Cribl acquires Radiant Security AI SOC assets in second 2026 deal

Cribl has acquired AI triage and investigation technology from Radiant Security, its second security acquisition this year after CardinalOps in July.

Two grey rectangular devices, each with a glowing green circular light, stand on a reflective white surface against a bright white background.

Cribl has acquired technology assets from Radiant Security's AI-native security operations centre product, adding autonomous triage, investigation and alert-resolution capabilities to its telemetry data platform. The deal is the San Francisco-based company's second security acquisition of 2026, following its purchase of CardinalOps in July, and signals a deliberate push to position Cribl's open telemetry platform as the operational layer beneath AI-driven security tooling.

The acquired intellectual property will be adapted to run as an application on Cribl's platform, enabling security teams to execute AI-driven investigations directly against telemetry data in place, rather than routing it through a separate tool that creates yet another data silo. The company says the approach allows triage logic to be generated on the fly for each individual alert, rather than depending on static, pre-built playbooks. No financial terms for either this acquisition or the CardinalOps deal have been disclosed.

The deal

Clint Sharp, co-founder and chief executive of Cribl, framed the acquisition in terms of market fragmentation. "Too much of the $121 billion security market is trapped in data silos, giving security teams incomplete information," he said. "By pairing AI SOC technology with Cribl's open telemetry platform, we're ending the era of siloed solutions and giving security teams the intelligence they need."

Andrew Braunberg, principal analyst at Omdia, said Cribl's strategy centres on converting raw telemetry into a unified foundation for AI-driven applications. "By layering AI SOC, threat detection, and observability on top of its open data platform, Cribl is enabling organisations to customise their security stacks and finally unlock the true value of their data," he said.

Cribl said the platform is trusted by roughly half of the Fortune 100, though it did not name a specific customer that will immediately deploy the new AI SOC capability.

Market context

The security operations centre market is undergoing a consolidation of tooling around shared data platforms, driven partly by the high cost of maintaining multiple point solutions with overlapping telemetry ingestion pipelines. Established SIEM vendors such as Splunk (now part of Cisco), Microsoft Sentinel, and Exabeam have each added AI-driven triage layers in the past two years, while a number of well-funded startups are building AI-native SOC automation as a standalone category.

Cribl's counter-position is that AI efficacy in security depends less on the sophistication of the model than on the quality and completeness of the underlying telemetry. Acquiring SOC automation capability rather than building it internally suggests the company prioritised speed to market over organic development, a pattern consistent with how cloud-era data platforms tend to expand into adjacent security workflows.

The broader regulatory context also adds urgency. Under the EU's NIS2 Directive, which came into force across member states in late 2024, organisations operating critical infrastructure face tighter incident-detection and reporting obligations. Platforms that can demonstrably reduce alert triage time and false-positive rates carry a compliance argument alongside the operational one.

What comes next

Cribl said further platform additions will be announced at CriblCon on 28 September 2026, making that event a key date for partners and enterprise buyers assessing whether the integrated AI SOC capability is production-ready. Observers will be watching for concrete performance benchmarks, named customer deployments, and clarity on how the acquired Radiant Security IP will be licensed relative to Cribl's existing subscription tiers.