Quick Summary
Covering the latest research from top Wall Street investment banks

AI-natives are disrupting cybersecurity, but the bigger opportunity comes from attack-surface expansion

Institution
Morgan Stanley
Date
2026-04-20
Authors
Meta A Marshall, Keith Weiss, CFA, Ryan Lountzis, Jonathan Eisenson, Abhishek S Murli
Company
-
Ticker
-
Industry
Software / Cybersecurity
Rating
Attractive
BullishLow confidenceAI is expanding the attack surface and driving up cybersecurity demand; the report believes the incremental opportunity is greater than the disruption AI-natives pose to the preventative security market.
AuthorsMeta A Marshall, Keith Weiss, CFA, Ryan Lountzis, Jonathan Eisenson, Abhishek S Murli
CoverageUnited States
Business segmentspreventative security、control point security、runtime security、identity security、data security、AI security
Research firm divisions/subsidiariesMorgan Stanley(Other)

AI summary card

AI-natives are disrupting cybersecurity, but the bigger opportunity comes from attack-surface expansion

Morgan Stanley believes AI will increase cyber threats and enterprise security spending, and that the roughly $220 billion incremental opportunity is likely to outweigh the risk of about 10% of the market being disrupted by AI-natives; it favors CRWD, PANW, OKTA, and SAIL.

Industry view is Attractive; preferred names are CRWD, PANW, OKTA, and SAIL.
Artificial intelligenceCybersecurityRuntime securityIdentity securityPlatform consolidation
  • AI lowers the cost of attacks while increasing their frequency and complexity; the report says 80-90% of attacks are already AI-generated.
  • AI-natives are most likely to disrupt preventative security, but this segment accounts for only about 10% of the security market; runtime, identity, and platform control layers are more defensive.
  • Runtime security is viewed as a key control layer because prompt injection, data leakage, and abuse risks in production environments require real-time detection and policy enforcement.
  • Incremental budget is expected to concentrate in areas such as EDR/XDR, identity and access management, data governance, prompt filtering, model monitoring, and agent governance.
  • The report favors CRWD, PANW, OKTA, and SAIL because of their broader platform coverage, faster AI product cadence, and more flexible pricing models.

Report interpretation

Overview

This report discusses the impact of AI-native models and product launches on the cybersecurity industry. Morgan Stanley believes AI will both create new challengers and expand the attack surface, reinforcing enterprise demand for detection, response, identity, and data governance. Although cybersecurity stocks have recently pulled back due to AI-native security-related announcements, the report judges that the opportunity from incremental AI security demand is greater than the risk of displacement.

Core views

The core view is that AI-natives are more likely to disrupt preventative security areas such as vulnerability discovery, application security testing, and cloud security posture management; however, networking, identity, access control, and runtime detection and response require low latency, determinism, and proprietary data, making incumbent platform vendors more defensive. AI will accelerate vulnerability discovery, but finding vulnerabilities is not the same as successfully exploiting them; modern enterprises still rely on multilayer defenses, EDR, XDR, and identity controls to block attack execution.

Analysis framework

The report uses a layered cybersecurity market framework to assess AI disruption and incremental demand: it divides the market into preventative security, control point/perimeter security, and runtime detection and blocking, and compares each layer's substitutability by AI-native models, cost structure, latency requirements, data advantages, and budget sources. The report also discusses the positioning of relevant companies in conjunction with enterprise security budgets, expanding AI attack surfaces, non-human identity governance, platform consolidation, and valuation methods.

Methodology notes

  • Industry layeringPrevent / Control Point / Runtime

    Cybersecurity is layered into pre-execution, entry-point control, and in-execution defense

    Preventative security includes vulnerability management, application security testing, and cloud posture management; control point security includes firewalls, zero trust, identity access management, and data loss prevention; runtime security includes EDR, XDR, SIEM, SOAR, NDR, and MDR. The report believes that the closer a layer is to real-time execution, the harder it is for current AI-native models to replace it.

  • Investment judgmentAI opportunity versus AI disruption

    Compare incremental AI security demand with AI-native displacement risk

    The report estimates that the incremental cybersecurity opportunity created by AI is about $220 billion, which it believes is greater than the AI-native disruption risk facing roughly 10% of the market; therefore, the net impact is positive.

