Cognyte Software

Israeli-headquartered cyber-intelligence and investigative-analytics company listed on Nasdaq as CGNT, spun off from Verint Systems in February 2021.
Cognyte Software is an Israeli-headquartered cyber-intelligence and investigative-analytics company listed on the Nasdaq under the ticker CGNT. The company develops software platforms for security and intelligence agencies, law-enforcement organizations, and corporate-security functions — communications analytics, open-source intelligence, network investigation, lawful intercept, and case management for national-security workflows. Cognyte was spun off from Verint Systems in February 2021, when Verint separated its cyber-intelligence operations from its customer-engagement business and listed the new entity as an independent publicly traded company. Cognyte is headquartered in Herzliya, Israel.
Cognyte is one of the few Israeli-rooted, US-listed, pure-play cyber-intelligence software companies. It sits inside the small cohort of publicly traded lawful-access and investigative-analytics vendors — a category historically defined by Verint, Cellebrite, and Cognyte itself — and stands apart from the offensive-cyber cluster (NSO Group, Candiru, Paragon) that has attracted the bulk of the international press attention on Israeli surveillance software.
Corporate history
Origins inside Verint
Cognyte's operational lineage predates the 2021 spin-off by more than two decades. The business began as the cyber-intelligence division of Verint Systems, itself carved out of Comverse Technology in the late 1990s and early 2000s. Comverse — a Nasdaq-listed Israeli-founded telecom software vendor — built its early franchise around voicemail and call-management systems for carriers, and its intercept-adjacent products became one of the seeds of what is now Cognyte's platform business.
Verint operated two distinct businesses under one roof for years: customer-engagement software sold to enterprises, and cyber-intelligence software sold to governments. The two shared a corporate parent but almost nothing else — different buyers, different sales cycles, different regulatory exposure, different capital-markets narratives. By the late 2010s, the internal case for separation was straightforward. Enterprise SaaS investors did not want government-customer risk in the multiple. Government customers did not want their vendor distracted by contact-center product roadmaps.
The February 2021 spin-off
Verint completed the separation on February 1, 2021, distributing Cognyte shares to Verint shareholders and listing Cognyte on the Nasdaq under CGNT. The transaction was a tax-free spin-off structured to give each business its own board, its own capital structure, and its own equity currency. Verint retained the customer-engagement software business (Nasdaq: VRNT). Cognyte took the cyber-intelligence software business.
The spin-off is the single most important structural event in Cognyte's history. It converted a segment inside a diversified software company into a standalone public-markets vehicle for Israeli cyber-intelligence — the first, and still the clearest, pure-play listing in the category.
Product portfolio
What Cognyte's software actually does
Cognyte's platforms address the analytic-investigation side of the cyber-intelligence stack. The core workflows are recognizable to any national-security analyst: collect from many sources; normalize; fuse; investigate; produce a case file that will hold up. The product portfolio maps onto that workflow.
- Communications analytics — processing of intercepted and lawfully obtained communications data at national scale. Voice, messaging, metadata. Speaker identification. Language and topic extraction. Link analysis across the graph of who is talking to whom.
- Open-source intelligence (OSINT) — collection and analysis of publicly available data across web, social, forums, marketplaces, dark-web sources. Entity resolution, sentiment, and pattern extraction on top of that firehose.
- Network and device investigation — analysis of telecom and IP network data to reconstruct activity, movements, and relationships associated with an investigative target.
- Lawful intercept — the standards-bound category of communications interception conducted by carriers on the order of a competent authority. Cognyte builds mediation and analytic layers on top of the intercept feed.
- Case management and fusion — the connective tissue. A single investigative environment that pulls the outputs of every collection stream into one case file, one entity graph, one exportable evidentiary record.
What Cognyte does not do
This is the point most public commentary gets wrong, so it is worth stating flatly. Cognyte does not build remote-implant spyware. It does not sell zero-click exploits. It does not operate in the same commercial category as NSO Group's Pegasus, Candiru's DevilsTongue, or Paragon's Graphite. Those products are offensive-cyber tools that compromise a target's device to extract data. Cognyte's products sit downstream of collection performed by the customer under the customer's own legal authority — carrier-mediated lawful intercept, open-source ingestion, network telemetry — and turn that collected data into investigative output.
The distinction matters commercially. Offensive-cyber vendors live and die by export-license controversies, individual targeting scandals, and platform-vendor lawsuits — the WhatsApp v. NSO litigation being the defining case. Analytic-investigation vendors like Cognyte face a different risk profile: long government procurement cycles, jurisdictional export controls on dual-use software, and the reputational overhang of operating in the same broad ecosystem as the offensive firms.
Financial profile
Fiscal 2026 results
Cognyte's fiscal year ends January 31. Fiscal 2026, reported in March 2026, was the strongest year in the company's post-spin history. Full-year revenue reached the guidance range around $400 million after a Q4 that came in at $106.2 million, up 12.4% year over year. Software revenue in the fourth quarter grew 22.6% to $45.9 million on stronger perpetual-license and term-subscription bookings. Non-GAAP gross margin hit 74.7% for the quarter — a company record — and non-GAAP operating income roughly doubled year over year to $12.1 million.
