The Business of Cyber Security

Buyer Tiers — From Consumer to Sovereign

Cybersecurity is usually mapped by what is defended — endpoint, identity, cloud, network. It can equally be mapped by who is buying, and that second map explains more about business models, margins, distribution, and consolidation than the product taxonomy does. A password manager sold to a household and an identity platform sold to a defence ministry protect a similar asset, but they are different industries: different acquisition costs, different churn, different sales cycles, different regulators, and almost entirely different acquirers.

Five tiers span the market. Each has a characteristic route to the customer, a characteristic economic model, and a characteristic set of buyers when its companies change hands.

Tier Who decides How it is sold Economic signature Typical acquirer
Consumer The individual or household App stores, OEM preloads, telco/ISP bundles, retail, direct e-commerce Low ARPU, very high volume, marketing-led CAC, subscription renewal economics Consumer-software consolidators, PE, telcos
SMB (via MSP) The business owner, executed by an outsourced IT provider Almost never direct — through MSPs, MSSPs and the distribution channel Per-seat, per-tenant, channel-margin-bearing; the MSP owns the relationship Channel roll-ups, PE platforms, MSP-focused vendors
Mid-market A first CISO or an IT director Hybrid — inside sales, VARs, marketplaces Land-and-expand, consolidation-prone, platform-susceptible Platform vendors, sponsor-backed consolidators
Enterprise A CISO with a security organisation and a budget committee Direct enterprise sales, VAR/SI-assisted, cloud marketplaces High ACV, long cycles, multi-year contracts, high net retention Strategic platform vendors, large-cap PE
Sovereign / government Programme offices and procurement authorities Contract vehicles, integrators, cleared primes Programme-cycle revenue, certification-gated, long procurement Federal integrators, defence primes, sovereign-aligned funds

The volume-versus-value inversion

The tiers sit in near-perfect inverse relationship between customer count and revenue per customer. Consumer security serves hundreds of millions of endpoints at single-digit-to-low-double-digit dollars per month; the sovereign tier serves a few hundred qualifying buyers worldwide at programme values in the millions to hundreds of millions. Everything between is a gradient.

Customer count and revenue per customer invert across the five tiers Illustrative orders of magnitude, not to scale. Both axes are logarithmic in spirit. revenue per customer → number of customers → Consumer 100M+ users · $ SMB via MSP millions of SMBs · $$ Mid-market 100k+ firms · $$$ Enterprise ~10k accounts · $$$$ Sovereign hundreds · $$$$$ Illustrative. Green = channel/volume economics; blue = direct enterprise motion; grey = procurement-gated. Exhibit: The Business of Cyber Security.
The diagonal is the whole point: the tiers trade customer count against revenue per customer at a roughly constant order of magnitude per step. Business models track the diagonal — marketing-led at the top left, procurement-led at the bottom right — and so do the acquirer sets.

Consumer security

The consumer tier is the oldest part of the industry and the one most often omitted from enterprise-centric market maps. It is large: one market estimate puts consumer security at roughly $47.8B in 2026, growing at about 9.5% annually to roughly $75.3B by 2031 (Mordor Intelligence). Treat third-party sizings as directional; the definitional boundary between antivirus, identity protection, VPN, and privacy tooling varies by source.

The scale player is Gen Digital (NASDAQ: GEN), the combination of Norton, LifeLock, Avast, AVG and Avira. For fiscal 2026, ended April 3 2026, Gen reported revenue of $5,000M, up 27%, on bookings of $5,107M, up 28%, against prior-year revenue of $3,935M; direct revenues were $4,137M (Gen Digital, May 7 2026). The growth rate reflects the MoneyLion acquisition alongside the core security subscription base, so it is not a clean read on organic consumer-security demand. Other significant participants include McAfee, Bitdefender, Trend Micro, Malwarebytes, Kaspersky, and the password-manager cohort (1Password, Dashlane, Bitwarden), plus consumer VPN and identity brands such as NordVPN (Nord Security) and Aura.

Three characteristics define the tier's economics. Customer acquisition is marketing-led rather than sales-led, so the P&L looks like consumer subscription software, not enterprise software: heavy brand and performance-marketing spend, no field sales organisation, and renewal rates rather than net revenue retention as the governing metric. Distribution is intermediated by platforms — OEM preloads, app stores, telco and ISP bundles, and increasingly retail banks and insurers bundling identity protection — which makes partner concentration a structural risk. And the product boundary has migrated from malware to identity and fraud: the growth is in identity-theft protection, credit monitoring, scam detection and privacy, not in signature-based antivirus.

The M&A pattern differs from the rest of the industry. Consumer security assets are bought by consumer-software consolidators and sponsors that underwrite subscriber cohorts, not by enterprise platform vendors — Gen itself is the product of serial consolidation (Symantec's consumer business, then Avast, then Avira and MoneyLion). The relevant diligence questions are cohort retention, channel concentration and pricing power, not ARR quality and net retention.

SMB, and why it is really the MSP tier

The SMB tier is not a direct market. Small businesses rarely employ security staff, so the buying decision is delegated to a managed service provider, and the vendor's actual customer is the MSP, not the end business. This makes SMB security a channel business at its core — covered in depth on MSSP, VAR/SI & MSP→MSSP and Operator Economics.

The consequence for threat exposure is structural and is the tier's defining feature: because one MSP administers many client tenants, compromising a single MSP yields access to its entire downstream client base. The MSP is simultaneously the distribution channel and the highest-value single point of failure, which is why remote monitoring and management (RMM) tooling — the MSP's own administrative software — has become a primary target. Telemetry across MSP-managed SMB environments in 2026 shows attackers impersonating RMM agents and abusing legitimate remote-access tooling rather than deploying conventional malware (Guardz, The 2026 State of MSP Threat Report). The detail is developed on MSSP and Threat Economy.

Economically, the tier runs on per-seat or per-tenant pricing that must support channel margin, multi-tenant management as a hard product requirement, and a price ceiling set by what an SMB will pay per user per month. Vendors that cannot deliver multi-tenancy, automated onboarding and MSP-friendly billing are structurally excluded regardless of product quality. The consolidation logic is correspondingly channel-shaped: MSP roll-ups by sponsors, and vendors acquiring to complete an MSP-deliverable bundle.

Mid-market

The mid-market is where a company hires its first security leader and stops buying purely through an outsourced provider. Budgets are real but small relative to enterprise, staff is thin, and the buyer is acutely susceptible to consolidation offers — a single platform that replaces six point products is a stronger proposition here than anywhere else in the market, because the binding constraint is people, not money. This is the tier where platform bundling does the most competitive damage to point-product vendors, and it is a primary driver of the platform dynamics on The Platform Wars and the buying behaviour on Demand & How Buyers Buy.

Enterprise

The enterprise tier supplies most of the industry's disclosed revenue and nearly all of its large-cap M&A. The buyer is a CISO with an organisation, a budget cycle and a board reporting line; the sale is direct or VAR/SI-assisted, increasingly transacted through cloud marketplaces (05a); and the economics are high-ACV, multi-year, and measured on net revenue retention. This is the tier the rest of this wiki addresses in most depth — see Vendors, Valuation Benchmarks and M&A Deals & Comps.

Sovereign and government

The sovereign tier is a distinct industry that happens to share technology with the commercial market. Buyers are programme offices and procurement authorities; access is gated by contract vehicles and certifications rather than by product competitiveness; and the incumbent advantage is procedural — an authorisation such as FedRAMP or a CMMC assessment is a slow, expensive barrier that makes an already-certified target acquisition-attractive on its paperwork alone (Certifications as Moats).

The tier also has a demand driver no commercial tier shares: state offensive capability. National cyber programmes generate the threat that the commercial market defends against, and they purchase capability directly. Public budget disclosure gives a sense of scale — US Department of Defense cyberspace activities were funded at roughly $14.5B in FY2025, the largest such budget in the world. The offensive market has its own price list: full-chain zero-click mobile exploits are publicly bountied in the $5–7M range for iOS and up to about $5M for Android by brokers such as Crowdfense. This is developed on Sovereign & Government, Federal Cyber Budget, National Cyber Powers and Offensive Cyber as an Asset Class.

Why the tier map matters for transactions

Tier is a better predictor of acquirer identity than product category. A data-security company selling to enterprises and a data-security company selling through MSPs have similar technology and almost no overlap in plausible buyers: the first is bought by a platform vendor on ARR quality, the second by a channel consolidator on partner count and per-tenant economics. Mispricing follows directly from mismatching the two — applying enterprise ARR multiples to channel-delivered revenue overstates value, and applying channel logic to enterprise ARR understates it.

Tier also determines which demand engine drives growth. Consumer tracks fraud and identity-theft incidence; SMB tracks insurance requirements and MSP adoption; mid-market and enterprise track regulation and breach exposure (Demand Engines); sovereign tracks appropriations and geopolitics. Companies that straddle tiers — a vendor selling both direct enterprise and through MSPs — need each motion underwritten separately, since blended metrics conceal the economics of both.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.