Investor signals #9: Cybersecurity, the frontline of trust in a world that can no longer afford to lose

“Cyber Hawk” ©2026. pitchhawk. All rights reserved.

The signal

In a digital world, cybersecurity is the frontline of trust. That statement has been true for a decade. What has changed in the last two years is the nature of the threat, the scale of the capital responding to it, and the emergence of a new investment thematic that is quietly reshaping how the most sophisticated defenders in the world think about where security actually lives.

Cybercrime costs now exceed $10 trillion annually.

Nominally, that is 1/3rd of U.S. GDP and 8% of global GDP.

Read that again 👆

It is larger than the entire global pharmaceutical industry. It is larger than the combined revenue of the twenty largest technology companies combined. And it is growing.

The adversary has been upgraded by AI. Large language models are now being used to generate sophisticated phishing campaigns at industrial scale, automate vulnerability discovery across millions of targets simultaneously, and create polymorphic malware that evolves fast enough to evade traditional signature-based detection.

AI has lowered the cost and expertise required to find and exploit software vulnerabilities to a level that demands a proportional defensive response. Enterprise security budgets are beginning to reflect that reality. The defenders have been upgraded too.

📱

Signal. Cybersecurity is not a technology sector with strong investor appetite. It is critical national and commercial infrastructure with a structural demand floor that grows every time a new AI capability is released, every time a new device connects to a network, and every time a geopolitical conflict spills into the digital domain. Without a solution, Anthropic CEO Dario Amodei warned AI could be capable within six to 12 months of leading a swarm that could take over the entire internet, among other risks.

Why it matters

The global cybersecurity market is expected to grow from $248 billion in 2026 to nearly $700 billion by 2034, representing a compound annual growth rate of 13.8%. Global cybersecurity spending already exceeds $520 billion in 2026. Those numbers describe a market that is not cyclical, not discretionary, and not dependent on a single policy regime. Every organisation that runs digital infrastructure needs cybersecurity. Every organisation that deploys AI creates new attack surfaces that require new defences. Every organisation that operates in a regulated industry faces increasing compliance requirements that mandate specific security postures.

The demand is structural. But the investment opportunity within that demand is not uniform. Professional investors are separating the businesses that benefit from structural tailwinds from the ones that are merely present in a large market, and that distinction has never been sharper than it is in 2026.

Three forces are converging to reshape the cybersecurity investment landscape simultaneously.

The first is AI on both sides of the equation. Attackers are using AI to move faster, target more precisely, and evade detection more effectively. Defenders are using AI to detect behavioural anomalies in real time, respond autonomously before human analysts can act, and compress mean time to detect from the industry average of 200-plus days to under one minute. The leading AI cybersecurity companies include CrowdStrike with its Falcon platform and Charlotte AI, Palo Alto Networks with Cortex XSIAM, Microsoft with Security Copilot, Darktrace with autonomous response, and SentinelOne with Purple AI for threat hunting. The businesses winning in this environment are the ones that can demonstrate AI defence capability that outpaces AI attack capability. That is now the central technical competition in the sector.

The second is platform consolidation. Enterprises spent years assembling point solutions, a different vendor for endpoint, another for cloud, another for identity, another for network security. The complexity of managing dozens of disconnected security tools has proven operationally unsustainable, and the attack surface created by the gaps between those tools has proven exploitable. The consolidation toward integrated platforms that share telemetry, correlate signals across surfaces, and respond autonomously is the dominant commercial dynamic in enterprise security purchasing right now.

The third is the on-premises AI thematic, and it is the most significant emerging investment signal in the sector that most mainstream commentary has not yet fully registered.

The on-prem AI thematic

Here is the dynamic that is reshaping cybersecurity investment in ways that pure cloud-native security businesses need to understand urgently.

As organisations deploy AI at enterprise scale, they are confronting a fundamental tension. AI systems are most useful when they have access to the most sensitive data. But the most sensitive data, classified government intelligence, critical infrastructure operational technology, patient health records, financial trading algorithms, defence logistics, is precisely the data that cannot leave the organisation's own environment and be processed by a cloud provider.

SentinelOne announced at RSAC 2026 that it is bringing autonomous AI security to on-premises and self-hosted environments, building on its existing advantage as the only next-generation cybersecurity company to deliver modern endpoint protection with zero cloud dependency. By ensuring all data is processed strictly within the customer's own environment, the offerings provide complete data privacy and sovereignty.

