Cybersecurity
Cross-cutting force · Security across every layer
- Why it matters
- Security failures at any layer undermine the layers above and below. An agent with excessive permissions is a governance problem, an identity problem and a data problem at the same time.
- The bottleneck
- Skilled people and coherent identity. Tooling is plentiful; the ability to operate it consistently is not.
- Who captures value?
- Platforms with broad telemetry and a position customers are reluctant to unpick, particularly where identity and detection meet.
- What could change?
- Machine identity for autonomous agents is an unsolved control problem, and whoever solves it convincingly could reshape the category.
Security is not a step in the sequence. Every layer adds attack surface, from firmware in the data centre to an agent holding credentials on someone's behalf.
Each addition to the ecosystem creates something new to defend. More data in more places, more identities, more automated systems taking actions without a human reviewing each one. Security vendors are selling into organisations that are deploying AI faster than they are securing it, which is a durable commercial position and an uncomfortable fact.
Tap or hover a box to see what it does
Endpoint and cloud protection
Detecting and responding to activity on devices and in cloud environments, where misconfiguration remains one of the most common routes in.
CrowdStrike
Provides cloud delivered endpoint detection and response, threat intelligence and related security modules.
Widely deployed across large enterprises, with a sensor footprint that improves detection as it grows. Agents acting autonomously on corporate systems make endpoint telemetry more valuable, not less.
Platform consolidation pressure, and the reputational cost of any incident affecting a component installed that widely.
SentinelOne
Provides endpoint and cloud security with automated detection and response.
A credible alternative in a category where buyers want a second option, particularly after any incumbent stumble.
Smaller scale than the leaders in a market where scale improves detection.
Wiz (Google)
Cloud security posture and workload protection, agreed for acquisition by Alphabet.
Cloud misconfiguration remains one of the most common routes into an environment, and AI workloads add new data paths worth watching.
Integration risk inside a much larger owner, and customers who prefer their security vendor to be cloud neutral.
Network, access and identity
Controlling who and what may reach which system. Agents need credentials too, which makes machine identity a growing part of the problem.
Palo Alto Networks
Sells network, cloud and security operations products as an integrated platform.
Security buyers are actively reducing vendor counts, which favours suppliers who can credibly cover several categories at once.
Platform deals can depress near term billings, and best of breed rivals keep winning individual categories.
Zscaler
Provides cloud delivered zero trust access, inspecting traffic between users, applications and the internet.
When applications and staff are both distributed, the network perimeter is a poor control point. Inspection in the cloud is the practical alternative.
Competing against both network incumbents and cloud providers bundling similar controls.
Cloudflare
Operates a global network providing content delivery, DDoS protection, zero trust services and edge compute.
It sits in front of a large share of web traffic, which gives it both a security vantage point and a natural place to put inference close to users.
Monetising a wide free tier is a long game, and the developer platform competes with the hyperscalers.
Okta
Provides identity and access management for workforce and customer applications.
Autonomous agents need credentials, and machine identity is becoming as significant a control problem as human identity.
Identity is bundled aggressively by the large cloud providers, and past security incidents left a mark.
How to think about the economics
- GrowthHigh
How quickly demand in this part of the ecosystem is expanding.
- Capital intensityLow
How much money has to be spent up front before revenue arrives.
- Competitive moatHigh
How difficult it is for a credible new entrant to take the business.
- Customer concentrationLow
How much revenue depends on a small number of buyers.
- Disruption riskModerate
How exposed the layer is to a technical or commercial shift.
This is a framework for thinking about the economics of a layer, not a recommendation. An important AI company, a strategically advantaged company, an investable security and an attractively valued security are four different things.
Where value may accrue
Telemetry scale, consolidation preference among buyers, and the operational cost of switching a control that touches everything.
Related questions
What is agentic AI?
Most AI use is still reactive: you ask, it answers. An agent is given a goal instead, and works out the intermediate steps, calling tools, reading data and looping until it decides the task is finished. That shift is why permissions, audit trails and identity suddenly matter so much. A chatbot that is wrong wastes your time. An agent that is wrong can take an action on your behalf, which is a different category of problem.
What is a foundation model?
A large, general purpose model trained on a very broad dataset, which can then be adapted to particular tasks. The GPT, Claude, Gemini and Llama families are all foundation models. They are called foundations because applications, tools and agents get built on top of them. Training one is an expensive bet that sitting at the base of the stack is where lasting value accrues, which is precisely the question the rest of this site is trying to help you think about.
Sources and further reading (2)+
- 1Investor relations and threat reporting · CrowdStrike
- 2Radar internet traffic and security data · Cloudflare
The AI ecosystem changes rapidly. Company positions, technologies and market data reflect information available at the date above.