Six alternative branches. These are subjective probabilities from the seed, not observed frequencies or investment recommendations.
Why this trend
It is where the sector's capital, its consolidation and its systemic risk all converge: Palo Alto's $25bn acquisition of CyberArk, $32bn for Wiz, identity as the control plane for agent access. It is also where the corpus's central methodological finding bites hardest — the load-bearing 109:1 machine-to-human identity ratio is vendor telemetry with no independent verification, so the sector's most-funded thesis rests on a number nobody can check.
Load-bearing assumption
Machine and agent identities can be brought under scoped, revocable, audited credentials at roughly the rate they are being created.
Preconditions
- Capability
clear for human identity, unproven for agent identity — no general defence against prompt injection exists
- Economics
clear — CrowdStrike $5.84bn ARR (+25%), Palo Alto NGS ARR $9.10bn, though substantially inorganic
- Supply
clear — software, not physical
- Demand
clear — identity is the line item CISOs fund first
- Permission
partial — four incompatible reporting clocks, one regulator (SEC) considering retreat
- Capital
clear but repriced — pre-revenue AI-security rounds carry a cost the 2021 cohort never faced
Consolidated core, contested edge
Security spending compounds at roughly the 10-11% Gartner models, reaching the mid-$300bn range by 2030. Three or four platforms take the majority of enterprise budget with identity as the control plane; AI security exists as a real but smaller category than forecast because hyperscalers bundle most of it. Regulatory reporting stabilises into a tolerable multi-clock routine. The decelerating element is measurable defensive performance: patching throughput and KEV remediation, which got worse in 2026, do not recover.
Mechanism
Buyers consolidate onto fewer platforms because the integration cost of best-of-breed exceeds its marginal efficacy, which is the same absorption cycle that took antivirus to endpoint protection to EDR to XDR. Venture keeps funding the next category anyway, because the acquirers pay for it. Machine identity governance ships as a platform module rather than a standalone category. Nothing in the operational metrics improves, because the binding constraint is throughput, not tooling.
Preconditions, early indicators and assumptions
- Calibration Basis
base_rate
- Preconditions
- Platform ARR growth tracking the stated multi-year targets within a reasonable band
- No catastrophic self-inflicted platform outage
- Reporting obligations stabilising rather than multiplying further
- Early Indicators
- Indicator
Palo Alto NGS ARR at or above $11.5bn for FY2027 (forecast F-04-07)
- Source
S-04-13 security pure-play investor relations, quarterly
- Would Be Visible By
2027-09
- Indicator
CrowdStrike customers on six or more modules exceeding 60%
- Source
S-04-13 CrowdStrike IR, quarterly
- Would Be Visible By
2028-06
- Indicator
The 2027 DBIR reporting vulnerability exploitation as the leading initial-access vector for a second edition (forecast F-04-03)
- Source
S-04-06 Verizon DBIR, annual
- Would Be Visible By
2027-07
- Affected Industries
- 04
- 02
- 01
- 07
- What Businesses Should Do
Treat identity consolidation as a concentration decision, not just a procurement one: write the failure mode into the contract. Fund patching throughput before funding another detection tool — it is the one independently measured metric that moved, and it moved backwards.
- Precedence Note
Distinguished from downside by the state of the public evidence base: base has mandatory reporting stabilising; downside has it contracting while vendor-supplied evidence takes over.
- Would Change Our Mind
CISA advisory publication volume falling year on year through 2027 alongside a CISA 2015 lapse.
- Assumptions
- Text
Consolidation improves outcomes enough that buyers keep consolidating, rather than merely improving procurement economics.
- Confidence
medium
- Load Bearing
true
- Basis
T-04-04; NGS ARR and 'platformisation customer' are company-defined metrics whose definitions have moved
- If Wrong
Buyers re-diversify on concentration-risk grounds and the revenue thesis weakens without the threat thesis changing.
- Text
Identity spending tracks the machine-identity population, which vendor telemetry puts at 109:1 against humans.
- Confidence
low
- Load Bearing
false
- Basis
T-04-01 evidence is labelled marketing; there is no independent verification of the ratio
- If Wrong
The category is smaller than modelled and growth rates disappoint without any change in threat.