📱

This is not a niche announcement. It is a signal of a category-defining shift.

Governments globally are treating reliance on foreign AI supply chains as a national security risk. Gartner predicts that by 2028, at least 80% of governments globally will deploy AI agents to automate routine decision-making, and sovereign AI has already reached peak priority status on the 2025 Gartner Hype Cycle for government services. The FBI identified Russian FSB groups targeting Cisco infrastructure inside U.S. critical facilities. CISA documented Chinese groups Volt Typhoon and Salt Typhoon using living-off-the-land tactics inside power grids, water systems, and pipeline networks. Every cloud-connected AI system deployed inside critical infrastructure adds another network path that state-sponsored adversaries can traverse.

The investment implication is significant. Businesses that can deliver AI-powered cybersecurity inside an organisation's own perimeter, with no cloud dependency, no data leaving the environment, and no foreign supply chain exposure, are addressing a demand that no cloud-native security vendor can satisfy.

🏰

That is a structural moat that does not depend on being the best product. It depends on being the only product that meets the sovereignty requirement.

Cisco launched its Sovereign Critical Infrastructure portfolio in September 2025 to address customers' needs for more control and autonomy over their digital infrastructure and data, spanning routing, switching, wireless, collaboration, and security solutions running under special license in air-gapped environments on customer premises, physically isolated from outside networks. IBM, F5, and a growing cohort of specialised sovereign AI security vendors are building the same capability for the same reason. The government and defence segment held the largest market share in the sovereign AI infrastructure market in 2025, and the healthcare, financial services, and energy sectors are following rapidly behind it.

For founders building in this space, the sovereign AI plus cybersecurity intersection is one of the most defensible commercial positions available in the entire technology landscape. Government procurement cycles are long, but the contracts are large, the switching costs are enormous, and the competitive set is far smaller than in the commercial cloud security market.

The investor angle, CrowdStrike and the anatomy of a fortress-strength commercial engine

No case study better illustrates what a fortress-strength commercial engine looks like in cybersecurity than CrowdStrike's recovery from the July 2024 global IT outage.

When a faulty software update triggered a worldwide IT failure, taking down millions of Windows machines and causing billions in economic damage across airlines, hospitals, and enterprises, the central question for investors was not whether the company would survive. It was whether customers would stay, and whether growth would recover before the damage became structural.

By the end of fiscal year 2026, the answer was definitive. Net new ARR grew 47% year-over-year in Q4 alone, reaching $331 million. For the full year, net new ARR hit $1.01 billion, the first time CrowdStrike had crossed that threshold. Ending ARR reached $5.25 billion, growing 24%, making CrowdStrike the fastest pure-play cybersecurity company to reach that milestone. Gross retention held at 97% throughout the recovery period.

🏆🏆🏆

The reason customers stayed is precisely the reason professional investors pay a premium for platform businesses over point solutions. CrowdStrike had become too embedded to remove. Not because customers were locked in contractually, but because the Falcon platform had become the intelligence layer across their entire security operation. Removing it would mean rebuilding their security architecture from scratch, a cost that far exceeded any frustration with the outage.

The $5.25 billion ARR milestone, 95% subscription mix, 115% net retention, and 50% adoption of six or more modules point to a business model where growth is increasingly self-reinforcing. Sweet.

The strategic question is no longer whether CrowdStrike can sustain growth. It is whether the Falcon platform can become the default cybersecurity operating system for the enterprise. CEO George Kurtz has articulated a clear path toward $10 billion in ending ARR, roughly doubling the current base.

The CrowdStrike story contains the most important lesson in cybersecurity investing.

📱

Trust, once built through genuine platform depth and consistent delivery, creates a commercial moat that survives even a catastrophic operational failure.

The businesses that professional investors pay premium multiples for in this sector are not the ones with the best marketing. They are the ones that have made themselves genuinely difficult to remove.

Beyond CrowdStrike, the M&A market is confirming where professional capital sees the most durable value. The need for AI-powered defence has fuelled acquisitions including Check Point's $300 million purchase of Lakera for LLM security, Palo Alto's $700 million Protect AI deal, and SentinelOne's $225 million Observo AI acquisition. Thoma Bravo completed a $5.3 billion acquisition of Darktrace.

144 AI security deals closed in 2025, making it the most active cybersecurity investment category.

The sector is not just generating strong organic growth. It is generating M&A activity that reflects how seriously large, sophisticated acquirers are treating the AI-native defence capability gap.

Still think its boring?

