NGE · Investment Letter · Issue 87 · June 2026

The Invisible War:
Cybersecurity and
the Companies
Building the Walls
of the Digital World.

Cybercrime will cost the world $10.8 trillion in 2026. That makes it the world's third largest economy — behind only the United States and China. A US data breach now costs organisations $10.2 million on average — the highest on record. AI has made attackers dramatically faster: the median time from initial compromise to data theft has dropped to under 80 minutes. The defenders are building faster too. Cybersecurity is the most important sector in technology that most investors still don't understand deeply enough.

Data sourced from CrowdStrike FY2026 Annual Results, Cybersecurity Ventures 2026 Report, Gartner Cybersecurity Spending Forecast 2025, Research and Markets Cybersecurity Market Report March 2026, and company filings. All figures current as of June 2026.

The Scale — Why This Is the Most Non-Discretionary Sector in Technology

$10.8 trillion in cybercrime.
The world's third largest economy.
You cannot opt out of defending against it.

There is a category of technology spending that behaves differently from all other technology spending. When budgets are cut, enterprise software is deferred. Cloud migrations are slowed. Digital transformation projects are paused. Cybersecurity is not paused. It cannot be. The moment you stop defending, you become a target. The moment you become a target without defence, the breach costs you more than the defence ever would have. Cybersecurity is the only technology category where the cost of not buying is higher than the cost of buying. That makes it the most structurally resilient sector in all of enterprise software.

The numbers make this concrete. Cybercrime costs reached $10.8 trillion globally in 2026 — up from $3 trillion in 2015. The attack surface has expanded with every device, every cloud service, every AI model, every remote worker, every supply chain connection. At the same time, the tools available to attackers have become dramatically more powerful. AI-generated phishing emails are now indistinguishable from legitimate corporate communications. Deepfake video of CFOs authorising wire transfers. Automated vulnerability discovery that finds zero-day exploits in hours. The cybersecurity industry exists because the alternative — not spending on defence — is categorically more expensive. No board of directors can explain to shareholders why they chose not to defend against a breach that cost $10.2 million to remediate.

$10.8T
Global cybercrime cost 2026 — world's third largest economy after US and China
$255B
Cybersecurity market 2025 — projected to reach $580B by 2031 at 14.68% CAGR
80 min
Median time from initial compromise to data theft in 2025 — down from hours in 2022
The Threat Landscape — What Has Changed

AI didn't just help the defenders.
It helped the attackers first.
And the attackers move faster.

The cybersecurity threat landscape in 2026 is categorically different from what it was five years ago — not in kind but in speed, scale, and sophistication. The same AI capabilities that are accelerating drug discovery, optimising supply chains, and generating investment research are simultaneously being deployed by criminal organisations, nation-state actors, and ransomware groups to attack digital infrastructure at a scale and speed that human defenders cannot match without AI-powered defences of their own.

Threat Type What Has Changed · 2026
AI Phishing
300% increase in deepfake-based social engineering attacks in 2025 (CrowdStrike). AI generates thousands of unique, contextually accurate phishing messages per hour — personalised with LinkedIn profiles, recent emails, company news. Detection by traditional email filters failing. 250% increase in AI deepfakes from 2024 to 2025.
Ransomware
Median dwell time — the period between initial compromise and detection — has collapsed from weeks to hours. Ransomware-as-a-service means criminal organisations with no technical capability can rent sophisticated attack tools. Average ransom payment crossed $1.5 million in 2025. Healthcare and critical infrastructure the primary targets.
Supply Chain Attacks
The SolarWinds attack (2020) demonstrated that compromising one supplier can expose thousands of downstream organisations simultaneously. Supply chain attacks increased 742% between 2019 and 2024. AI accelerates the identification of vulnerable nodes in complex supply chains. The CrowdStrike outage of July 2024 — a software update, not an attack — showed the systemic fragility of concentrated security infrastructure.
Nation-State Actors
China, Russia, North Korea, and Iran all maintain sophisticated state-sponsored cyber operations. Nation-state attacks are no longer primarily espionage — they are pre-positioning for potential kinetic conflict. Critical infrastructure (power grids, water systems, financial systems) increasingly targeted for reconnaissance and potential sabotage. The line between cybersecurity and national security has dissolved.
AI Model Attacks
New threat category: prompt injection, model poisoning, and adversarial attacks against AI systems themselves. As AI becomes embedded in critical decision-making — credit scoring, medical diagnosis, autonomous vehicles — the security of the AI model becomes a national security issue. Check Point's $300M acquisition of Lakera (LLM security) signals where the next wave of security investment will flow.
The Giants — Who Is Winning the Invisible War

Platform consolidation.
The era of 50 point solutions
is ending.
The era of 3 platforms
is beginning.

