SASIGNAL ATLASCross-industry intelligence / Research desk
SIGNAL ATLAS / RESEARCH DESK

Cybersecurity & digital trust

Dossier · Cybersecurity & digital trust · Original Phase 1 research

Cybersecurity & digital trust

Industry ID: 04 | Slug: cybersecurity | Researched: 2026-09-15 | Analyst: agent

Source-quality warning specific to this sector. Nearly every widely-circulated cybersecurity statistic originates with a vendor that sells a remedy for the thing the statistic describes. This dossier privileges CISA, ENISA, NIST, the FBI's IC3, the SEC, the European Commission, ITRC and audited company filings. Where a vendor figure is used it is labelled with its sponsor and marked estimate or marketing. Three figures that appear constantly in the trade press are deliberately not used here as facts: any "cost of a data breach" average, any "unfilled cybersecurity jobs" count, and any "$X billion market by 2032" projection from an unnamed methodology.


1. Definition and boundaries

In scope. Software, hardware and services whose purpose is to protect information systems, the data in them and the identities that access them: network and endpoint security, cloud and data security, identity and access management, application and product security, security operations and detection engineering, cryptography including the post-quantum migration, threat intelligence and incident response, fraud and abuse prevention where the mechanism is technical, offensive security services, and the regulatory and insurance wrapper that prices and compels all of the above. AI security is in scope in both directions: securing AI systems (model, agent, pipeline, tool-calling surface) and AI used offensively and defensively.

Explicitly out of scope, and who owns it.

  • Physical security, guarding and surveillance hardware — industrial and facilities sector. Only the network-attached parts (cameras, access control) cross the boundary, and then usually as an OT security problem.
  • Privacy compliance and data governance as a legal discipline — legal and professional services. GDPR programme management is not cybersecurity even when the same person owns it.
  • Payments fraud where the mechanism is financial rather than technical — fintech. Card fraud loss allocation belongs there; account takeover belongs here.
  • Defence and intelligence offensive cyber capability as procurement — aerospace and defence. Nation-state activity is in scope as a threat; selling exploits to governments is a defence-industrial business.
  • General IT infrastructure and observability — enterprise software. Splunk was an observability company that became a security company by acquisition, which is precisely why the boundary is contested.

The live boundary disputes.

  1. AI security. Is "securing AI" a cybersecurity subcategory or an AI-platform feature? Gartner models it as a security line item reaching $37.6bn by 2030; hyperscalers are shipping guardrails as platform features at no incremental price. Both can be true for a while; only one survives.
  2. Identity. Identity is simultaneously an IT administration function, a security control and, increasingly, the substrate of enterprise AI. Palo Alto paid for CyberArk on the third reading.
  3. Fraud and abuse. The FBI books $20.877bn of 2025 US cybercrime losses, of which $8.648bn is investment fraud — mostly a confidence crime executed over the internet, not a security-control failure. Sector sizing that includes it is inflating.
  4. Resilience. DORA and the EU Cyber Solidarity Act regulate operational resilience, of which cyber is one cause. Backup and recovery vendors sit on the boundary and market on both sides of it.

2. Subcategories

Subcategory What distinguishes it
Identity and access management Governs who and what may act. Now the largest consolidation target because machine and agent identities have made it the hardest problem, not the most routine one.
Network and edge security Firewalls, SASE, zero-trust access. The oldest revenue base; edge appliances are also the most-exploited initial access surface.
Endpoint and XDR Agent-on-the-host detection and response. The category CrowdStrike defined and the one with the clearest public consolidation metrics.
Cloud and data security CNAPP, CSPM, DSPM. Fastest-consolidating category, absorbed by hyperscalers (Google/Wiz) and platforms.
Application and product security SAST/DAST, software supply chain, SBOM. Being re-scoped by the EU Cyber Resilience Act from a best practice into a market-access requirement.
Security operations SIEM, SOAR, MDR, and now agentic triage. Where the labour constraint bites hardest and where the least-verified claims live.
Cryptography and PKI Certificate lifecycle, HSMs, key management. Dormant for a decade; reactivated by a dated federal post-quantum mandate.
Threat intelligence and IR Attribution, hunting, breach response. Increasingly a loss-leader inside platforms rather than a standalone business.
Fraud, abuse and digital trust Identity verification, bot mitigation, deepfake detection. The consumer-facing edge of the sector and the one with the largest measured dollar losses.
OT and ICS security Industrial protocols, air-gap erosion, safety-critical constraints. 18.2% of ENISA's threat categories; long asset lives make it the hardest to remediate.
AI security Model and agent runtime protection, AI gateways, MCP security. The only segment Gartner models as accelerating through 2030.
Governance, risk and compliance Control mapping, audit automation, regulatory reporting. Turned from a cost centre into an operating function by the 2026 reporting deadlines.
Cyber insurance and risk transfer Underwriting, modelling, incident-response panels. A price signal on the sector that is independent of vendor marketing.

3. Market structure

Concentration: consolidating oligopoly at the top, persistently fragmented below. The structure is a barbell and has been stable in that shape for a decade. A handful of platform vendors capture the consolidating budget while several thousand point vendors compete for the remainder and for acquisition.

  • Palo Alto Networks: FY2026 revenue $11.48bn, Next-Generation Security ARR $9.10bn (+63%, substantially inorganic after the CyberArk close), RPO $21.2bn, FY2027 revenue guidance $14.10–14.20bn, stated FY2030 NGS ARR target $20bn. (Palo Alto Networks press release, 2026-09-01, Tier A.)
  • CrowdStrike: ARR $5.84bn (+25%) for the quarter ended 2026-07-31, record net new ARR $333m, Falcon Flex ARR $2.29bn (+101%), and 51% of subscription customers on six or more modules. (CrowdStrike IR, 2026-08-26, Tier A.)
  • Total market size: $248.9bn of worldwide end-user information security spending in 2026, +12.7% constant currency, reaching $372.6bn by 2030 at a 10.7% CAGR. This is Gartner's estimate (Forecast: Information Security, Worldwide, 2024–2030, 2Q26, G00855892, dated 2026-06-25), reported via a secondary analyst blog. Treat it as estimate, never as fact: Gartner itself revised 2026 from $244.2bn (March) to $246.2bn (April) to $248.9bn (June). A figure that moves 2% per quarter is not a measurement.

