Protection Matters
Cybersecurity’s Winners and Losers
Nuance has not been an especially strong suit of the AI Trade to date.
Ask anyone over the past two months about what the rise of agentic coding agents means for cybersecurity and they’ll likely tell you it’s going to result in an explosion of demand. And they’re probably right – after all, agentic AI coding getting better has correlated pretty much 1:1 with frightening cybersecurity breaches increasing in frequency.
That was distinctly not the case just six short months ago.
In Q1, we watched the market punish cybersecurity stocks so aggressively that we were left searching for adjectives to describe the phenomenon.
On January 24th, we found one:
Since then, the market has rewarded us for opting to go with the obvious (“In the immediate term, supercharged agentic hacking is probably a good thing for cybersecurity stocks”) instead of the convoluted (“Here’s my 40 point explanation, relying on 8 unique predictions about the future, as to why SaaS will broadly be fine”).
We dove deeper into the AI-related upside for cybersecurity names, such as Cloudflare (NET US), in sections of Agentic Utilities in March. A couple weeks later, most of them went on a tear. And a tear that was resilient against the momentum bloodshed relative to AI infrastructure and semis.
Now, contrary to the days when cybersecurity was yet another baby in a whole lot of unwanted bathwater, shares of companies that can reasonably claim to defend you against the coming wave of frighteningly effective bad actors have outperformed.
But we don’t want to suffer from the market version of Gell-Mann Amnesia – you know the one, where you see a selloff and go “It’s crazy the market can get this dislocated and create such obvious mispricing” and then never wonder if the same observation would apply at any point during the rally.
So we’re going beyond just the agentic utility angle and determining who’s best insulated from AI risks, who can reap the most of the coming boom in security spending and who should be feeling a little… insecure.
Who’s Got Protection, Who Gets Screwed, in Cybersecurity
With security back in vogue, we believe the market has done a wholesale discounting of the fears that took the sector out of favor in the first place. While that’s mostly correct, in our view, we believe there’s a promising setup from here to go long still underappreciated AI/cyber winners (either AI for cybersecurity or cybersecurity against AI) and short participants of the rally that haven’t proven they’re actually resilient to the threat.
While it may not have been obvious to casual observers earlier in the year that immediate cybersecurity demand would be positively impacted by agentic AI improving, we’ve now crossed the Rubicon. Since agentic coding agents debuted, and with their continued improvements, weekly cyberattacks per organization have steadily risen (after a plateau in 2022-2023).
Anyone paying attention can see the trend.
OpenAI reported recently that its agents had escaped confinement, hacked Hugging Face, and tried to infect projects on GitHub. The agent exploited a “zero day” vulnerability in third-party software that had apparently not yet been discovered by any of the vulnerability management incumbents. It snuck past traditional cyber defenses and orchestrated a sophisticated campaign. It accessed the internet and hacked Hugging Face, an AI tools company with information the agent wanted.
In response to the news that OpenAI’s rogue agent had become a bad actor, Hugging Face announced that (due to guardrails), they were forced to fight back using a Chinese open-source model.
The properties and capabilities that made a Chinese open-source model the right tool for Hugging Face also make it a game-changer for would-be attackers. A new era of AI-enabled, semi- and fully-autonomous cyberattacks will only increase demand for the products of most leading public cybersecurity vendors.
Anthropic didn’t do much to quell any potential fears that this might have just been an isolated incident – announcing not one but three real-world incidents occurring in their cybersecurity evals. In summary:
It doesn’t stop there, either. Iranian cyberattackers breached American water systems. Hackers are stealing Bitcoin from cold storage crypto wallets.
It’s clear that there are enormous opportunities for most cybersecurity companies in the AI era. Customers are redirecting budgets toward IT security. At the same time, we’ve seen the wholesale threat of commoditization from AI loom.
Our view is that there will be a stark contrast between winners and losers in the space, and it doesn’t take much digging to figure out who they are.
Discerning Winners and Losers
Our thesis regarding the winners and losers is best summed up in three key points:
1) In the near term, AI will create a cybersecurity boom as models uncover an avalanche of existing vulnerabilities, bad actors are super charged, and AI increases software creation, complexity, and attack surfaces faster than it eliminates threats. AI has the potential to produce Log4J-scale incidents with alarming frequency, meaning that fear, remediation work, and proactive resiliency efforts drive larger cybersecurity budgets and strong quarters.
2) Rising cybersecurity demand from AI does not translate evenly to durable vendor share across the industry. The size of the opportunity will result in new, AI-native entrants and will also incentivize existing platforms to offer solutions.
3) AI will commoditize products that produce an answer while strengthening products that enforce decisions or autonomously solve issues. For some companies, the threat from competitors will be compounded by the threat of having their product torn out and replaced (either added to an enterprise suite by another company or done internally). The safest from disruption will be companies that own something AI cannot easily or readily reproduce. That can be an inline enforcement point, telemetry, hardware, data, or distribution. The most vulnerable cybersecurity companies sell reports, scores, alerts, or analysis using commoditized data about the past, as the number of novel threats that emerge over the next decade will dwarf the number that have been cumulatively amassed since the dawn of the internet.
It’s easy to claim that any company selling a cybersecurity solution will see huge benefits. But, that discounts the reality of what’s going on and fails to capture the nuance of how AI is changing the industry.
We applied our framework to public companies across the sector, to determine where we believe the most upside (and least risk) for cybersecurity exposure lives. When we split up the broader cybersecurity ecosystem into five broad categories, it becomes a lot clearer where the most challenged companies sit.
While all of these areas are likely to see an increase in demand that’s at least tangentially associated with AI, factoring in competitive threats, commoditized analysis/human labor, the value of hard enforcement and recovery infrastructure leaves us with a better picture.
Names focused on vulnerability management are the most at risk of both being replaced by AI and having their incumbent status disrupted by new entrants (whether startups or players expanding their offerings). LLMs are already being used by vendors to discover new vulnerabilities.
On the other end of the spectrum, network security hardware, coordination, and enforcement-oriented platforms retain a moat that is ultimately difficult for competitors to challenge and for AI to replace in any meaningful way. All while benefitting from a near term boom in demand.
Below the paywall, we go deep into the security landscape to detail a long/short basket strategy as well as some individual names and pairs.
Our work ultimately led us to again collaborate with investigative journalists Hunterbrook to interview more than a dozen cybersecurity experts. And seek out answers by attempting to vibe code a functional alternative to an existing cybersecurity product to determine how exposed the company offering it is.











