Article
Article

The AI Cybersecurity Arms Race: Where the Money Is Actually Flowing

AI is creating one of the biggest technology buildouts of our generation.

Published Sep 12, 2026Updated Sep 12, 202619 min read

AI is creating one of the biggest technology buildouts of our generation.

But every new AI model, agent, data center, cloud workload and autonomous workflow creates another problem:

How do you secure it?

That question is creating a second-order investment opportunity underneath the AI infrastructure boom.

The AI trade isn’t only about GPUs, networking, data centers and power.

It is also about protecting everything being built on top of them.

And the cybersecurity industry is beginning to change accordingly.

The important question for investors isn’t simply:

“Will cybersecurity grow?”

It almost certainly will.

The better question is:

Which layers of cybersecurity capture the largest share of the AI-driven spending cycle?


AI Is Creating a New Cybersecurity Spending Cycle

The numbers are striking.

Gartner’s January 2026 forecast estimates worldwide spending specifically categorized as AI cybersecurity will rise from approximately $25.9 billion in 2025 to $51.3 billion in 2026 and $86.0 billion in 2027. That’s more than a tripling in two years.

But there is another, more specific market emerging inside that broader number.

Gartner estimates spending on securing AI itself will reach approximately $4.8 billion in 2027, up 68.7% from 2026, with spending approaching $7.7 billion in 2028.

That distinction matters.

There are really two overlapping opportunities:

1. AI used to improve cybersecurity

and

2. Cybersecurity designed specifically to protect AI

The second category is still relatively young.

And that’s where the next wave could develop.


The Attack Surface Is Expanding

Traditional enterprise security was designed around relatively predictable environments:

Employees.

Endpoints.

Servers.

Corporate networks.

Applications.

Now add:

AI models
AI agents
Cloud workloads
APIs
Vector databases
Machine identities
Autonomous workflows
Third-party models
Open-source AI components
Data pipelines

The attack surface becomes dramatically larger.

And AI agents introduce something particularly important:

They can act.

A compromised employee account is dangerous.

A compromised autonomous agent with access to corporate systems can potentially be much more dangerous because the machine can execute actions at speed and scale.

Gartner expects more than half of successful attacks against AI agents by 2029 to exploit weaknesses such as access controls and prompt injection.

That creates demand for security products that didn’t exist at meaningful scale a few years ago.


The Eight-Layer AI Cybersecurity Map

I would break the opportunity into eight major layers.

1. Threat Detection & Response

$CRWD | $PANW | $S | $AKAM

This is arguably the most important battleground.

The basic problem:

Can security software identify an attack faster than the attacker can execute it?

AI changes that equation.

Instead of relying primarily on known signatures, modern platforms increasingly analyze behavior, anomalies, identities, endpoints, cloud activity and network telemetry.

CrowdStrike

CrowdStrike is one of the clearest examples of the platformization of cybersecurity.

Its Falcon platform now spans endpoint security, cloud security, identity, data protection, observability, threat intelligence and AI-related security capabilities.

And the financial performance shows that the platform strategy is gaining traction.

In Q2 FY2027:

  • Revenue reached $1.47 billion, up 26% YoY
  • ARR reached $5.84 billion, up 25%
  • Net new ARR reached a record $333 million
  • Free cash flow reached $377 million
  • Falcon Flex ARR surpassed $2.29 billion, up 101% YoY

That’s important because the cybersecurity battle is increasingly shifting from:

“Which point product is best?”

to:

“Which platform can become the security operating layer?”

CrowdStrike clearly wants to be one of those platforms.


Palo Alto Networks: The Consolidation Machine

$PANW

Palo Alto is approaching the same opportunity from a different starting point.

It began as a network-security powerhouse and has expanded aggressively into cloud security, security operations, AI security and identity.

Its latest results reinforce the platform thesis.

Palo Alto said it added nearly $1 billion of net new NGS ARR in a single quarter in FY2026 and is targeting $20 billion of NGS ARR by FY2030.

That is a massive ambition.

The investment thesis isn’t simply that cybersecurity spending grows.

It is that enterprises increasingly want to consolidate vendors.

Instead of buying ten separate security products, CIOs and CISOs increasingly have an incentive to buy a platform that covers multiple layers.

That creates a potentially powerful flywheel:

More modules → larger contracts → more data → better detection → higher switching costs → greater platform consolidation.


2. Cloud Security

$NET | $ZS | $OKTA | $RBRK | $DDOG

If AI is the engine of the next technology cycle, the cloud is where much of that engine operates.

And cloud security may be one of the fastest-growing layers.

The reason is straightforward:

The corporate perimeter is disappearing.

Employees work remotely.

Applications live in the cloud.

AI agents access applications.

APIs connect everything.

Data moves across multiple environments.

Traditional “inside vs. outside” security becomes less useful.


Zscaler: Security Without the Traditional Network

$ZS

Zscaler is one of the clearest plays on this transition.

Its Zero Trust architecture is designed around connecting users, workloads and applications without relying on the traditional corporate network perimeter.

