CrowdStrike and Okta Trade at Big Premiums Despite Unproven AI Payoff

Cybersecurity stocks have enjoyed a good run in 2026 as investors bet on the idea that they’ll benefit from companies shoring up their defenses against AI-fueled online threats. The S&P Kensho cybersecurity index is up 41% this year compared to an 11% rise in the S&P 500 over the same period.
But some of the names attracting the most interest, such as cloud-based security firm CrowdStrike and identity security software provider Okta, have soared to valuation highs that should give investors in the sector pause. So far, there’s limited evidence that their revenue growth is getting a boost from new AI concerns.
Cybersecurity valuations are at “eye-watering levels,” according to Fatima Boolani, an equity analyst at Citi who covers cybersecurity stocks including CrowdStrike and Okta, which means they’re “not as compelling” despite the potential for their business to expand as AI usage introduces new cybersecurity threats.
Take CrowdStrike, whose stock is up 103% so far this year. CrowdStrike trades at 36 times next year’s estimated sales, according to S&P Global Market Intelligence, close to its highest multiple in its history as a public company. But CrowdStrike’s revenue growth slowed to 21.7% in the year ending January, from 29.4% a year earlier. It’s expected to accelerate slightly to 24.8% this fiscal year, before settling at around 22% in both fiscal 2028 and fiscal 2029.
That hardly deserves the kind of multiple at which CrowdStrike is trading. ServiceNow, which historically has focused on selling software to automate corporate processes such as human resource management and customer service support, is also making inroads into selling security software. It has been growing consistently at a 20% to 22% rate in recent years. In line with that history, it is expected to grow 22.2% in its current fiscal year, which ends in December. And yet ServiceNow trades at a multiple of just eight times next year’s estimated sales.
Then there’s Okta, which sells software to help businesses confirm workers’ identities and ensure they have access to the right systems. It’s a particularly hot area within the cybersecurity landscape. That’s because of the proliferation of AI agents, which can complete tasks on behalf of a user without needing approval at each individual step. Okta has just started introducing new products to address security for AI agents.
Yet Okta’s growth has slowed to just 11.8% in the year to January, and it’s expected to grow at 11.2% this fiscal year. That’s a little below Salesforce, which is expected to grow at 11.5% this year. And yet Okta trades at nine times forward sales, a sizable premium to Salesforce at just under five times.
To be sure, the pipeline of contracted revenue Okta expects to recognize over the next year grew a bit faster, at 14%. But that’s hardly fast enough to justify Okta’s multiple. The median forward revenue multiple for software companies is four times, well below Okta’s, while the median growth rate for the next 12 months is 13%, higher than Okta’s current expansion rate.
That suggests that while its suite of agentic AI security tools, which only became generally available in April, seems promising, Okta’s valuation has gotten ahead of tangible AI results.
“We find it difficult to call the timing of when AI Agent work really gets mature enough to scale AND how they would commercially benefit enough to exceed our current model,” Bernstein analysts wrote in a Sept. 17 note arguing that the company is among a spate of cybersecurity names that is “fully valued.” They added that Okta’s pricing model for its AI security tools as well as the scale of demand for those offerings is “still unclear.”
Why aren’t these firms growing faster, given the immense cyberthreats posed by AI? While businesses are spending more on cyber, the market is very crowded—and only getting more so. Aside from the older cybersecurity firms like CrowdStrike, Palo Alto Networks and Okta, Google and Microsoft both have sizable cybersecurity offerings. Google, for instance, bought cybersecurity firm Mandiant in 2022, and in March it acquired Wiz, another security firm.
Then there’s a bunch of newer startups that have emerged to deal with AI agent–related security problems, as we reported here.
And there’s also a chance that AI labs such as Open AI and Anthropic will eventually launch their own cybersecurity tools. As things stand now, many cybersecurity firms, including CrowdStrike, sell AI products built on top of foundation models from OpenAI and Anthropic.
“[Large language models] are strong at being able to reason over large frames of data, and I think that [frontier model builders] can provide the AI agents that can reason over the data, triage the data and take steps that a human security analyst would otherwise have to do to go investigate, triage and remediate these things,” said KeyBanc Capital Markets analyst Eric Heath.
Heath noted that he has been tracking job postings by OpenAI and Anthropic and concluded that the two firms have “broader ambitions” in cybersecurity than their current offerings suggest.
The fact that firms like CrowdStrike build products on top of AI firms’ models makes them vulnerable to price increases by the AI labs. And if the AI firms go direct, they could undercut the established cybersecurity firms on price.
SentinelOne, a cybersecurity software firm, explicitly called out this risk in its August quarterly report, saying that “as new competitors introduce new products or services that are similar to or compete with ours, we may be unable to effectively optimize our prices through increases or decreases, attract new customers at our offered prices or based on the same pricing model as we have used historically.”
Until investors know more about the contours of the potential disruption the frontier labs could wreak on the cybersecurity sector, it’s probably wiser to hold off on investing more capital into cybersecurity firms at today’s valuations.