Where margin actually sits. Not in the products with the loudest marketing. Margin concentrates in (a) platform subscription software with high gross margins and multi-year commitments — CrowdStrike posted 81% non-GAAP subscription gross margin; (b) identity, because switching costs are the highest in the sector and the control plane is sticky; and (c) security services and MDR, where the margin is lower but the revenue is contractually durable and the customer cannot easily reabsorb the function. Margin is thin in hardware appliances, in commoditised scanning, and in threat intelligence, which is increasingly given away to sell something else.

Barriers to entry. Low to build, extremely high to distribute. A competent team can build a credible point product in a year; reaching enterprise procurement requires references, compliance certifications (SOC 2, FedRAMP, ISO 27001), a channel, and a security-of-the-security-vendor story that has hardened considerably since the 2023–24 run of vendor compromises. The practical barrier is that the buyer's default is now "does my platform vendor do this yet", which compresses the window in which a point product can win on capability alone.

Pricing power. Held by: Microsoft (bundling, because security is a rounding error on an E5 seat); the two or three platform vendors with genuine consolidation leverage; and the cyber insurers — except that insurers have voluntarily surrendered it, with cyber rates down for twelve consecutive quarters (Marsh Q2 2026: −4% globally, −2% US). Buyers have gained power in the mid-market, where capacity is abundant and vendors are numerous. Nobody in the value chain has pricing power over security services labour.


4. Who matters

Leading companies. Palo Alto Networks (https://www.paloaltonetworks.com) · CrowdStrike (https://www.crowdstrike.com) · Microsoft Security (https://www.microsoft.com/security) · Google Cloud Security / Mandiant / Wiz (https://cloud.google.com/security) · Cisco (Splunk) · Zscaler (https://www.zscaler.com) · Fortinet · Check Point · SentinelOne · Cloudflare (https://www.cloudflare.com) · Okta (https://www.okta.com) · CyberArk, now part of Palo Alto (https://www.cyberark.com).

Notable startups. Cyera (DSPM, ~$1.7bn raised) · Torq (agentic SOC, $140m Series D Jan 2026 at a reported $1.2bn) · 7AI ($130m Series A Dec 2025) · Oasis Security (NHI, $120m Series B Mar 2026) · XBOW (autonomous pentest, $120m Series C Mar 2026) · Noma Security · WitnessAI · GitGuardian (Paris, $50m Feb 2026) · Socure ($156m at $5.2bn, Aug 2026) · Operant AI, Runlayer, Helmet Security, Manufact (the entire disclosed MCP-security cohort, ~$40m combined). All round figures are Crunchbase-derived third-party aggregations, not audited.

Active investors. Cyberstarts (https://cyberstarts.com) · Ten Eleven Ventures (https://www.1011vc.com) · Insight Partners · Sequoia · Accel · Evolution Equity · Ballistic Ventures · Glilot Capital · Team8.

Platforms and standards bodies. NIST CSRC (https://csrc.nist.gov) · OWASP GenAI Security Project (https://genai.owasp.org) · Cloud Security Alliance (https://cloudsecurityalliance.org) · CVE Program (https://www.cve.org) · FIRST · IETF · MITRE ATT&CK (https://attack.mitre.org).

Regulators. CISA (https://www.cisa.gov) · SEC (https://www.sec.gov) · ENISA (https://www.enisa.europa.eu) · European Commission DG CNECT (https://digital-strategy.ec.europa.eu) · UK NCSC (https://www.ncsc.gov.uk) · BSI Germany · ANSSI France · Japan NISC (https://www.nisc.go.jp) · HKMA · ONCD (https://www.whitehouse.gov/oncd/).

Research institutions. Carnegie Mellon SEI/CERT · NIST NCCoE · Google Threat Intelligence Group · Anthropic threat intelligence · Citizen Lab (Toronto) · Ruhr-Universität Bochum · KU Leuven COSIC.

Trade organisations. ISC2 (https://www.isc2.org) · FS-ISAC · Health-ISAC · Cyber Threat Alliance · Momentum Cyber (M&A data).

Consumer and civil-society groups. Identity Theft Resource Center (https://www.idtheftcenter.org) · Electronic Frontier Foundation · Access Now Digital Security Helpline · Ransomware Task Force (IST).


5. Products, business models, technologies, customers

Major products. Consolidated security platforms sold as multi-year subscriptions (Palo Alto Cortex/Prisma/Strata, CrowdStrike Falcon, Microsoft Defender/Sentinel); identity control planes (Entra, Okta, CyberArk); cloud-native application protection; managed detection and response; and a fast-growing layer of AI-specific controls — AI gateways, guardrails, agent authorisation brokers and MCP proxies.

How money is actually made, and how it is changing. The dominant model is per-seat or per-workload subscription with annual escalators, increasingly repackaged as a consumption commitment that the customer draws down across modules — CrowdStrike's Falcon Flex, at $2.29bn ARR growing 101%, is the clearest instance. This is a deliberate shift from "sell the customer another product" to "sell the customer a budget", and it is what makes platform consolidation measurable: module attach at 51% for six-plus modules is a real number, not a marketing claim. Services revenue is being repriced downward by automation claims while services demand rises with regulatory workload. The newest model is the one with the least evidence: outcome-priced or agent-priced security operations, sold on the premise that a vendor's AI agent replaces analyst headcount.

