Splunk Acquires Automated Threat Analysis Startup TwinWave Security and Names New Security Leader

The job of an enterprise security professional has never been easy but it has only gotten harder in recent years thanks to an ever-expanding attack surface and shocks to the macro environment. In fact, 65% of organizations saw an increase in attempted cyberattacks, while 54% reported that their business-critical applications suffered unplanned downtime due to a cybersecurity incident, according to global research conducted by Splunk and the Enterprise Strategy Group.

The pandemic and other major disruptions — from political turmoil to supply chain issues — have changed how organizations have to operate today. The changing threat landscape and proliferation of tools is increasing the volume of security breaches and outages — and making the lives of security operation center (SOC) analysts more difficult than ever before.

Our customers continue to demand secure, seamless, always-on experiences from organizations despite what security analysts have to do to make that happen.

This is why cyber resilience — the ability to prevent, respond and quickly recover from events that have the potential to disrupt key business processes, service delivery and access to technology — has become a top business priority to help mitigate cyber risk. At Splunk, we are helping organizations achieve cyber resilience by deploying a data-centric approach to security, delivering faster and better threat detection, investigation, and response.

It’s in the spirit of this mission that today I’m proud to announce that Splunk has acquired TwinWave Security, a cyber security start-up with unique technology that automatically follows and analyzes complex attack chains that would otherwise require cumbersome manual workflows for security analysts.

This acquisition extends our security leadership and as part of this acquisition, we’re also announcing that TwinWave’s CEO and co-founder, Mike Horn, will become our Senior Vice President and General Manager of Security. TwinWave’s three founders are experienced senior technology and product leaders, and will play key roles in our security product, and engineering teams. They bring 60 years of combined security experience and complementary, differentiating product capabilities to help shape the future of Splunk’s security business.

For our customers, TwinWave’s products and services expand Splunk’s mission-critical security analytics and automation capabilities to strengthen Splunk's leadership in helping customers quickly and accurately detect, analyze and respond to an ever-changing landscape of security threats. TwinWave’s solutions will help our customers save time, improve detections and analyze more threats with flexible integrations, and deep automated analysis.

TwinWave adds critical capabilities to empower the security analyst with cloud-native automated threat analysis with verdicts that can activate remediation playbooks within security, orchestration, automation and response (SOAR) for end-to-end automation.

Acquiring TwinWave gives us the ability to bring in highly specialized industry leaders outside of Splunk’s existing capabilities. They have the ability to hit the ground running with existing products, relationships and deep domain expertise. Mike and the team share our passion about customers and helping them be more resilient. Welcome, Mike and team!

Safe Harbor Statement

This blog contains forward-looking statements about the expectations, beliefs, intentions and strategies relating to Splunk’s acquisition of TwinWave Security. Such forward-looking statements include statements regarding the expected benefits of the acquisition of TwinWave, the impact of the acquisition on Splunk’s existing and future products and services, and the capabilities of TwinWave’s products and services, including when added to Splunk’s. There are a significant number of factors that could cause actual results to differ materially from statements made in this blog post, including: difficulties encountered in integrating the business, technologies, personnel and operations; costs related to the acquisition; market acceptance of the acquisition and resulting products and services; Splunk’s inability to realize value from its significant investments in its business, including product and service innovations; and general market, political, economic and business conditions. Additional information on potential factors that could affect Splunk’s financial results is included in the company’s Quarterly Report on Form 10-Q for the fiscal year ended July 31, 2022, which is on file with the U.S. Securities and Exchange Commission (“SEC”) and Splunk’s other filings with the SEC. Splunk does not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

----------------------------------------------------
Thanks!
Garth Fort

Related Articles

Security Predictions 2026: What Agentic AI Means for the People Running the SOC
Leadership
10 Minute Read

Security Predictions 2026: What Agentic AI Means for the People Running the SOC

Splunk's Hao Yang shares our security predictions for 2026 and how agentic AI is reshaping how we see the SOC.
The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility
Leadership
4 Minute Read

The Performance Playbook: Why Business Context Is the Key to Customer-Centric Visibility

Systems show symptoms. Business context shows impact. Discover why the future of observability is understanding what matters most to your customers.
MachineGPT, Agentic AI, and the New Foundation for Digital Resilience
Leadership
4 Minute Read

MachineGPT, Agentic AI, and the New Foundation for Digital Resilience

MachineGPT is foundational to the rise of Agentic AI in the enterprise, which is poised to fundamentally reshape digital operations – and it's advancing faster than we expected.
MachineGPT: Speaking the Language of Machines to Shape the Future of AI
Leadership
4 Minute Read

MachineGPT: Speaking the Language of Machines to Shape the Future of AI

MachineGPT brings the power of generative AI to one of the most overlooked resources: machine data. Splunk SVP & GM Kamal Hathi explains why mastering data as the heartbeat of the digital world is a game changer.
Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25
Leadership
3 Minute Read

Powering and Protecting the AI Revolution: A New Era for Splunk and Cisco at .conf25

Splunk's Kamal Hathi recaps our innovation highlights from .conf25, marking a pivotal moment for Splunk and Cisco as we deliver significant new value to our customers that make the use of AI a practical reality in their organizations.
Machine Data: Fighting Fire With Fire for Digital Resilience
Leadership
2 Minute Read

Machine Data: Fighting Fire With Fire for Digital Resilience

Kamal Hathi shares how Cisco and Splunk are helping organizations manage the explosion of machine data and AI-driven complexity, delivering real-time digital resilience to counter threats at machine speed and scale.
.conf25: Reinventing Digital Resilience for the Agentic Era
Leadership
3 Minute Read

.conf25: Reinventing Digital Resilience for the Agentic Era

Kamal Hathi shares how Cisco and Splunk deliver the data foundation, agentic intelligence, and cross-domain insights needed to build a more secure, resilient, and always-on digital enterprise.
UK Needn’t Fear The Data Deluge
Leadership
4 Minute Read

UK Needn’t Fear The Data Deluge

UK businesses face a data explosion—fueling growth but also raising risks in security, compliance, and operations. With smart data management strategies, organisations can regain control, boost resilience, and turn data into a true competitive edge.
Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco
Leadership
7 Minute Read

Digital Resilience By Design: Seamless Troubleshooting Across Splunk & Cisco

Cisco and Splunk deliver Digital Resilience by Design with seamless troubleshooting across security, observability, and networking domains, powered by AI innovations to manage complexity and stay ahead of risk.