Sovereign & Government Market

Government is a large, distinct cybersecurity buyer with its own procurement rails, vendors, and M&A dynamics. Its spending is counter-cyclical to commercial demand, and it functions increasingly as a national-security and industrial-policy arena.

Related drill-downs: The Federal Integrators covers where government cyber spending lands (Leidos, Booz Allen, GDIT, CACI, SAIC, Peraton; the Accenture–Dragos pattern; and DOGE/appropriation risk). The Federal Cyber Budget & Appropriations covers the FY2027 request (~$26.7B; DoD up, civilian/CISA down) and the PBR→appropriation→obligation→outlay pipeline. The Procurement Rails covers how funds reach a vendor (GSA MAS/OneGov, GWACs Alliant 3/Polaris/CIO-SP, NASA SEWP, and Carahsoft as master aggregator). National Cyber Powers covers the states that shape the market (US/China/Russia/Israel/UK-Five Eyes/Iran/NK), capability tiers, and their links to M&A. Offensive Cyber as an Asset Class covers the spyware/exploit trade (NSO, Intellexa, Paragon), the sanctions wall, and the defensive mirror. Sovereign AI & Digital Sovereignty covers the four-layer stack (chips/cloud/models/data), the EU "Germany Stack" and Gulf champions (G42/HUMAIN), and the acquire-local/JV M&A pattern.

US federal cyber spending (FY2027 request)

The current ask is the FY2027 President's Budget Request, released ~Apr 2026 — proposed, not yet appropriated. It totals roughly $26.7B (one outlet headlined ~$27.5B on a broader accounting). The shape is bifurcated: defense up, civilian flat-to-down, CISA cut. See The Federal Cyber Budget for the full breakdown by pool and the appropriation→obligation→outlay pipeline.

Pool FY2027 request (approx.) Notes
DoD / military cyber ~$14.5B Up from ~$13.5B requested for FY2026; ~$7.4B military cyber ops + ~$6.4B cyberspace ops
Civilian agency cyber ~$12.2B Down from ~$12.5B (FY2026) — cyber inside every civilian department
CISA ~$2.49B Net reduction −$386M / −867 positions vs FY25 CR (~$707M cut from programs); politically contested
Federal IT topline (cyber rides inside) ~$75.7B Modernization pull-through for cyber

The FY2027 picture is mixed and politically contested: proposed civilian cuts (CISA in particular) alongside a defense increase. Net effect: budget pressure on civilian agencies, continued growth on the defense/IC side. These figures are requested, not enacted — watch appropriations outcomes vs. the request.

State, local and small-utility demand

Below the federal buyer sits a second public-sector tier with entirely different economics: state, local, tribal and territorial (SLTT) government, municipal water and wastewater systems, rural electric providers and community banks. It is a large population of small accounts with no security staff, ageing operational technology and no budget line a vendor can build a territory around. Nothing about it resembles the federal procurement described below — no GWAC, no aggregator, no certification moat worth clearing for the contract size.

The public funding vehicle for the government part of that tier is the State and Local Cybersecurity Grant Program (SLCGP), created under the Infrastructure Investment and Jobs Act and authorised at $1B across four fiscal years, an average of $250M a year. Its FY2025 allocation was $91.75M. The Government Accountability Office found that $172M — 17.2% of the authorisation — had reached states as of Aug 1 2024, funding 839 projects. Grant money passes through state administrative agencies to sub-recipients, so the vendor-visible demand arrives in small, delayed, project-shaped tranches rather than as recurring contract value.

