Core Concepts & Mental Models
A map of the analytical concepts and mental models that run through The Business of Cyber Security — presented in brief, as a companion to the research pages. Each entry names a lens the book uses and states the idea in one or two lines, then points to the wiki page where the underlying market data lives. This page is a concept index, not a summary: it deliberately omits the book's evidence, deal walk-throughs, numbers, and playbooks, which are developed in full in the book itself. Use it to navigate the wiki by idea rather than by segment.
The central reframe
Cybersecurity is an economy, not only a technical discipline. Money flows from the organizations that need protection to the vendors and service providers that supply it, and onward to the investors, lenders, and acquirers who finance, consolidate, and replace those suppliers. Treating the sector as an economy — with its own laws of demand, capital, and exit — makes otherwise surprising outcomes (very large acquisitions of young companies) look structured rather than random. See Overview and Market Structure.
The organizing question. At each link in the value chain, three questions decide outcomes: who captures the value, how, and who is buying or selling it. Every page in this wiki is, in effect, one link examined through that question.
Product versus position. Awards and headlines follow the best product; durable value follows whoever holds the position in the flow of money — the seat inside a customer's operations, the distribution, the data. A superior product frequently loses to a better-positioned one. See Profit Pools.
The capital allocator and ecosystem operator. The people who consistently win are rarely those with the best technology; they are those who best understand where value originates, concentrates, and is mispriced — and position where it is about to be captured. This is framed not as the opposite of technical skill but as its senior partner: the scarcest competence is integration — absorbing an acquired product into one data model, one console, one motion, and selling it back to an owned base.
The creative-destruction engine. An acquisition wave is not the industry settling into a final shape; it is one stroke of a permanent cycle in which old technology is obsoleted, relevant companies are absorbed, and new capability is funded as the attack surface expands. Value and capital are destroyed as relentlessly as they are created — for every headline acquisition there are companies sold for a fraction of peak value, and others that find no buyer at all. See Consolidation.
Part I — The Market
The Trillion-Dollar Defense (size and stakes). Security spending — roughly a quarter-trillion dollars a year on vendors, and more again on people — is non-optional and compounding faster than the technology market around it. The scale, not the drama, is what makes it an industry worth analyzing as a business. See Market Sizing.
Demand You Didn't Choose (the manufactured market). Almost no one wants to buy security; organizations buy because two external engines the industry cannot switch off leave them no choice — criminals who innovate and regulators who respond. Because demand is manufactured externally, it is unusually durable and predictable: the customer is a conscript, not a volunteer, and conscripts renew. See Economics and Regulation.
The 70-Tool Problem (how buyers actually buy). Enterprises run dozens of overlapping tools and increasingly cannot operate what they own; the drive to consolidate onto fewer platforms — not any single new threat — is the strongest force deciding which vendors win. Buyers trade some best-of-breed capability for the ability to actually run their stack. See Consolidation.
One Industry, Multiple Markets (the delegation ladder). There is no single cybersecurity market: buyers from the largest enterprises down to the household purchase security in different ways, and strategy depends on which rung a company sells to. Capability the largest buyers run in-house is delegated, rung by rung, to providers and bundles further down. See Market Structure and VAR/SI/MSP.
Where the Money Settles (profit pools). Total revenue shows how big a segment is; profit pools show where money actually accumulates and, more importantly, where it is moving. Acquirers pay for a position in a pool — future capture — not for present revenue. See Profit Pools.
The Cost of Every Defended Dollar (unit economics). Security companies are priced on the machinery of recurring revenue — how cheaply a dollar of ARR is added and how reliably it compounds and retains — which is why the market pays multiples that look irrational against current earnings. See Unit Economics.
Part II — The Builders
The War for the Console (platforms vs. point products). Platform gravity is the industry's strongest competitive force: once a buyer standardizes on a platform, that platform captures each adjacent category, and a standalone product must reach escape velocity or sell. Distribution, more than product, decides the platform wars. See Consolidation.
The Absorption Clock (the landscape, category by category). Every category runs a clock from invention at the modular edge to absorption into a platform; where a category sits on that clock indicates whether its companies are future platforms or future acquisitions. See Category Creation and The Graduating Class.
The 99 Percent (the services economy). Most organizations cannot run their own defense, so services — consulting, MSSP, MDR — is the industry's largest and most fragmented layer, and rolling up the firms that deliver it has become a major deal engine. Scale here is bought, not built. See MDR and VAR/SI/MSP.
The Tollbooth (channel and go-to-market). Most security software reaches its buyer through a toll road of distributors and resellers; whoever controls that road effectively taxes the industry, which is why sponsors pay billions for "boring" distribution. Go-to-market is often a better predictor of who wins than technology. See VAR/SI/MSP.
Part III — The Capital Engine
Manufacturing the Targets (venture capital). Venture capital is the industry's target factory: it deliberately funds more companies than can survive, because the winners are acquired at prices that pay for the graveyard. The hardest problem a security startup solves — earning a CISO's trust — is what a large early check is really buying. See Venture Capital and Time to Trust.
The Roll-Up Machine (private equity). Private equity is now the dominant owner of scaled cybersecurity: it takes companies private, rebuilds their economics, and returns them — often at a markedly higher value — turning fragmented vendors into re-rated platforms. See Consolidation and Buyer-Universe Matrix.
The Strategic on Your Cap Table (corporate venture). A strategic investor's check is rarely just money; it is an option on the company — a way to validate product fit and pre-position an acquisition. Corporate venture arms frequently invest early and buy later. See Corporate VC & IQT.
The Silent Half of Every Buyout (lenders and private credit). The quietest party in a buyout — the lender — sets the real price ceiling, and the debt market's read on a security company is often more candid than the equity market's. See Lenders & Credit and Private Credit.
What a Cyber Company Is Worth (valuation and structure). Valuation answers what an asset is worth; structure — cash versus stock, earnouts, the gap between signing and closing — answers who actually gets paid, when, and conditional on what. The headline price is rarely what anyone receives. See Valuation Benchmarks and Comps Methodology.
Where Value Changes Hands (exits). Exit premiums are driven more by scarcity than by control — the buyer's fear that a unique asset never comes up again. A company exits into the highest-priced market open to it, which is usually a strategic acquirer rather than the public market. See M&A Deals & Comps.
Part IV — Creating and Capturing Value
After the Wire Clears (the value-creation playbook). Value after a deal is created by lowering the acquired business onto better economics — distribution, margin, pricing — and the best acquirers run that as a repeatable playbook. The prize is not the asset bought but the machine it is run through. See Value-Creation Playbook.
The Integration Graveyard (why most acquisitions fail). Most acquisitions fail after the close, not before; the risks are known and routinely underpriced, and the difference between success and the graveyard is whether integration was staffed and funded like the deal itself. See Why Acquisitions Fail.
The Operator's Trilemma (build, buy, or partner). Build-buy-partner is fundamentally a question about time and credibility: buying purchases market position that building cannot deliver fast enough, which is why even the largest builders buy much of their growth. See Value-Creation Playbook.
What Could Break the Machine (the bear case). The sector can de-rate even while companies hit their numbers; the honest bear case — AI compressing the value of incumbency, platform models failing to survive an agentic era — deserves more attention than any bull slide. See Bear Case & Disruption.
Part V — The Adversary as an Economy
The Adversary's P&L (crime as a business model). Cybercrime is a functioning industry with brands, franchises, affiliates, and margins; because it is an economy rather than a set of individuals, dismantling one gang does not shrink the market, and demand for defense does not stop. See Threat Economy and Ransomware-as-a-Service.
Tomorrow's Deals in Today's Attacks (threat as a leading indicator). Attack data tends to move 12–24 months ahead of deal data, so reading where attackers are going — not the deal announcements — signals which defensive categories get funded and bought next, and whether a buyer is early or merely another bidder. See Threat as a Leading Indicator and Signals & Threat Intelligence.
Part VI — The Sovereign Dimension
The Sovereign Dimension (power, markets, and sovereign AI). States are now the largest actors on both sides of the ledger — apex attackers and an enormous, rule-bound market — and no commercial strategy survives contact with the sovereign dimension unchanged. Governments buy outcomes, set rules, and increasingly treat security and AI capability as instruments of national power. See Sovereign & Government and Sovereign AI.
Part VII — The Rules and the Future
The Salesforce You Never Hired (regulation as a demand engine). Each new regulation acts as a sales force the industry never hired: compliance deadlines create dated, mandatory demand that is visible years in advance, and value accrues to whoever positions before the deadline prices it in. See Regulation and Regulatory Calendar as Catalyst.
Security for AI (the new attack surface). Every AI agent an organization deploys behaves like a new kind of employee — one with system access and no judgment — and securing agents is a new budget line with no incumbent, which makes it a fresh land grab. See AI Security and MCP & Agent Identity.
The Agentic Turn (AI for security). AI re-prices security work: value shifts from human analysts toward whoever owns the data and workflow the machines run on, which is why acquirers increasingly buy the data and the workflow rather than the headcount. See AI Security and AI-Security Vendors.
AI as Strategic Asset (Fable & Mythos). Frontier models are strategic assets a state can restrict or switch off, so any business built on rented model access carries a sovereign dependency most balance sheets do not price. See Fable & Mythos / Export Control.
How to Win (the decade ahead). The book's synthesis: the decade favors whoever already holds the data and the distribution, and a valuation reset tends to accelerate consolidation rather than stop it — cheaper targets meet cash-rich acquirers. The closing argument turns into a distinct allocation for each seat at the table — founder, investor, operator, banker, board. See Value-Creation Playbook.
These concepts are the connective tissue of the wiki: the research pages supply the current data, and the mental models above supply the frame for reading it. The full development of each — the evidence, the deal analyses, and the per-role playbooks — is the subject of the book, The Business of Cyber Security.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.