AI is reshaping cybersecurity budgets, identity boundaries, and security operating models
AI summary card
AI is reshaping cybersecurity budgets, identity boundaries, and security operating models
Bernstein's CISO call shows that AI is the core catalyst for incremental cybersecurity spending, with budget priorities flowing toward AI governance, non-human identity, data protection, attack surface reduction, and automated SOC.
- Cybersecurity spending continues to outpace overall IT spending, and changes on both the offensive and defensive sides of AI are the main drivers of incremental budget.
- Identity is becoming the new security boundary, with governance of non-human identities and AI agent permissions listed by CISOs as key priorities.
- Enterprises prefer to free up budget by consolidating legacy platforms and buying modules from existing core vendors, rather than broadly procuring standalone point products.
- Security operations are shifting from traditional SIEM and manual response toward automation, Agentic SOC, and response orchestration across security pillars.
- The report explicitly states that this transcript does not change target prices or investment recommendations.
Report interpretation
Overview
This report compiles Bernstein's conference call transcript with three CISOs from the insurance, manufacturing, and healthcare software industries, covering mid-2026 cybersecurity budget trends, AI impact, identity governance, vendor consolidation, and security operations automation. The core conclusion is that AI is no longer just an emerging theme, but is comprehensively reshaping cybersecurity strategy at the levels of budgets, architecture, risk management, and vendor selection.
Core views
First, cybersecurity budgets are more resilient than overall IT budgets, with most interviewees indicating budget growth or at least protection. Second, AI is driving both threat-side risks and governance needs around internal enterprise AI usage, making it the largest catalyst for incremental spending. Third, identity security—especially non-human identity, AI agent permissions, least privilege, and time-bound access—is becoming the new security boundary. Fourth, under budget constraints, the main funding source is not unlimited new budget, but retiring legacy platforms, reassessing the existing security stack, and adding modules from core vendors. Fifth, the strategic importance of traditional SIEM is declining, and security operations are evolving toward Agentic ITDR/SOC, automated investigation, orchestration, and response.
Analysis framework
The report uses conference transcript takeaways and industry expert interviews, combined with the background of a recent 100-CISO survey, to distill commonalities and differences among three types of enterprises in budget growth, priorities, and vendor selection. The focus of the analysis is not on a single company's financial model, but on inferring cybersecurity software demand direction from CISO purchasing intentions.
Methodology notes
Conference call with three CISOs
By discussing budgets and priorities with security leaders from the insurance, manufacturing, and healthcare software industries, the report assesses changes in cybersecurity demand.
CISO budget survey
The report cites a recent survey of 100 CISOs as background, noting that average cybersecurity budget growth typically exceeds overall IT budget growth.
Risk monetary quantification
The healthcare software CISO mentioned using the FAIR methodology to quantify potential event losses and using that to seek incremental AI-related budget from the board.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- CrowdStrikeCore vendor related to endpoint security and security operations
- Strengths
- Frequently praised on the call for its innovation capabilities, benefiting from demand in endpoint, security operations automation, and AI threat response.
- Weaknesses
- Valuation is high, and the report table shows a Market-Perform rating.
- Comparison
- Compared with point-solution vendors, core platform vendors are more likely to win budget through module expansion.
- Risks
- Vendor consolidation may pressure pricing, and budget constraints may also delay purchases of new modules.
- OktaVendor related to identity security and access governance
- Strengths
- Identity is becoming the new security boundary, and governance of non-human identity and AI agent permissions is increasing the strategic importance of identity platforms.
- Weaknesses
- It needs to prove that its capabilities can cover modern AI agent and non-human identity governance needs.
- Comparison
- It holds an independent leader positioning within the identity pillar, rather than being part of an end-to-end security suite.
- Risks
- If large platform vendors accelerate catch-up in identity governance, independent identity vendors may face consolidation pressure.
- Palo Alto NetworksIntegrated cybersecurity platform vendor
- Strengths
- Praised on the call for innovation capabilities, benefiting from platformization, cloud security, network security, and vendor consolidation.
- Weaknesses
- Enterprises do not want to rely solely on a single vendor end-to-end; consolidation mainly occurs within core security pillars.
- Comparison
- Compared with point-product vendors, it has stronger platform expansion capabilities, but still needs to compete with leaders in each security pillar.
- Risks
- If customers stick to a best-of-breed strategy across multiple pillars, the room for end-to-end platformization may be lower than expected.
- WizCloud security vendor
- Strengths
- Frequently praised on the call for innovation capabilities; cloud migration and AI workload governance are increasing demand for cloud security.
- Weaknesses
- The report does not provide specific financial model or rating data.
- Comparison
- Seen as an innovative leader in the core cloud security pillar.
- Risks
- When budgets are tight, customers may prioritize buying add-on modules from existing vendors rather than new standalone products.
- Torq / TinesStartups in automated security operations and orchestration
- Strengths
- CISOs prefer 'Switzerland'-type tools that can observe and orchestrate across security pillars, fitting the Agentic SOC trend.
- Weaknesses
- As startups, their scale, channels, and enterprise standardization procurement capabilities may be weaker than those of large platforms.
- Comparison
- Compared with traditional SIEM, they are better aligned with demand for automated investigation, orchestration, and response.
- Risks
- Large security platforms may build automation and response capabilities internally, compressing the space for standalone tools.
- Traditional SIEM vendorsTraditional security information and event management
- Strengths
- They still have an installed base and value in log analysis.
- Weaknesses
- The report says traditional SIEM is strategically declining relative to Agentic ITDR/SOC models, with lower investment priority.
- Comparison
- Next-generation threat detection, intelligence, orchestration, and automated response capabilities are receiving more attention.
- Risks
- If they cannot evolve toward automation, threat intelligence, and response closed loops, their share of budget may continue to be squeezed.
Key data
- Security budget growth in the insurance industry sample12%-15%The insurance industry CISO said this year's security spending is expected to increase by about 12%-15%, focused on AI-related risk and visibility.
- IT budget change in the manufacturing industry sampleIT budget down 10%, security budget flatThe manufacturing CISO said the overall IT budget was required to decline by 10%, but the security budget remained stable.
- Security budget as a share of IT in the manufacturing industry sampleAbout 6%The CISO said cybersecurity accounts for only about 6% of the overall IT budget, but this also includes manufacturing IT and embedded product security.
- 2026 security budget for the healthcare software sampleAbout $20 millionThe CISO of a healthcare data analytics company said the 2026 security budget is about $20 million, or around 10%-12% of the overall IT budget.
- Budget growth rate for the healthcare software sampleMay ultimately grow about 20% YoYInitial growth was expected at 6%-7%, then additional funding was sought from the board due to concerns about the attack capabilities of frontier AI models.
- Average budget growth rate in the CISO surveyAbout 4%-6%+At the start of the call, it was mentioned that average security budget growth across industries was about 4%-6% or higher, with some companies reaching double-digit growth rates.
- Impact on investment recommendationsNo impact to target prices or investment recommendationsThe report explicitly states that this transcript does not affect target prices or investment recommendations.
Impact & implications
For investing, this transcript supports the view that demand for cybersecurity software continues to have structural resilience, especially benefiting vendors tied to identity security, cloud security, endpoint, AI governance, data protection, and automated security operations. At the same time, CISOs are more inclined to consolidate vendors within core security pillars, suggesting that companies with strategic platform positioning and innovation capabilities are more likely to win incremental budget, while point products and lower-priority areas such as traditional SIEM may face budget pressure.
Risks
- If AI-related security demand shifts from pilot projects to standardized built-in functions, the monetization opportunity for independent AI governance or security point products may be lower than expected.
- Budget constraints may lead enterprises to prioritize add-on modules from existing vendors, squeezing opportunities for new vendors and best-of-breed point products.
- While vendor consolidation benefits platform vendors, it may also bring stronger pricing pressure and module discounts.
- Lower-priority areas such as traditional SIEM, security service edge, email security, and security browsers may face relative budget declines.
- Non-human identity and Agentic SOC are still in the early stages of evolution, and customer procurement standards and winning vendor landscapes are not yet fully established.
What to watch
- Whether cybersecurity budgets in 2026 to 2027 continue to outpace overall IT budgets.
- Changes in enterprise AI usage volume, token consumption, internal AI agent deployment, and related governance budgets.
- Procurement priorities for non-human identity, IGA, privileged access management, and least-privilege controls.
- The migration speed from traditional SIEM to Agentic ITDR/SOC, automated investigation, and response orchestration.
- Whether core vendors such as CrowdStrike, Okta, Palo Alto Networks, and Wiz can absorb consolidation budgets through module expansion.
- Whether CISOs continue to prefer neutral automation tools across security pillars, such as Torq and Tines.