Two six-month programmes announced four days apart in the same week both target this tier, and both are supplied rather than funded. On Aug 31 2026 the Office of the National Cyber Director and Texas Cyber Command launched Project Watershed 250 in San Antonio — the first state-based, industry-centric pilot under the current national cyber strategy — providing Texas water and wastewater utilities with red-teaming, system hardening and AI tooling at no cost for six months, with national expansion contingent on the results. Twelve companies appeared at the rollout as contributors: Parsons, Microsoft, Fortinet, Google Cloud, Palo Alto Networks, Amazon Web Services, Reflection AI, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos. On Sep 3 2026 OpenAI announced Daybreak for Frontline Defenders, a $1B commitment of subsidised model access, training and technical assistance targeted for consumption over six months, prioritising water and wastewater systems, electric grid operators, SLTT government, community and regional banks, nonprofits and open-source maintainers, and delivered through more than 35 partner products and partner-operated services (AI Security).

Neither is appropriated money. Watershed 250 is donated capability and staff time, and a water-sector practitioner quoted by CyberScoop characterised it as having no real money behind it, describing the government as asking industry to fund what it should fund itself. OpenAI's $1B is a supplier's valuation of discounts against its own undisclosed list prices, with neither the subsidy percentage nor the post-subsidy price stated. Read as a commercial matter, both are market-development expense booked against a segment that does not currently buy — the same pattern as the credits committed under Project Glasswing and Daybreak's earlier water-incident support (20e). What the contributors acquire is position: Watershed 250 is explicitly a template for national expansion, and the twelve names on the pilot are the reference set a national programme would be specified around. The overlap with the Glasswing and Daybreak partner rosters is substantial, which is the same short list of platform vendors being selected a third time.

Two consequences follow for the tier itself. First, both programmes expire on a stated six-month horizon, so a cost arrives afterwards for buyers whose inability to carry that cost is the reason the programmes exist; the plausible absorbers are a reauthorised grant programme, the MSP or MSSP that wrapped the capability into a managed price, or nobody. Second, both subsidise tooling and not headcount, so for operators defined by having no security staff the binding constraint is unchanged — which points the near-term revenue at the managed-services layer that supplies the staff rather than at product (MSSP, MDR). (CyberScoop, Aug 31 2026 · Office of the Texas Governor · OpenAI, Sep 3 2026 · CISA — SLCGP · FEMA — FY2025 SLCGP fact sheet)

How government buys security

Government-focused vendors & integrators

Booz Allen Hamilton, Leidos, SAIC, GDIT (GD), CACI, Peraton, ManTech (Carlyle), Parsons, BAE Systems, Palantir (gov analytics), Anduril (defense tech), Secturion (Carlyle; NSA-certified hardware encryption for defense platforms — acquired Jul 27, 2026), plus FedRAMP-authorized commercial vendors (CrowdStrike, Palo Alto, Zscaler, Okta, Microsoft GCC High).

International & sovereign markets

Why sovereign nations build cyber capabilities

States invest in cyber for the same reasons they invest in any instrument of national power — but cyber is uniquely attractive because it is cheap, deniable, scalable, and operates below the threshold of armed conflict. Core motives:

  1. Espionage — steal state secrets, military plans, and (for some states) commercial IP and economic data at scale.
  2. Military advantage — disrupt adversary command-and-control, degrade infrastructure, and "pre-position" implants for use in a future conflict.
  3. Coercion & influence — sabotage, ransomware-by-proxy, and information operations to shape adversary behavior and domestic opinion.
  4. Defense & deterrence — protect critical infrastructure (power, finance, water, telecom) and signal the capacity to retaliate.
  5. Revenue (for some regimes) — North Korea funds the state via crypto theft and cyber-enabled fraud (see Threat Economy).

Cyber is a domain where war and peace blur: adversaries treat cyber operations as a continuous spectrum rather than a binary state, which is why capability is maintained and used constantly, not only in wartime.

