The global private security market is $278 billion in 2026, heading to $394 billion by 2034. The counter-drone market will triple from $4.5 billion to $14.5 billion by 2030. AI in cybersecurity is on a 25% compound annual growth rate. A drone capable of shutting down an airport costs under $500 and can be bought online. The threat environment has industrialised — and so, finally, has the response. Private and industrial security is not a defensive allocation any more. It is one of the highest-conviction structural growth stories of the next decade.
Not investment advice. Not a recommendation to buy or sell. Research and long-horizon thinking only. Consult a qualified financial advisor before making any investment decision. Figures cited are sourced from Fortune Business Insights, MarketsandMarkets, Coherent Market Insights, Technavio, Knowledge Sourcing, and Domain-B, current as of June 2026.
Security spending has always grown in response to threats. What has changed in the 2024–2026 period is the nature of the threat itself: it has industrialised. A commercial drone capable of disrupting an airport costs under $500, requires no technical expertise to operate, and is available on any consumer electronics platform. The same AI capabilities that power enterprise productivity tools power adversarial deepfakes, AI-generated phishing campaigns, and automated vulnerability scanning of industrial control systems. The Ukraine conflict normalised drone warfare in ways that any non-state actor, criminal organisation, or disgruntled individual can now apply — and the Red Sea cable-cutting events this series covered in Letter 45 confirmed that critical physical infrastructure is as vulnerable to low-cost disruption as digital infrastructure has been for years.
The consequence for security spending is not incremental. It is structural. Over 55% of organisations globally have already deployed drones for security surveillance. Fifty percent report reduced costs and improved operations post-adoption. Counter-drone systems — which barely existed as a commercial category five years ago — are now being purchased by airports, energy utilities, port operators, and stadium operators as standard infrastructure, not discretionary capability. The US Department of Homeland Security launched a dedicated office for counter-drone technology in January 2026. The EU's security technology procurement increased significantly following the Baltic cable incidents and expanded following the Red Sea disruptions. This is not a cycle. It is a permanent uplift in the baseline level of security infrastructure that every critical facility, industrial complex, and major enterprise must now maintain.
"A drone capable of shutting down an airport costs under $500 and can be bought online. The asymmetry between attacker and defender has never been greater — and that asymmetry is what makes the security industry's growth structural rather than cyclical."
The single fastest-expanding threat category. Drone incursions at airports, energy facilities, ports, and critical infrastructure are growing in frequency and sophistication simultaneously. Consumer drones modified for payload delivery, swarm attacks, and targeted surveillance are documented threat vectors that existing perimeter security — fences, guards, CCTV — cannot address. The threat is volumetric (many cheap drones), fast (faster than human response), and increasingly AI-coordinated.
The collapse of the distinction between digital and physical security. Industrial control systems for power grids, water treatment, and manufacturing are increasingly networked — and the attack surface is the same whether the adversary is trying to steal data or stop a turbine. AI-powered threat detection is now the primary response, with the AI in cybersecurity market growing at 25%+ CAGR because human analysts simply cannot process the volume of alerts generated by modern threat environments.
Documented, current, and escalating. The subsea cable incidents (Letter 45), the Nordstream pipeline attack, and the documented targeting of European energy infrastructure have shifted the status of critical infrastructure from a theoretical risk category to an active operational reality. Every utility, energy company, port, and data centre now faces a procurement mandate — not a choice — to upgrade its physical and electronic security posture.
The attacker's tool getting cheaper faster than the defender's. AI-generated deepfakes for executive impersonation fraud, AI-powered spear phishing that personalises at scale, and AI-assisted penetration testing tools that find vulnerabilities faster than human red teams — all of these are available commercially to adversaries at marginal cost. The security industry's response — AI-powered detection, behavioural anomaly identification, automated incident response — is real and growing, but is running behind the attack capability curve.
