Owner's Guides

Security Companies for Sale: Guarding, Monitoring, Cyber

Who buys US security and cybersecurity companies now, real RMR, EBITDA and ARR multiples by segment, licensing transfer, process and tax.

Palmstone Capital Research12 min read

One roof, five different businesses.

If you're searching security companies for sale, the first thing to fix is which business you actually have. A guard agency, an alarm-monitoring book, an electronic security integrator, a cybersecurity consultancy and a cyber software company sell into different buyer pools at different multiples, and pricing them off one blended number is the single fastest way to lose credibility with a serious buyer. This page walks through who is buying each segment right now, what the numbers actually look like, how licensing and contracts transfer, and where sales go wrong. If you're specifically searching cyber security company for sale, jump to the cybersecurity sections below; the mechanics are closer to software M&A than to guarding.

The outsourced U.S. contract security market ran approximately $35.3 billion from 2024 through September 2025, including about $4.4 billion of electronic security and integration revenue, with roughly 880,000 people employed. Average guarding EBITDA margin sits at 7% to 8%, with efficient operators reaching 12% or more. Guarding and technology M&A tracked seven large transactions worth about $1.5 billion of acquired revenue in that window, plus around 40 smaller, mostly unannounced deals. Allied Universal alone completed 12 acquisitions worth roughly $830 million of combined revenue. On the cyber side, Momentum Cyber recorded 400 global transactions in 2025 worth about $96.1 billion of disclosed value, and U.S. cybersecurity startups raised $11.5 billion, the highest annual total since 2022.

01

Who Is Buying Right Now

Guarding and facilities consolidators. Allied Universal is the most acquisitive name in the market, buying 12 companies for roughly $830 million of aggregate revenue, including Pinnacle Security, CI Security Specialists and MaxSent in five deals worth about $490 million in early 2025 alone. GardaWorld bought OnSolve and Stealth Monitoring in 2024 and is expanding into U.S. remote monitoring and technology. Securitas Technology paid roughly 16x trailing EBITDA, about $3.2 billion, for Stanley Security's systems-integration business in 2022, the benchmark large-platform precedent, not a small-deal comparison. Prosegur buys guarding, monitoring and cash-services businesses at a smaller U.S. scale.

Electronic security and fire-life-safety platforms. Convergint, PE-backed, bought Fiber Solutions in 2025 and A+ Technology & Security Solutions in 2026, and fits well-managed regional integrators with service contracts and public-sector work. Everon, backed by GTCR, acquired ADT's B2B multifamily business in 2025 and values commercial recurring revenue and national-account capability. Pye-Barker Fire & Safety, Pavion (Wind Point Partners), Sciens Building Solutions (Carlyle) and Zeus Fire and Security (Access Holdings) all run active tuck-in programs in fire, alarm, inspection and security, usually pricing on a sum-of-parts basis across recurring inspection revenue and EBITDA.

Alarm-account buyers. ADT, Vector Security, Guardian Alarm and Rapid Response Monitoring, along with regional dealers, buy account books rather than the legal entity. Pricing runs almost entirely off eligible monthly RMR, not a company-level EBITDA multiple.

Cybersecurity strategics. Google Cloud paid $32 billion for Wiz in 2025 after buying Mandiant in 2022. Palo Alto Networks announced CyberArk at $25 billion in 2025. Cisco closed Splunk in 2024. CrowdStrike and Zscaler, which bought Red Canary in 2025, buy product and data adjacency, often ahead of EBITDA maturity. These are exceptional strategic prices; do not apply them to an ordinary private seller.

Cyber-focused PE. Thoma Bravo, whose portfolio includes Sophos (which completed the Secureworks acquisition in 2025), Proofpoint, SailPoint and Darktrace, looks for mature ARR and a path to cash flow. Francisco Partners, Vista Equity Partners, EQT, Clearlake and Crosspoint Capital Partners run similar plays across identity, governance and managed services. MSSP-focused consolidators, including Evergreen Services Group/Alpine Investors, Thrive/Court Square, Netrix Global/OceanSound, Blue Mantis/Abry and Integris, buy adjusted EBITDA and contracted monthly recurring revenue in managed IT and security services.

