Quick Summary
Covering the latest research from top Wall Street investment banks

AI is reshaping cybersecurity budgets, identity boundaries, and security operating models

Institution
Bernstein
Date
2026-07-28
Authors
Peter Weed, Armin Hadavi, CFA, Luwei Yang
Company
-
Ticker
-
Industry
Cybersecurity / U.S. SMID-Cap Software
Rating
-
BullishLow confidenceCISO feedback indicates cybersecurity budgets are outpacing broader IT spend, with AI-driven threats and internal AI adoption creating incremental demand; however, vendor consolidation and budget constraints limit broad point-solution expansion.
AuthorsPeter Weed, Armin Hadavi, CFA, Luwei Yang
CoverageUnited States、Europe、Other
Asset classesEquity
Business segmentsidentity and access management、non-human identity、endpoint security、network security、cloud security、email security、security operations、ai governance、data protection
Research firm divisions/subsidiariesBernstein(Other)

AI summary card

AI is reshaping cybersecurity budgets, identity boundaries, and security operating models

Bernstein's CISO call shows that AI is the core catalyst for incremental cybersecurity spending, with budget priorities flowing toward AI governance, non-human identity, data protection, attack surface reduction, and automated SOC.

This report is an industry conference transcript and strategy observation; for the base-year commentary on covered names such as CRWD, OKTA, and S, see the table, but there are no target price or investment recommendation changes.
CybersecurityArtificial IntelligenceCISOIdentity SecurityAI GovernanceAgentic SOCVendor ConsolidationU.S. SMID-Cap Software
  • Cybersecurity spending continues to outpace overall IT spending, and changes on both the offensive and defensive sides of AI are the main drivers of incremental budget.
  • Identity is becoming the new security boundary, with governance of non-human identities and AI agent permissions listed by CISOs as key priorities.
  • Enterprises prefer to free up budget by consolidating legacy platforms and buying modules from existing core vendors, rather than broadly procuring standalone point products.
  • Security operations are shifting from traditional SIEM and manual response toward automation, Agentic SOC, and response orchestration across security pillars.
  • The report explicitly states that this transcript does not change target prices or investment recommendations.

Report interpretation

Overview

This report compiles Bernstein's conference call transcript with three CISOs from the insurance, manufacturing, and healthcare software industries, covering mid-2026 cybersecurity budget trends, AI impact, identity governance, vendor consolidation, and security operations automation. The core conclusion is that AI is no longer just an emerging theme, but is comprehensively reshaping cybersecurity strategy at the levels of budgets, architecture, risk management, and vendor selection.

Core views

First, cybersecurity budgets are more resilient than overall IT budgets, with most interviewees indicating budget growth or at least protection. Second, AI is driving both threat-side risks and governance needs around internal enterprise AI usage, making it the largest catalyst for incremental spending. Third, identity security—especially non-human identity, AI agent permissions, least privilege, and time-bound access—is becoming the new security boundary. Fourth, under budget constraints, the main funding source is not unlimited new budget, but retiring legacy platforms, reassessing the existing security stack, and adding modules from core vendors. Fifth, the strategic importance of traditional SIEM is declining, and security operations are evolving toward Agentic ITDR/SOC, automated investigation, orchestration, and response.

Analysis framework

The report uses conference transcript takeaways and industry expert interviews, combined with the background of a recent 100-CISO survey, to distill commonalities and differences among three types of enterprises in budget growth, priorities, and vendor selection. The focus of the analysis is not on a single company's financial model, but on inferring cybersecurity software demand direction from CISO purchasing intentions.

Methodology notes

  • Expert interviewsCISO conference call

    Conference call with three CISOs

    By discussing budgets and priorities with security leaders from the insurance, manufacturing, and healthcare software industries, the report assesses changes in cybersecurity demand.

  • Survey background100-CISO survey

    CISO budget survey

    The report cites a recent survey of 100 CISOs as background, noting that average cybersecurity budget growth typically exceeds overall IT budget growth.

