Quick Summary
Covering the latest research from top Wall Street investment banks

AI Reshapes Cybersecurity: Near-Term Opportunities Center on Automated Response, While Long-Term Growth May Be Led by Agentic AI Security and New Cross-Platform Vendors

Institution
Bernstein
Date
Authors
Peter Weed, Armin Hadavi, Luwei Yang
Company
U.S. SMID-Cap Cybersecurity Software and AI Security
Ticker
CRWD, OKTA
Industry
Cybersecurity Software and AI Security
Rating
MixedHigh confidenceLong-termThe report believes AI will create significant opportunities in security operations, agentic AI security, and cross-platform analytics. However, new entrants may capture more of the incremental value, while incumbent vendors and certain application security products face risks of displacement or disruption.
AuthorsPeter Weed, Armin Hadavi, Luwei Yang
CoverageUnited States

AI summary card

AI Reshapes Cybersecurity: Near-Term Opportunities Center on Automated Response, While Long-Term Growth May Be Led by Agentic AI Security and New Cross-Platform Vendors

Bernstein believes AI not only improves the efficiency of existing security work but also creates a new market for protecting AI agents. “Neutral” startups spanning endpoint, network, cloud, and identity systems may be better positioned than incumbent platforms to capture incremental opportunities arising from new buyers and architectures.

No changes were made to models, target prices, or ratings; the report provides no unified industry rating or target price.
CybersecurityAI Agent SecurityAI-Native SOCDetection and ResponseIdentity SecurityApplication SecurityPlatformizationStartups
  • AI is viewed as the most important platform shift in cybersecurity in decades and introduces an entirely new attack surface.
  • The clearest near-term opportunities are in real-time risk remediation and detection and response, where massive data volumes and complex decisions are well suited to AI automation.
  • Agent identity, intent recognition, dynamic permissions, and behavioral observability may form new product categories over the next several years.
  • “Neutral” platforms that aggregate data across endpoint, network, cloud, identity, and applications may capture greater incremental value than any single security pillar.
  • AI labs are most likely to move deeply into code security, scanning, and vulnerability prioritization, but are unlikely to enter areas such as security operations comprehensively.
  • Platformization remains valuable, but its core value comes from a unified data and automation layer rather than a unified interface or fewer vendors.
  • The report made no changes to any models, target prices, or ratings.

Report interpretation

Overview

Based on Bernstein's discussion with cybersecurity entrepreneur and former Palo Alto Networks cloud and AI business leader Amol Mathur, the report analyzes how AI will reshape security products, buyer structures, the competitive landscape, and platformization pathways. Its central conclusion is that AI can both strengthen existing security operations and create a new market for protecting AI agents, with cross-platform AI-native vendors and startups serving new buyers potentially occupying more advantageous positions.

