The Business of Cyber Security

National Cyber Powers

Nation-states shape the cybersecurity market more than they buy from it. The threat actors that drive private demand (15), the export-control regimes that gate cross-border M&A (20f), the talent pipelines that seed startups (07c), and the procurement budgets that fund the integrators (14b) all trace back to a handful of state cyber powers and how they behave. A buyer underwriting a cyber asset is implicitly underwriting a view of which states will be spending, attacking, and restricting over the hold period.

The capability tiers

Cyber power is usually scored on three axes — offensive capability (the ability to project effect), defensive/resilience capability (the ability to protect one's own systems), and commercial/ecosystem strength (the depth of the domestic vendor and talent base). The International Institute for Strategic Studies' framework and academic indices broadly converge on a tiered picture, even where they disagree on rankings.

Two superpowers, a deep second tier, and the commercial outliers Illustrative positioning: offensive reach (x) vs. commercial/ecosystem depth (y). Not a precise index. offensive capability / global reach → commercial ecosystem depth → USA China Russia Israel UK Five Eyes (AUS/CAN/NZ) Iran N. Korea full-spectrum commercial-strong, narrower reach offense-heavy, thinner commercial base Illustrative, synthesizing IISS Cyber Power tiers and public reporting. Colors: gold = allied superpower; blue = allied commercial; red = adversary/sanctioned. Exhibit: The Business of Cyber Security.
The U.S. is the only state strong on both axes — full-spectrum offense *and* the world's deepest vendor/VC ecosystem. China is closing on reach and has a large (but more domestically-walled) commercial base. Israel and the UK punch far above their size on the commercial axis, which is why they export talent and startups into the global deal market. The adversary cluster (Russia/Iran/NK) is offense-heavy but commercially thin and sanction-walled — relevant to deals as *threat drivers and compliance landmines*, not as counterparties.

The powers, by name

United States. The only full-spectrum power: NSA (signals intelligence/offense), U.S. Cyber Command (military operations, elevated to a unified combatant command in 2018), CISA (civilian defense, 14b), and the world's deepest commercial ecosystem (the vendors of 03, the VCs of 07, the integrators of 14a). U.S. policy — export controls, the entity list, Treasury sanctions (14e, 20f) — is itself a market-shaping force well beyond U.S. borders.

China. The strategic peer competitor. Civil-military fusion channels a vast talent base across two parallel programmes with different missions: the PLA Cyberspace Force, created in April 2024 as successor to the Strategic Support Force, prepares the battlefield and targets foreign militaries, while the Ministry of State Security (MSS) handles industrial espionage, intellectual-property theft and diaspora surveillance. The split maps onto the two best-known campaigns — Volt Typhoon (PLA-linked; active since at least mid-2021; critical-infrastructure pre-positioning via unpatched edge devices at utilities, telecoms and ports, then operating through the devices' own administrative tools so security software registers nothing) and Salt Typhoon (MSS-linked; telecom intrusion via a known Cisco router flaw, reaching call-routing and location systems). Both were publicly disclosed in 2023–2024 and together reframed the U.S. threat model toward "living-off-the-land" persistence; by August 2025 the FBI and CISA assessed Salt Typhoon had reached 200-plus organisations across 80 countries, including nine U.S. carriers. The scale of the espionage programme is long-established — the 2015 OPM breach exposed 22.1 million records covering 19.7 million individuals and 5.6 million fingerprints, and the IP Commission's estimate of Chinese IP theft, cited in the 2018 USTR Section 301 report, ran to $225–600B annually. China's domestic vendor ecosystem is large but largely walled off from Western M&A by data-security law (16e) and reciprocal export controls. China is now also closing on the offensive axis through AI: on Jun 28 2026 the WSJ ("China Has Matched Anthropic in Cybersecurity, Resetting AI Race") reported that Zhipu AI's open-weight GLM-5.2 matched leading U.S. models at finding software security bugs (besting Claude Opus 4.8 on some benchmarks — though the parity claim rests on a narrow benchmark, not a head-to-head with the most capable restricted model, and GLM-5.2 still lags on other tasks). Two independent evaluations have since measured the gap: the UK AI Security Institute (Jul 17 2026) put GLM-5.2's cyber capability 4 to 7 months behind the closed frontier, and SaferAI (Aug 2 2026) put its offensive-cyber capability 2 to 4 months behind — both narrower than the open-weight lag measured through 2025, and both noting the model carries no removable safeguards (20e). The significance is that frontier offensive-cyber capability is becoming multipolar and open-weight, weakening any "U.S.-monopoly" reading of the offense axis (20e, 20f).

Russia. Offense-heavy and tightly fused with criminal ecosystems — the GRU (military), SVR (foreign intel, behind the 2020 SolarWinds/UNC2452 campaign), and FSB, alongside a permissive harbor for ransomware crews (15). Commercially severed from Western markets by post-2022 sanctions; relevant to deals almost entirely as a threat and sanctions-screening concern.

Israel. The commercial-power outlier. Unit 8200 (and 81, Mamram) functions as a national pre-seed program — its alumni founded a disproportionate share of the world's cyber unicorns (Check Point, CyberArk, Wiz, Palo Alto's acquired core, and much of the AI-security cohort). Israel exports companies and talent into the global deal market more than any other state of its size.

United Kingdom & the Five Eyes. The UK (GCHQ, NCSC) is a top-tier offensive/defensive power with a credible commercial base and an activist national-security investment screen (the National Security and Investment Act). Australia, Canada, and New Zealand complete the Five Eyes intelligence-sharing core — smaller ecosystems but deeply integrated procurement and certification regimes (16e).

Iran & North Korea. Asymmetric powers. Iran runs disruptive and influence operations; North Korea is unique in running cyber as a revenue line — the Lazarus/APT38 complex steals cryptocurrency at state scale to fund the regime (15e). Both are offense-focused, commercially negligible, and pure compliance-risk from a deal lens.

Why it matters for M&A

State behavior shows up in a deal three ways. (1) Demand. Threat campaigns (Volt/Salt Typhoon, ransomware harbors) are the leading indicator beneath enterprise and government security budgets — when a campaign is disclosed, the relevant sub-segment's pipeline inflects (22). (2) Supply. National talent pipelines (Unit 8200, GCHQ, NSA) determine where the next acquirable companies are formed — concentrating sourcing in Israel, the U.S., and the UK. (3) Friction. State controls — CFIUS, the UK NSI Act, China's data-security law, U.S. export controls and sanctions — decide which cross-border deals can actually close. A target with foreign-government customers, foreign ownership, or sanctioned-jurisdiction exposure carries clearance risk that can delay or kill a transaction.


Sources: IISS — Cyber Capabilities and National Power (tiered framework) · CISA — Volt Typhoon advisory · CISA — Salt Typhoon / PRC telecom targeting guidance · U.S. Cyber Command — history/elevation · Israel Unit 8200 foundry model: see 07c and its sources. Dates herein are framework/contextual; specific campaign-disclosure dates per the linked CISA advisories.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.