The cybersecurity industry has historically been fragmented — thousands of vendors, each solving a specific problem, each requiring separate deployment, management, and integration. The average enterprise in 2019 ran 76 separate security tools. The complexity itself became a vulnerability: too many tools, too many alerts, too few security professionals to monitor all of them. The consolidation wave of 2024–2026 is the market's answer to this problem. Platform companies are acquiring point solution specialists and integrating them into comprehensive platforms that can be managed from a single pane of glass. The number of cybersecurity vendors will shrink from thousands to hundreds in three years.

CrowdStrike NASDAQ: CRWD Cloud Endpoint · XDR · AI-Native

The defining company of the cloud-native cybersecurity era. FY2026 revenue of $4.81 billion — up 22% year-on-year. Annual recurring revenue of $5.25 billion, with net new ARR crossing $1 billion for the first time. Gross retention at 97% — a figure that reflects genuine switching costs. 50% of customers use six or more modules; 34% use seven or more — the platform consolidation playing out in real customer data.

The Falcon platform's intelligence advantage is structural, not temporary. CrowdStrike processes more than 1 trillion security events per day across its customer base, feeding the AI models that detect novel threats before they spread. Each new customer makes the platform smarter for all customers — a data network effect that point solutions cannot replicate. The January 2024 acquisition of SGNL (identity management) and the browser-security arm race against Zscaler extend the platform into new attack surfaces.

The July 2024 software update outage — which grounded airlines, halted hospitals, and disrupted critical infrastructure globally — was the company's most dangerous moment. It survived because customers with CrowdStrike deeply embedded had no viable alternative to switching back on and staying. That survival, at scale, under pressure, is the ultimate proof of switching cost moat.

$5.25B ARR · 97% gross retention · 22% growth · The platform that won cloud endpoint.
Palo Alto Networks NASDAQ: PANW Network · Cloud · AI Security · Platformisation

The largest pure-play cybersecurity company by revenue and market cap. Palo Alto's strategy — "platformisation" — is the most explicit articulation of the consolidation thesis. The company is actively offering customers the ability to consolidate multiple security vendors onto the Palo Alto platform, sometimes offering free or discounted access to new modules in exchange for displacing competitors. It is a land-and-expand strategy executed at enterprise scale.

The CyberArk acquisition in July 2025 for $25 billion — the largest cybersecurity deal in history — added identity security, the fastest-growing security category. Palo Alto's Q4 FY2025 delivered $2.5 billion in revenue, beating expectations. Net retention for platform customers at 120% — meaning customers spend 20% more each year after joining the platform. The acquisition machine continues: $2.8 billion cloud security acquisition in Q1 2026, plus Protect AI ($700M) for AI security capabilities.

120% net retention for platform customers. The broadest portfolio in enterprise security after CyberArk.
Microsoft Security NASDAQ: MSFT The Quiet Giant · $37B Security Business

The most underappreciated competitive threat in cybersecurity. Microsoft has quietly built a $37 billion cybersecurity business — making it larger than CrowdStrike, Palo Alto, and Zscaler combined. The mechanism: bundling. When a Fortune 500 company already pays for Microsoft 365 E5, adding Defender and Sentinel costs effectively nothing incremental. The security features are already included. The deployment friction is near-zero for companies already on Microsoft infrastructure.

This is the most powerful competitive moat in enterprise software: distribution through an existing dominant platform. Microsoft doesn't need to win cybersecurity deals — it needs not to lose them. Every security budget dollar that stays within the Microsoft ecosystem is revenue that CrowdStrike and Palo Alto cannot capture. Security Copilot — Microsoft's AI security assistant — extends this advantage into the AI era. The company that controls the operating system, the email, the productivity suite, and the cloud has the best possible position to control the security layer too.

$37B security business. Bundled distribution through Microsoft 365. The competitor pure-play vendors cannot price-compete against.
Zscaler NASDAQ: ZS Zero Trust · SASE · Cloud Security

The canonical zero-trust architecture company. Zero-trust is the security philosophy that replaces the old "castle and moat" model — where everything inside the network is trusted — with a model where nothing is trusted by default. Every access request is verified, regardless of where it originates. With 41% of enterprises having adopted zero-trust architecture in 2025 (up from 24% in 2023), the remaining 59% represent years of deployment cycles ahead.