02

Valuation: The Basis Changes by Segment

Don't let anyone quote you one multiple for a mixed security business. Guarding, monitoring, integration and cyber each carry different margins, risk and valuation logic, so a buyer will re-cut your P&L by segment regardless of how you present it. A few definitions matter before any number means anything: enterprise value, or EV, is what the multiple produces before debt and cash adjustments; equity proceeds is what actually lands in your account after debt, working capital, escrow, earnout and fees; RMR is contracted recurring monthly monitoring or service revenue only, never hardware sales, installation projects or pass-through telecom charges; SDE, seller's discretionary earnings, adds back one owner's normalized pay and is most relevant under roughly $500,000 of owner earnings; ARR is monthly recurring subscription revenue times 12, adjusted for churn, not bookings or total contract value.

Small mixed security businesses. BizBuySell's closed-sale data from 2021 through 2025 shows a middle-50% range of 1.95x to 3.29x SDE, or 0.49x to 1.14x revenue. This category blends guards, cameras, alarm and monitoring, so treat it only as a small-deal sanity check, not a primary basis.

Alarm monitoring, priced on monthly RMR. 2024 averages ran approximately 36x monthly RMR (3.0x annualized) for books under $50,000 of monthly RMR, and about 46x monthly RMR (3.8x annualized) above $500,000. Roughly 2% of industry RMR changed hands in 2024. Exceptional commercial-heavy books with low attrition and clean, assignable contracts can reach 46x to 52x; weak residential books with high attrition sit at 24x to 34x. Expect a holdback of 10% to 20% of consideration for 6 to 12 months against attrition and invalid accounts.

Manned guarding. Small tuck-ins under roughly $10 million of revenue currently price at 5.0x to 7.0x adjusted EBITDA. Regional flagships between $10 million and $100 million, with a management team and a diversified book, price at 8.0x to 10.0x or higher. Historical large-company precedent runs 10x to 12x: AlliedBarton at 11.6x in 2015, U.S. Security Associates just over 10x in 2018, G4S around 11x in 2021. None of those apply directly to a small operator.

Electronic security integrators. Below $500,000 of EBITDA, 3.0x to 5.0x; $500,000 to $2 million, 5.0x to 7.0x; $2 million to $10 million, 7.0x to 10.0x; above $10 million with scaled management and a strong service mix, 9.0x to 13.0x. The Stanley Security precedent at roughly 16x is an exceptional large-platform outcome, not a benchmark for a private seller.

Cybersecurity services, MSSP and MDR. Sub-$1 million owner-operated consultancies run 3.0x to 5.0x SDE. From $500,000 to $2 million of adjusted EBITDA, 5.0x to 8.0x; $2 million to $5 million with material contracted MRR, 7.0x to 10.0x; above $5 million with a management team and high recurring mix, 9.0x to 13.0x. Capstone Partners put the broad disclosed 2025 average for mixed cyber M&A at 10.9x EBITDA and 2.3x revenue, with service businesses drawing lower revenue multiples than software.

Cybersecurity software and SaaS. Under $5 million ARR with weak growth or retention, 2.0x to 4.0x revenue; $5 million to $20 million ARR with 20% to 40% growth, 4.0x to 8.0x; above $20 million ARR with 30%-plus growth and strong net retention, 6.0x to 12.0x; a scarce category leader with AI, cloud or identity adjacency, 12.0x to 20.0x or more as an exceptional strategic outcome. Capstone's disclosed 2025 software-only average was 6.3x revenue. Momentum Cyber found that 47% of disclosed cybersecurity revenue multiples from 2020 through 2025 came in at 5.0x or below, and only 16% reached 15x or higher, so the headline strategic deals you read about are not the norm.

