The Business of Cyber Security

The Six Domains

The cyber market spans thousands of vendors across hundreds of categories, but it can be organized around one question: what is being protected, and at which layer? Funding taxonomies, analyst maps, and platform roadmaps converge on six top-level domains. This section sets out what each domain defends, how its vendors earn revenue, how it differs from its neighbors, where it sits on the consolidation clock, and what that implies for M&A.

When Palo Alto paid ~$25B for CyberArk (closed Feb 11, 2026), it acquired the identity domain to complete a platform that already spanned network and cloud — a network-and-cloud aggregator adding the identity control plane of the AI era. Most large strategic cyber deals are domain moves of this kind. (Palo Alto Networks press release)

The organizing principle: what is protected, at which layer

Security spending is organized around assets (what is being protected) and control layers (where the control sits). Crossing the two yields six durable domains. They are not mutually exclusive — a single deal (say, a CNAPP platform) can touch three of them — but buyer budgets, analyst quadrants, and vendor org charts all line up on these six. Worldwide information-security end-user spending is on track for roughly $244B in 2026 (+12% constant-currency, off ~$213B in 2025, Gartner), and how that pool divides across the six domains — and which domain is growing fastest — indicates where the M&A pressure sits. (Gartner forecast, via Software Strategies, Mar 2026)

The six domains

1 · Identity & Access (the new perimeter). Protects who and what can do what. Sub-segments: workforce IAM/SSO/MFA, privileged access (PAM), identity governance (IGA), customer identity (CIAM), and the fast-rising non-human / machine identity (workloads, secrets, agents). How it makes money: per-identity or per-seat subscription with strong expansion as customers add modules. Why it's different: identity is infrastructure — it sits in the authentication path of every app, which makes it sticky and strategically central. Leaders: Microsoft Entra, Okta, CyberArk (now PANW), SailPoint, Ping. M&A relevance: highest strategic pull of any domain in 2026 — as security becomes AI-mediated and agents outnumber humans, identity becomes the control point, which is exactly why PANW paid up for CyberArk. (See Identity.)

2 · Endpoint (the device frontier). Protects laptops, servers, workloads, mobile. Sub-segments: EPP, EDR, XDR, mobile defense. How it makes money: per-endpoint subscription; the agent on the device becomes a distribution beachhead for selling adjacent modules. Why it's different: the endpoint agent is one of the strongest land-and-expand vectors in security — owning it enables upsell of identity, cloud, and SecOps from the same install. Leaders: CrowdStrike, Microsoft Defender, SentinelOne, Palo Alto (Cortex). M&A relevance: consolidated at the top, but the EDR agent is the launchpad for the platform wars. (See Endpoint.)

3 · Network (the traffic layer). Protects data in transit and the connections between users, apps, and clouds. Sub-segments: firewalls/NGFW, secure web gateway, SASE/SSE, NDR, microsegmentation, DDoS. How it makes money: historically appliance + support; now migrating to cloud-delivered SASE subscriptions. Why it's different: it is the most under structural pressure — the value is melting from on-prem appliances into cloud-delivered service, and the hyperscalers are bundling the basics. Leaders: Palo Alto, Cisco, Fortinet, Zscaler, Cloudflare. M&A relevance: appliance incumbents buy cloud-native capability to survive the architecture flip. (See Network & SASE.)

4 · Cloud (the fastest-growing domain). Protects cloud infrastructure, workloads, and configurations. Sub-segments: CSPM, CWPP, CNAPP, KSPM, cloud detection & response. How it makes money: consumption- or workload-based subscription that scales with the customer's cloud footprint. Why it's different: it is the growth engine — Gartner pegs cloud security as the fastest-growing subsegment at ~29% in 2026 — and it regenerates new categories every time the cloud stack adds a layer. Leaders: Wiz (now Google, $32B close Mar 11, 2026), Palo Alto (Prisma), Microsoft Defender for Cloud, CrowdStrike. M&A relevance: the most active acquisition vector — Google's $32B Wiz acquisition is the largest pure-cyber deal to date. (See Cloud; deal per TechCrunch, Mar 11 2026.)