Zscaler's FY2026 delivered 26% revenue growth and $6.1 billion in contracted revenue — a backlog that provides visibility into future revenue that most software companies cannot match. The February 2026 acquisition of SquareX launched a browser-security arms race with CrowdStrike, recognising that the browser is now the primary attack surface in a world of cloud-native work. OpenAI's Trusted Access for Cyber programme in April 2026 anointed Zscaler as one of three platform consolidators alongside CrowdStrike and Palo Alto — the most significant third-party endorsement in the industry's recent history.

$6.1B contracted revenue. 26% growth. Zero-trust market leader. 59% of enterprises still to adopt.
The Unicorns — Private Market Leaders to Watch

The next wave.
Companies solving problems
that didn't exist five years ago.

Wiz
~$15B valuation · IPO expected Q2–Q3 2026

Cloud security posture management. Google offered $12B to acquire it in 2024 — Wiz declined. IPO filing in 2026 targets $15B+ valuation. Scans entire cloud environments for misconfigurations in minutes, not weeks. The fastest-growing cybersecurity company in history by ARR growth rate. $500M+ ARR. Every major cloud-native enterprise needs it.

Netskope
$9.6B · NASDAQ: NTSK · Listed Sep 2025

Successfully IPO'd September 2025 at $9.6B market cap — the first major cybersecurity listing in years. Proved public markets will support high-growth security assets at rational valuations. SASE (Secure Access Service Edge) platform. The green light for 2026's cybersecurity IPO wave.

Cato Networks
$4.8B Series G 2025 · IPO 2026 target

SASE platform alternative to Zscaler. Series G at $4.8B in 2025. Bankers hired. Cloud-native SASE built on its own global private backbone — not using public internet routing. Competing with Zscaler and Palo Alto in the network security transformation market.

SentinelOne
NASDAQ: S · $5.6B · Most-discussed takeout

Listed but deeply undervalued relative to CrowdStrike at 5.6× sales vs CrowdStrike's premium. $1.06B ARR, 23% growth. GovRAMP High status makes it the leading candidate for a government-focused acquirer. Founder-CEO has declined sale talks before — but the valuation gap makes it the most-discussed acquisition target in cybersecurity.

Cyera / Securiti AI
AI Data Security · Fastest-growing category

Data Security Posture Management — knowing where your sensitive data is, who has access, and whether it's at risk. AI workloads turning data security into a board-level priority. As LLMs are trained on enterprise data, the security of training data becomes existential. Early-stage but the fastest-growing subcategory in enterprise security.

Lakera · Protect AI
LLM Security · New frontier · Already acquired

The newest category: securing AI systems themselves against prompt injection, model poisoning, and adversarial attacks. Check Point acquired Lakera for $300M. Palo Alto acquired Protect AI for $700M. Both in 2025. The speed of these acquisitions signals how fast the LLM security category is developing — and how quickly the platforms are moving to own it.

The Investment Thesis — Why This Sector Compounds

Non-discretionary spending.
Expanding attack surface.
AI on both sides.
Platform consolidation creating
winner-take-most dynamics.

Four structural forces make cybersecurity one of the most compelling long-term investment sectors in technology — and they all reinforce each other.

First: the attack surface expands every year without exception. Every new device, every new cloud service, every new AI model, every new remote worker creates new attack surface. The IoT devices in a smart factory, the AI assistants processing confidential data, the supply chain connections between thousands of companies — each is a potential entry point. The attack surface cannot shrink. It can only grow. This means cybersecurity demand structurally expands with digital adoption — which is the most reliable growth tailwind in enterprise technology.

Second: AI accelerates both attacks and defences, but the economic incentives favour the defenders long-term. AI makes attacks cheaper to launch and more sophisticated to detect. But AI also makes defences more effective — CrowdStrike's 1 trillion daily security events feed AI models that detect novel threats in real time. The asymmetry matters: defenders must be right every time, attackers only once. AI begins to close this asymmetry by automating the detection and response that human analysts cannot perform at the required speed and scale.

Third: platform consolidation creates winner-take-most dynamics — exactly as it does in enterprise software broadly. Once CrowdStrike's Falcon platform is deployed across an enterprise, with six or more modules integrated, the switching cost is enormous. The company that loses a $3 million cybersecurity platform deal doesn't lose $3 million — it loses the next 10 years of expanding spend from that customer as new modules are added. CrowdStrike's 97% gross retention and Palo Alto's 120% net retention for platform customers are the quantitative expression of this dynamic.

