Cyber security stocks are pumped up on P(doom)

The buzzword of the moment is a made-up mathematical function that reflects the probability of AI inducing mass destruction. But even as P(doom), as it is known, seemingly rises, so too do the share prices of companies that might offer some protection. Cybersecurity companies Palo Alto Networks, CrowdStrike and Fortinet have more than doubled over the past six months.

Line chart of Cyber security vendors’ market capitalisation (rebased) showing Playing it safe

It isn’t hard to see why: AI isn’t just adept at escaping from its sandbox to infiltrate other organisations, from Hugging Face to the Australian government. It also provides bad actors with the muscle power to create deepfakes that fool security systems, craft personalised “phishing” emails and trick AI agents operating within companies into leaking data.

Besieged by ever-increasing cyber threats, organisations are hurling money at the problem. Cyber security spend will grow by 10 per cent a year on average between 2025 and 2030, according to a report by TD Cowen citing Gartmore data. Analysts are pencilling in annual revenue growth of about a fifth for the next two years for sector giants Palo Alto and CrowdStrike, on S&P Capital IQ estimates.

Column chart of Total cybersecurity spend ($bn) showing A king's ransom

But while there is little doubt that security will eat up a growing proportion of company budgets, the question is how long traditional cyber vendors can capture the spoils. The fear must be that the LLMs whose products are causing the problems will be best placed to solve them.

To some extent, that’s already true. Since Anthropic released its powerful Mythos model last April, LLMs have become the go-to provider of software scanning services, able to spot thousands of vulnerabilities that had previously gone unnoticed. Providing software vendors with “patches” — corrections to buggy code — is an LLM-adjacent business opportunity.

But figuring out which of the thousands of potential holes need fixing first and getting the updated software into companies isn’t — or at least not yet. Traditional cyber security vendors, deeply embedded in their customers’ organisations, have a competitive advantage here. It isn’t hard to see how the models and the vendors might team up to fight software-related threats.

Meanwhile, in an AI world, traditional cyber security vendors continue to do what they were doing before — just a lot more of it. More than 80 per cent of attacks are centred on human issues such as stolen identities and compromised passwords according to Bernstein. AI helps criminals to do this, but model makers are not best placed to spot this activity. And vendors can exploit network effects that LLMs don’t have, using an attack on one client to inform the defences of everyone else.

Over time, perhaps, AI companies’ relationships with their clients will also grow broader and closer as they focus on providing enterprise applications. But the increased volume of AI-enabled cyber attacks, of all shapes and sizes, is likely to outweigh whatever niche LLMs carve out. And, unlike many software providers, cyber security vendors don’t risk disintermediation by every Tom, Dick and Harry: even the most cost-conscious company isn’t likely to delegate doom avoidance to the vibe coders.

camilla.palladino@ft.com

Lex sends a newsletter every Wednesday with additional insights, the pick of the week’s columns and links to what we’re reading. Premium subscribers to the FT can sign up

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论