The Business of Cyber Security

Endpoint Security

Endpoint is the most mature and most concentrated domain in cybersecurity, a late-stage oligopoly in which three vendors hold roughly half the market. CrowdStrike's July 2024 global outage demonstrated both the reach and the fragility of a single agent running on every machine. This page expands on the endpoint-security domain within Vendors.

What endpoint security is

Endpoint security protects the devices where work happens — laptops, servers, mobile, and increasingly cloud workloads and containers — via a lightweight agent that prevents, detects, and responds to attacks. The category evolved through three eras, and the era a vendor operates in shapes its multiple:

The endpoint agent is a valuable position in security because it sits on every device and generates the richest behavioral telemetry. The vendor that owns the agent owns the data that trains the detection models and feeds the SOC — which is why endpoint vendors (CrowdStrike) became platform companies, not the other way around.

How each actor makes money and how they differ

Vendor Owner Posture Differentiation / economics
CrowdStrike CRWD Platform / buyer Single-agent Falcon + module land-and-expand; ~120%+ net retention; the modern benchmark — endpoint as platform on-ramp
Microsoft MSFT Bundler Defender for Endpoint bundled into E5; competes on price-to-zero, not features — the structural threat to every standalone
SentinelOne S Independent challenger Autonomous/AI-led agent; the scaled #3, perennially discussed as a take-private/strategic candidate
Palo Alto (Cortex XDR) PANW Platform / buyer Endpoint as a feeder into the XSIAM SOC platform, not a standalone P&L
Sophos Thoma Bravo Sponsor consolidator EPP/EDR + MDR; acquired Secureworks (~$859M, 2025) for Taegis + services scale (see 06a)
Trend Micro 4704.T Independent Broad platform; reportedly explored a sale — a scaled potential target
Trellix STG Sponsor-held McAfee+FireEye merger; legacy base, services-heavy
Cybereason, Bitdefender, Trend, Tanium, Trellix various Sub-scale / niche Sub-scale EDR = consolidation targets; Tanium owns endpoint management+security adjacency

The competitive picture: CrowdStrike and Microsoft are the gravity wells — one through product strength and net retention, the other by bundling endpoint to near-zero inside E5. SentinelOne is the swing asset — the only scaled independent left, which makes it both the most-discussed strategic target and the hardest to value. Vendors below the top three are consolidation targets, because sub-scale EDR cannot out-invest the leaders on detection models or absorb Microsoft's price pressure.

Endpoint market share

Approximate global endpoint share (late 2025, est.) 5% 10% 15% 20% ~18%CrowdStrike ~17%Microsoft ~12%SentinelOne ~7%Trend/TM ~6%Sophos ~40%All others
Approximate share, late 2025 (estimates; sources vary by methodology). The top three control roughly half the market; the long tail of sub-scale EDR is the consolidation supply. Microsoft's share is bundled into E5, so its *effective* pricing pressure exceeds its share.

Signature deals & events

The bear case

The endpoint bull case is that the agent is the platform. The bear case is that Microsoft bundles the agent to zero: if Defender for Endpoint is "good enough" and free inside E5, the standalone EDR premium compresses to the security-first, multi-OS, and high-assurance buyer only, and the long tail collapses faster than the leaders can roll it up. A test of the thesis is CrowdStrike's net retention and new-logo growth against Microsoft's Defender attach inside E5. If Microsoft's bundled share keeps climbing while CrowdStrike's net-new logo growth slows, the agent-as-platform thesis is being commoditized from below.

Cross-references: Vendors, Identity, Thoma Bravo, Earnings, Bear Case.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.