The Business of Cyber Security

Industry History

The cyber market can be read as the record of a single moving process: each new computing platform opens a new attack surface, a security category forms around it, a wave of vendors is funded, the category consolidates onto a platform, and the next computing shift moves the control point again. The five eras — antivirus → perimeter → endpoint/cloud → zero-trust → agentic — trace that pattern, which serves as a forecasting tool for the next deal wave.

In 2025–26 the two largest moves were Google–Wiz ($32B, cloud) and Palo Alto–CyberArk ($25B, identity) — a hyperscaler acquiring the cloud era's defining company and a network incumbent acquiring the identity control point. Both follow the recurring pattern: an incumbent of the prior era acquiring the control point of the next. Over four decades that control point has migrated from the network, to the endpoint, to identity, and toward the AI/agent layer. The eras below trace that path.

Era 1 · Antivirus & the signature (≈1987–2003): security as an installed product

The first commercial security category formed around the PC and the file-based virus. The control point was the file, and the defense was a signature — a known-bad fingerprint. McAfee (founded 1987), Symantec/Norton, Trend Micro, and Kaspersky built the first scaled security businesses on per-seat antivirus licenses sold through retail and OEM channels. The business model was a product sale with an update subscription — closer to packaged software than to today's recurring platforms. What ended the era: the signature model broke against polymorphic and zero-day malware (a signature cannot match malware never seen before), and the internet moved the threat from the file to the connection. The recurring lesson: a defense tied to a static artifact (the signature) loses to attackers who can vary the artifact faster than defenders can catalog it.

Era 2 · The perimeter & the firewall (≈1994–2010): security as a defended perimeter

As enterprises connected to the internet, the control point moved to the network boundary. The firewall became the defining product, and the mental model was the castle and moat: trusted inside, untrusted outside. Check Point pioneered the stateful firewall; Cisco, Juniper, and later Palo Alto Networks (founded 2005) built the next-generation firewall (NGFW) that inspected application traffic, not just ports. This is the appliance era — security sold as hardware boxes with support contracts and channel-led distribution, the economics that still anchor Fortinet and the network incumbents. What ended the era (slowly): mobility, SaaS, and cloud dissolved the perimeter — when apps and users live outside the moat, the moat protects an empty castle. The perimeter never died, but it stopped being the control point.

Era 3 · Endpoint, cloud & the SaaS pivot (≈2010–2019): security as a subscription

Two shifts converged. First, the perimeter's collapse pushed defense back onto the endpoint — but as detection and response (EDR), not signatures. CrowdStrike (founded 2011) is the archetype: a cloud-delivered agent that streams telemetry to a central brain, sold as a per-endpoint subscription. This is the era's deepest change — security moved from perpetual licenses and appliances to recurring SaaS, which re-rated the whole industry's economics (and its multiples; see Unit Economics). Second, workloads moved to the cloud, opening an entirely new domain — CSPM, CWPP, and eventually CNAPP — where Wiz, Palo Alto (Prisma), and Microsoft would later compete. What defined the era: the recurring-revenue model and the data flywheel (more telemetry → better detection) that made the cloud-native platforms structurally advantaged over appliance incumbents.

Era 4 · Zero trust & identity (≈2019–2024): security as a decision on every request

The perimeter's final dissolution — remote work, SaaS sprawl, cloud — produced a new doctrine: zero trust, "never trust, always verify." The control point moved again, this time to identity: if there's no perimeter, the question becomes who (or what) is making this request, and should it be allowed? Okta, Microsoft Entra, CyberArk, and SailPoint became strategically central; SASE/SSE (Zscaler, Netskope, Palo Alto) re-platformed network security as a cloud-delivered, identity-aware service. Why it matters for M&A: this era is why identity now commands the highest strategic premium of any domain — the doctrine made identity the new perimeter, and the platforms are buying it (PANW–CyberArk). The era also industrialized the non-human identity problem that defines the next one: machines, workloads, and secrets already outnumber human identities many-fold.

Era 5 · The agentic turn (≈2024– ): security of AI and security by AI

The current era is defined by AI on both sides of the equation. On offense, generative AI lowers the cost of phishing, malware, and reconnaissance and adds a new attack surface — the models, agents, and data pipelines themselves (prompt injection, model theft, agent hijacking; see AI Security). On defense, the agentic SOC promises to automate detection and response, concentrating advantage in whoever has the most telemetry and the best models (see Agentic SOC). The control point is migrating again — toward the AI/agent layer and the identity of non-human actors. The open strategic question of 2026, and the one driving the largest deals, is which incumbent captures this layer: the security platforms (PANW, CRWD), the hyperscalers (Microsoft, Google), or — the genuine bear case — the frontier model labs themselves, who could absorb the outcome layer the security platforms are racing to build.

The pattern, in one exhibit

Each era is a wave: a new computing platform opens a surface, a category forms and is funded, it consolidates onto a platform, and the next shift moves the control point on. The arrow under the timeline captures the pattern — the control point has migrated network → endpoint → identity → AI/agent — and the durable winners (Palo Alto, Microsoft, CrowdStrike) are those that rode the migration across eras rather than defending a single station.

Five eras — and the control point keeps moving Each computing shift opens a surface, funds a category, consolidates onto a platform, then moves the control point on. 1 · Antivirus ≈1987–2003 Control: the file McAfee, Symantec, Trend, Kaspersky model: license + updates 2 · Perimeter ≈1994–2010 Control: the network Check Point, Cisco, Palo Alto (NGFW) appliance + support 3 · Endpoint/Cloud ≈2010–2019 Control: the endpoint CrowdStrike, Wiz, Prisma, Defender SaaS subscription 4 · Zero Trust ≈2019–2024 Control: identity Okta, Entra, CyberArk, Zscaler, SailPoint model: per-identity SaaS 5 · Agentic ≈2024– Control: AI / agents PANW, CRWD, MSFT, Google · the AI labs? model: outcome / agentic The control point migrates → file network endpoint identity AI / agent The durable winners rode the migration across eras (PANW: network→cloud→identity→AI); the casualties defended one station. Every era-defining deal — Google–Wiz $32B (cloud), PANW–CyberArk $25B (identity) — is an incumbent buying the next control point. Source: company histories; deal closes per company filings (Google–Wiz Mar 11 2026; PANW–CyberArk Feb 11 2026). Exhibit: The Business of Cyber Security.
The line under the cards is a forecasting tool: the control point has moved network → endpoint → identity → AI/agent, and it will move again. The next deal wave depends on where the next computing shift moves the control point — and which incumbent is short that station. See Platform Wars and The Bear Case.

What history predicts

Three regularities hold across all five eras and are worth underwriting. (1) New surface → new category → consolidation. Every computing shift creates a category that is fragmented at birth and consolidates onto a platform within ~5–10 years; the deal wave is most intense in the consolidation phase. (2) The control point migrates, and the budget follows it. Value accrues to whoever owns the current control point — which is why the highest premiums in 2026 sit in cloud and identity, the two most recent stations. (3) Incumbents survive by riding the migration, not defending a station. Palo Alto is the case study — it crossed from network appliances to cloud (Prisma) to identity (CyberArk) to AI (Cortex/XSIAM); Symantec, which stayed near the file/perimeter, was broken up and absorbed. The falsifiable risk to the pattern: if the AI labs capture the agentic layer directly, the next control point may sit outside the security industry entirely — the first era in which the winning platform isn't a security company (see Bear Case).

Cross-references: Market Structure, The Six Domains, Unit Economics (the SaaS re-rating of Era 3), Platform Wars, AI Security, Sub-Segment Deep Dives (the consolidation life-cycle), The Bear Case.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.