I. Quick Summary of the Key Points
Half a year ago, the entire market was worried that AI would take away the business of the SaaS industry, and even the cybersecurity sector was feared to be directly replaced by large models. However, in 2026, the cybersecurity sector of the U.S. stock market became the biggest dark horse in the entire market: the sector’s ETFs increased by more than 40% for the year, and the stock prices of leading companies nearly doubled. CrowdStrike, the cybersecurity giant that was once involved in a widespread Windows blue-screen error, even reported the fastest growth in orders since its establishment. Essentially, people had completely misunderstood the relationship between AI and cybersecurity: AI has not only not eliminated cybersecurity but has instead increased the demand for it several times over. AI security has evolved from a theoretical topic to a real market segment where large companies are spending substantial amounts of money. Cybersecurity has become the third AI application to generate revenue in the tens of billions of dollars, following AI-powered coding and video creation.
II. Detailed Analysis
1. Fears of AI Taking Away Jobs Half a Year Ago; Now Cybersecurity Is the Hottest Sector in the U.S. Stock Market
The contrast in this market trend is astonishing: In February 2026, after OpenAI launched a large security model that could automatically scan code for vulnerabilities, all cybersecurity stocks fell by more than 10% in one day. Everyone thought that AI would handle security issues on its own, and no one would need to spend money on cybersecurity services anymore. However, six months later, the situation reversed completely. The cybersecurity sector grew by more than 50% on average, with Fortinet rising 117% and Palo Alto rising 107%. Even CrowdStrike, which was previously the least favored, saw its stock price soar by 20% on the day its second-quarter financial results were released. Most notably, as a mature company with annual service fees of nearly $6 billion, CrowdStrike’s new annual service fee growth rate jumped from 32% in the first quarter to 51%. This is almost unprecedented in the entire SaaS industry, where growth rates usually stabilize at around 30% for established companies.
2. The New Money for Cybersecurity Comes From Three Different Sources
Many people think that the rise in cybersecurity prices is due to speculation, but the growth actually comes from real corporate procurement orders, with clear sources of funding:
- New Budgets: Employees now freely share company confidential documents with ChatGPT, and there were no corresponding security products to address this issue before. CrowdStrike’s new “AI tool monitoring” service has tripled the total service fees from paid users in just three months, with even global banks placing large orders in the tens of millions of dollars to identify who is leaking sensitive data to large models. This is entirely new spending.
- Expansion of Existing Business: AI agents (automated AI workers) are being deployed by companies, increasing the number of accounts that need to be managed. Each AI agent needs to log into systems, access databases, and modify business data, effectively creating hundreds of thousands or even millions of “invisible new employees” that require security management, expanding the market for identity and cloud security by more than 30%.
- Changed Payment Models: Cybersecurity companies have changed their pricing models, increasing customer spending by 40%. Previously, adding new features required a lengthy internal approval process. CrowdStrike’s “universal prepaid card” model allows companies to set a total budget and then easily activate additional features such as AI monitoring and identity management, matching the fast pace of the AI era. Customers using this model are spending 40% more on average.
3. Everyone Was Wrong: Large Models Cannot Take Away Cybersecurity’s Business
Many people assumed that AI would replace cybersecurity companies because it could find vulnerabilities, but they overlooked two key barriers:
- Access to Security Data: Cybersecurity companies have already installed lightweight tools on every employee’s computer and server, allowing them to immediately detect unauthorized access and data leaks. Large models cannot simply install monitoring on thousands of devices without the company’s cooperation.
- Control Over Critical Operations: Detecting hacker attacks is just the first step; to prevent them, companies need to disconnect infected servers and lock down compromised accounts. Any mistake in these operations can cripple the entire business. The widespread Windows blue-screen errors caused by CrowdStrike were due to such operational errors. No company would entrust such critical operations to a third-party model company like OpenAI. Cybersecurity companies have spent years establishing complex systems for permission control and error tracking, which would be too costly for large models to replicate.
4. The Rise in Stock Prices Is Not About Performance but About a Fundamental Change in the Industry
The industry has reached a new consensus: AI and cybersecurity are not in a competitive relationship but work together. Large models help with vulnerability analysis and alert detection, reducing the cost for cybersecurity companies. In turn, cybersecurity companies have become a necessary checkpoint for all AI applications. Cybersecurity is now essential for businesses using AI, as it ensures that AI functions within acceptable security boundaries. The high valuation of cybersecurity stocks reflects the core value of this position in the future AI ecosystem.