Measurement arrives
CIRCIA finalises and produces the first compelled, structured, large-N incident dataset; the CRA Single Reporting Platform does the same for product vulnerabilities in the EU. Within three years there is an empirical basis for control efficacy. Insurers reprice on evidence rather than questionnaires, and the vendor-marketing distortion in the sector's evidence base materially reduces — which is a commercial threat to several categories and a public good.
Mechanism
Two mandatory regimes with fixed clocks generate structured data at national scale: CIRCIA across 16 sectors and roughly 300,000 entities, and the CRA's 24-hour, 72-hour and 14-day reporting to national CSIRTs and ENISA. Regulators publish aggregate de-identified statistics because that is what makes the burden politically defensible. Buyers and insurers start asking vendors for efficacy evidence against a public baseline, which the vendors cannot manufacture.
Preconditions, early indicators and assumptions
- Calibration Basis
analogue
- Preconditions
- CIRCIA reaching a final rule
- The CRA Single Reporting Platform operating at volume rather than nominally
- At least one regulator publishing aggregate statistics from mandatory reports
- Early Indicators
- Indicator
CIRCIA final rule published in the Federal Register with a stated effective date (forecast F-04-01)
- Source
S-04-12 Federal Register, daily
- Would Be Visible By
2027-12
- Indicator
CISA or ENISA publishing aggregate de-identified incident statistics derived from mandatory reports
- Source
S-04-01 CISA and S-04-03 ENISA, irregular
- Would Be Visible By
2028-12
- Indicator
Marsh cyber rate declines reversing as carriers reprice on evidence rather than capacity
- Source
S-04-09 Marsh Global Insurance Market Index, quarterly
- Would Be Visible By
2028-06
- Affected Industries
- 04
- 02
- 07
- 01
- What Businesses Should Do
Build your incident reporting pipeline once, against the strictest clock (24 hours), and map the others onto it. If mandatory datasets arrive, the organisations that can answer 'what actually works' from public data will negotiate insurance and vendor contracts from a much stronger position.
- Precedence Note
Requires published aggregate statistics, not merely a rule in force. A rule that collects data nobody sees stays in base.
- Would Change Our Mind
CIRCIA finalising and CISA declining to publish any aggregate statistics for two years.
- Assumptions
- Text
Regulators publish aggregate statistics from mandatory reports rather than keeping them internal.
- Confidence
low
- Load Bearing
true
- Basis
The HHS OCR breach portal is the working model; CIRCIA has no equivalent publication commitment
- If Wrong
The data is compelled but invisible, and the evidence base stays vendor-supplied — which is the downside branch.
- Text
CISA retains the capacity to run a 300,000-entity reporting regime.
- Confidence
low
- Load Bearing
false
- Basis
T-04-17; CISA headcount down roughly a third on figures last verified in mid-2025
- If Wrong
The regime exists but under-delivers, which looks like base rather than upside.
Capacity gap
Federal capacity keeps contracting, CISA 2015 is not durably reauthorised so private-to-government sharing degrades, and CIRCIA is finalised but under-resourced. Breach-notice vector disclosure, already at a record-low 24%, falls further. The sector's shared evidence base becomes almost entirely vendor-supplied at exactly the moment third-party concentration is rising, so nobody can independently measure the concentration risk everyone is accumulating.
Mechanism
Appropriations pressure reduces CISA advisory output and staffing. Issuers converge on voluntary Item 8.01 filings over mandatory Item 1.05 ones, and the pending petition to rescind Item 1.05 removes even that. State breach-notice laws do not require vector disclosure, so the share keeps falling. Vendors become the only source of vector and efficacy data, and their incentive is alarm. Insurers, twelve quarters into softening, have no evidence base on which to re-harden until a loss event forces it.