Industrial security — protecting manufacturing facilities, logistics hubs, energy infrastructure, data centres, and critical supply chain assets — is the segment this letter has most conviction in, precisely because it is the segment where the procurement decision has moved from discretionary to mandatory. A data centre that hosts AI compute without perimeter drone detection, insider threat monitoring, and AI-powered physical intrusion detection is now an uninsurable asset in several markets — insurance underwriters are actively pricing the absence of these systems into premiums. An energy facility without cyber-physical security integration is, post-Nordstream, a board-level liability rather than an IT department conversation.
The industrial segment was valued at $127 billion in 2024 and is the fastest-growing application within the broader private security market. Asia-Pacific is expected to contribute 43% of growth going forward — driven by the same urbanisation, industrialisation, and critical infrastructure buildout that this series identified in earlier letters on Indo-Pacific growth corridors and the global grid investment supercycle. The robot-rich manufacturing facilities described in Letter 43 require robot security: physical perimeter protection, insider threat detection, and AI-powered anomaly monitoring of the robots themselves as a new attack surface.
AI-powered compute infrastructure is the world's most concentrated high-value target. A single hyperscale data centre failure can disrupt continental-scale services. Physical perimeter drone detection, biometric access control, and insider threat monitoring are now standard procurement — not optional extras. The data centre security sub-market is growing faster than the overall industrial segment.
Post-Nordstream and post-Red Sea cable incidents, every energy utility in Europe and Asia is reassessing its physical and cyber-physical security posture. Counter-drone systems at substations, AI-powered SCADA monitoring, and physical perimeter hardening are being procured simultaneously, driven by a combination of regulatory mandate and insurance market pressure.
Ports are the chokepoints of global trade, and drone threats — from smuggling surveillance to targeted disruption — have made airspace monitoring a core port security requirement. Orange Business launched Orange Drone Guardian specifically for port and critical infrastructure protection in March 2026. The maritime security technology market is a direct extension of the seabed frontier thesis in Letter 45.
Corporate campuses and smart buildings are deploying integrated security platforms that combine access control, CCTV, drone surveillance, AI anomaly detection, and cyber monitoring in a single managed service. This convergence is creating a new market category — Security-as-a-Service (SecaaS) — where the recurring revenue model mirrors the SaaS transition in enterprise software, with equivalent margin characteristics.
The security industry has historically been a low-margin, labour-intensive, commoditised services market dominated by Allied Universal, Securitas, G4S, and a handful of other large players competing primarily on price. The technology transition is genuine and is creating new margin pools — but it is also attracting well-capitalised technology incumbents (Palantir, Palo Alto Networks, Axon, Motorola Solutions) who bring software-scale economics to a market the legacy players built on headcount. The risk for traditional security services companies is not that demand falls — it won't — but that the margin expansion accrues to the technology layer rather than the services layer, compressing the economics of the companies that deploy guards while enriching the companies that sell the AI platforms those guards report into.
The $394 billion private security market projection to 2034 is the steady-state baseline — the high-growth opportunity is in the technology sub-segments, where CAGRs of 17-25% are genuinely sustained by structural demand rather than cyclical expansion. An investor choosing between the broad market and the technology sub-segments is choosing between a steady, defensive compounder and a growth trade. Both are valid allocations; they are not the same allocation, and conflating them is the most common error in security sector analysis.
The security industry's transformation from a labour-intensive, low-margin, largely invisible sector into a technology-driven, high-growth, strategically critical one is one of the least discussed structural shifts in the current investment landscape. The reason is simple: security doesn't generate the kind of consumer-facing excitement that AI chips, humanoid robots, or the next social media platform do. But the structural forces driving its growth — an industrialised threat environment, critical infrastructure procurement mandates, AI-powered attack capabilities requiring AI-powered defence, and a drone democratisation that has permanently altered the cost equation of physical disruption — are as durable as any of the other structural themes this series has tracked. The world has discovered, at cost, that its critical infrastructure was underprotected. The spending to fix that is only beginning.
Long-horizon thinking on capital, technology, and the forces shaping the next decade of wealth creation. Written from first principles. Not consensus. Not noise.