The board expanded the share-repurchase program by $20 million in March 2026, taking the authorized total to $60 million. Management affirmed a fiscal 2028 revenue target of approximately $500 million and an adjusted EBITDA margin above 20%.
Fiscal 2027 guidance and Q1
For fiscal 2027, management guided to approximately $448 million in revenue at the midpoint — roughly 12% growth — with the growth split modeled as 50% from installed-base expansion, 25% from new international customers, and 25% from US growth initiatives. The mix reflects Cognyte's real center of gravity: a large, sticky base of national-security customers where each renewal cycle is an expansion opportunity, plus a US federal push where the company has historically been under-indexed relative to its international footprint.
Q1 fiscal 2027, reported in June 2026, showed the US federal exposure working against the model in the short term. A US government shutdown period disrupted federal engagements, weighing on quarterly EPS. Management characterized the impact as timing rather than demand — federal discussions resumed post-shutdown — and pointed to a LexisNexis channel partnership as one of the levers on the US side of the plan.
Model characteristics
Cognyte runs a hybrid revenue model. Perpetual licenses remain part of the mix because government customers often prefer them for procurement, budgeting, and security reasons. Term-based subscriptions and SaaS are the growth vector. Recurring revenue reached roughly 47% of total revenue in Q4 fiscal 2026 and continues to build. Gross margin north of 70% is the structural feature that makes the model work — it is what allows a business of this scale, in this vertical, to generate cash while investing in R&D and international sales coverage.
Leadership
Elad Sharon is CEO. Sharon ran the cyber-intelligence business inside Verint before the spin-off and carried the mandate across the transaction. David Abadi is CFO. Dean Ridlon leads investor relations. The management team is substantially the same team that operated the business as a Verint segment, which is unusual for a spin-off and speaks to the operational continuity of the franchise — the corporate wrapper changed in 2021, the product, customers, and go-to-market did not.
Position in the Israeli cyber-intelligence cohort
The Israeli lawful-access ecosystem
Cognyte sits inside the Israeli-rooted lawful-access ecosystem alongside Cellebrite — the Nasdaq-listed digital-forensics leader — and, historically, the parts of the ecosystem traced back to Unit 8200 and adjacent IDF signals-intelligence formations. The Unit 8200 lineage is the durable talent story of Israeli cyber-intelligence: the training pipeline that seeded Check Point, CyberArk, NSO, Cognyte, Cellebrite, Wiz, and dozens of privately held firms in the same broad category.
Where Cognyte sits versus offensive-cyber vendors
Israeli cyber-intelligence, in international press coverage, is often collapsed into a single category dominated by NSO. That is a category error. NSO, Candiru, and Paragon are offensive-cyber vendors selling remote-implant capabilities against mobile devices. Cognyte is an analytic-investigation vendor selling case-management and fusion software that sits on top of data the customer collects under its own legal authority. The buyers overlap — national-security agencies, intelligence services, national police forces — but the product, the risk profile, and the regulatory exposure are different categories of business.
The WhatsApp v. NSO litigation, which produced a $167 million punitive damages verdict against NSO in 2025 (later reduced to $4 million by Judge Phyllis Hamilton in October 2025, with a permanent injunction), is the defining legal case for the offensive-cyber category. Cognyte was not a party to that case. It has not been the subject of an equivalent platform-vendor lawsuit. That is not an accident — it is a function of the category the company operates in.
Publicly listed pure-play status
Cognyte is one of the very small number of publicly listed pure-play cyber-intelligence software companies globally. Verint, its former parent, no longer counts — Verint post-spin is a customer-engagement software business. Cellebrite is the closest Israeli comparable, and it operates in the adjacent digital-forensics vertical rather than in the communications-analytics and OSINT-fusion vertical Cognyte anchors. The rest of the category is privately held, government-adjacent, or embedded inside larger defense-electronics groups.
Why Cognyte matters to the Israeli tech story
Cognyte is the cleanest public-markets read on the Israeli cyber-intelligence software category. Verint's spin-off separated the signal from the noise: investors who want exposure to Israeli-built investigative-analytics software have a listed, audited, quarterly-reporting instrument to buy. That is rare in this vertical globally and it is the reason Cognyte shows up in almost every serious analysis of the Israeli cyber-intelligence public-markets footprint.
It is also the counter-example to the common press narrative that Israeli cyber-intelligence is synonymous with offensive spyware. Cognyte is Israeli, listed, growing double-digit, expanding gross margin, buying back stock, and operating on the analytic side of the stack. It is the version of the Israeli cyber-intelligence story that keeps working through the news cycles that damage the offensive-cyber vendors.
Key facts
- Ticker: CGNT (Nasdaq)
- Headquarters: Herzliya, Israel
- CEO: Elad Sharon
- CFO: David Abadi
- Spin-off date: February 1, 2021, from Verint Systems
- Fiscal year end: January 31
- FY2026 revenue: approximately $400 million
- FY2027 guidance (midpoint): approximately $448 million
- FY2028 target: approximately $500 million; adjusted EBITDA margin above 20%
- Share repurchase authorization: $60 million (expanded March 2026)
- Primary customers: national-security agencies, intelligence services, military intelligence units, national police forces, corporate security functions
- Category: analytic-investigation software — not offensive-cyber / remote implants