Segment Basis Typical current range Status
Small mixed security business SDE 1.95x-3.29x Established, 2021-2025 closed sales
Alarm monitoring book Monthly RMR 36x-46x Established 2024 average
Guarding tuck-in Adjusted EBITDA 5.0x-7.0x Established current quote
Guarding regional flagship Adjusted EBITDA 8.0x-10.0x+ Established current quote
Electronic security integrator Adjusted EBITDA 3.0x-13.0x by size Estimate, size-tiered
Cyber services/MSSP Adjusted EBITDA 3.0x-13.0x by size Estimate, size-tiered
Cyber software/SaaS EV/ARR or revenue 2.0x-20.0x by growth Estimate, growth-tiered

Worked example. A regional alarm and integration business carries $600,000 of monthly commercial RMR above the $500,000 tier, priced at 44x monthly RMR, giving roughly $26.4 million of RMR-based value. Its separate installation and service arm runs $1.8 million of adjusted EBITDA, priced at 8x as a mid-tier integrator, adding $14.4 million. Combined indicative enterprise value is about $40.8 million before debt, a working-capital peg, a 15% attrition holdback on the RMR piece, and transaction costs. That sum-of-parts approach, not one blended multiple, is how a real bidder will build the number.

03

Deal Structure and What Actually Reaches You

Small strategic deals can be mostly cash at close. PE and platform deals typically layer in rollover equity, often 10% to 30% of proceeds, which is illiquid and exposed to future leverage. Earnouts or retention holdbacks, often 10% to 25% of headline value, are common wherever customer retention, ARR growth or founder sales continuity is uncertain. Guarding and project businesses usually carry a working-capital peg, and a shortfall reduces equity proceeds dollar for dollar. Unpaid payroll taxes, accrued bonuses, deferred revenue and pending litigation get treated as debt-like items and come straight off the top. Headline enterprise value and the check you actually receive are two different numbers, and the gap is often the difference between a good outcome and a disappointing one.

04

Licensing and Contract Transfer

No single U.S. security license exists. Guard agencies, alarm operators, low-voltage and fire-alarm contractors, central stations and individual guards are all regulated at the state and sometimes local level, and the license usually belongs to the entity or a qualifying individual, not to the business as a saleable asset. California's Bureau of Security and Investigative Services licenses Alarm Company Operators and Private Patrol Operators, requires a Qualified Manager and DOJ/FBI background checks on principals, and currently targets 125 days to process a new Alarm Company Operator application. Florida requires each alarm business to be qualified by a properly licensed individual, and transferring to a new entity ends the old entity's qualification. New York requires a corporate qualifier who actually directs day-to-day operations, not a name on paper. An asset sale often forces a new entity license and local permits; a stock sale can preserve the entity license but still triggers principal, officer and change-of-control filings.

On the cyber side there's no generic federal license, but obligations follow the data and the customer. CFIUS can review foreign control of a U.S. cyber business touching critical technology, critical infrastructure or sensitive personal data, and a voluntary filing can provide safe harbor. HSR antitrust filing applies above a $133.9 million size-of-transaction threshold for deals closing on or after February 17, 2026. Federal contracts generally require novation under FAR 42.1204 when the performing assets move to a new entity; a stock sale with no change in the contracting entity usually avoids that. Cleared businesses face DCSA facility-clearance review on ownership and foreign ownership, control or influence (FOCI) changes. Public-company customers must disclose material cyber incidents to the SEC within four business days of a materiality determination, and expect your own customer contracts to demand faster notice than any statute requires.

Contract transfer follows the structure. Asset sales usually need written assignment consent; change-of-control clauses in a stock sale can still trigger consent or termination even though the legal entity hasn't changed. Alarm customer contracts need validating for term, renewal, assignment rights and any dealer lien before you count that RMR as eligible. Cyber customer contracts carry security addenda, BAAs, data-processing agreements and change-of-control consent language that need mapping before disclosure, not after.

05

Tax Treatment

A stock sale generally produces capital-gain treatment for shareholders, with no basis step-up for the buyer absent a special election. An asset sale allocates price under IRC Section 1060, filed on Form 8594, with different tax character across inventory, equipment, covenants and goodwill; Section 197 goodwill is amortized over 15 years by the buyer. C corporations often push toward a stock sale to avoid the double tax an asset sale can trigger at the corporate level and again on distribution. S corporation and subsidiary sellers can use a Section 338(h)(10) or Section 336(e) election to get the buyer's asset tax treatment inside a legal stock sale. Cyber founders with eligible original-issue C corporation stock may use IRC Section 1202 QSBS: for stock acquired after July 4, 2025, the exclusion phases to 50% at three years, 75% at four, 100% at five, with a per-issuer cap of the greater of $15 million or 10x basis and a $75 million issuer gross-asset ceiling at issuance; older stock generally follows the prior $10 million/$50 million rules and five-year hold. California does not conform to the federal Section 1202 exclusion, so state tax can erase part of the benefit regardless of the federal position.

06

Process and Timeline

Stage Typical duration Security-specific work
Exit readiness and valuation 3-6 weeks Segment revenue into guarding, projects, RMR, cyber MRR, ARR; normalize EBITDA; reconcile licenses and claims
Buyer list, teaser, data room 2-4 weeks, overlapping Separate strategic, PE, account-book and software buyer tracks; redact vulnerability-sensitive detail
Outreach and initial bids 4-6 weeks Staged NDA disclosure, IOIs with cash/rollover/earnout breakdown
Management meetings and final bids 2-4 weeks Branch visits or SOC review, RMR and ARR cohort deep dives
LOI negotiation 1-2 weeks EV basis, working-capital peg, eligible RMR/ARR, escrow, licensing conditions
Confirmatory diligence and QoE 6-10 weeks Financial QoE, contract sampling, payroll and claims, license schedule, code and incident review
Purchase agreement 4-8 weeks, concurrent Reps and indemnities, employment terms, transition services
Regulatory and consents 2-16+ weeks, concurrent State license changes, HSR if applicable, CFIUS, FAR novation, customer consents
Closing and transition 1-2 weeks after conditions Funds flow, lien releases, credential transfer, working-capital true-up

A clean private company with no unusual approval typically closes in 4 to 7 months from preparation start. A multi-state physical operator, a federal contractor or a regulated-data cyber provider often runs 6 to 12 months. An account-book-only alarm sale can close in 6 to 12 weeks if the contract files are clean. A competitive cyber-software process with full technical diligence typically runs 5 to 8 months.

07

Common Mistakes

One multiple for the whole business. Monitoring RMR, installation projects, guarding, cyber consulting and software all carry different economics. A buyer re-cuts the P&L by segment regardless of how the seller presents it.

Counting ineligible RMR or ARR. Hardware leases, reimbursables, expiring contracts and delinquent accounts inflate the number and cost credibility the moment a buyer tests it.

Missing contract consent and renewal defects. Nonassignable agreements, unclear change-of-control language and defective auto-renewals can remove revenue from the valuation base entirely.

Owner or single-qualifier dependence. Founder-held customer relationships or a sole state license qualifier can force an earnout, an employment term or a delayed closing.

Guard-labor and claims exposure. Wage-and-hour claims, 1099 misclassification, union obligations and workers' compensation reserves are direct deal killers when they surface late.

Undisclosed cyber weaknesses. A missed breach, poor logging, unresolved critical vulnerabilities or lapsed cyber insurance undermines a technical seller's product story and expands indemnity demands.

08

FAQ

It depends on segment first. Small mixed security businesses sold at roughly 1.95x to 3.29x SDE in recent closed sales; guarding tuck-ins currently quote around 5x to 7x EBITDA; quality alarm books trade around 36x to 46x monthly RMR; cyber software typically prices on ARR or revenue. One blended number across all of that misrepresents the business.

Monitoring and contracted service accounts are commonly valued on monthly RMR. Installation, hardware and project revenue should be valued separately on adjusted EBITDA. A sum-of-parts calculation is more accurate for a mixed business.

Often not in an asset sale. Requirements vary by state and license type. A stock sale can preserve the entity license but can still require principal, officer, qualified-manager or change-of-control filings.

Asset sales usually require assignment consent. Stock sales can still trigger change-of-control clauses. Federal government contracts can require novation. The answer comes from a contract-by-contract review, not a general assumption.

No. Consulting and labor-heavy services are usually valued on SDE or EBITDA, with a premium for contracted MSSP or MDR revenue. Proprietary subscription software with strong growth and retention is valued on ARR or revenue instead.