Core views

The report first defines AI as the most significant architectural change in cybersecurity in decades, rather than an ordinary feature added to existing products. Enterprises are rapidly deploying AI in response to board-level mandates, but security teams are still determining the associated risks. This may create a new purchasing center within enterprises that is separate from traditional security pillars. The report believes this environment, in which buyers are not yet entrenched and the supply landscape remains greenfield, favors startups. New entrants can also adopt a neutral, “Switzerland-like” position, aggregating data across endpoint, network, cloud, identity, applications, and AI systems without being constrained by existing product lines, platform narratives, or sales teams. Incumbent vendors may instead face an “innovator's dilemma”: existing investments and priorities make it difficult to establish a clean new product position or use their existing commercial teams to reach new buyers. The analysis distinguishes between “using AI to secure” and “securing AI itself.” The former uses AI to improve the efficiency of threat detection, triage, red-team testing, vulnerability management, prevention, remediation, and response. As attackers use AI to increase the speed of attacks, security operations centers must also respond at near-machine speed. The report divides security operations outcomes into three pillars: risk prevention, risk remediation, and detection and response. It concludes that the most prominent near-term opportunities lie in real-time remediation and detection and response. These activities combine large data volumes, complex decisions, and stringent timeliness requirements, making them particularly suitable for AI automation. The market may also see more forms of “DR” and detection-and-response products designed specifically for AI. “Securing AI itself” refers to protecting AI systems, especially autonomous agents. Agents are trusted entities whose behavior can be influenced by prompts, external content, tools, and context. Even when their actions appear authorized, they may still cause harm, making traditional approaches that identify only unauthorized behavior inadequate. The report therefore derives two long-term opportunities: agent security and agent identity. Identity infrastructure vendors such as Okta can provide the foundation for agent identity and permissions, but comprehensive agent protection must also understand intent in real time. Ideally, permissions would be dynamically restricted according to the specific task an agent is currently performing. This requires security products to observe prompts, objectives, workflows, and actual behavior, creating new categories in agent observability, intent analysis, and protection. Modern attacks span multiple security domains, while endpoint, network, cloud, SASE, and identity tools each see only part of the risk. Network and endpoint vendors can capture opportunities in the next-generation SIEM and detection-and-response scenarios for which they are responsible—for example, Palo Alto Networks serving network operations or related platform buyers and CrowdStrike serving endpoint teams. However, the report believes broader incremental value may accrue to cross-platform vendors positioned above these pillars. AI-native SOC platforms can use agents as automated analysts to investigate alerts, correlate evidence across multiple systems, and prioritize incidents that genuinely require human attention, thereby alleviating the longstanding signal-to-noise problem. New vendors such as Torq, 7AI, Prophet, and Dropzone exemplify this direction. This shift may also unbundle the traditional SIEM model in which one vendor controls both the data and analytics layers. Data platforms such as Snowflake and Databricks argue that customers should retain control of the underlying data, with independent security analytics capabilities operating on top of it. If this architecture develops, AI-native SOC vendors could work across all security pillars, while security context generated by the different pillars would be centrally stored in a data-lake-style master data repository. The focus of competition would consequently shift from what an individual security product can see to who can aggregate data, understand context, and produce high-confidence results. For AI labs such as OpenAI and Anthropic, the report believes their initial move into cybersecurity is motivated by self-protection: they need to prevent AI coding agents from generating insecure code and reduce the risk of AI agents being used to find vulnerabilities or conduct social-engineering attacks. AI labs are most likely to focus on application security, particularly code security, code scanning, software testing, and vulnerability prioritization. AI models can reason across codebases, assess exploitability, and filter for genuinely important vulnerabilities, potentially leading customers to question why they still need to pay separately for certain specialized tools. Code-scanning and vulnerability-prioritization products face the greatest disruption pressure. However, the report does not expect AI labs to expand aggressively into broader areas such as security operations, detection and response, or exposure management. These markets are not necessary to address their own strategic risks and require substantial investment in security-domain expertise, workflows, integrations, and productization. While AI labs must still prioritize competition for agent market share and product quality, broad security pillars that lack a direct strategic need and have high barriers to entry are unlikely to become priorities. The report also emphasizes that security products cannot serve only the security teams that discover and prioritize risks. Security teams are the “facilitators” within enterprises, while developers, DevOps teams, cloud operations personnel, and other operators are the “executors” who actually perform remediation. Successful products should embed security insights directly into these executors' existing workflows rather than force them to switch to standalone security tools. Wiz is cited as an example of a product built for both security teams and DevOps and cloud operations personnel. As the scale of code and AI agents expands, the remediation burden on executors will continue to rise, increasing demand for security insights available at the point of work. AI may therefore shift some value and spending closer to development, DevOps, and cloud operations workflows. Platformization may remain effective in the AI era, but the report applies a stricter definition of platform value: a true platform should have a unified data layer, a shared taxonomy, and a unified automation layer, and should be able to correlate data across infrastructure, applications, endpoints, employees, and AI systems. This shared risk context can improve risk prioritization, remediation efficiency, and blast-radius assessment in detection and response. Simplified vendor management, contracts, support, and interfaces are secondary benefits. The tasks and workflows of highly specialized teams such as firewall management and SOC teams differ substantially, so a unified interface may not provide equal value. As headless architectures and flexible AI-driven interactions emerge, the long-term importance of fixed-function interfaces may decline further. From an investment perspective, the discussion supports Bernstein's previous view that incumbent vendors may capture only limited incremental value when new technology architectures and new buyers emerge. The report will continue monitoring startups in both “AI for cybersecurity” and “security for AI,” and believes category leaders may remain independent and ultimately go public, while laggards may be acquired by large platforms or incumbent vendors seeking entry into the market. This discussion did not prompt Bernstein to change any models, target prices, or ratings.

Analysis framework

The report begins with an interview with an entrepreneur who has more than 20 years of experience in cloud security, data security, application security, endpoint security, and security operations, and cross-validates the views with Bernstein's prior CISO interviews and surveys. The analysis first distinguishes between “using AI to improve security” and “protecting AI systems,” then breaks down opportunities across risk prevention, risk remediation, and detection and response. It subsequently compares the competitive positions of single security pillars, cross-platform vendors, AI labs, and startups, and finally discusses how purchasing roles, workflows, and platform architectures affect value capture.

Methodology notes

  • (Method Outside the Taxonomy)

    Cross-validation of an entrepreneur expert interview with CISO research

    The report primarily draws on the industry experience of a veteran cybersecurity product leader and cross-checks these views against enterprises' receptiveness to startups in prior CISO interviews and surveys.

  • Competition and Strategy FrameworkMoat / competitive advantage

    A neutral, “Switzerland-like” position across security pillars

    The report compares the data, context, and buyer-reach capabilities of single-product pillars and independent cross-platform vendors, concluding that neutral vendors unconstrained by existing product lines may find it easier to establish a competitive advantage.

  • Competition and Strategy FrameworkValue chain analysis

    Division of security workflows between “facilitators” and “executors”

    The report distinguishes between security teams responsible for identifying and prioritizing risks and the development, DevOps, and cloud operations teams that actually perform remediation, using this distinction to determine which workflows products should enter and where spending may flow.

  • Competition and Strategy FrameworkProduct life cycle

    Formation of new AI security categories and competition between new and incumbent vendors

    Starting from new attack surfaces, new purchasing centers, and a greenfield supply landscape, the report analyzes the roles that startups, category leaders, and incumbent platforms may play as categories such as agent security progress from their formative stage toward independent product markets.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • Palo Alto Networks
    As an incumbent cybersecurity platform, it can capture opportunities in next-generation SIEM and detection-and-response scenarios within its own pillars, but it also represents an incumbent facing challenges from new architectures and buyers.
    Strengths
    Possesses an established platform, data, customer relationships, and network and cloud security capabilities.
    Weaknesses
    The report believes existing priorities, product investments, platform narratives, and commercial teams may create an innovator's dilemma.
    Comparison
    A single pillar has localized advantages, but cross-platform “neutral” vendors may find it easier to aggregate data and context from other security pillars.
    Risks
    New buyers may prefer new best-of-breed products, leaving incumbent platforms with only a limited share of incremental value.
  • CrowdStrike(CRWD)
    The endpoint security vendor is positioned to benefit from AI-driven opportunities in detection and response and next-generation SIEM within its area of responsibility.
    Strengths
    Can serve endpoint teams and leverage the security data and context within its own pillar.
    Weaknesses
    The endpoint perspective covers only part of a cross-domain attack chain.
    Comparison
    Compared with AI-native SOC platforms operating across endpoint, network, cloud, and identity, its cross-pillar visibility may be more limited.
    Risks
    Broader incremental value in detection and response may flow to independent cross-platform vendors.
  • Okta(OKTA)
    Can provide identity and permissions infrastructure for AI agents, making it an important participant in agent identity systems.
    Strengths
    Can provide the foundational layer for agent identity and permissions management.
    Weaknesses
    Identity infrastructure alone is insufficient to assess agent intent in real time.
    Comparison
    Comprehensive agent security also requires specialized protection products that observe prompts, objectives, workflows, and behavior.
    Risks
    Some value in the new category may be captured by vendors specializing in agent intent analysis and observability.
  • AI-native SOC vendors such as Torq, 7AI, Prophet, and Dropzone
    Positioned above traditional security pillars, they use AI agents to investigate alerts, correlate evidence, and filter for incidents that genuinely require human attention.
    Strengths
    Can operate across security pillars and aggregate data and context from a neutral position.
    Comparison
    Their architecture separates security analytics from the underlying SIEM or data lake, unlike the traditional model in which vendors control both the data and analytics layers.
    Risks
    Category leaders and laggards may diverge significantly, with the latter potentially becoming acquisition targets for large platforms.
  • Snowflake、Databricks
    These data platforms advocate allowing customers to retain control of underlying security data while independent analytics tools operate on top of it.
    Strengths
    Can serve as the master-data or data-lake-style storage layer for context spanning security pillars.
    Comparison
    This model challenges the bundled architecture in which traditional SIEM vendors own both the data and analytics layers.
  • AI labs such as OpenAI and Anthropic
    Most likely to enter application security through code security, code scanning, software testing, and vulnerability prioritization.
    Strengths
    AI models can reason across codebases, assess exploitability, and determine which vulnerabilities genuinely matter.
    Weaknesses
    Broader security operations, detection and response, and exposure management require substantial domain expertise, workflows, integrations, and productization.
    Comparison
    They may directly challenge specialized vendors in application security but have weaker incentives and capabilities to enter broader security pillars.
    Risks
    Their top priorities remain AI agent market share and quality, making broad cybersecurity product development unlikely to be a priority.

Key data

  • Interviewee's Industry ExperienceMore than 20 yearsSpanning cloud security, data security, application security, endpoint security, and security operations, with prior roles at McAfee, Akamai, IBM, and Palo Alto Networks.
  • Security Operations Outcome Framework3 pillarsRisk prevention, risk remediation, and detection and response.
  • Key Near-Term OpportunitiesReal-time risk remediation and detection and responseThe report believes the data volumes and decision complexity in these areas are particularly suitable for AI-driven automation.
  • Agent Security Formation PeriodOver the next several yearsThe report expects agent security, agent identity, intent understanding, and observability to potentially develop into important new categories.
  • CRWD, OKTA, and S Valuation Base Year2026The report's stock table states that these three are based on 2026.
  • Changes to Models, Target Prices, and RatingsNoneBernstein explicitly stated that the discussion resulted in no changes to any models, target prices, or ratings.

Impact & implications

The report believes the industry value created by AI will not be distributed evenly across all cybersecurity vendors. Near-term value is more likely to flow into automated remediation and detection and response, while long-term value may shift toward agent identity, intent analysis, and protection. Cross-platform AI-native vendors have an advantage because they can integrate data from multiple security domains and serve new buyers. Incumbent platforms can still benefit within their own pillars and through unified data layers, but specialized application security tools may face direct competition from AI labs, while platform value will increasingly depend on data and automation rather than a unified interface.

Risks

  • AI expands the attack surface and increases attack speed. Even when trusted agents perform ostensibly legitimate actions, prompts, context, or external data may influence them to cause harm.
  • AI labs may disrupt code scanning and vulnerability prioritization, potentially leading customers to reduce spending on certain specialized application security products.
  • Due to the innovator's dilemma, conflicts with platform narratives, and difficulty reaching new buyers, incumbent vendors may capture only a limited share of incremental AI security value.
  • Individual endpoint, network, cloud, or identity products lack complete cross-domain context and may be unable to independently generate high-confidence security results.
  • Separating security analytics from the data layer may challenge the traditional bundled SIEM model, while headless architectures may also weaken the long-term value of fixed-function interfaces.

What to watch

  • Monitor whether independent category leaders emerge in “AI for cybersecurity” and “security for AI.”
  • Monitor whether enterprises form a new purchasing center around AI risks that is independent of traditional security pillars.
  • Watch when agent identity, intent understanding, dynamic permissions, and behavioral observability become clearly defined product categories.
  • Monitor whether AI-native SOC platforms can improve alert signal-to-noise ratios across security pillars and drive the separation of security analytics from the underlying data layer.
  • Watch the depth of AI labs' entry into code scanning and vulnerability prioritization and whether they expand into broader cybersecurity areas.
  • Monitor whether AI shifts security spending further from SOC workflows toward development, DevOps, and cloud operations workflows.
  • Watch whether the value of platformization continues to be supported by unified data and automation layers rather than dominated by a unified interface.
  • Monitor potential paths in which category-leading startups remain independent and go public, while laggards are acquired by large incumbent platforms.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins