Cybersecurity is one of the most durable growth categories in enterprise technology. Corporate cybersecurity budgets have grown at roughly 8–12% per year for over two decades, through recessions, expansions, and every intervening cycle. The reasons for the durability are structural: the threat landscape expands independently of the economic cycle, and the cost of failure — data breach, ransomware, regulatory penalty — is asymmetric enough that under-investment is rarely a viable option even in the tightest budget environments. Understanding the sector requires understanding why the growth is durable and why the returns to investors have been more variable than the top-line growth suggests.

The demand pattern

Cybersecurity spending grows through every phase of the economic cycle. Recessions may slow the growth rate somewhat but rarely produce absolute declines. This is unusual — most enterprise IT categories see meaningful cyclicality — and reflects the specific asymmetry of the risk. A company that under-invests in security and experiences a breach faces costs (regulatory, reputational, direct remediation) that dwarf the savings from any budget cut.

The result is that the industry has grown consistently through every downturn since the sector became meaningful in the late 1990s. Total global spending has grown from tens of billions of dollars in the 2000s to well over $200 billion annually by 2026. Multiple sub-segments — endpoint protection, network security, cloud security, identity management, security operations, data protection — have each grown to substantial scale.

The structure of the market

The cybersecurity market is highly fragmented. Unlike some other technology segments where 3–5 vendors capture the majority of revenue, cybersecurity has dozens of independent public companies plus a very large number of private ones. The reasons for the fragmentation are structural: the threat landscape is diverse, so a comprehensive security program requires multiple specialised tools; the pace of new threats is fast enough that startups can enter with novel approaches faster than incumbents can respond; and enterprise buyers often prefer best-of-breed tools over integrated suites in security specifically.

Some categories have consolidated more than others. Endpoint protection has become dominated by a handful of vendors (CrowdStrike, SentinelOne, Microsoft's built-in Defender for enterprise). Identity management has consolidated around Okta and Microsoft. Network firewalls have consolidated around Palo Alto Networks, Fortinet, and Check Point. But even in these consolidated segments, the number of meaningful competitors is larger than in most enterprise IT.

The Microsoft factor

Microsoft's growing role in enterprise cybersecurity is one of the most-discussed structural changes of the past several years. Through a combination of built-in security features in Windows and Office 365, dedicated products (Microsoft Defender, Sentinel, Purview), and pricing bundles that make security features effectively free with existing licence spends, Microsoft has captured meaningful share from independent security vendors.

The competitive dynamic has become a persistent overhang for pure-play security companies. Any category where Microsoft has a "good enough" offering embedded in an existing enterprise licence faces pressure on pricing power and growth. This pressure has been most visible in endpoint protection, where Microsoft Defender's inclusion in enterprise Windows licences has forced independent vendors to differentiate on capabilities beyond what Microsoft offers.

Whether this pattern will spread to other security segments is one of the sector's key open questions. Independent vendors argue that specialised excellence beats built-in adequacy for security specifically, and that CIOs will continue paying for best-of-breed even when adequate alternatives are bundled. Microsoft's revenue growth in security-specific products suggests the argument is only partly correct — some buyers are consolidating on the bundle.

The AI acceleration

The AI cycle has affected cybersecurity in two significant ways. First, security operations are being augmented by AI tools that reduce the workload on human analysts — pattern recognition, alert triage, and automated response are all improving materially with generative AI capabilities. Second, threat actors are also using AI to accelerate the development of new attacks, which increases the pace at which security investments must scale to keep up.

The net effect on security spending is expansionary. Companies are investing simultaneously in AI-augmented defensive capabilities and in defending against AI-augmented offensive capabilities. Both directions of investment support continued sector growth.

The sub-segments worth distinguishing

Endpoint protection. Software running on individual devices (laptops, servers, mobile devices) to detect and prevent malicious activity. Consolidated market; CrowdStrike, SentinelOne, and Microsoft dominate.

Network security. Firewalls, intrusion detection, network segmentation. Palo Alto Networks, Fortinet, Cisco, Check Point are the largest names.

Cloud security. Protection for workloads running in AWS, Azure, and GCP. A fast-growing segment with less consolidated market share; Wiz (recently acquired by Google), Palo Alto's Prisma Cloud, and various specialty providers compete.

Identity and access management. Managing who has access to what systems. Okta, Microsoft, and Ping Identity are the largest independents.

Security operations. Tools and services for security teams to detect, investigate, and respond to threats. Splunk (now Cisco), Microsoft Sentinel, CrowdStrike Falcon, and many others.

Data protection and compliance. Ensuring data is handled according to regulatory requirements and internal policies. Fragmented segment.

Managed security services. Outsourced security operations for organisations that cannot staff or run their own security teams. Large market, dominated by professional services firms (Accenture, Deloitte, IBM) alongside specialised MSSPs.

Why investor returns have been variable

Despite the durable demand growth, investor returns in cybersecurity stocks have been highly variable. The reasons are the standard ones for high-growth technology sub-sectors: multiples expand and contract based on interest-rate cycles and growth-multiple sentiment, individual companies win or lose specific product cycles, and the constant emergence of new competitors keeps pressure on established leaders.

The 2020–2021 period saw cybersecurity multiples reach extremes — many companies traded at 30x forward sales at the peaks. The 2022 correction was severe, with many former highfliers falling 60–80%. The sector recovered materially in 2023–2024 but multiples have remained more disciplined than during the peak period.

The frame this implies

Cybersecurity is one of the most reliable growth sectors in technology, with a demand pattern that is unusually stable across economic cycles. That does not make cybersecurity stocks reliably good investments — the multiples at which growth is available vary enormously, and the competitive dynamics within the sector are challenging even for companies with excellent products. The best cybersecurity investments have generally required both a defensible business position and a reasonable entry multiple, and the second condition has been much more variable than the first.

Educational content only. Not investment advice.