Technologies that matter. Post-quantum cryptography (ML-KEM, ML-DSA, and the X25519MLKEM768 hybrid now carrying two-thirds of browser traffic to Cloudflare); eBPF and kernel-adjacent telemetry; confidential computing; passkeys and phishing-resistant authentication; the Model Context Protocol and whatever replaces it as the agent tool-calling standard; and, unglamorously, patch and configuration automation — the technology whose absence the DBIR actually measured deteriorating.

Customer segments and what they buy on.

  • Large regulated enterprise (finance, healthcare, energy). Buys on auditability, regulatory mapping and vendor viability. Slowest to switch, highest lifetime value.
  • Mid-market. Buys on total cost and on whether the insurer or a customer contract requires it. Most exposed to the soft insurance market removing that forcing function.
  • Government and defence. Buys on certification (FedRAMP, CMMC, national schemes) and increasingly on sovereignty — a growing tailwind for European and Japanese vendors.
  • Digital-native technology companies. Buys on API quality and developer experience, and is the only segment currently buying AI-agent security in volume.
  • Consumers. Buy almost nothing directly; receive breach notices (471.2m in US H1 2026) and bear fraud losses ($20.877bn reported to IC3 in 2025).

6. Geography

Production (where security products are built). Two centres dominate: the US west coast and Israel. Israel's density is structural — CyberArk, Wiz, Cyera, Torq, Noma, Oasis and Operant all have Israeli founding teams — and the CyberArk acquisition, which prompted Palo Alto to take a secondary Tel Aviv listing under the CYBR ticker, formalised the link. Europe produces far fewer scale-ups; GitGuardian (Paris) is a notable exception, consistent with the macro brief's finding that Europe is the structurally weak leg of global venture at $25.6bn in Q2 2026.

Capital. Overwhelmingly US. The distortion flagged in the macro brief applies with full force here: with >70% of Q2 2026 global VC going to AI-focused companies and two AI labs taking 43% of H1 funding, "cybersecurity funding" totals are increasingly a measure of how many security startups successfully labelled themselves AI companies.

Demand. Broadly distributed but priced very differently. Marsh's Q2 2026 data shows cyber insurance rates falling 14% in IMEA and 10% in LAC against only 2% in the US — the US market is both the most mature and the most loss-affected.

Regulation. This is where geography genuinely diverges, and it is the most consequential split in the sector.

Europe (regional source: ENISA and the European Commission). The EU has built the densest cyber rulebook in the world and is now enforcing it. The Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 over NIS2 transposition, seeking lump sums plus daily penalties; roughly two-thirds of member states had transposed by mid-2026, and no administrative fine against a named entity had been publicly disclosed — enforcement is still at the supervisory-notice stage, with Germany's BSI and Italy's ACN issuing formal orders. The Cyber Resilience Act's manufacturer reporting obligations began 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report, filed to a national CSIRT and ENISA through a Single Reporting Platform. ENISA's own Threat Landscape 2025 (4,875 curated incidents, July 2024 – June 2025) shows a materially different threat mix from US sources: DDoS at 76.7% of incidents, public administration the most-targeted sector at 38.2%, Germany the most-affected member state at 23.4% of cybercrime incidents, and state-aligned activity at 7.2% across 46 tracked intrusion sets.

Japan (regional source: Baker McKenzie Tokyo on the ACD law). Japan enacted its Active Cyber Defense law on 16 May 2025, phasing to full effect by 2027. It obliges critical infrastructure operators across 15 sectors to report incidents to ministries and the Prime Minister's Office, requires telecommunications providers to permit government access to cross-border communications data where attack-related traffic is suspected (subject to an Oversight Committee), and requires IT vendors to act on government vulnerability notifications. This is the most significant expansion of state cyber powers among democratic allies in a decade and is badly under-covered in English-language security media.

United States. Moving in the opposite direction on capacity: CISA's workforce fell from roughly 3,200 to roughly 2,200, field cybersecurity advisers from ~164 to 97, CIRCIA's final rule has slipped twice, and the Cybersecurity Information Sharing Act of 2015 has been running on short extensions since lapsing in the late-2025 shutdown.


7. Historical trend patterns

Over 25 years this sector has run a reliable cycle: a novel attack class appears, a category of point products forms around it, the category is declared the future of security, budgets shift, and within five to eight years it is absorbed into a platform as a feature. Antivirus → endpoint protection → EDR → XDR is the same product absorbed three times. The useful question about any new category is never "is the threat real" — it usually is — but "is the control a product or a feature".

Specific false positives in this sector, worth naming because they are still cited:

  • Blockchain for cybersecurity (2017–2019). Identity-on-chain, threat-intel-on-chain, PKI-on-chain. Substantial funding, essentially zero enterprise deployment. Resolved by quiet disappearance rather than by disproof.
  • SOAR (2017–2021). Sold as eliminating Tier-1 analyst work through automated playbooks. The orchestration was easy; the integrations and the decision logic were not. The category did not fail commercially — it was absorbed into SIEM — but it failed at its stated purpose. This is the closest available analogue to the 2026 agentic-SOC wave and it is almost never mentioned in current marketing.
  • Deception technology / honeypot platforms (2016–2020). Elegant, well-evidenced, genuinely effective in trials. Failed on operational burden. A reminder that efficacy does not imply adoption.
  • "Zero trust" as a product (2019–2023). A sound architectural principle that was sold as a purchasable state. Every vendor shipped a zero-trust SKU; the underlying segmentation and identity work mostly did not happen. Now largely retired as marketing language, which is the tell that a concept has been absorbed or abandoned.
  • Security awareness training as a primary control (2010s). Sustained investment; the DBIR's human-element share has not moved enough to justify it as a first-line control.
  • The 2015–2020 "cyber talent shortage" framing. Produced a decade of workforce-gap headlines from bodies selling certifications. The 2024–26 reality — hiring freezes, layoffs affecting security teams, entry-level roles under automation pressure — is nearly the inverse.

What has genuinely persisted across the full period: identity as the attack path; patching as the unsolved operational problem; the gap between control purchase and control operation; and the reliable failure of security spending to track security outcomes.


8. What is changing now (as of 2026-09-15)

Five things are true simultaneously, and holding all five at once is the analytical task.

One: the measurable defensive metrics got worse. The 2026 DBIR found median patching time lengthening from 32 to 43 days and KEV remediation among ~13,000 surveyed organisations falling from 38% to 26%. Vulnerability exploitation overtook stolen credentials as the leading initial access vector (31%) for the first time in 19 years. None of this is about AI; it is about operational throughput, and it deteriorated.

Two: attack breadth is being decoupled from attacker headcount. Anthropic's September 2026 report documents autonomous agent fleets running scheduled collection jobs unattended, 2,100+ Azure tokens exfiltrated across 40+ tenants in 34 hours, and intrusion-to-bulk-theft timelines of two to three hours. This is the most concrete public evidence to date and it comes from a single vendor with a single provider's visibility and no independent corroboration published. It should change planning assumptions; it should not yet be treated as an established population-level fact.

Three: the money consolidated, hard. Palo Alto closed CyberArk in February 2026 and reported $9.10bn of NGS ARR against a $20bn FY2030 target; Alphabet's $32bn Wiz agreement and ServiceNow's $11.6bn of security purchases took total 2025 sector M&A to roughly $96bn across ~400 deals, with three acquirers accounting for $72bn. Venture kept funding the next generation anyway. Both are the equilibrium, not a transition.

Four: the regulatory clock became an operating constraint. CRA manufacturer reporting went live on 11 September 2026, four days before this research date. NIS2 enforcement moved to litigation. CIRCIA is still not final. Japan's ACD law is phasing in. The SEC regime is deflating. A multinational now faces four incompatible reporting clocks and one regulator actively considering retreat.

Five: the macro environment does not support the sector's own story. With the FOMC holding at 3.50–3.75% on a 9–3 vote with three dissents in favour of a hike, sticky 3–4% inflation, and an explicit FOMC flag on AI-firm valuations and leveraged infrastructure financing, every multi-year security platform commitment and every AI-security round is being underwritten at a capital cost the 2021 cohort never faced. The sector's revenue is holding up well — Palo Alto guiding to 23–24% growth, CrowdStrike to a raised FY2027 — but the funding concentration flagged in the macro brief means sector funding totals are badly skewed by AI labelling.


9. The five lists

Five most important current trends

  1. Identity as the contested perimeter, with machine identities now dominating it (T-04-01)
  2. Third-party compromise at roughly half of all breaches (T-04-02)
  3. Exploitation outpacing patching — the measured defensive deterioration (T-04-03)
  4. Platform consolidation winning on revenue while best-of-breed wins on capital (T-04-04)
  5. Mandatory incident reporting on four incompatible clocks (T-04-07)

Five fastest-growing signals

  1. AI-orchestrated intrusion campaigns at machine tempo (T-04-09)
  2. Prompt injection and the MCP tool-calling attack surface (T-04-10)
  3. Agent identity governance and zero standing privilege for non-humans (T-04-13)
  4. "Securing AI" as the only accelerating security spend segment (T-04-14)
  5. Post-quantum migration moving from advisory to mandate (T-04-12)

Five trends most likely to affect businesses

  1. Mandatory reporting as an operating function (T-04-07) — overlaps with the "most important" list; unavoidably so, because it is the one with a dated deadline already past
  2. Third-party compromise at half of breaches (T-04-02) — also overlaps
  3. Post-quantum migration with contractor flow-down by 2030 (T-04-12)
  4. Cyber insurance losing its grip as a de facto regulator (T-04-18)
  5. Security budget growth decoupled from headcount (T-04-05)

Five trends most likely to affect consumers

  1. Mega-breach concentration through shared platforms (T-04-08) — 471.2m US victim notices in H1 2026, 58% of them from a single education-platform event
  2. Fraud and abuse at scale — $20.877bn of reported US losses in 2025, $7.7bn of it borne by people over 60
  3. Ransomware's shift toward data-theft extortion (T-04-06), which moves the harm from downtime to disclosure
  4. Declining transparency in breach notices — only 24% disclosed an attack vector in H1 2026
  5. Passkey and phishing-resistant authentication rollout, the one genuinely positive consumer-facing shift

Overlaps, stated plainly. T-04-02 and T-04-07 appear on two lists each because the business impact of a threat and its strategic importance are not independent in this sector. T-04-08 and T-04-06 are the consumer-facing faces of T-04-02.


10. Overhyped / overlooked / cooling / reversing

Most overhyped

The autonomous AI SOC replacing Tier-1 analysts. The evidence problem is stark: a deliberate search for independent adoption or efficacy data in September 2026 returned exclusively vendor blogs, vendor-sponsored buyer's guides and consultancy content marketing. No neutral study, no regulator dataset, no peer-reviewed evaluation of autonomous triage accuracy in production could be located. Meanwhile roughly $300m+ has gone into the named startups in twelve months. The specific evidence that hype outruns substance: the one independently measured operational metric that moved in 2026 — patching throughput — moved backwards, and the category's direct historical analogue, SOAR, made the identical promise in 2017 and failed on the identical problem. Vendor-published alert-reduction percentages measure workload inside the tool, not detection efficacy, and are trivially gamed by suppressing alerts. A defensive agent that reads attacker-controlled alert content is also, per OWASP, a prompt-injection target.

"Q-Day is imminent." Published estimates for a cryptographically relevant quantum computer span the early 2030s to the mid-2040s. The near-term dates circulating in 2026 come predominantly from cryptocurrency-community figures with direct exposure to quantum-vulnerable signature schemes, not from quantum hardware groups. The real driver of 2026 PQC spending is a dated executive order, not an updated capability estimate — and conflating the two produces the wrong programme sequencing. Note the honest caveat: the programme is not overhyped, the rationale is. The mandate is real, dated and binding on federal contractors by 2030.

