Sovereign & Government Market
Government is a large, distinct cybersecurity buyer with its own procurement rails, vendors, and M&A dynamics. Its spending is counter-cyclical to commercial demand, and it functions increasingly as a national-security and industrial-policy arena.
Related drill-downs: The Federal Integrators covers where government cyber spending lands (Leidos, Booz Allen, GDIT, CACI, SAIC, Peraton; the Accenture–Dragos pattern; and DOGE/appropriation risk). The Federal Cyber Budget & Appropriations covers the FY2027 request (~$26.7B; DoD up, civilian/CISA down) and the PBR→appropriation→obligation→outlay pipeline. The Procurement Rails covers how funds reach a vendor (GSA MAS/OneGov, GWACs Alliant 3/Polaris/CIO-SP, NASA SEWP, and Carahsoft as master aggregator). National Cyber Powers covers the states that shape the market (US/China/Russia/Israel/UK-Five Eyes/Iran/NK), capability tiers, and their links to M&A. Offensive Cyber as an Asset Class covers the spyware/exploit trade (NSO, Intellexa, Paragon), the sanctions wall, and the defensive mirror. Sovereign AI & Digital Sovereignty covers the four-layer stack (chips/cloud/models/data), the EU "Germany Stack" and Gulf champions (G42/HUMAIN), and the acquire-local/JV M&A pattern.
US federal cyber spending (FY2027 request)
The current ask is the FY2027 President's Budget Request, released ~Apr 2026 — proposed, not yet appropriated. It totals roughly $26.7B (one outlet headlined ~$27.5B on a broader accounting). The shape is bifurcated: defense up, civilian flat-to-down, CISA cut. See The Federal Cyber Budget for the full breakdown by pool and the appropriation→obligation→outlay pipeline.
| Pool | FY2027 request (approx.) | Notes |
|---|---|---|
| DoD / military cyber | ~$14.5B | Up from ~$13.5B requested for FY2026; ~$7.4B military cyber ops + ~$6.4B cyberspace ops |
| Civilian agency cyber | ~$12.2B | Down from ~$12.5B (FY2026) — cyber inside every civilian department |
| CISA | ~$2.49B | Net reduction −$386M / −867 positions vs FY25 CR (~$707M cut from programs); politically contested |
| Federal IT topline (cyber rides inside) | ~$75.7B | Modernization pull-through for cyber |
The FY2027 picture is mixed and politically contested: proposed civilian cuts (CISA in particular) alongside a defense increase. Net effect: budget pressure on civilian agencies, continued growth on the defense/IC side. These figures are requested, not enacted — watch appropriations outcomes vs. the request.
How government buys security
- Procurement rails: GSA schedules, GWACs, SEWP; Carahsoft is the dominant public-sector distributor/aggregator.
- Certifications as moats: FedRAMP (cloud), IL4/IL5 (DoD), CMMC (defense contractors — see 16), StateRAMP (state/local). These gate the market and make certified vendors acquisition-attractive.
- Prime/sub structure: Large integrators (Booz Allen, Leidos, SAIC, GDIT, CACI, ManTech, Peraton) prime; specialized cyber firms sub or get acquired.
Government-focused vendors & integrators
Booz Allen Hamilton, Leidos, SAIC, GDIT (GD), CACI, Peraton, ManTech (Carlyle), Parsons, BAE Systems, Palantir (gov analytics), Anduril (defense tech), Secturion (Carlyle; NSA-certified hardware encryption for defense platforms — acquired Jul 27, 2026), plus FedRAMP-authorized commercial vendors (CrowdStrike, Palo Alto, Zscaler, Okta, Microsoft GCC High).
International & sovereign markets
- Israel — the densest cyber startup ecosystem outside the US; Unit 8200 alumni; major source of acquisition targets (Wiz, CyberArk, Check Point, Orca, Cyera all Israeli-rooted).
- UK / Europe — NCSC; NIS2/DORA-driven demand (see 16); active PE roll-ups (Infinigate, NCC Group). On Jul 7, 2026 the NCSC announced Cyber Shield, a national-scale agentic-AI cyber defense program (agentic red/blue teams, national-level scanning and mitigation) built with academia, critical-infrastructure operators, frontier labs, and the security industry — the UK's counterpart to the US EO-14409 track (detail on AI Security).
- Gulf (UAE, Saudi) — sovereign-fund-backed cyber investment (e.g., national champions, large gov contracts); sovereign wealth as a capital source.
- Sovereignty trend — "digital sovereignty" / data-residency rules favor local/regional vendors and drive cross-border M&A and JV structures, especially in the EU.
Why sovereign nations build cyber capabilities
States invest in cyber for the same reasons they invest in any instrument of national power — but cyber is uniquely attractive because it is cheap, deniable, scalable, and operates below the threshold of armed conflict. Core motives:
- Espionage — steal state secrets, military plans, and (for some states) commercial IP and economic data at scale.
- Military advantage — disrupt adversary command-and-control, degrade infrastructure, and "pre-position" implants for use in a future conflict.
