Decoding the world of cybersecurity

Quorum Cyber agrees deal for Ontinue

Quorum Cyber has agreed to acquire Ontinue, combining two Microsoft-focused managed-security providers with operations spanning the UK, continental Europe, and North America.

Quorum Cyber agrees deal for Ontinue
Summary
  • Quorum Cyber has signed a definitive agreement to acquire Microsoft-focused managed-security provider Ontinue.
  • Ontinue serves more than 250 enterprises, NGOs, and institutions across Europe and the US.
  • The companies will continue operating independently until customary closing conditions and required approvals are completed.

Edinburgh-headquartered Quorum Cyber has signed a definitive agreement to acquire Ontinue, bringing together two Microsoft-focused managed-security providers as automation and artificial intelligence play a larger role in security operations.

Ontinue is being sold by EQT Mid Market Europe. Financial terms have not been disclosed, and the transaction remains subject to customary closing conditions and any required approvals. The companies will continue to operate independently until completion.

Ontinue provides managed extended detection and response services across Microsoft environments and serves more than 250 enterprises, non-governmental organisations, and institutions in Europe and the US through a 24-hour operating model.

The business was developed inside Open Systems before being carved out as a standalone company in 2023. EQT says Ontinue has approximately doubled in scale under its ownership and has also made acquisitions in data science, AI, and cybersecurity services.

Quorum Cyber said the proposed combination would bring together managed detection and response, incident response, professional services, risk reduction, and AI-driven security operations. Both businesses have built substantial portions of their services around Microsoft’s security ecosystem.

The deal adds to consolidation across managed security, where providers face pressure to handle larger volumes of telemetry, identities, endpoints, and cloud activity without increasing analyst headcount at the same rate.

Automation can absorb parts of that workload through alert enrichment, investigation, correlation, and response orchestration. Providers also need sufficient scale to maintain round-the-clock operations, incident-response capability, threat intelligence, and the engineering work required to integrate constantly changing platforms.

Consolidation can simplify procurement for organisations trying to reduce the number of security suppliers they manage, but it can also deepen dependency on a smaller number of service providers.

A managed detection provider may have access to endpoint telemetry, cloud activity, identity systems, security alerts, and privileged response workflows. A change in ownership or operating model can therefore have implications for data processing, subcontractors, escalation paths, service continuity, and privileged access.

The companies’ Microsoft focus creates another dimension. Standardising security operations around one ecosystem can improve integration between identity, endpoint, cloud, and productivity tooling, but it can also concentrate architectural dependency.

That dependency increasingly sits inside third-party and operational-resilience programmes. DORA and NIS2 have placed greater emphasis on supplier oversight, incident escalation, continuity, access control, and accountability where external providers support important systems.

Ontinue also promotes an agentic security operations model in which AI systems perform parts of investigation and response while people retain oversight. If the acquisition completes, those capabilities are expected to form part of the combined company’s wider managed-security proposition.

Automation within an outsourced SOC introduces its own governance requirements. Customers need clarity over which actions can be carried out automatically, which require approval, how decisions are logged, and how responsibility is divided when a response action affects production systems.

The transaction has not yet closed, so integration remains prospective. If completed, it will give Quorum Cyber a larger presence across the UK, DACH region, North America, and the wider Microsoft security market as managed-security providers compete increasingly on scale, automation, and breadth of responsibility.

×