And AI is increasingly becoming part of the company’s growth thesis.

In Q4 FY2026, Zscaler reported:

  • Revenue growth of 25% YoY
  • ARR growth of 25% YoY
  • Continued platform expansion across Zero Trust, data security, SecOps and security for AI

The important point isn’t simply the growth rate.

It’s the direction.

Zscaler increasingly wants to secure not just people, but also:

workloads + applications + data + AI agents.

That’s a much larger addressable market.


Cloudflare: The Edge Security Angle

$NET

Cloudflare is a slightly different animal.

It sits at the edge of the internet and combines networking, performance, application security and increasingly sophisticated security services.

The attraction is that AI workloads create more traffic, more applications, more APIs and more potential attack surfaces.

Cloudflare therefore represents a broader internet infrastructure + security thesis rather than a pure cybersecurity bet.

That distinction matters when comparing valuations.

You’re not buying the same business as CrowdStrike or Zscaler.

You’re buying a platform positioned at the intersection of:

networking + security + edge computing + developer infrastructure + AI.


3. Identity: The Security Layer Attackers Actually Want

$OKTA | $CYBR

If cybersecurity has one layer that investors shouldn’t underestimate, it is identity.

Why?

Because attackers don’t always need to break through a firewall.

Sometimes they simply need to become you.

As enterprises deploy more AI agents, machine identities become increasingly important.

Employees have identities.

Applications have identities.

Cloud workloads have identities.

AI agents will have identities.

And those identities need permissions.

That makes identity security one of the most strategically important pieces of the AI-security puzzle.


CyberArk: Privileged Identity Is Becoming Machine Identity

$CYBR

CyberArk has historically focused heavily on privileged access management.

That positioning becomes particularly interesting in an AI-agent world.

Why?

Because the fundamental question becomes:

What is this agent allowed to do?

And perhaps even more importantly:

How do you prevent an AI agent from doing something it was never supposed to do?

Gartner’s forecast that access-control weaknesses could account for more than half of successful attacks against AI agents by 2029 reinforces why identity and privilege controls are becoming central to AI security.

This could make identity one of the most structurally durable cybersecurity categories.


4. Data Security & Cyber Resilience

$RBRK | $VRNS

AI is ultimately a data business.

And that creates another enormous security requirement:

Protect the data.

Data has become the fuel for AI.

If attackers can steal, corrupt, encrypt or manipulate that data, they can potentially damage the entire AI workflow.


Rubrik: The Recovery Side of the Equation

$RBRK

Rubrik is particularly interesting because it approaches the problem from data security and recovery.

Its latest numbers show the demand isn’t theoretical.

In Q2 FY2027:

  • Subscription ARR grew 33% YoY to $1.66 billion
  • Revenue grew 38% YoY to $427.3 million
  • The company raised FY2027 guidance

Rubrik increasingly describes its opportunity around agentic cyber resilience.

That is an important evolution.

Traditional backup asks:

“Can we restore the data?”

Cyber resilience asks:

“Can the organization continue operating and recover rapidly after an attack?”

In an AI-driven enterprise, that distinction becomes even more important.


5. Network Security

$CSCO | $FTNT | $CHKP | $GEN | $FFIV | $ATEN

This is the old guard.

And “old” doesn’t mean irrelevant.

Cisco, Fortinet and Check Point have enormous installed bases, customer relationships and cash flows.

The question is whether they can successfully migrate those advantages into an AI-driven security architecture.

This creates an interesting investment debate.

The cloud-native companies have faster growth.

The legacy companies have:

customers + infrastructure + cash flow + distribution.

The winner may not necessarily be the company with the newest AI model.

It may be the company that can add AI capabilities to the largest existing security footprint.


6. Vulnerability & Exposure Management

$TENB | $RPD

Before you can defend an organization, you need to understand:

Where are we vulnerable?

That is the core idea behind exposure and vulnerability management.

AI can make this process more useful by helping prioritize vulnerabilities based on:

  • likelihood of exploitation
  • business importance
  • attacker behavior
  • asset exposure
  • identity relationships
  • potential impact

The opportunity is moving from:

“Here are 50,000 vulnerabilities.”

to:

“These 17 are the ones you should fix first.”

That is a much more valuable product.


7. IT Services & Government Cybersecurity

$BAH | $LDOS | $PSN | $INFY

This is the less exciting but potentially more defensive side of the thesis.

AI cybersecurity adoption doesn’t happen automatically.

Organizations need:

Implementation.

Integration.

Migration.

Compliance.

Training.

Monitoring.

Government agencies need even more of it.

That creates an implementation layer underneath the cybersecurity software market.

Booz Allen, Leidos and Parsons therefore provide a different type of exposure.

They aren’t pure cybersecurity software companies.

They’re closer to:

“Someone has to actually deploy all this technology.”

That can make these names less sensitive to individual product cycles, although they remain exposed to government budgets and contract timing.


8. AI-Native Security

This is the layer I would watch most closely.

Because the market is only beginning to develop.

