Technology thesis · Cybersecurity
high conviction established matureCybersecurity
AI cyber defence concentrates where buyers are already protected; the AI-augmented damage through 2027 lands on SMBs and startups whose bespoke code sits outside hyperscaler default protection.
Position maintained continuously · last reviewed Jun 24, 2026
The thesis
Core thesis
Cybersecurity faces a structural crisis: AI-powered attacks outpace human defenders, the talent gap widens to 4M+ unfilled positions, and the industry consolidates into platform plays. Machine identities outnumber human employees 82 to 1. Agentic AI now handles portions of ransomware attack chains — reconnaissance, vulnerability scanning, even ransom negotiations — without human oversight. The 'CEO doppelganger' threat (AI-generated real-time replicas) represents a new attack category no existing defence addresses.
State of the art (2026)
The category has tipped from 'AI in cybersecurity' to AI versus AI. In November 2025 Anthropic disclosed the first reported AI-orchestrated cyber-espionage campaign – Chinese group GTG-1002 manipulated Claude into running 80–90 per cent of an operation against roughly 30 targets autonomously. Consolidation is now structural: Palo Alto Networks closed its 25 billion dollar CyberArk acquisition in February 2026 and Google completed its 32 billion dollar purchase of Wiz in March 2026, planting identity and cloud security inside the platform giants. Microsoft Security already clears 20 billion dollars annually. Defensive AI – CrowdStrike Charlotte, Microsoft Security Copilot, Palo Alto agentic SOC tooling – concentrates with buyers who were already well protected.
Platformisation is the winning strategy
The industry is moving from 50+ point products to 3-5 consolidated platforms. Palo Alto Networks leads this strategy explicitly. CrowdStrike dominates endpoint. Zscaler owns zero-trust network access. The losers will be point-product vendors without platform ambitions — acquisition targets or irrelevant.
Everything below is live inside CanaryIQ
The full analysis behind the verdict — the structure is real; the content unlocks when you log in.
Signal stack
Evidence stacked leading → lagging
Technology-native KPIs
Metrics that predict trajectory, tracked over time
Landscape map
Who builds what — and who depends on whom
Catalyst calendar
Dated events that will move the position
Technology roadmap
Milestones on the path to maturity
Watchlists
Companies, people and papers — each with a remove-by condition
Decision frameworks
The same call, framed for your desk
Thesis changelog
When our view changed, and why
Change our mind
3 disconfirming conditions
Comparable wave
The historical analogue on the S-curve
Common mistakes
What the market gets wrong right now
The rest is inside
You've read the verdict. The file is much deeper.
The full signal stack, technology-native KPIs tracked over time, the landscape of who depends on whom, the dated catalyst calendar, decision frameworks for every desk, live watchlists and the changelog of every time our call on Cybersecurity has changed — all live inside CanaryIQ.