5 · Application & Data (the content layer). Protects code, APIs, data, and the inbox. Sub-segments: AppSec/ASPM, API security, software supply chain, data security (DSPM/DLP/encryption), and email/collaboration security. How it makes money: developer-seat or data-volume subscription. Why it's different: it is the most fragmented of the six — dozens of sub-scale specialists in AppSec, DSPM, and email, each a feature a platform may absorb. Leaders: Snyk, Checkmarx, Veracode (AppSec); Varonis, Cyera, Rubrik, BigID (data); Proofpoint, Abnormal (email). M&A relevance: the most fragmented of the six, supplying the largest supply of tuck-in and roll-up targets. (See AppSec, Data, Email.)

6 · Security Operations (the detection & response layer). Protects nothing directly — it is the cross-cutting nervous system that ingests telemetry from the other five domains and turns it into detection, investigation, and response. Sub-segments: SIEM, SOAR, TIP, MDR/managed detection, and the emerging agentic SOC. How it makes money: data-volume (SIEM) or per-outcome/managed subscription. Why it's different: it sits on top of the other five, which is why it is where the data/AI flywheel concentrates — more telemetry → better models → better detection. Leaders: Microsoft Sentinel, Google SecOps, CrowdStrike, Splunk (Cisco), Palo Alto (XSIAM). M&A relevance: the battleground for the AI turn; whoever wins the agentic SOC wins the layer that aggregates all the others. (See SecOps & SIEM, Agentic SOC.)

A cross-cutting seventh area, GRC / compliance / TPRM (Vanta, Drata, AuditBoard), sits across all six domains rather than inside one — it governs and evidences the controls the six domains implement, and represents regulation-driven demand delivered as software (see GRC & TPRM, Demand Engines).

Where the budget sits — and where it's moving

The exhibit shows an illustrative division of the ~$244B 2026 security pool across the six domains, paired with each domain's consolidation stage. The takeaway is not the exact percentages (taxonomies overlap and sources differ) but the shape: network and SecOps are the largest pools, cloud is the fastest-growing, identity carries the highest strategic premium, and application/data is the most fragmented — which is precisely why the deal flow clusters where it does.

Security spend share by domain (2026E) Illustrative share of the ~$244B 2026 information-security pool by domain; shares are estimates and do not sum cleanly (overlapping taxonomies). 5% 10% 15% 20% 25% Network / SASE ~20% · consolidating Security Operations ~19% · AI battleground Identity & Access ~18% · highest premium Cloud ~16% · fastest (+29%) Application & Data ~13% · most fragmented Endpoint ~14% · consolidated Source: domain shares illustrative (author estimate); pool size & cloud growth — Gartner via Software Strategies, Mar 2026. Exhibit: The Business of Cyber Security.
The shape matters more than the decimals: the largest pools (network, SecOps) are consolidating, the fastest-growing pool (cloud, +29%) and the highest-premium pool (identity) draw the biggest strategic deals, and the most fragmented pool (application & data) supplies the most roll-up targets. A target's domain indicates its likely buyer set. See TAM & Sizing and Deals.

Relevance to M&A

Placing a company on the map — which domain, which sub-segment, which consolidation stage — indicates the likely buyer universe (which platforms have a gap in that domain), the multiple (scarce or strategic domains like identity and cloud price higher than fragmented ones like email), and the risk (a feature inside a consolidating domain faces a "sell-or-be-bundled" clock). The domains also frame the platform wars: PANW, CRWD, and Microsoft are each trying to own enough domains to become the customer's default — network+cloud+identity for PANW, endpoint+SecOps for CRWD, everything-bundled-in-E5 for Microsoft (see Platform Wars).

Cross-references: Market Structure, TAM & Market Sizing, Vendors and the per-domain dives [03a–03m], M&A Deals, Valuation by Sub-Segment, Sub-Segment Deep Dives, Demand Engines.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.