- Coercion & influence — sabotage, ransomware-by-proxy, and information operations to shape adversary behavior and domestic opinion.
- Defense & deterrence — protect critical infrastructure (power, finance, water, telecom) and signal the capacity to retaliate.
- Revenue (for some regimes) — North Korea funds the state via crypto theft and cyber-enabled fraud (see Threat Economy).
Cyber is a domain where war and peace blur: adversaries treat cyber operations as a continuous spectrum rather than a binary state, which is why capability is maintained and used constantly, not only in wartime.
National cyber powers (offense + defense)
| State / bloc | Posture | Notable |
|---|---|---|
| United States | Strongest offensive + defensive | US Cyber Command (CYBERCOM) + NSA; CISA for civilian defense; widely credited (with Israel) for Stuxnet (2009/2010), an early cyber-weapon against Iran's Natanz centrifuges |
| China | Top-tier; espionage-heavy | Broad campaigns against national-security, economic, and IP targets; critical-infrastructure pre-positioning |
| Russia | Top-tier; disruptive | Establishing a dedicated military cyber command; sabotage, malware insertion, and influence ops |
| Israel | Elite per-capita | Unit 8200 — the talent engine behind much of the global cyber startup industry |
| Iran, North Korea | Rising; asymmetric | Iran: critical-infra targeting, often via ransomware proxies. North Korea: state-funded crypto theft |
| UK, "Five Eyes" (UK/US/CAN/AUS/NZ) | Strong, allied | Intelligence-sharing alliance; UK NCSC + National Cyber Force |
| EU members (France, Germany, etc.) | Defensive-led | National agencies (ANSSI, BSI); EU-level coordination |
Offensive vs. defensive split: most states run both — an intelligence/military arm for offensive operations (CYBERCOM, Unit 8200, Russia's GRU/SVR-linked groups) and a civilian agency for national defense and critical-infrastructure protection (CISA, NCSC, ANSSI, BSI).
Sovereign AI & sovereign cybersecurity
"Digital sovereignty" has moved from policy debate to strategic priority: cloud, data, and AI are now treated as backbones of economic competitiveness and national security. It encompasses who operates and controls the technology environment, how data is governed, where workloads execute, and under whose jurisdiction AI models run — well beyond simple data residency.
Sovereign AI is the AI-specific case: nations deciding which parts of the AI stack (compute, models, data, applications) they must own, control, or merely govern versus partner for. Approaches differ: - Canada — public investment in sovereign compute for sensitive workloads while procuring global foundation models. - India — application-led sovereignty: multilingual/voice foundation models embedded in Digital Public Infrastructure, rather than owning the whole stack. - EU & Gulf states — sovereign cloud regions, data-localization, and national-champion strategies; Gulf sovereign wealth funding domestic AI/cyber capability.
Sovereign-AI capital signal (Jun 18 2026): Dream Security (Israel; founders Shalev Hulio, ex-NSO, and Sebastian Kurz, former Austrian chancellor) raised $260M at a $3B valuation (co-led by Bicycle Capital and Group 11; Antler, Bain Capital Ventures, Tru Arrow also participating) to build sovereign AI cyber infrastructure that governments fully own and operate — ~$412M raised to date, nearly 3× the $1.1B Series B (Bain Capital, early 2025). Hulio cited ~$300M in government sales last year across Europe, the Middle East/Gulf, and Asia. Read-through: sovereign cybersecurity AI is hardening into its own venture-fundable asset class with government revenue at scale — a durable tailwind and an emerging comp for any sovereign/critical-infrastructure security target.
Offensive cyber as an emerging asset class
A distinct, defense-tech-adjacent sub-segment is forming: AI-driven offensive cyber built for the US military and Intelligence Community (and allied governments). Unlike commercial security (which is defensive and FedRAMP-gated), these are mission-systems vendors selling capability, with cleared talent and program-of-record economics as the moat. Two 2026 datapoints frame the category:
| Date | Company | Round | Valuation | Notes |
|---|---|---|---|---|
| Jun 17, 2026 (→ Jul 20 extension) | Twenty | $100M Series B (led by Accel; Friends & Family Capital, Point72 Ventures, Caffeinated Capital), + $30M from Khosla Ventures in Jul 2026 | $1.2B (Jul 2026 extension, up from $1.0B at the June round; total funding ~$168M) | "America's first VC-backed cyber-warfare startup"; AI-driven end-to-end offensive systems for the US military/IC, human judgment kept central. Founded 2024; CEO Joe Lin. Backers incl. In-Q-Tel, General Catalyst, and Tim Junio (ex-Expanse CEO; Expanse→Palo Alto Networks, $1.25B, 2020). Pentagon deployment reported Jul 2026. |
| Jun 18 2026 | Dream Security | $260M (co-led Bicycle Capital + Group 11) | $3.0B | Sovereign-AI cyber for governments (defensive/national-infrastructure side); see above. ~$300M gov sales last year. |
Sources: Bloomberg, Jun 18 2026 · PR Newswire
Adjacent market: the venture-backed defense-technology industry sharing this buyer is mapped on Defense Technology.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.