Preconditions, early indicators and assumptions
- Calibration Basis
base_rate
- Preconditions
- CISA advisory volume falling year on year
- Item 1.05 filings declining relative to Item 8.01
- Breach-notice vector disclosure falling below 24%
- Early Indicators
- Indicator
Form 8-K Item 1.05 filings in calendar 2027 fewer than in calendar 2026
- Source
S-04-04 SEC EDGAR full-text search, realtime
- Would Be Visible By
2028-02
- Indicator
ITRC reporting breach-notice vector disclosure below 24% for a half-year period
- Source
S-04-07 ITRC, quarterly
- Would Be Visible By
2027-09
- Indicator
CISA advisory publication volume declining year on year
- Source
S-04-01 CISA advisories, daily
- Would Be Visible By
2027-12
- Affected Industries
- 04
- 02
- 07
- 01
- What Businesses Should Do
Assume the public evidence base degrades and build your own: your incident data, your patch throughput, your third-party inventory. Treat any vendor statistic without a published methodology as marketing, including the ones that support your budget request.
- Precedence Note
Distinguished from failure by whether a loss event has occurred. Downside is the evidence base degrading quietly; failure is a correlated loss that exceeds modelled aggregates.
- Would Change Our Mind
CIRCIA finalising on schedule with funded implementation and CISA advisory volume rising.
- Assumptions
- Text
US federal cyber capacity keeps contracting through at least one more appropriations cycle.
- Confidence
medium
- Load Bearing
true
- Basis
T-04-17; CISA headcount figures last verified mid-2025 (~3,200 to ~2,200) and the 2026 position is unknown
- If Wrong
Capacity is restored, mandatory reporting delivers, and mass moves to upside.
- Text
SEC Item 1.05 continues to deflate into voluntary Item 8.01 filings.
- Confidence
medium
- Load Bearing
false
- Basis
T-04-16; 29 mandatory versus 50 voluntary filings over two years, with petition 4-856 pending
- If Wrong
The mandatory channel recovers and one leg of the evidence base holds.
Agentic tempo breaks the model
AI-orchestrated campaigns scale as the Anthropic data suggests they might — 13-agent collection fleets, 2,100+ tokens across 40+ tenants in 34 hours, intrusion to bulk exfiltration in two to three hours. Mid-market organisations lose the protection of attacker labour scarcity. Human-speed incident response becomes structurally inadequate and the sector re-architects around automated containment and blast-radius limitation rather than detection.
Mechanism
Attack breadth decouples from attacker headcount, so the population of targets worth attacking expands to include organisations that were previously uneconomic. The MCP and agent-authorisation layer — funded at roughly $40m across the named startups against an estimated 200,000 vulnerable instances — is the technical chokepoint and it is two orders of magnitude under-capitalised relative to its exposure. Defenders respond by moving the control from detection to standing-privilege elimination, which is the identity thesis arriving through the back door.
Preconditions, early indicators and assumptions
- Calibration Basis
analogue
- Preconditions
- A corroborated, multi-source rise in breach rates among sub-1,000-employee organisations
- Independent corroboration of the agentic tempo claims from a second AI provider or a national CSIRT
- Prompt injection remaining without a general defence
- Early Indicators
- Indicator
An MCP-related vulnerability added to the CISA KEV catalogue (forecast F-04-08)
- Source
S-04-02 CISA KEV, weekly
- Would Be Visible By
2027-12
- Indicator
The 2027 DBIR showing a step-change in intrusion-to-exfiltration times
- Source
S-04-06 Verizon DBIR, annual
- Would Be Visible By
2027-07
- Indicator
A second documented autonomous-agent intrusion at a named third party (forecast F-01-07)
- Source
S-04-01 CISA advisories and S-04-16 CSA, irregular
- Would Be Visible By
2027-12
- Affected Industries
- 04
- 01
- 02
- 07
- What Businesses Should Do
Reduce blast radius rather than adding detection: scope and expire every non-human credential, and assume any agent that reads attacker-controlled content is compromisable. The 61% standing-privilege figure is vendor telemetry, but the direction is not in dispute and the remediation is cheap relative to the exposure.
- Precedence Note
Distinguished from failure by whether losses correlate. Disruption is many independent organisations compromised faster; failure is one shared platform compromising thousands simultaneously.
