Cyber security vendors: who is paid when incidents rise
The trade everyone reaches for after a breach - buy the security vendors - is the one with the least evidence behind it. What actually drives this sector is a budget cycle, not a news cycle.
At a glance
- Business model
- Subscription software; annual recurring revenue rather than product sales
- Scale reference
- CrowdStrike reported ARR of about 5.25bn USD, growing near 24% year on year
- Mid-cap reference
- SentinelOne crossed 1.06bn USD of ARR, up about 23%
- Structural risk
- A security agent runs with deep system privilege - the vendor can become the outage
What these companies actually sell
Cyber security vendors sell subscriptions to software that runs continuously inside a customer's environment: an agent on every endpoint, an inspection layer in front of every network request, a set of detections updated daily. The customer is not buying a product so much as renting a capability, and the contract renews annually. That structure is the reason the sector is analysed through annual recurring revenue rather than through revenue - ARR is the run rate of what is already committed, and it moves before reported revenue does.
The competitive logic follows from the agent. Once a vendor's software is on every machine in an organisation, adding a second product to the same agent is cheap for the customer and enormously profitable for the vendor. This is why the leaders keep expanding into adjacent categories and why net retention - what existing customers spend this year against last - is watched as closely as new customer counts.
Scale is now considerable and still compounding. CrowdStrike has reported annual recurring revenue of roughly 5.25 billion dollars growing near 24 per cent, Zscaler sits above three billion with growth above 25 per cent, and SentinelOne crossed 1.06 billion, up about 23 per cent. Growth at that rate at that size is rare outside this sector, and it is what the valuations are paying for.
ARR, not revenue. It is the committed run rate, it moves first, and every argument about this sector is really an argument about how long it keeps compounding.
Why the budget survives what other budgets do not
Security spending is defended in downturns in a way that most enterprise software is not. The reason is not that executives value it more highly - it is that cutting it requires someone to sign their name to the decision, and the asymmetry of that signature is obvious to everyone in the room. A cut that saves a modest sum and precedes an incident ends a career; the same cut that precedes nothing saves a modest sum.
The demand driver underneath is regulatory as much as technical. Disclosure rules now require listed companies to describe their risk management and board oversight annually, and European directives impose reporting duties with hard deadlines on a wide population of firms. Compliance obligations convert security from a judgement call into a documented process, and documented processes get funded.
The newer driver is that the attack surface itself is growing along a new axis. As organisations deploy AI systems with access to internal data and the ability to act, both the defensive and the offensive sides acquire capabilities they did not have, and the security budget acquires a line item that did not exist. Whether that becomes a durable category or an expensive detour is the live argument in the sector, and it is priced as though the answer is already known.
- The budget is asymmetric: the cost of underspending is career-ending, the cost of overspending is a line item.
- Regulation converts security from judgement into documented process, and process gets funded.
- Land-and-expand through a single agent makes net retention the sector's core metric.
- AI adds an attack surface and a product category at the same time, on both sides of the market.
Where the money sits in the stack
The market divides into layers, and the layers have very different economics. Endpoint sits closest to the machine and has the strongest lock-in, because replacing an agent on every device in a company is a project rather than a purchase. Network and access layers sit in front of the traffic and are stickier still once the routing depends on them. Identity is the layer attackers actually target, and the one most organisations under-fund relative to its importance.
Consolidation runs through all of it. Buyers who spent a decade assembling best-of-breed tools are now trying to reduce vendor count, which favours the platforms and squeezes single-product companies from both sides - the platform bundles the feature away, and the buyer wants fewer contracts anyway. That dynamic drives the acquisition activity that keeps reshaping the sector.
For anyone valuing these companies, the layer matters more than the logo. A vendor whose product is a feature of someone else's platform has a growth rate with an expiry date, however good the technology is. A vendor that owns the agent has a distribution channel for everything it builds next.
1Identity
Where most intrusions begin, and where budgets lag the risk
2Endpoint
An agent on every machine
The strongest lock-in in the sector
3Network and access
Inspection in front of the traffic; sticky once routing depends on it
4Cloud posture
Configuration rather than intrusion; the fastest-growing layer
5Detection and response
The data layer where the other four report
The consolidation battleground
Behind the subscription
The rest of this entry is the part that changes a decision: what moves the price, which contract sets it, who ships it and where that can be cut off.
What actually moves these shares
Six drivers, and a direct answer on the one everybody assumes: no, breaches at other companies do not reliably move the sector.
Where the sector is traded
The names, the tickers and the one structural difference that decides which of them a shock actually reaches.
When the vendor is the incident
One customer, one faulty update, and a bill larger than most breaches. The 2024 case that reset how this risk is priced.
How this shows up in prediction markets
The sector rarely gets its own market. What it gets instead, and how to price the version that does list.
Included with a subscription
Create an account to unlock the full entry — price drivers, trading venues, trade flows and the live markets attached to it.
Frequently asked questions
- Do cybersecurity stocks go up after a big breach?
- Not reliably, and the belief is stronger than the evidence. Enterprise security is bought on annual budget cycles with long procurement, so a breach at an unrelated company does not generate orders. Headline moves that are not later confirmed by an ARR print tend to fade. If you want to test the thesis, test it on a sector basket rather than on whichever name reacted most.
- Why is ARR the metric rather than revenue?
- Because these are subscriptions. Annual recurring revenue is the committed run rate of what customers have already contracted, so it moves before reported revenue does and shows the trajectory more cleanly. Alongside it, net retention - what existing customers spend this year against last - determines whether growth is compounding on the installed base or being bought with sales spending.
- What happened with CrowdStrike in 2024?
- On 19 July 2024 a faulty content update to its Windows sensor caused system crashes on an estimated 8.5 million devices, halting airlines, hospitals and broadcasters worldwide. No attacker was involved. CrowdStrike's shares fell about a third within a fortnight, and Delta Air Lines - which cancelled roughly 7,000 flights - put its own cost above 500 million dollars. The two companies sued each other.
- Is the sector expensive?
- By conventional measures, yes. Reported forward earnings multiples have run near 90 times for the sector leader and in the 30s to 50s for peers, which prices years of continued compounding. That makes these long-duration assets: they are more sensitive to interest rates and to small revisions in expected growth than their defensive reputation suggests.
- Is a security vendor itself a risk?
- Yes, and it is the sector's most specific tail risk. The agent that makes endpoint security work runs with deep system privilege on every machine it protects, so a defect propagates with the same reach as the protection. Deploying one vendor everywhere is both the value proposition and a correlated failure mode, as 2024 demonstrated at economy scale.
Primary sources
- CrowdStrike - Investor relations and quarterly results
- Palo Alto Networks - Investor relations
- TechCrunch - Microsoft says 8.5m Windows devices were affected by the CrowdStrike outage
- CNBC - Delta and CrowdStrike sue each other over the 2024 outage
- CNBC - CrowdStrike and Palo Alto hit records after Black Hat
Growth rates, multiples and prices are stated as of the fact check above and change quarterly. Nothing here is investment advice or a recommendation on any security.
Related entries
Prediction markets carry real risk of loss. Nothing on Market Guy is financial advice — it is research tooling to help you think, not a signal to trade.