Fourth: the regulatory environment is tightening globally, converting optional security spending into mandatory compliance. The SEC now requires public companies to disclose material cybersecurity incidents within four business days. The EU's NIS2 directive expands mandatory cybersecurity requirements across 18 critical sectors. India's Digital Personal Data Protection Act creates compliance obligations for any company handling Indian citizen data. Each new regulation converts discretionary security investment into non-discretionary compliance spending. The market is being enlarged by regulators who are responding to the same threat landscape that drives organic demand.

The Honest Read — The Risks That Matter

Valuation is the primary risk in cybersecurity investing. CrowdStrike traded above 100× forward earnings in late 2025. Palo Alto peaked near 70×. Zscaler above 80×. High-multiple stocks absorb disproportionate damage during broad tech selloffs, and Q1 2026 delivered exactly that repricing. The companies are excellent. The question at any given moment is whether the current price already reflects the excellence. The structural tailwinds are durable. The entry timing matters enormously.

Microsoft is the competitive risk that pure-play investors systematically underweight. A $37 billion security business, growing, bundled into products that enterprises already pay for — this is not a niche competitor. It is the dominant distribution channel in enterprise IT offering "good enough" security at marginal-zero incremental cost. Pure-play vendors win on best-of-breed capability. Microsoft wins on distribution, integration, and price. The market is large enough for both. But the margin compression that bundling creates for the pure-plays is real and structural.

The CrowdStrike outage of July 2024 demonstrated systemic fragility. When one security vendor's faulty update takes down 8.5 million Windows devices globally — grounding airlines, halting hospitals, disrupting financial systems — the concentration risk of the cybersecurity industry becomes visible. The platforms that have won are deeply embedded in critical infrastructure. When they fail, the consequences are global. This concentration is both the source of the moat and the source of the risk. The regulators have noticed and the oversight is increasing.

The NGE View

The verdict.

What We Believe
Cybersecurity is the most structurally non-discretionary sector in enterprise technology. The cost of not spending is higher than the cost of spending — a statement that applies to almost no other category in enterprise software. With cybercrime at $10.8 trillion annually, data breach costs at $10.2 million per incident, and regulatory requirements expanding across every major jurisdiction, the demand for cybersecurity is not correlated with economic cycles. It grows with the attack surface. The attack surface grows with digitalisation. Digitalisation is irreversible. Therefore cybersecurity demand is structurally irreversible — one of the very few genuine investment theses that holds across economic cycles.
The platform consolidation wave is creating CrowdStrike, Palo Alto, and Zscaler as the Salesforce, ServiceNow, and Workday of enterprise security. Just as those companies built platforms that captured expanding wallet share from point solutions across CRM, IT service management, and HR, the security platform companies are capturing an expanding share of security budgets by integrating more capabilities onto fewer platforms. The 97% gross retention and 120% net retention numbers are not just good metrics — they are the quantitative signature of winner-take-most platform dynamics playing out in real time.
AI is the most important variable in cybersecurity over the next five years — on both sides. AI-powered attacks — deepfakes, automated vulnerability discovery, AI-generated phishing — are escalating faster than pre-AI defences can adapt. AI-powered defences — anomaly detection at 1 trillion events per day, automated threat hunting, real-time response — are the only mechanism that can match the velocity of AI-powered attacks. The companies that build the best AI security models, trained on the largest security datasets, will have structural advantages that compound over time. CrowdStrike and Palo Alto are already there. The race to build LLM security (Lakera, Protect AI, Cyera) is the next frontier.
The safe digital world is not a destination. It is a continuous arms race. Every advance in defensive capability is met with a corresponding advance in offensive capability. The attack surface expands every year. The sophistication of attacks increases every year. The cost of breaches rises every year. This is not a problem that gets solved — it is a problem that gets managed, continuously, by an industry whose demand is therefore permanent. The companies building the walls of the digital world are not building walls that will eventually be high enough. They are building an industry whose relevance is guaranteed by the same forces — digitalisation, AI, geopolitical tension, expanding connectivity — that are driving the rest of the economy. In a world where everything of value is digital, cybersecurity is the lock on the door. You do not remove the lock when the neighbourhood improves. You upgrade it.
NGE · A Futuristic Investment Letter

Long-horizon thinking on capital, technology, and the forces shaping the next decade of wealth creation. Written from first principles. Not consensus. Not noise.

— Pawan Bhatia · NextGen Economics · Bangalore, India