- Would Change Our Mind
The 2027 DBIR showing intrusion-to-exfiltration times unchanged, with no independent corroboration of the agentic tempo claims.
- Assumptions
- Text
The agentic tempo observed in one provider's telemetry generalises to the population.
- Confidence
low
- Load Bearing
true
- Basis
T-04-09 is marked single_source; Anthropic's September 2026 report has no independent corroboration published and equivalent OpenAI and Google GTIG reports were not retrieved
- If Wrong
The branch is a single vendor's visibility mistaken for a population fact, and its mass returns to base.
- Text
No general defence against prompt injection emerges.
- Confidence
medium
- Load Bearing
false
- Basis
Dossier 04 §11 — an open research question, not an engineering backlog item
- If Wrong
The agent attack surface narrows sharply and the branch weakens.
Brussels sets the global baseline
CRA reporting produces usable data, NIS2 penalties land, and the EU regime becomes the de facto global standard through market-access leverage the way GDPR did, while the US regime continues to deflate. Product security becomes a market-access requirement rather than a differentiator, and non-EU manufacturers adopt CRA conformity globally rather than maintaining two product lines.
Mechanism
CRA manufacturer obligations, live since 2026-09-11, generate 24-hour, 72-hour and 14-day reports through the Single Reporting Platform, with open-source stewards joining from 2027-12-11. The Commission's July 2026 referral of Ireland, Spain, France and the Netherlands to the Court of Justice forces transposition, and the first named-entity fines establish that the regime is real. Manufacturers conclude that a single compliant product line is cheaper than two, so the EU standard exports without any non-EU legislation.
Preconditions, early indicators and assumptions
- Calibration Basis
base_rate
- Preconditions
- No deferral of CRA obligations
- At least one named-entity NIS2 administrative fine
- Non-EU manufacturers adopting CRA conformity globally rather than regionally
- Early Indicators
- Indicator
An EU member-state competent authority publicly disclosing a NIS2 administrative fine against a named entity (forecast F-04-02, resolution gap)
- Source
S-04-03 ENISA and S-04-10 European Commission, irregular
- Would Be Visible By
2027-12
- Indicator
ENISA or the Commission publishing CRA Single Reporting Platform volumes
- Source
S-04-10 European Commission CRA reporting portal, irregular
- Would Be Visible By
2028-06
- Indicator
EUVD and NVD enrichment divergence widening, indicating fragmentation in vulnerability coordination
- Source
S-04-11 European Vulnerability Database, daily
- Would Be Visible By
2027-12
- Affected Industries
- 04
- 02
- 03
- 13
- 09
- What Businesses Should Do
If you ship products into the EU, the 24-hour early-warning clock is already running — build to it and use it everywhere. Watch the open-source steward obligations landing 2027-12-11; they reach maintainers who have no compliance function at all.
- Precedence Note
Regulatory outranks base when an enforcement action lands, even if spending patterns look base-like. Obligations in force without enforcement stay in base.
- Would Change Our Mind
Two years of CRA operation with no published report volumes and no NIS2 fine against a named entity.
- Assumptions
- Text
EU enforcement against named entities becomes public, rather than being handled confidentially as several critical-infrastructure supervisors prefer.
- Confidence
low
- Load Bearing
true
- Basis
No registry source consolidates NIS2 enforcement; this is recorded as a resolution gap on forecast F-04-02
- If Wrong
The regime binds but is unobservable, which functionally collapses this branch into base.
- Text
Manufacturers choose one global product line over an EU-specific one.
- Confidence
medium
- Load Bearing
false
- Basis
The GDPR analogue; the counter-example is app-store economics, which fragmented by jurisdiction inside nine months (macro addendum 2)
- If Wrong
The EU standard stays regional and does not export.
Systemic aggregation event
A compromise of a shared identity provider, cloud control plane or widely deployed security agent produces simultaneous loss across thousands of organisations, exceeding modelled insurance aggregates. The cyber insurance market hardens violently after twelve consecutive quarters of softening; consolidation is reframed from efficiency to concentration risk; a government backstop debate begins in earnest. The sector's own consolidation thesis turns out to have been its largest systemic risk.
Mechanism
Concentration into a handful of identity providers, cloud platforms and security agents means a single failure propagates across the economy rather than across a customer list. The mechanism is aggregation, not frequency: carriers priced a book on independent losses and receive correlated ones. ITRC's H1 2026 data already shows the shape — a single Instructure Canvas event accounting for 275 million of 471.2 million victim notices. CrowdStrike's July 2024 outage is the existing proof of concept for propagation without an adversary.
Preconditions, early indicators and assumptions
- Calibration Basis
base_rate
- Preconditions
- Continued concentration into a small number of identity and platform providers
- Insurance capacity remaining abundant and terms broad until the event
- No mandated diversity requirement in enterprise procurement
- Early Indicators
- Indicator
Any cyber catastrophe bond triggering, or a major carrier publicly restating cyber reserves
- Source
S-04-09 Marsh Global Insurance Market Index, quarterly
- Would Be Visible By
2028-12
- Indicator
ITRC reporting supply-chain victim notices above 280.6m for a half-year period (forecast F-04-05)
- Source
S-04-07 ITRC, quarterly
- Would Be Visible By
2027-09
- Indicator
Enterprise RFPs adding explicit vendor-diversity requirements, visible in public-sector solicitations
- Source
S-04-20 UK NCSC and national guidance, weekly
- Would Be Visible By
2028-06
- Affected Industries
- 04
- 02
- 01
- 07
- 09
- What Businesses Should Do
Know which single provider failure takes your business offline, and price the alternative before you need it. Ask your insurer how it models aggregation across your own vendor stack; if it cannot answer, that is the finding.
- Precedence Note
Failure outranks all other branches on occurrence. Disruption becomes failure at the point where losses are correlated rather than independent.
- Would Change Our Mind
A large shared-platform compromise occurring and being absorbed within modelled aggregates, which would show the concentration risk is priced.
- Assumptions
- Text
Insurance aggregates are modelled on independent rather than correlated losses, so a shared-platform event exceeds them.
- Confidence
medium
- Load Bearing
true
- Basis
T-04-18 and S-04-09; twelve consecutive quarterly cyber rate declines with carriers competing on broader coverage and lower deductibles
- If Wrong
The event is absorbed, the market does not harden, and the branch's consequence disappears even if the event occurs.
- Text
Concentration continues rather than reversing on concentration-risk grounds before an event occurs.
- Confidence
medium
- Load Bearing
false
- Basis
T-04-04; roughly $96bn of 2025 sector M&A with three acquirers accounting for $72bn
- If Wrong
The exposure shrinks ahead of the event and the loss is smaller.
Additional scenario notes
- Probabilities Sum
1
- What Must Be True To Grow
- Machine and agent identities come under scoped, revocable, audited credentials at roughly the rate they are created
- Platform consolidation continues to improve outcomes rather than only procurement economics
- Mandatory reporting regimes produce data rather than only obligations
- Security budgets keep growing at double digits while headcount does not, so the money keeps going into software
- What Could Stop It
- Evidence-base capture — with CISA contracting, vector disclosure at 24% and the SEC regime deflating, the share of public evidence produced by parties with a commercial interest in alarm is rising
- Correlated platform failure — the sector's consolidation thesis is also its largest systemic risk
- Regulatory whiplash — four reporting clocks, one possibly rescinded, one slipped twice, one just started, one two years late in a third of its jurisdiction
- Attention withdrawal — the autonomous AI SOC category has no independent adoption or efficacy data at all, which is how categories deflate
- Workforce pipeline collapse — automating Tier-1 removes the training ground for the seniors the systems still require
- Uncertain Assumptions
- That machine identities outnumber humans 109:1 — vendor telemetry with no independent verification
- That 61% of privileged access is granted as standing privilege — same source, same limitation
- That agentic intrusion tempo generalises beyond one provider's visibility — T-04-09 is marked single_source
- That roughly 200,000 vulnerable MCP instances exist — modelled from package-download telemetry by a commercial scanner vendor, not enumerated
- Authored
2026-09-15