Software Eats Services
AI is reshaping the economics of the services half of the cybersecurity industry, not only making products better and offense cheaper. The dynamic termed "software eats services" covers the mechanism, the margin and pricing math, the valuation re-rating, and the strategic fork it forces on every services business.
This is branch B of the AI × Cybersecurity framework: AI makes services better, and software encroaches on services. It sits between branch A (AI makes products better) and branch C (AI makes offense better / the demand side). Related pages include Service Providers, MSSP, MDR, The Agentic SOC, and Pricing & Business Models.
The thesis
AI converts what used to be sold as variable human labor into fixed software cost — so software steadily eats the services business, putting structural pricing pressure on services and forcing every services firm to either evolve into a software-like business or be compressed and rolled up.
The mechanism — why this is happening now
A cybersecurity service (a managed SOC, a consulting engagement, an incident response retainer, a penetration test) is fundamentally billable human hours wrapped in expertise. Its cost base is people, and people do not scale at zero marginal cost — which is why services businesses have historically carried 30–60% gross margins versus 75–85% for software (see Profit Pools, Valuation).
Agentic AI attacks exactly that cost base. When an AI SOC analyst triages the alerts a tier-1 human used to handle, when an agent drafts the pentest report or runs the first pass of a compliance assessment, the variable labor line converts to a fixed software line. Three consequences follow:
- Margins can re-rate up — a services business that automates its delivery can move gross margin from the 40s–50s toward the 60s–70s, approaching software.
- But price can re-rate down — if the automation is available to everyone, the savings get competed away to the customer. The service gets cheaper, not just cheaper to deliver. This is the pricing-pressure half that services incumbents underweight.
- The boundary moves — work that was "a service" becomes "a product feature." A platform ships a managed tier and disintermediates the standalone services firm entirely.
Which of (1) and (2) dominates is the central uncertainty of the services cohort, and it is not the same answer for everyone — it depends on whether the firm owns something the automation cannot copy.
What decides which side of the fork a firm lands on
A services firm keeps the automation upside (margin) instead of surrendering it (price) only if it owns something the software cannot replicate:
- Proprietary data / telemetry feeding the models (owned detections, incident corpus).
- Trust and relationships — the reason the buyer chose a human in the first place; hardest to automate.
- Certifications and regulated access — FedRAMP/IL-level clearances, audit authority, regional compliance.
- A distribution channel / installed base that lowers CAC and locks in renewals.
- Outcome ownership — being paid for a result (breach prevented, control attested) rather than hours, which lets the firm keep AI-driven savings.
Absent one of these, the firm is selling undifferentiated labor into a market where the marginal cost of that labor is collapsing — the textbook setup for deflation.
The valuation re-rate
The prize is a change of valuation regime. Human-heavy services trade on EV/EBITDA (~8–14×); software trades on EV/revenue at a large premium (Valuation). A services business that credibly converts to recurring, automated, higher-margin, software-like revenue can move from the first regime toward the second — the single largest value-creation lever in the cohort.
- The benchmark print: Zscaler's ~$675M acquisition of Red Canary (~4.8× ARR) priced an MDR business on a software-like multiple, not a services one — because the acquirer paid for an automatable outcome and telemetry, not billable hours. It is the reference every MDR founder and sponsor now anchors to (see MDR, Deals).
- Platforms buying the automation engine: Databricks–Panther (agentic detection onto a security lakehouse) and Torq–Jit fold the software that eats the service directly into the platform.
- The roll-up corollary: sub-scale MSSPs/MDRs that cannot afford to build agentic capability become motivated sellers — the buy-and-build math in 06e now runs on "acquire, then automate the delivery to re-rate the margin," not just "acquire and integrate."
It applies to every services segment
This is not an MSSP story; it is the defining pressure across the entire services map. The move is the same everywhere — automate the repeatable core, and defend/own the part AI can't copy:
| Segment | What AI automates (software encroaches) | The evolve-or-compress move |
|---|---|---|
| MSSP / MDR (04a/04b) | Tier-1 triage, alert correlation, routine response | Own detections/telemetry + outcome pricing; sell recurring software-like ARR |
| Consulting / Big Four (04d) | Assessments, framework mapping, first-draft deliverables | Escape the billable hour into productized/annuity subscriptions |
| Incident response / DFIR (04e) | Triage, log parsing, first-pass forensics | Retainer + platform telemetry; be the breach-moment product, not just the crew |
| Offensive / PTaaS (04f) | Recon, common-vuln discovery, report generation | Continuous, subscription-ized testing; own the autonomous-pentest engine |
| vCISO / advisory (04g) | Policy drafting, posture reporting, compliance mapping | Productize the CISO's judgment into a recurring platform seat |
The pricing model shifts from seats to consumption and outcomes
Branch B shows up not only in margins but in the pricing model. A mid-2026 Wall Street sector note documents the shift the whole services-and-software layer is making: from seat-based subscriptions toward consumption- and outcome-based pricing (CBP) — and in that note's proprietary CISO survey, CBP was the single most-preferred pricing model. That is the services-to-software thesis expressed on the invoice: when the value is an AI-delivered outcome rather than a named human seat, the buyer wants to pay for the result, and the vendor that owns the outcome can keep the AI-driven savings instead of surrendering them.
The transition is not free, and the bears have a real point the note takes seriously: moving from upfront seat cash to usage that ramps slowly creates a revenue "air pocket" during the switch. But that is a timing risk, not a thesis-killer — and it rewards the platforms and the automated, outcome-owning providers (branch A + B) that can absorb the gap, while punishing the sub-scale, seat-dependent operators that cannot. It is the same fork: evolve to software-like, outcome-priced economics, or be compressed.
(Source: mid-2026 Wall Street cybersecurity sector research and its CISO purchasing survey.)
The falsifiable version
The thesis is testable. The signals to watch: whether the gross margins of scaled managed-security providers rise as agentic delivery lands (margin-capture case) or whether their pricing/NRR erodes as the savings are competed away (deflation case); whether platforms ship managed tiers that disintermediate standalone services; and whether services M&A multiples migrate from EV/EBITDA toward EV/revenue for the automated leaders. Cross-check against The Agentic SOC and the AI × Cyber tracker.
Why it connects to the other branches
Software eating services (B) is inseparable from the other branches: the same AI leap that lets a platform automate a managed service (B) also raises the ceiling on its product (A), and is driven by the same models that make offense cheaper and expand the demand services are sold against (C). And as services become software, they inherit software's new attack surface — pulling them into Security for AI. Held together, the four branches are one story: AI is re-pricing the entire cybersecurity value chain, on both the supply and the demand side at once.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.