In recent months, the stock prices of cybersecurity companies have surged, as investors bet that the threats posed by cutting-edge AI models will boost their business. A basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since hitting a low on April 10, shortly after Anthropic restricted the release of its Mythos AI model.
Zhitong Finance APP has learned that Meta Muse and OpenAI Astra are driving AI from answering questions to autonomously executing tasks, while also continuously elevating cybersecurity to a foundational capability that enterprises must invest in alongside expanding their AI deployments. This is why a basket of cybersecurity stocks tracked by Wall Street giant Goldman Sachs has more than doubled since hitting a low on April 10.
On September 24, the Australian government disclosed that on June 18, while using an internal model to analyze public pharmaceutical expenditures, OpenAI's AI agent, after repeatedly encountering access restrictions, autonomously sought alternative pathways and gained unauthorized access to certain sections of Medicare's statistical reporting portal. OpenAI did not notify the Australian authorities until September 10, and the manner and timing of that notification prompted dissatisfaction from Australian Prime Minister Anthony Albanese. At present, there is no evidence that any personal information was compromised, and the portal in question operates independently of patient data and the health‑insurance payment system; however, this incident has brought issues such as AI agent permission boundaries, behavioral auditing, and incident‑reporting mechanisms to the forefront of regulatory scrutiny.
The industrial significance of this incident lies in the fact that security investments are becoming an essential prerequisite for the large-scale deployment of AI. Australia has established an interagency task force to review its government's cyber defense, incident response, and legal frameworks; meanwhile, the Minister for Government Services has called for an assessment of whether the A$160 million cybersecurity infrastructure upgrade outlined in the previous budget can be accelerated, and for measures to expedite the migration or decommissioning of legacy portals.
Security vendors have also been involved in handling cutting-edge model incidents: Earlier, during its post-incident review of the Hugging Face event, OpenAI disclosed that it had collaborated with external consultants such as CrowdStrike to investigate the scope and impact of the activity. This reveals a very clear and specific pathway through which cybersecurity demands are expanding in the era of AI agents: as the capabilities of state-of-the-art AI agents grow, the range of systems and operations requiring protection expands; real-world incidents expose control gaps, further driving procurement for security assessments, system upgrades, and continuous monitoring.
Palo Alto Networks CEO Nikesh Arora previously raised the issue of an estimated $1 trillion "cybersecurity debt" during the company's earnings call on September 1, highlighting the pressing need to modernize outdated security architectures. He noted that roughly $1 trillion worth of pre-AI-era cybersecurity technologies worldwide requires urgent modernization, emphasizing that about $1 trillion in global cybersecurity infrastructure is not yet equipped to address AI-driven threats—a gap that will create long-term growth opportunities for the industry.
The capital markets have already reacted strongly to this shift. The basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since its low on April 10, with CrowdStrike, Palo Alto Networks, and Fortinet all surging over 130% during the same period; since the last trading day before Anthropic CEO Amodei called for a slowdown in the development of cutting-edge models—September 11—the basket has risen another 19%.
Another Wall Street financial giant, Bank of America, views cybersecurity as a key investment theme and a critical pillar in the AI era, while Bernstein is focused on whether revenue growth can match the robust acceleration implied by the stock price. Current pricing discrepancies center on the intensity of commercialization: how much of the newly emerging security demand will translate into subscriptions, modular purchases, and recurring revenue. With CrowdStrike's forward P/E ratio exceeding 170, Palo Alto Networks at 91, and Fortinet at 48, the realization of orders and upward revisions to earnings forecasts have become important supports for future market performance.
Whether open-source AI prevails or closed-source AI does, the cybersecurity perimeter must remain in place!
From the perspective of the underlying system architecture, an agent's capabilities stem from the synergy between large models and the execution environment: the model generates plans, the execution framework invokes browsers, code‑editing tools, databases, and business APIs, the CPU handles task orchestration and tool execution, while memory and storage maintain context, files, and operational states. As systems like Muse and Astra become capable of handling longer, more complex tasks, the scope of what enterprises must protect expands to encompass agent identities, access credentials, tool connections, runtime environments, and cross‑system data flows. Consequently, security controls must be embedded throughout the execution process—covering who initiates an operation, which permissions are used, what data is accessed, whether human approval is required, and whether anomalous behavior can be promptly intercepted.