National cyber powers (offense + defense)

State / bloc Posture Notable
United States Strongest offensive + defensive US Cyber Command (CYBERCOM) + NSA; CISA for civilian defense; widely credited (with Israel) for Stuxnet (2009/2010), an early cyber-weapon against Iran's Natanz centrifuges
China Top-tier; espionage-heavy Broad campaigns against national-security, economic, and IP targets; critical-infrastructure pre-positioning
Russia Top-tier; disruptive Establishing a dedicated military cyber command; sabotage, malware insertion, and influence ops
Israel Elite per-capita Unit 8200 — the talent engine behind much of the global cyber startup industry
Iran, North Korea Rising; asymmetric Iran: critical-infra targeting, often via ransomware proxies. North Korea: state-funded crypto theft
UK, "Five Eyes" (UK/US/CAN/AUS/NZ) Strong, allied Intelligence-sharing alliance; UK NCSC + National Cyber Force
EU members (France, Germany, etc.) Defensive-led National agencies (ANSSI, BSI); EU-level coordination

Offensive vs. defensive split: most states run both — an intelligence/military arm for offensive operations (CYBERCOM, Unit 8200, Russia's GRU/SVR-linked groups) and a civilian agency for national defense and critical-infrastructure protection (CISA, NCSC, ANSSI, BSI).

Sovereign AI & sovereign cybersecurity

"Digital sovereignty" has moved from policy debate to strategic priority: cloud, data, and AI are now treated as backbones of economic competitiveness and national security. It encompasses who operates and controls the technology environment, how data is governed, where workloads execute, and under whose jurisdiction AI models run — well beyond simple data residency.

Sovereign AI is the AI-specific case: nations deciding which parts of the AI stack (compute, models, data, applications) they must own, control, or merely govern versus partner for. Approaches differ: - Canada — public investment in sovereign compute for sensitive workloads while procuring global foundation models. - India — application-led sovereignty: multilingual/voice foundation models embedded in Digital Public Infrastructure, rather than owning the whole stack. - EU & Gulf states — sovereign cloud regions, data-localization, and national-champion strategies; Gulf sovereign wealth funding domestic AI/cyber capability.

Sovereign-AI capital signal (Jun 18 2026): Dream Security (Israel; founders Shalev Hulio, ex-NSO, and Sebastian Kurz, former Austrian chancellor) raised $260M at a $3B valuation (co-led by Bicycle Capital and Group 11; Antler, Bain Capital Ventures, Tru Arrow also participating) to build sovereign AI cyber infrastructure that governments fully own and operate — ~$412M raised to date, nearly 3× the $1.1B Series B (Bain Capital, early 2025). Hulio cited ~$300M in government sales last year across Europe, the Middle East/Gulf, and Asia. Read-through: sovereign cybersecurity AI is hardening into its own venture-fundable asset class with government revenue at scale — a durable tailwind and an emerging comp for any sovereign/critical-infrastructure security target.

Offensive cyber as an emerging asset class

A distinct, defense-tech-adjacent sub-segment is forming: AI-driven offensive cyber built for the US military and Intelligence Community (and allied governments). Unlike commercial security (which is defensive and FedRAMP-gated), these are mission-systems vendors selling capability, with cleared talent and program-of-record economics as the moat. Two 2026 datapoints frame the category:

Date Company Round Valuation Notes
Jun 17, 2026 (→ Jul 20 extension) Twenty $100M Series B (led by Accel; Friends & Family Capital, Point72 Ventures, Caffeinated Capital), + $30M from Khosla Ventures in Jul 2026 $1.2B (Jul 2026 extension, up from $1.0B at the June round; total funding ~$168M) "America's first VC-backed cyber-warfare startup"; AI-driven end-to-end offensive systems for the US military/IC, human judgment kept central. Founded 2024; CEO Joe Lin. Backers incl. In-Q-Tel, General Catalyst, and Tim Junio (ex-Expanse CEO; Expanse→Palo Alto Networks, $1.25B, 2020). Pentagon deployment reported Jul 2026.
Jun 18 2026 Dream Security $260M (co-led Bicycle Capital + Group 11) $3.0B Sovereign-AI cyber for governments (defensive/national-infrastructure side); see above. ~$300M gov sales last year.

Sources: Bloomberg, Jun 18 2026 · PR Newswire

Adjacent market: the venture-backed defense-technology industry sharing this buyer is mapped on Defense Technology.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.