Most overlooked

The MCP and agent-authorisation layer is under-capitalised by roughly two orders of magnitude relative to its exposure. Total disclosed funding across the four named MCP-security startups is about $40m. CSA estimates 200,000 vulnerable MCP instances across a supply chain of 150m+ package downloads, with a systemic command-injection flaw in the STDIO transport across all official SDKs and at least one unpatched critical CVE as of May 2026. Attention has missed it because the money went to the word "identity" — $120m to Oasis, $700m to Saviynt, $25bn to CyberArk — while the actual technical chokepoint sits at the protocol layer where there is no incumbent to acquire and no established buyer.

Japan's Active Cyber Defense law. A major democratic ally has granted its state access to cross-border communications data and pre-emptive cyber powers, phasing in through 2027, and the English-language security press has barely covered it. Any multinational with Japanese critical-infrastructure customers has new obligations most of them have not read.

The declining transparency of breach notices. Only 24% of H1 2026 US breach notices disclosed an attack vector, the lowest share ITRC has recorded. This quietly degrades the entire public evidence base for the sector and hands the narrative to vendors, who are the only remaining source of vector data. It is a structural problem and nobody is lobbying about it.

Trends that appear to be cooling

The SEC cyber disclosure regime. Indicator that turned: 29 mandatory Item 1.05 filings versus 50 voluntary Item 8.01 filings over two full years, with a pending petition (SEC File 4-856) to rescind Item 1.05 outright. Issuer behaviour has converged on the voluntary channel.

US federal cyber capacity. Indicator that turned: CISA headcount down roughly a third; CISA 2015 running on stopgaps since the late-2025 lapse; CIRCIA slipping twice.

Cyber insurance as a de facto security regulator. Indicator that turned: twelve consecutive quarters of cyber rate decline, with carriers now competing on broader coverage, expanded terms and lower deductibles — the exact inverse of the 2021–22 hard market when insurers effectively mandated MFA and EDR.

Ransom payment as the norm. Indicator that turned: payment rate at a possible all-time low of 28%, 69% of DBIR victims not paying, total on-chain payments down 8% to $820m — while claimed victims rose ~50%.

Trends that may reverse, and the mechanism

  • The soft cyber insurance market reverses on a single correlated-loss event: a hyperscaler or shared-SaaS compromise producing simultaneous claims across a book. The mechanism is aggregation, not frequency, and Marsh's own data on capacity abundance is the setup for it. Early indicator: any carrier publicly restating cyber reserves.
  • The US deregulatory drift reverses on a major incident with attributable regulatory failure. CISA budgets and CIRCIA timelines are politically reversible within one appropriations cycle. Early indicator: an SEC enforcement action for under-disclosure.
  • Platform consolidation reverses if a platform vendor suffers a catastrophic self-inflicted outage — CrowdStrike's July 2024 event is the existing proof of concept — or if antitrust review blocks a major deal. Early indicator: enterprise RFPs adding explicit vendor-diversity requirements.
  • The AI-security funding wave reverses with a general AI capex correction, which the FOMC has explicitly flagged as a financial-stability risk. Early indicator: down rounds or flat extensions in the 2026 agentic-security cohort.
  • The post-quantum mandate could be extended or rescinded by a subsequent administration; the 2030/2031 dates are executive, not statutory. Early indicator: OMB guidance slipping past its September 2026 deadline without a new date.

11. Risks and major uncertainties

Sector-specific risks.

  1. Correlated platform failure. Concentration into a handful of identity providers, cloud platforms and security agents means a single failure propagates across the economy. The sector's own consolidation thesis is also its largest systemic risk, and no vendor's marketing acknowledges this.
  2. Evidence-base capture. With CISA contracting, breach-notice vector disclosure at 24%, and the SEC regime deflating, the share of this sector's public evidence produced by parties with a commercial interest in alarm is rising. This dossier's own difficulty in sourcing the AI SOC section is a symptom.
  3. Regulatory whiplash. Four reporting clocks, one of which (SEC) may be rescinded, one of which (CIRCIA) has slipped twice, one of which (CRA) just started, one of which (NIS2) is two years late in a third of its jurisdiction. Compliance investment made against any one of these carries real timing risk.
  4. Capital cost. Sticky 3–4% inflation with a hawkish-leaning FOMC makes debt-financed consolidation and pre-revenue AI-security rounds materially more expensive to carry than the 2021 cohort assumed.
  5. Workforce pipeline collapse. Automating the Tier-1 analyst role removes the training ground for the senior analysts those same systems still require. This is a five-to-ten year risk that nobody's P&L captures.

Genuine unknowns — "we don't know" (answerable, currently unmeasured).

  • What fraction of deployed AI agents operate under scoped, revocable, audited credentials. Measurable; nobody has measured it.
  • Whether autonomous SOC systems have acceptable false-negative rates. Measurable by standard evaluation methods; no vendor publishes it and no independent body has tested it.
  • Whether AI has changed aggregate breach rates. The 2026 DBIR's observation window ends 2025-10-31 and structurally cannot answer this; the 2027 edition can.
  • Actual PQC deployment outside browser-to-CDN TLS. Cloudflare measures one leg; nobody measures code signing, PKI or embedded systems.
  • Current CISA headcount and advisory output. Last verified figures date to mid-2025.

"Nobody can know" (genuinely unknowable now).

  • When a cryptographically relevant quantum computer arrives. The early-2030s-to-mid-2040s range is honest; anyone narrowing it is selling something.
  • Whether a general defence against prompt injection exists. This is an open research question, not an engineering backlog item.
  • Whether offensive or defensive capability benefits more from AI. Both sides get the same tools; the asymmetries (defenders have ground truth, attackers need only one success) point in opposite directions and there is no basis for netting them out yet.
  • The true scale of undisclosed nation-state pre-positioning in critical infrastructure.