Australia's Signals Directorate technical guidance explicitly states that the execution framework linking external tools to business systems—beyond large models and AI agent systems—is a critical point where organizations can directly enforce access controls, monitoring, and governance. Accordingly, cybersecurity emerges as a core beneficiary segment within the AI industry chain, characterized by strong "model‑agnostic neutrality." Whether enterprises deploy closed‑source model APIs, self‑host open‑weight models, or concurrently invoke multiple models, they must manage identities, permissions, data access, and runtime behavior.
Model upgrades or vendor switches will not eliminate these control requirements; deploying across clouds and models, on the contrary, enhances the value of unified governance. The Australian Signals Directorate also emphasizes that while models may be replaced over time, the execution framework and its security governance ecosystem can become more enduring organizational capabilities. Specific products have already moved in this direction: Okta treats agents as independent non-human identity management entities, providing short-lived credentials, per‑use tool invocation authorization, and auditing; SailPoint, meanwhile, governs agent owners, permissions, and lifecycles through cross‑cloud and cross‑application connectors.
Cutting-edge model capabilities are also enhancing the service‑delivery capacity of security vendors themselves. On September 22, Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, which integrates Anthropic's Claude Mythos 5, OpenAI's GPT‑5.6‑Cyber, and open‑weight models, selecting the most appropriate model for each specific task. It conducts continuous security testing across web applications, APIs, cloud infrastructure, code repositories, and network assets, while providing actionable remediation recommendations. This service is now offered on an annual subscription basis. In this same cycle of model advancements, enterprises' defensive needs are being met, while security platforms can expand their detection coverage, shorten response times, and transform these capability upgrades into revenue‑generating, ongoing services. These dynamics provide a concrete business case demonstrating that "regardless of which model‑development path takes the lead, security platforms stand to participate in value creation."
On the earnings front, CrowdStrike reported second-quarter revenue of approximately $1.471 billion for its fiscal year 2027, ending July 31, up 26% year over year; its annual recurring revenue (ARR) reached $5.84 billion, a 25% year-over-year increase, with net new ARR of $332.8 million for the quarter, up 51% year over year. These figures indicate that security demand has already begun to materialize in the incremental business of certain vendors, though this quarter preceded the fresh wave of market enthusiasm sparked by Muse and Astra in September. Looking ahead, the growth drivers worth watching include expanding coverage to non-human identities, cloud workloads, and AI applications—factors that are encouraging customers to add more security modules, extend subscription contracts, and deepen their platform usage. The investment appeal of security vendors will increasingly hinge on their ability to translate enterprises' need for "AI to operate securely" into sustained growth in recurring revenue and cash flow.
Cybersecurity stocks are red-hot, but some investors are beginning to question whether the rally can sustain itself over the long term.
In recent months, the stock prices of cybersecurity firms have surged, as investors bet that the threats posed by cutting-edge AI models will boost these companies' business. However, some stocks have risen so sharply that investors are beginning to question whether they have become overvalued.

As shown in the chart above, consumer inertia is gradually being broken, and concept stocks related to AI have seen significant gains recently. A basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since hitting a low on April 10. Earlier, Anthropic restricted the release of its Mythos AI model due to concerns that it could be used to launch cyberattacks. Since then,$CrowdStrike (CRWD.US)$, Palo Alto Networks$Palo Alto Networks (PANW.US)$and$Fortinet (FTNT.US)$Their stock prices all rose by more than 130%, placing them among the top ten best-performing constituents of the S&P 500 over the same period.
The sharp rally has made these stocks among the most highly valued in the market. According to data compiled by Bloomberg, CrowdStrike's forward price-to-earnings ratio exceeds 170 times, second only to Tesla within the S&P 500. Palo Alto Networks' share price is equivalent to 91 times its expected earnings over the next 12 months, making it the fifth-most highly valued stock in the index. Fortinet's P/E ratio stands at 48 times, ranking 16th.

As shown in the chart above, concerns about AI safety have driven a sharp rally in cybersecurity software stocks; the chart depicts the performance since December 31, 2025.
"If you're considering entering the market now, you need to recognize that the price you're paying already reflects expectations that everything will be perfect going forward," said Brad Lang, Chief Investment Officer at Wealthspire, which manages roughly $593 billion in assets. "The tailwinds for cybersecurity are clear, but if any signs of weakness emerge—whether it's a slowdown in AI‑related capital spending, or even just a decline in the number of sophisticated AI‑driven attacks—their revenue growth could decelerate, and their stock prices could plunge."
This rally stands in stark contrast to the start of the year, when concerns about AI disrupting established business models triggered a broad, indiscriminate sell-off across the software sector. With the industry posting robust financial results, many of those worries have eased. Meanwhile, recent warnings from within the AI community about the technology's potential to pose serious risks have provided investors with another reason to buy cybersecurity stocks.
Since September 11, Goldman Sachs' cybersecurity stock basket has risen by 19%. September 11 was the last trading day before Anthropic CEO Dario Amodei called for a slowdown in the development of state-of-the-art models.
Today, the need to bolster cybersecurity defenses is widely acknowledged; the question is whether these companies can generate sufficient revenue and profit growth to meet the lofty expectations embedded in their eye-popping valuations.
"The cybersecurity sector may already have overextended," Bernstein analyst Peter Weid recently said in a note downgrading Palo Alto Networks,$Okta (OKTA.US)$and$SentinelOne (S.US)$It warned when assigning the rating.
In a report dated September 17, he wrote that while the sector does indeed have genuine demand, "stock prices in the sector appear to be pricing in an expectation that growth will accelerate to a level comparable to that of hyperscale cloud computing services or usage‑based software businesses such as databases." However, Weide noted that the growth of the cybersecurity business may be constrained by practical factors, including the number of employees at client organizations.
Nevertheless, fundamentals appear to be moving in the right direction. At the end of August, CrowdStrike issued revenue guidance that exceeded expectations, driving its stock price up by more than 20% on the day following the earnings release—the largest single-day gain since 2019.
"The 'Mythos moment' has led the market to broadly embrace the view that deploying AI requires robust security," CEO George Kurtz said in the earnings release. "Every enterprise will rely on AI to operate, and ensuring AI safety represents the largest market opportunity we have ever faced."
This year has already seen numerous cyberattacks carried out with the aid of AI, as well as intrusion incidents perpetrated by AI agents, raising alarms among cybersecurity experts and AI developers.
On Thursday, Australian Prime Minister Anthony Albanese stated that an OpenAI model had breached a government website earlier this year, gaining unauthorized access to files on a site used to report health statistics.
In July, OpenAI stated that its AI model had inadvertently breached Hugging Face. Last week, Google disclosed that its Gemini AI model similarly infiltrated the systems of three companies during security testing.
"We believe the market is increasingly pricing in a step-change rise in cyber risks, which supports both higher security spending and a more aggressive valuation framework for the entire sector," Bank of America analyst Tal Liani wrote in a report on September 18. In raising his price targets for CrowdStrike, Okta, and SailPoint, he described cybersecurity as "a major investment theme of the AI era and a key enabler underpinning its development."
Josh Taves, Managing Director of Post Oak Group, stated that although cybersecurity stocks have already risen significantly, valuation signals can still be misleading if growth exceeds expectations.
"Given how much the cybersecurity sector has already rallied this year, I understand why investors might be taking a more cautious stance. However, even as I expect budgets for other types of software to shrink as AI models take over routine tasks, security spending should remain robust—and may even grow," he said. "In this environment, traditional valuation metrics are less reliable than they once were. With demand so strong, investors are willing to pay higher valuations."