The tipping point, trust is slow to build and fast to lose

There’s an investability hallmark that deserves more attention than it typically receives.

📱

Hybrid work and cloud reliance increase demand, but buyers adopt slowly while new product trust and credibility take time to build.

That is the most important commercial friction in cybersecurity, and it is the thing that most founders building in this space underestimate.

Security purchasing decisions are not made by the same buyer who purchases a SaaS productivity tool or a marketing platform. They are made by CISOs and security teams whose professional reputation depends on the reliability of the products they deploy. A new security vendor, however technically excellent, faces a trust deficit that takes time, customer references, third-party validation, and often a proof-of-concept deployment to close. The sales cycle is long. The proof-of-value requirement is demanding. And the consequence of a failure, as CrowdStrike demonstrated in July 2024, can be catastrophic at global scale.

📱

That friction is both the challenge and the moat.

It is what makes it hard to enter the market. It is also what makes it hard to leave once you are embedded. The businesses that understand this dynamic, that invest in building trust before they need it, that accumulate the customer references and regulatory certifications and third-party validations that the next enterprise buyer will demand, are the ones that build lasting commercial positions.

The businesses that underestimate it are the ones that discover, too late, that having a technically superior product is necessary but not sufficient to win a large enterprise security contract.

Founder challenge

If you are building, enabling, or monetising in cybersecurity, whether that is endpoint, cloud, identity, network, OT security, AI-native defence, sovereign on-premises security, or any of the enabling tools and services that support the broader ecosystem, the question every professional investor will ask is not whether your technology works.

Here are the more likely questions you will encounter.

đŸ›Ąïž Does your business sit on the AI defence side of the equation or the AI attack surface side? The businesses that use AI to detect, respond, and predict faster than attackers can adapt are building structural advantages. The businesses that are simply adding AI features to existing approaches are adding marketing language.

đŸ›Ąïž Is your commercial engine built around platform depth or point solution capability? In a market consolidating rapidly toward integrated platforms, the question is not whether your product is excellent. It is whether your product can become part of a platform that an enterprise cannot easily remove. Switching cost is moat. Switching cost is what survived CrowdStrike's worst day.

đŸ›Ąïž Have you mapped your sovereign AI opportunity? If your product can deliver AI-powered security inside an organisation's own perimeter, with no cloud dependency and no foreign supply chain exposure, you have access to a government, defence, critical infrastructure, and regulated industry market that cloud-native competitors cannot reach. That is a structural moat worth building explicitly into your business and investment thesis. Not there? Rebuild.

đŸ›Ąïž How long does it take a new enterprise customer to trust you enough to deploy your product in their most critical environment? That timeline is your most important commercial constraint, and the investment required to shorten it, customer references, certifications, proof-of-concept programmes, third-party validation, is work that needs to happen before you walk into the capital markets, not after.

The founders who answer those questions with precision and evidence leave the room with capital. The ones who can't discover, too late, that a technically superior cybersecurity product without a trust foundation is not a commercial engine. It is an expensive engineering project waiting for a breach to make its case.

How pitchhawk helps you answer those questions

At pitchhawk, we don't start with your pitch.

📱

We start with your underlying business and investment thesis.

Using an outside-in, buy-side perspective, we diagnose whether you’ve been able to transform your innovation into a fortified and investable business. We pressure-test the underlying commercial engine to reveal the structural signals professional investors recognise. Then we help fortify what already exists, build what's missing, and show you how to wrap it in an investment thesis that helps professional investors recognise what you've actually built.

In cybersecurity, that work reveals more clearly than almost any other sector whether a founder has built a trust asset or a technology asset. Those are not the same thing. And professional investors, the ones writing the large cheques and leading the large acquisitions, have become very precise about the difference.

Our mission is simple. Helping founders transform innovations into Fortress-Strong, Investor-Ready (and Buyer-Ready) businesses that professional investors can quickly recognise and confidently back.

đŸ›Ąïž Are you listening to the signal?

pitchhawk is.

Mike 🖐

Innovation rarely stalls because of a lack of ideas.

It stalls in the gap between a great innovation and a fortress-strong investable business.

That gap never closed because nobody was incentivised to provide founders with an independent investor's lens.

pitchhawk is.

© pitchhawk, 2025-6. All rights reserved. You may not copy, reproduce or imitate our services, content, frameworks or intellectual property.

Next
Next

Investor signals #8: Biotech and life sciences, where the science is extraordinary and the commercial engine is everything