← All sectors / The AI transformation

06 · Cybersecurity

Defense for the AI era

Curve position

Growth

Binding constraint

An identity control plane built for agents, which does not yet exist.

Defense for the AI era

Cybersecurity is the rare sector where AI raises demand on both sides of the fight. Attackers use models to write malware, craft phishing at scale, and probe systems faster than humans can respond; defenders answer with AI-driven detection, automated response, and identity verification built for a world of deepfakes.

Historically, each computing shift birthed a security generation — networks made firewalls, cloud made cloud-security platforms, each minting multi-billion-dollar leaders. AI is the next shift, and the pattern argues the next generation of leaders is being founded and funded right now.

The structural driver is asymmetry: attack costs are collapsing faster than defense costs. When a convincing spear-phish or cloned voice costs pennies to generate, volume explodes, and only machine-speed defense can hold the line. Security has become an AI-versus-AI contest with enterprise budgets as the prize.

Security spend is among the most protected line items in software — breach risk is existential, regulatory penalties are rising, cyber insurance demands controls, and boards treat posture as governance. Even in soft macro tapes, security budgets bend rather than break.

The attack surface compounds with adoption: every AI agent granted permissions, every API exposed, every connected device widens the perimeter. Securing AI itself — model integrity, data pipelines, agent permissions, prompt-injection defense — is emerging as a new category with no entrenched incumbent.

Platform consolidation favors large vendors bundling network, endpoint, cloud, and identity into single agreements. But innovation keeps birthing specialists, and acquirers pay premium multiples for them — giving smaller names a defined exit path that supports valuations across the tier.

The value chain spans prevention (identity, network, endpoint), detection and response (monitoring, SOC tooling), and increasingly assurance for AI itself. Services — managed detection, incident response — wrap around all of it, growing with attack volume regardless of which products win.

The overlooked layer includes identity-security specialists (the control plane of an agent-filled world), operational-technology security for factories and utilities, data-security posture vendors, and services firms doing incident response as attack volume climbs.

Competitive dynamics are consolidation versus specialization in permanent tension: platforms bundle and discount, specialists out-innovate on the frontier, and acquirers arbitrate the difference. The frontier keeps moving — today identity and AI-model security, tomorrow agent-to-agent trust.

Risks: crowded competition and marketing noise make product differentiation hard to underwrite; platform bundling squeezes point solutions; security spending consolidates in downturns; and a genuine defensive breakthrough from the model layer could reorder the vendor landscape quickly.

What to watch: breach-frequency and claims data from cyber insurers, identity-attack statistics, federal security mandates, platform-vendor module attach rates, and M&A multiples for specialists. The research watches where the threat moves before the budget line catches up.