12. Scenarios to 2030

Base — "Consolidated core, contested edge." Security spending compounds at roughly the 10–11% Gartner models, reaching the mid-$300bn range by 2030. Three or four platforms take the majority of enterprise budget; identity is the control plane; AI security exists as a real but smaller category than forecast because hyperscalers bundle most of it. Regulatory reporting stabilises into a tolerable multi-clock routine. Breach counts stay flat, victim counts keep concentrating into platform events. Falsifiable early indicator: Palo Alto's NGS ARR tracking toward the $20bn FY2030 target within ±15% at the FY2028 mark, and CrowdStrike's six-plus-module attach exceeding 60%.

Upside — "Measurement arrives." CIRCIA finalises and produces the first compelled, structured, large-N incident dataset; the CRA Single Reporting Platform does the same for product vulnerabilities in the EU. Within three years there is an actual empirical basis for control efficacy, insurers reprice on evidence rather than on questionnaires, and the vendor-marketing distortion in this sector's evidence base materially reduces. Indicator: CISA or ENISA publishing aggregate, de-identified incident statistics from mandatory reports by end-2028.

Downside — "Capacity gap." Federal capacity keeps contracting, CISA 2015 is not durably reauthorised so private-to-government sharing degrades, CIRCIA is finalised but under-resourced, and the sector's shared evidence base becomes entirely vendor-supplied. Meanwhile third-party concentration keeps rising. Indicator: CISA advisory publication volume falling year-on-year through 2027, or a CISA 2015 lapse without immediate extension.

Disruption — "Agentic tempo breaks the model." AI-orchestrated campaigns scale as the Anthropic data suggests they might, mid-market organisations lose the protection of attacker labour scarcity, and human-speed incident response becomes structurally inadequate. The sector re-architects around automated containment and blast-radius limitation rather than detection. Indicator: a corroborated, multi-source, population-level rise in breach rates among sub-1,000-employee organisations, or the 2027 DBIR showing a step-change in intrusion-to-exfiltration times.

Regulatory — "Brussels sets the global baseline." CRA reporting produces usable data, NIS2 penalties land, and the EU regime becomes the de facto global standard by market-access leverage the way GDPR did, while the US regime continues to deflate. Product security becomes a market-access requirement rather than a differentiator. Indicator: the first NIS2 administrative fine against a named entity, and non-EU manufacturers adopting CRA conformity globally rather than maintaining two SKUs.

Failure — "Systemic aggregation event." A compromise of a shared identity provider, cloud control plane or widely-deployed security agent produces simultaneous loss across thousands of organisations, exceeding modelled insurance aggregates. The cyber insurance market hardens violently, consolidation is reframed as concentration risk, and a government backstop debate begins in earnest. Indicator: any cyber catastrophe bond triggering, or a major carrier restating cyber reserves.


13. Data gaps and limitations

What could not be verified within this research window.

  1. No independent corroboration of the AI-attack claims. Anthropic's September 2026 report is the load-bearing source for T-04-09 and T-04-11. CyberScoop's coverage is derivative and contains, by its own omission, no external expert commentary. Equivalent OpenAI and Google GTIG reports were not retrieved. Both trends are marked single_source.
  2. No independent adoption or efficacy data for the AI SOC category, at all. Every locatable source was vendor-produced or vendor-sponsored. T-04-19 is marked unverified with evidence quality 1. This absence is itself a finding.
  3. CISA current headcount and advisory output. The best figures available date to mid-2025 (~3,200 → ~2,200). The 2026 position is unknown.
  4. Debevoise 8-K tracker returned HTTP 403. The 29/50/5 filing counts were obtained via a secondary summary of the Debevoise post and should be re-verified directly against EDGAR full-text search before being used as a load-bearing figure.
  5. Aon's Q1 2026 cyber data is paywalled. Only the directional headline (rate declines moderating) is confirmed. Marsh's index is the only quantified cyber pricing source used.
  6. Okta and Zscaler current financials could not be retrieved from investor pages within this window; both entity records are marked unverified rather than estimated.
  7. CVE Program record counts. cve.org requires JavaScript and returned nothing; the CISA KEV JSON feed returned HTTP 403 through this environment's proxy. Vulnerability volume figures are therefore absent from this dossier rather than approximated.
  8. Google/Wiz deal completion status as of 2026-09-15 was not independently confirmed. The entity record reflects this.
  9. Web search budget was exhausted mid-research (shared session limit), curtailing planned work on Google GTIG zero-day counts, 2026 cybersecurity IPO activity, UK NCSC Annual Review figures, and the CVE Program funding position.

Where the numbers conflict (also recorded per-trend in contradictions[]):

  • Primary initial access vector: DBIR says vulnerability exploitation at 31% with credentials second; ENISA says phishing at ~60% and exploitation at 21.3%. Different populations (global IR-contributed breaches vs publicly reported EU incidents) and different definitions.
  • Third-party share of breaches: DBIR ~48–50%; ENISA supply chain 10.6%. Any-involvement versus primary-classification.
  • 2026 security market size: Gartner itself at $244.2bn (March) → $246.2bn (April) → $248.9bn (June). Same modeller, 2% per quarter.
  • US ransomware incidence: FBI IC3 3,611 complaints and $32.3m losses; Chainalysis $820m paid globally with claimed victims up ~50%. A measure of US reporting incompleteness.
  • Q-Day timing: early 2030s to mid-2040s in aggregate; near-term dates come from financially exposed non-specialists.

