct strategic bet rather than folding Hornetsecurity's customers quietly into its existing enterprise sales motion.

Why Is Email Security Consolidating Right Now?

Three forces are pushing vendors together at once: Microsoft 365's dominance as the shared attack surface, MSP buyers who want fewer consoles to manage, and private capital chasing recurring revenue in a still-fragmented market. Research from Mordor Intelligence describes consolidation intensifying through 2024 and 2025, pointing to Proofpoint's purchase of Hornetsecurity alongside Cisco's $28 billion acquisition of Splunk as evidence that customers increasingly want an integrated security fabric rather than piecemeal controls.

Proofpoint is not the only vendor rolling up MSP-focused email security. In mid-2025, private equity firm Bregal Milestone combined its portfolio company Redstor with TitanHQ to form CyberSentriq, a platform explicitly built to serve the more than 3,000 MSPs and 150,000 SMBs the two companies already supported, with a stated target of $100 million in annual recurring revenue by 2028. That is a private-equity-driven roll-up rather than a strategic acquisition by a larger security vendor, but the underlying logic is identical: bundle email security, backup, and awareness training into one contract before someone else does.

Channel analysts have been predicting this for a while. Canalys Chief Analyst Jay McBain has argued that MSPs want fewer tools but more outcomes, and that they would rather manage one interconnected platform with consolidated billing than a dozen disconnected agents, a point raised in ITEuropa's analysis of the consolidation trend. Vendors are responding to that demand signal by buying their way into breadth instead of building it organically.

A Pattern, Not an Isolated Deal

Looking at the last eighteen months of activity, a clear shape emerges. Large, well-capitalized players and private equity sponsors are both racing to own the MSP relationship rather than compete for it deal by deal.

TransactionApprox. ValueWhat It Combined
Proofpoint + Hornetsecurity$1.8 billionEnterprise human-centric security platform plus MSP-native M365 email, backup, and compliance suite
TitanHQ + Redstor (CyberSentriq)Undisclosed, targeting $100M ARR by 2028Email/web security plus backup and data protection, both already MSP-first
Cisco + Splunk$28 billionNetwork, email, and endpoint telemetry unified with SIEM analytics

Each deal follows the same script even though the buyers differ in size and structure. Point-product vendors that spent a decade earning MSP trust are being absorbed into platforms whose growth targets, pricing models, and product priorities are now set several ownership layers away from the technicians actually running the service desk.

What Should MSPs Actually Do About It?

MSPs should treat every acquisition announcement from a security vendor as a trigger to re-verify contracts, roadmaps, and exit terms rather than an event to simply monitor from a distance. Consolidation is not inherently bad for the channel, but it changes the risk calculus of any vendor relationship, particularly when that vendor sits directly in the mail flow.

Government cybersecurity authorities have been direct about this exposure for years. A joint advisory from CISA, the NSA, the FBI, and international partners warned that MSPs should understand their own supply chain risk and manage the cascading risk it poses to customers, precisely because a single compromised or disrupted provider can affect every downstream client at once. An acquisition does not create a breach, but it does create the kind of platform transition, support handoff, and licensing change that raises the odds of a misconfiguration slipping through unnoticed.

A few questions are worth asking of any vendor going through, or likely to go through, a roll-up:

  • Will pricing tiers, minimum seat counts, or contract terms change once integration is complete, and is that spelled out anywhere in writing?
  • Does the acquired product's support team stay in place, or does support move to a larger, less specialized queue?
  • Is the roadmap for the acquired product public, or has it gone quiet since the deal closed?

None of those questions have comfortable answers in the first year after a transaction this size. That uncertainty is exactly why domain-level visibility that does not depend on which mailbox security vendor an MSP happens to be using at the moment matters more, not less, during a consolidation wave.

The Case for Verification That Sits Outside the Stack

Bundled platforms are convenient, but convenience is not the same as assurance. Whatever email security suite an MSP settles on, whether it is Hornetsecurity's platform under new ownership, a CyberSentriq bundle, or something else entirely, the underlying domain configuration, SPF and DKIM alignment, and DMARC enforcement status still need independent, ongoing verification that does not disappear or change scope the moment a vendor gets acquired.

That is the argument for keeping a layer of domain-security scanning separate from whichever suite handles inbound filtering. ActiScan's approach was built around that separation from day one, checking client domains against DNS-level authentication standards regardless of which upstream mail security vendor is in place this quarter or next. MSPs who want to see how that fits alongside an existing email security contract can walk through the getting-started guide in under an hour, and most technicians run their first full domain audit before their coffee gets cold.

For MSPs currently reassessing their stack because a core vendor just changed hands, or because pricing questions from a newly merged provider have started showing up in renewal conversations, comparing plans on the pricing page is a reasonable next step before committing to another multi-year contract. Consolidation in the vendor market is not going to slow down, and a free account signup takes less time than reading the fine print in most acquisition press releases.

The Bottom Line

Proofpoint's $1.8 billion bet on Hornetsecurity is not really a story about one vendor buying another. It is a signal that the email security market has decided the MSP channel is worth fighting over, and that the fight will be won with platform breadth and balance sheets rather than single-product excellence. MSPs that treat this as background noise risk waking up to a very different vendor relationship than the one they signed up for, while those who build independent verification into their own operations will weather the next roll-up with far less disruption to their clients.

← Back to all posts