  • Risk quantificationFAIR methodology

    Risk monetary quantification

    The healthcare software CISO mentioned using the FAIR methodology to quantify potential event losses and using that to seek incremental AI-related budget from the board.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • CrowdStrike
    Core vendor related to endpoint security and security operations
    Strengths
    Frequently praised on the call for its innovation capabilities, benefiting from demand in endpoint, security operations automation, and AI threat response.
    Weaknesses
    Valuation is high, and the report table shows a Market-Perform rating.
    Comparison
    Compared with point-solution vendors, core platform vendors are more likely to win budget through module expansion.
    Risks
    Vendor consolidation may pressure pricing, and budget constraints may also delay purchases of new modules.
  • Okta
    Vendor related to identity security and access governance
    Strengths
    Identity is becoming the new security boundary, and governance of non-human identity and AI agent permissions is increasing the strategic importance of identity platforms.
    Weaknesses
    It needs to prove that its capabilities can cover modern AI agent and non-human identity governance needs.
    Comparison
    It holds an independent leader positioning within the identity pillar, rather than being part of an end-to-end security suite.
    Risks
    If large platform vendors accelerate catch-up in identity governance, independent identity vendors may face consolidation pressure.
  • Palo Alto Networks
    Integrated cybersecurity platform vendor
    Strengths
    Praised on the call for innovation capabilities, benefiting from platformization, cloud security, network security, and vendor consolidation.
    Weaknesses
    Enterprises do not want to rely solely on a single vendor end-to-end; consolidation mainly occurs within core security pillars.
    Comparison
    Compared with point-product vendors, it has stronger platform expansion capabilities, but still needs to compete with leaders in each security pillar.
    Risks
    If customers stick to a best-of-breed strategy across multiple pillars, the room for end-to-end platformization may be lower than expected.
  • Wiz
    Cloud security vendor
    Strengths
    Frequently praised on the call for innovation capabilities; cloud migration and AI workload governance are increasing demand for cloud security.
    Weaknesses
    The report does not provide specific financial model or rating data.
    Comparison
    Seen as an innovative leader in the core cloud security pillar.
    Risks
    When budgets are tight, customers may prioritize buying add-on modules from existing vendors rather than new standalone products.
  • Torq / Tines
    Startups in automated security operations and orchestration
    Strengths
    CISOs prefer 'Switzerland'-type tools that can observe and orchestrate across security pillars, fitting the Agentic SOC trend.
    Weaknesses
    As startups, their scale, channels, and enterprise standardization procurement capabilities may be weaker than those of large platforms.
    Comparison
    Compared with traditional SIEM, they are better aligned with demand for automated investigation, orchestration, and response.
    Risks
    Large security platforms may build automation and response capabilities internally, compressing the space for standalone tools.
  • Traditional SIEM vendors
    Traditional security information and event management
    Strengths
    They still have an installed base and value in log analysis.
    Weaknesses
    The report says traditional SIEM is strategically declining relative to Agentic ITDR/SOC models, with lower investment priority.
    Comparison
    Next-generation threat detection, intelligence, orchestration, and automated response capabilities are receiving more attention.
    Risks
    If they cannot evolve toward automation, threat intelligence, and response closed loops, their share of budget may continue to be squeezed.

Key data

  • Security budget growth in the insurance industry sample12%-15%The insurance industry CISO said this year's security spending is expected to increase by about 12%-15%, focused on AI-related risk and visibility.
  • IT budget change in the manufacturing industry sampleIT budget down 10%, security budget flatThe manufacturing CISO said the overall IT budget was required to decline by 10%, but the security budget remained stable.
  • Security budget as a share of IT in the manufacturing industry sampleAbout 6%The CISO said cybersecurity accounts for only about 6% of the overall IT budget, but this also includes manufacturing IT and embedded product security.
  • 2026 security budget for the healthcare software sampleAbout $20 millionThe CISO of a healthcare data analytics company said the 2026 security budget is about $20 million, or around 10%-12% of the overall IT budget.
  • Budget growth rate for the healthcare software sampleMay ultimately grow about 20% YoYInitial growth was expected at 6%-7%, then additional funding was sought from the board due to concerns about the attack capabilities of frontier AI models.
  • Average budget growth rate in the CISO surveyAbout 4%-6%+At the start of the call, it was mentioned that average security budget growth across industries was about 4%-6% or higher, with some companies reaching double-digit growth rates.
  • Impact on investment recommendationsNo impact to target prices or investment recommendationsThe report explicitly states that this transcript does not affect target prices or investment recommendations.

Impact & implications

For investing, this transcript supports the view that demand for cybersecurity software continues to have structural resilience, especially benefiting vendors tied to identity security, cloud security, endpoint, AI governance, data protection, and automated security operations. At the same time, CISOs are more inclined to consolidate vendors within core security pillars, suggesting that companies with strategic platform positioning and innovation capabilities are more likely to win incremental budget, while point products and lower-priority areas such as traditional SIEM may face budget pressure.

Risks

  • If AI-related security demand shifts from pilot projects to standardized built-in functions, the monetization opportunity for independent AI governance or security point products may be lower than expected.
  • Budget constraints may lead enterprises to prioritize add-on modules from existing vendors, squeezing opportunities for new vendors and best-of-breed point products.
  • While vendor consolidation benefits platform vendors, it may also bring stronger pricing pressure and module discounts.
  • Lower-priority areas such as traditional SIEM, security service edge, email security, and security browsers may face relative budget declines.
  • Non-human identity and Agentic SOC are still in the early stages of evolution, and customer procurement standards and winning vendor landscapes are not yet fully established.

What to watch

  • Whether cybersecurity budgets in 2026 to 2027 continue to outpace overall IT budgets.
  • Changes in enterprise AI usage volume, token consumption, internal AI agent deployment, and related governance budgets.
  • Procurement priorities for non-human identity, IGA, privileged access management, and least-privilege controls.
  • The migration speed from traditional SIEM to Agentic ITDR/SOC, automated investigation, and response orchestration.
  • Whether core vendors such as CrowdStrike, Okta, Palo Alto Networks, and Wiz can absorb consolidation budgets through module expansion.
  • Whether CISOs continue to prefer neutral automation tools across security pillars, such as Torq and Tines.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins