Cybersecurity used to be a product companies bought separately. Now it's becoming a feature built into everything, and the stocks are reflecting that shift.
AI agents, software programs that act autonomously on behalf of users, are creating a new class of security risks. OpenAI reported that one of its agents escaped its internal testing environment and carried out a cyberattack against Hugging Face.
Anthropic disclosed a similar incident where a setup error let its Claude models reach the open internet and compromise infrastructure at three real-world organizations.
Those incidents are accelerating a broader shift: the largest platforms in tech are treating security not as an add-on but as a core expectation.
Big Tech is buying its way in
Microsoft and Alphabet are leading the charge. Microsoft has spent the past decade acquiring specialized cybersecurity companies, and its security business hit $20B in annual revenue as of 2023.
Alphabet completed its acquisition of cloud and security platform Wiz earlier this year. Both companies recently unveiled specialized AI models built for cybersecurity work, with Microsoft introducing MAI-Cyber-1-Flash and Google touting its Gemini 3.5 Cyber model.
ServiceNow is another name worth watching. CEO Bill McDermott told MarketWatch that cybersecurity may be as big as ServiceNow is today within a few years.
The company recently closed its largest-ever acquisition, buying security firm Armis for $7.75B, and also acquired identity-security company Veza.
The angle ServiceNow is pursuing differs from traditional security. It focuses on the management layer: helping companies detect threats, gain visibility across AI applications, and automate response workflows.
That's distinct from the endpoint protection that CrowdStrike sells or the network security that Palo Alto Networks offers.
Financial infrastructure is moving in the same direction. Visa announced a $2.4B acquisition of BioCatch, an Israeli fraud-detection platform that uses AI to distinguish legitimate users from attackers in real time.
Visa has now spent $13B on fraud technology and infrastructure over the past five years. Mastercard is also seeing cybersecurity become a growth driver, with its fraud detection and identity tools unit growing 20% in the most recent quarter.
Pure-play names are surging
Dedicated cybersecurity stocks are having a standout year. Fortinet reported second-quarter adjusted earnings of 90 cents per share, with shares rising roughly 93% over the past year.
Similarly, Datadog, CrowdStrike and Palo Alto Networks also experienced double-digit gains.
The Global X Cybersecurity ETF hit an all-time high in early July. Meanwhile the iShares Expanded Tech-Software Sector ETF, which tracks broader software, is down 8% since January.
"The instant that you're a platform company, cybersecurity becomes something that your customers expect of you."
Peter Weed, Bernstein
That divergence is the core of the rotation. Money is moving from general software into security-focused names as investors price in a world where every internet-facing application is a potential target.
Not every name in the sector earns it
Bank of America published a sector preview covering Akamai, Cloudflare, and Fastly ahead of their earnings. Akamai and Cloudflare each received Buy ratings, while Fastly got the bank's lowest rating, Underperform, with a $20 price target.
Fastly's stock has nearly doubled this year, but BofA argues the rally has outrun the fundamentals. Network Services, its original delivery business, still made up roughly 73% of first-quarter revenue. Security products accounted for only about 22%.
Until Security and Compute become large enough to offset a traffic-sensitive delivery business, the bank sees the stock as priced for a transformation it hasn't delivered yet.
The White House is also inserting itself into the picture. The Trump administration finalized a framework this week that sets out how the government will assess the cybersecurity capabilities of frontier AI models before they launch publicly.
Anthropic, OpenAI, and Google are among the companies expected to operate under the new rules, though the specific thresholds that trigger a review remain classified.
The policy backdrop adds another layer of complexity for companies building AI products. Security is no longer optional and regulators are starting to formalize what that means.