Gartner estimates spending on securing AI at $2.84 billion in 2026, rising to $4.78 billion in 2027. The categories include:

  • AI application security
  • AI usage control
  • AI governance
  • AI gateways
  • other AI-security products

And the growth rates are enormous.

AI usage control is projected to grow 73% in 2027.

AI gateways are projected to grow 70.9%.

AI application security is projected to grow 67.5%.

Those aren’t mature-market growth rates.

They are signs of an emerging category.


The Agentic AI Problem

This could become the next major cybersecurity battleground.

A chatbot answering a question is one thing.

An AI agent that can:

  • send emails
  • access databases
  • execute transactions
  • modify code
  • deploy infrastructure
  • communicate with customers
  • make purchasing decisions

is fundamentally different.

The agent has agency.

That means security architecture has to evolve.

Companies will need systems that can answer:

Who is this agent?

What is it allowed to access?

What is it allowed to execute?

Who approved the action?

Was the request manipulated?

Can the activity be stopped in real time?

Can the organization recover if the agent is compromised?

This creates a new security stack around AI agents.

And it potentially connects several of the companies on this map.

Identity.

Endpoint security.

Cloud security.

Data security.

Network security.

Governance.

Runtime protection.

Cyber resilience.


The Big Investment Theme: Consolidation

There is one structural trend I would watch above everything else:

Cybersecurity platform consolidation.

CISOs don’t want 30 dashboards.

They don’t want 30 vendors.

They don’t want to integrate dozens of disconnected systems.

They want fewer platforms that can see across:

Endpoint → Identity → Cloud → Network → Data → AI.

That creates an enormous advantage for companies with the scale and capital to acquire or build missing capabilities.

This is why CrowdStrike and Palo Alto are particularly interesting to watch.

The competition may eventually become less about having the best individual security product and more about owning the security platform.


The AI Cybersecurity Investment Map

If I were organizing the watchlist, I’d separate the companies into different baskets.

Platform Leaders

$CRWD
$PANW

Broadening across multiple cybersecurity layers.

Cloud / Zero Trust

$ZS
$NET
$OKTA

Cloud-native infrastructure, access and identity.

Data / AI Resilience

$RBRK
$VRNS

Protecting the data layer and recovering from attacks.

Identity

$CYBR
$OKTA

Critical as human and machine identities multiply.

Legacy Security Leaders

$CSCO
$FTNT
$CHKP

Large installed bases attempting to modernize.

Exposure Management

$TENB
$RPD

Finding vulnerabilities before attackers exploit them.

Government / Implementation

$BAH
$LDOS
$PSN
$INFY

The services and integration layer.


My Highest-Conviction Areas to Watch

If I had to reduce this entire market map to a few themes rather than dozens of tickers, I would focus on five.

1. AI Agent Security

Potentially the newest and fastest-growing category.

2. Identity

Every AI agent needs permissions.

3. Cloud Security

The traditional corporate perimeter is disappearing.

4. Platform Consolidation

The biggest vendors are attempting to absorb more of the security budget.

5. Cyber Resilience

Prevention will never be perfect.

Organizations also need to survive and recover when prevention fails.


The Risks

This isn’t a one-way trade.

Cybersecurity stocks can be expensive.

High-growth software companies are particularly vulnerable to:

  • rising bond yields
  • multiple compression
  • slower enterprise IT spending
  • elongated sales cycles
  • competition
  • platform consolidation
  • acquisition integration
  • AI commoditization

There is also an important paradox.

AI can make cybersecurity better.

But AI can also make attackers better.

Attackers can automate reconnaissance.

Generate convincing phishing.

Discover vulnerabilities faster.

Scale social engineering.

Create malicious code.

Manipulate AI agents.

That means the arms race isn’t ending.

It is accelerating.


The Bottom Line

The AI infrastructure buildout creates a second-order opportunity that investors can easily overlook.

AI needs:

Compute.

Compute needs:

Data centers.

Data centers need:

Power.

And the entire AI ecosystem needs:

Security.

The cybersecurity market therefore isn’t simply another software sector.

It is becoming critical infrastructure for the AI economy.

The biggest opportunity may not come from the company with the most impressive AI demo.

It may come from the company that becomes embedded deeply enough into the enterprise that removing it becomes almost impossible.

That’s why I would watch the battle between:

$CRWD vs. $PANW

for platform consolidation,

$ZS vs. $NET

for cloud and edge security,

$CYBR vs. $OKTA

for identity,

and

$RBRK

for cyber resilience and the data layer.

And then keep an eye on the emerging AI-security category itself.

Because we’re still early.

Gartner’s latest forecast puts spending specifically on securing AI at nearly $4.8 billion in 2027, growing almost 69% in a single year. Meanwhile, broader AI-cybersecurity spending is projected at $86 billion in 2027.

The AI revolution is creating enormous amounts of digital infrastructure.

And wherever there is valuable infrastructure, there will be attackers.

The more AI we deploy, the more valuable cybersecurity becomes.

That’s the investment thesis.


Not financial advice.