Non-US coverage. ENISA and the European Commission are cited directly for the EU. Japan is covered via an English-language Baker McKenzie Tokyo analysis of the Active Cyber Defense law; the primary Japanese-language NISC materials were not read and are registered as a monitorable source (S-04-21) rather than cited. No Chinese, Korean, Indian or Latin American primary sources were consulted — a real gap for a sector where China-nexus activity is a central concern and where India is a fast-growing demand market ($3.4bn forecast 2026).


14. Ranking scorecard

# Criterion Score Justification
1 speed_of_change 4 The competitive picture genuinely turned over in 2026 — CyberArk absorbed, Wiz absorbed, an entire AI-security category formed — but the top four vendors have been the top four for five years.
2 economic_importance 3 ~$249bn of end-user spending (Gartner estimate) is material but small against IT at $6.15tn; the sector's importance is protective and second-order, not GDP-weight.
3 capital_invested 4 ~$96bn of 2025 M&A and multi-billion venture flows, but heavily concentrated in three acquirers and distorted by AI labelling.
4 company_product_density 5 Several thousand distinct vendors, dozens of overlapping categories, and a new one (agent security) forming inside twelve months. Among the highest density of any sector.
5 regulatory_impact 5 Four active reporting regimes on incompatible clocks, EU infringement litigation, a dated post-quantum executive order with contractor flow-down, and Japan's ACD law. Rule-making determines outcomes here more than in almost any other sector.
6 consumer_impact 3 471.2m US victim notices in H1 2026 and $20.877bn of reported losses are real, but consumers buy almost nothing directly and have little agency. High exposure, low engagement.
7 strategic_importance 5 Nation-state pre-positioning in critical infrastructure, the post-quantum transition, and the security of AI systems are all first-order national-security questions.
8 intelligence_demand 5 Every board has a mandated cyber reporting line; CISOs are the most-surveyed buyer persona in enterprise IT. Demonstrated demand is unambiguous.
9 paid_research_opportunity 4 A large existing paid-research market (Gartner, Forrester, IDC, Omdia, Momentum Cyber) with established willingness to pay, but crowded and with high-quality free alternatives from CISA and ENISA.
10 data_availability 3 Genuinely excellent primary sources (KEV, EDGAR, IC3, ITRC, ENISA, CRA) sit alongside a vendor-marketing layer that dominates search results and a measurable decline in breach-notice transparency. Good data exists; it is not what surfaces.
11 cross_industry_influence 4 Sets constraints on cloud, AI deployment, finance, healthcare and manufacturing, and the CRA makes product security a market-access condition across all hardware and software. Influences rather than drives.

15. Sources

  1. "2026 Data Breach Investigations Report" — Verizon Business — https://www.verizon.com/business/resources/reports/dbir/ — 2026-05-19 — B
  2. "Software vulnerabilities overtake stolen credentials as top breach entry point, 2026 DBIR finds" — Verizon — https://www.verizon.com/about/news/breach-industry-wide-dbir-finds — 2026-05-19 — B
  3. "Verizon DBIR: Vulnerability exploitation is the dominant initial access vector" — Help Net Security (Zeljka Zorz) — https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/ — 2026-05-20 — B
  4. "ITRC: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year" — Identity Theft Resource Center — https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/ — 2026-07-22 — A
  5. "2025 Internet Crime Report" — FBI Internet Crime Complaint Center — https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf — 2026 (covering calendar 2025; exact release date not confirmed) — A
  6. "ENISA Threat Landscape 2025" — European Union Agency for Cybersecurity — https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf — 2025-10 — A
  7. "Fact Sheet: President Donald J. Trump Secures the Nation Against Advanced Cryptographic Attacks" — The White House — https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-secures-the-nation-against-advanced-cryptographic-attacks/ — 2026-06-22 — A
  8. "The White House's post-quantum executive order is an important milestone. It's time to get to work" — Cloudflare — https://blog.cloudflare.com/post-quantum-eo-2026/ — 2026-06-23 — B
  9. "Cyber Resilience Act — Reporting obligations" — European Commission, DG CNECT — https://digital-strategy.ec.europa.eu/en/policies/cra-reporting — 2026-09-11 — A
  10. "Preparing for the EU Cyber Resilience Act: Key Reporting Obligations From 11 September 2026" — Goodwin Procter — https://www.goodwinlaw.com/en/insights/publications/2026/09/alerts-lifesciences-technology-preparing-for-eu-cyber-resilience-act — 2026-09 — B
  11. "NIS2 enforcement enters a new phase: four states head to court" — Varthalitis — https://www.varthalitis.eu/p/nis2-enforcement-enters-a-new-phase — 2026-07-13 — B
  12. "CIRCIA, other big cyber rules expected to get finalized this fall" — Federal News Network — https://federalnewsnetwork.com/cybersecurity/2026/07/circia-other-big-cyber-rules-expected-to-get-finalized-this-fall/ — 2026-07 — B
  13. "Cybersecurity Incident Disclosure: Form 8-K Tracker (Two-Year Update)" — Debevoise & Plimpton — https://www.debevoisedatablog.com/2026/05/21/cybersecurity-incident-disclosure-form-8-k-tracker-two-year-update/ — 2026-05-21 — B (direct access returned HTTP 403; counts obtained via secondary summary — re-verify against EDGAR)
  14. "Joint Petition for Rulemaking to Amend the SEC Cybersecurity Rule (File 4-856)" — US Securities and Exchange Commission — https://www.sec.gov/rules-regulations/2025/05/joint-petition-rulemaking-amend-sec-cybersecurity-risk-management-strategy-governance-incident — 2025-05-22 — A
  15. "Global commercial insurance rates fall 6% in Q2 2026 — Global Insurance Market Index" — Marsh — https://www.marsh.com/en/corp/about/news/global-commercial-insurance-falls-6-percent-q2-2026.html — 2026-07-23 — A
  16. "Cyber rate drops slowing down in Q1 2026, says Aon" — Intelligent Insurer — https://www.intelligentinsurer.com/cyber-rate-drops-slowing-down-in-q1-2026-says-aon — 2026-05-12 — B (paywalled beyond headline)
  17. "Crypto Ransomware: 2026 Crypto Crime Report" — Chainalysis — https://www.chainalysis.com/blog/crypto-ransomware-2026/ — 2026-02-26 (updated 2026-03-04) — B
  18. "Countering misuse of AI: September 2026" — Anthropic — https://www.anthropic.com/threat-intelligence-report-september-2026 — 2026-09 — B
  19. "AI lets small actors run state-level hacking campaigns, Anthropic report finds" — CyberScoop (Greg Otto) — https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/ — 2026-09-10 — B
  20. "CSA Research Note: MCP Security Crisis — Systemic Design Flaws in AI Agent Infrastructure" — Cloud Security Alliance — https://labs.cloudsecurityalliance.org/research/csa-research-note-mcp-security-crisis-20260504-csa-styled/ — 2026-05-04 — B
  21. "Prompt injection still drives most agentic AI security failures in production" — Help Net Security / OWASP GenAI Security Project — https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/ — 2026-06-11 — B
  22. "Gartner's $248.9B security forecast makes securing AI the only segment accelerating through 2030" — Software Strategies Blog (Louis Columbus), citing Gartner G00855892 dated 2026-06-25 — https://softwarestrategiesblog.com/2026/07/06/gartner-2q26-information-security-forecast-securing-ai-2030/ — 2026-07-06 — C
  23. "Gartner Forecasts Information Security Spending in India to Total $3.4 Billion in 2026" — Gartner — https://www.gartner.com/en/newsroom/press-releases/2026-03-09-gartner-forecasts-information-security-spending-in-india-to-total-3-billion-us-dollars-in-2026 — 2026-03-09 — B
  24. "CrowdStrike Reports Second Quarter Fiscal Year 2027 Financial Results" — CrowdStrike Holdings — https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-reports-second-quarter-fiscal-year-2027-financial — 2026-08-26 — A
  25. "Palo Alto Networks Reports Fiscal Fourth Quarter and Fiscal Year 2026 Financial Results" — Palo Alto Networks — https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-reports-fiscal-fourth-quarter-and-fiscal-year-2026-financial-results — 2026-09-01 — A
  26. "Palo Alto Networks Completes Acquisition of CyberArk to Secure the AI Era" — Palo Alto Networks — https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era — 2026-02-11 — A
  27. "Palo Alto Networks Introduces Idira" — Palo Alto Networks — https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-introduces-idira--the-next-generation-identity-security-platform-built-for-the-ai-enterprise — 2026-05-12 — B (vendor marketing; 109:1 identity ratio marked marketing)
  28. "$3.6 Billion in Crunchbase funding, $96 Billion in M&A, and 10 Agentic AI security startups Reshaping 2026" — Software Strategies Blog (Louis Columbus), aggregating Crunchbase and Momentum Cyber — https://softwarestrategiesblog.com/2026/03/28/agentic-ai-security-startups-funding-mna-rsac-2026/ — 2026-03-28 — C
  29. "CISA workforce cut by nearly one-third so far" — Cybersecurity Dive — https://www.cybersecuritydive.com/news/cisa-departures-trump-workforce-purge/749796/ — 2025-06-04 — B
  30. "Trump admin will push for 'long-term' reauthorization of key cyber data-sharing law" — Nextgov/FCW (Edward Graham, David DiMolfetta) — https://www.nextgov.com/cybersecurity/2026/05/trump-admin-will-push-long-term-reauthorization-key-cyber-data-sharing-law/413395/ — 2026-05-07 — B
  31. "Japan's New Active Cyber Defense Law: Impact on Businesses" — Baker McKenzie (Takase, Tatsuno, Sharman et al.) — https://connectontech.bakermckenzie.com/japans-new-active-cyber-defense-law-impact-on-businesses/ — 2026-01-22 — B (regional source for Japan)
  32. "Cyber Europe 2026: All eyes on the EU's collective response and resilience" — ENISA — https://www.enisa.europa.eu/news/cyber-europe-2026-all-eyes-on-the-eus-collective-response-and-resilience — 2026-06-11 — A
  33. "Post-Quantum Cryptography Timelines: When Will Organizations Migrate?" — The Quantum Insider (Mohib Ur Rehman) — https://thequantuminsider.com/2026/08/07/post-quantum-cryptography-timelines/ — 2026-08-07 — C
  34. "ISC2 Study Finds Cybersecurity Budget Constraints Remain, But Do Not Worsen, While Skill Needs Grow" — ISC2 — https://www.isc2.org/Insights/2025/12/ISC2-Publishes-2025-Cybersecurity-Workforce-Study — 2025-12-04 — B
  35. Crunchbase News, cybersecurity section (incl. "So Far, 2026 Is A Solid Year For Cybersecurity Startup Funding", 2026-07-10; "AI Seed Investors Flock To Cybersecurity", 2026-07-24; Socure $156m at $5.2bn, 2026-08-27) — Crunchbase — https://news.crunchbase.com/sections/cybersecurity/ — 2026-08-27 — B
  36. "GitGuardian raises $50M to expand nonhuman identity and AI agent security" — SiliconANGLE — https://siliconangle.com/2026/02/11/gitguardian-raises-50m-expand-non-human-identity-ai-agent-security/ — 2026-02-11 — B
  37. "Known Exploited Vulnerabilities Catalog" — CISA — https://www.cisa.gov/known-exploited-vulnerabilities-catalog — accessed 2026-09-15 — A (JSON feed returned HTTP 403 through this environment's proxy; no counts extracted)
Research provenance
Source artifact
02-dossiers/04-cybersecurity.md
Corpus date
15 September 2026
Prepared for this site
16 September 2026
Site publication
18 September 2026
Verification
Inherited; not fully rechecked