  • Company screeningAI security platform defensibility

    Screen beneficiaries by platform scale, AI product speed, runtime execution, and flexible pricing

    The report favors vendors with a clear agentic security roadmap, rapid AI product launches, runtime execution capabilities, proprietary data advantages, and consumption-based/flexible pricing models.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • CrowdStrike Holdings Inc (CRWD)
    Beneficiary of AI security and runtime detection demand
    Strengths
    Strong in endpoints, XDR, and platform capabilities; flexible pricing such as Falcon Flex helps reduce friction in adoption of new modules.
    Weaknesses
    Premium pricing may face pressure from lower-cost substitutes and competition.
    Comparison
    Compared with AI-native models, CRWD's advantages lie in real-time detection, proprietary security data, and enterprise-grade execution capabilities.
    Risks
    More difficult new customer acquisition, weaker-than-expected endpoint demand, lower-cost alternatives compressing premium pricing, and weak hiring conditions affecting upsell.
  • Palo Alto Networks Inc (PANW)
    Beneficiary of platform consolidation, network control points, and expanding AI security capabilities
    Strengths
    Broad platform coverage across network security, next-generation firewalls, SASE, Cortex, and Prisma, making it well positioned to capture enterprise security consolidation demand.
    Weaknesses
    A slowdown in firewall refresh cycles may affect growth.
    Comparison
    Compared with point tools, PANW is better able to embed AI security capabilities into existing network, cloud, and analytics platforms.
    Risks
    Firewall refreshes slower than expected, increased competition driving higher sales and marketing investment, and limited profit leverage.
  • Okta, Inc. (OKTA)
    Beneficiary of identity security and non-human identity governance
    Strengths
    Strong foundation in identity and access management; growth in AI agents, APIs, and machine identities increases the importance of identity governance.
    Weaknesses
    Its mature-growth profile causes it to trade at a discount to high-growth security software companies.
    Comparison
    Compared with traditional human-user identity management, the AI era requires continuous verification, least-privilege control, and real-time auditing for agents and machine identities.
    Risks
    A significant slowdown in overall security spending, stronger competition from large vendors such as Microsoft, and slower-than-expected resolution of execution issues.
  • SailPoint Inc (SAIL)
    Beneficiary of identity governance, machine identity, and adjacent data governance markets
    Strengths
    Enterprise IGA and identity governance capabilities can extend into machine identity, data governance, and AI agent access control.
    Weaknesses
    Success of expansion beyond core IGA still needs to be proven.
    Comparison
    In AI environments, identity governance expands from authentication to lifecycle management, permission control, and behavioral auditing, increasing SAIL's relevance.
    Risks
    Expansion into adjacent markets underperforming expectations, pressure from federal-related exposure, and slower-than-expected migration of maintenance customers.

Key data

  • AI-driven incremental cybersecurity opportunity$220bnThe report believes the opportunity created by AI's expansion of the threat surface is significantly greater than the market being disrupted.
  • Share of the market facing AI-native disruption risk~10%Mainly concentrated in preventative security, such as vulnerability management, application security testing, and cloud posture management.
  • Share of AI-generated attacks80-90%The report says attacks have already become highly AI-driven, boosting demand for detection, response, and identity security.
  • Current cybersecurity market size~$300bnIncluding services, accounting for about 6-7% of the overall IT budget.
  • Share of control point security TAM~50%Including network, identity, access, and data controls.
  • Share of runtime security TAM~40%Including in-execution detection and response capabilities such as EDR, XDR, SIEM, SOAR, NDR, and MDR.

Impact & implications

In terms of investment implications, AI-native announcements have weighed on cybersecurity stock sentiment in the short term, but the report believes this is more like the historical disruption cycle when cloud vendors entered security, rather than a structural replacement of core platforms. If enterprises accelerate deployment of AI agents and generative AI applications, budgets for runtime protection, identity governance, data security, and platformized security may continue to rise, benefiting leading vendors with coverage across endpoints, networks, cloud, identity, and data.

Risks

  • AI-native models may launch more complete standalone products in preventative security, compressing the space for traditional vendors.
  • Models, data access, and pre-release partnerships may trigger value transfer, but visibility into current agreement structures and long-term impact remains limited.
  • If enterprise security budgets slow, incremental AI security demand may be insufficient to offset pressure on traditional spending.
  • Large platform vendors and competitors such as Microsoft may intensify competition in identity, networking, and security platforms.
  • If lower-cost models break through in high-frequency, low-latency security scenarios, the defensiveness of existing runtime and control point vendors may decline.

What to watch

  • Whether AI-native vendors expand from vulnerability discovery into commercially viable standalone security products.
  • The AI security roadmaps, product release cadence, and customer adoption of CRWD, PANW, OKTA, and SAIL.
  • Whether enterprises shift budgets from fragmented point tools to integrated platforms.
  • The actual procurement scale for non-human identity, AI agent governance, prompt filtering, model monitoring, and data leakage protection.
  • Whether pre-release model partnerships and data-sharing arrangements limit cybersecurity vendors' ability to commercialize derived insights.
  • Whether AI inference cost, latency, and accuracy are sufficient to replace high-throughput, real-time security workloads.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins