The Business of Cyber Security

Category Creation

Wiz sold to Alphabet/Google for $32B (announced March 2025, completed March 11, 2026), the largest cyber deal to date — roughly five years from founding. Beyond the speed, the deal illustrates the value of category ownership. Wiz did not win by building a better scanner; it named and defined CNAPP (Cloud-Native Application Protection Platform), a frame that recast legacy point tools (CSPM, CWPP, vuln scanning) as features of the thing Wiz sold. By the time competitors responded, the budget line, the analyst quadrant, and the buyer's mental model all carried Wiz's name. CrowdStrike did the same with EDR, Zscaler with cloud-delivered SASE/SSE, Okta with identity-as-the-new-perimeter. In security, the company that names the problem often captures the budget that forms around it.

What category creation is

Most startups compete within a category defined by someone else; they win on features, price, or execution and earn a "better mousetrap" multiple. A category creator defines a new budget line — a new acronym, a new analyst category, a new line item in the CISO's plan — and for a window owns the default answer to it. That ownership is worth a premium for three structural reasons.

First, the budget is new, not stolen. Selling into an existing category is a share fight against incumbents with references and channel; creating one means the buyer is adding spend, which is far easier than ripping out. Second, the creator sets the evaluation criteria. When Wiz defined CNAPP, RFPs started asking for Wiz's features by name — incumbents had to retrofit. Third, mind-share compounds into the exit. A strategic acquirer pays up to buy the category leader, because owning the named default is worth more than owning a faster product (see the moat map on 33). The premium for "the CNAPP company" or "the EDR company" is a scarcity premium on the name itself.

The category-creation playbook

Category creation in security follows a recognizable sequence. It is not marketing veneer; it is a go-to-market strategy that reorders the buyer's priorities.

Stage The move Security-specific proof
1 · Name a real, unaddressed pain Find a problem buyers feel but can't yet articulate or budget for Cloud misconfig (Wiz/CNAPP); endpoint detection gap (CrowdStrike/EDR); cloud access (Zscaler)
2 · Coin the frame A crisp acronym/category that reframes incumbents as features CNAPP, EDR→XDR, SASE/SSE, DSPM, ITDR, CTEM, "AI-SPM"
3 · Recruit design partners & researchers Co-author the definition with credible CISOs; publish research Compresses time-to-trust; seeds the references
4 · Win the analysts Get Gartner/Forrester to create the category (new MQ/Wave/Hype Cycle) Gartner's first Exposure-Management MQ legitimized CTEM (03k)
5 · Make the category the RFP Buyers evaluate the category, scored on the creator's criteria "Show me your CNAPP" becomes the default question
6 · Defend or sell before the bundle Incumbents copy the frame and bundle it; creator must out-run or exit Platforms absorbed AI-security as a "feature" within ~12 months (03l)

The strategy's defining risk lives in stage 6 and is the bear case: a created category can be re-absorbed into a platform as a feature before the creator reaches escape velocity. The same mechanism that makes naming powerful — it reframes the buyer's model — invites the platform vendor to add the feature and re-bundle the budget. AI-security is the live example: five startups defined "security for AI," and within roughly a year Cisco, Check Point, SentinelOne, Palo Alto, and Cato had each bought one and folded it into the platform. The creator wins only if it either reaches platform scale itself (CrowdStrike, Wiz) or sells into the bundle wave at the top (the AI-security cohort).

The category life curve Strategic value of the category leader over time (illustrative) high low escape velocity → platform (Wiz, CRWD) bundled away as a feature analyst category created the fork: sell or scale name painown the RFP Illustrative. Pattern from EDR (CrowdStrike), CNAPP (Wiz), SASE (Zscaler) vs. AI-security cohort (absorbed). Exhibit: The Business of Cyber Security.
The premium is real but time-boxed. The creator's exit value is highest at "the fork" — when the category is established and the platforms are bidding to own the name, but before they have built the feature themselves.

Relevance to M&A

Category position is one of the largest swing factors in a security company's valuation, and it is legible from outside the company. A target that owns a named category (analyst-recognized, its name in the RFP) commands a scarcity premium and a broad buyer universe — every platform that lacks the category will bid. A target that is a fast-follower inside someone else's category competes on growth and price and sells at a "feature" multiple. Establishing which of these a company is — early in a sale process — determines the narrative, the buyer list, and the price floor.

The timing read is sharp: the optimal sell-side window is at "the fork" — after the category is established and strategics are circling, but before the platforms ship their own version and re-bundle the budget. Wait too long and the created category becomes a checkbox the acquirer builds for free. The AI-security cohort sold at the right moment; a hypothetical sixth AI-security startup arriving in 2026 sells into a market where every platform already has the feature — a much weaker position.


See also

Sources: Google completes $32B Wiz acquisition (TechCrunch, Mar 11 2026); category framing from Gartner Hype Cycle / MQ category creation (CNAPP, CTEM); Gartner first Exposure-Management MQ (see page 03k sources).


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.