The Business of Cyber Security

Threat Economy

The attacker side is the demand generator for the industry. Security spend is downstream of a threat, and how attackers monetize indicates where defensive demand — and therefore M&A — concentrates next.

Related drill-downs: Ransomware-as-a-Service, Initial-Access Brokers, Nation-State & APTs, BEC, Fraud & Social Engineering, The Cybercrime Supply Chain & Laundering, Threat as a Leading Indicator, and Notable Breaches & Their Costs.

How attackers make money

Method Mechanism Monetization
Ransomware / extortion Encrypt + steal data ("double extortion") Crypto ransom payments
Ransomware-as-a-Service (RaaS) Platform licensed to affiliates Affiliate keeps 70–80%, operator 20–30%
Initial Access Brokers (IABs) Sell stolen credentials/access Per-access sale on dark-web forums
Business Email Compromise (BEC) Social-engineered wire fraud Direct fund transfer (largest $ losses)
Data theft & resale Steal PII/PHI/credentials Sold in bulk on markets
Cryptojacking / fraud Hijack compute / payment fraud Mined crypto, carding
Nation-state / espionage IP theft, sabotage, pre-positioning Strategic (not always financial)
DDoS-for-hire / "booters" Rent attack infrastructure Subscription
Affiliate 70–80% Operator 20–30% RaaS ransom split — the franchise model 2025: ~$820M on-chain ransom (−8% YoY) · >$1.3B total illicit flows · attacks +50%
Ransomware-as-a-service economics: developers license tooling to affiliates who run the attacks and keep the larger share.

The cybercrime supply chain

The ransomware-as-a-service supply chain A specialized, revenue-shared criminal economy that runs like SaaS DEVELOPERSbuild the ransomware20–30% AFFILIATESrun the attacks70–80% license platform → INITIAL ACCESS BROKERSsell stolen creds / entry sell access ↑ RaaS PLATFORMtooling · support · escrow MONEY LAUNDERINGmixers · mules · OTC desks → cash-out ransom $ ↓ Splits per Chainalysis/Sophos; 2025 on-chain ransom ~$820M (−8% YoY), >$1.3B total illicit flows.
Developers license the platform to affiliates (who keep the larger share and buy entry from initial-access brokers); proceeds route through laundering to cash-out. Specialized, revenue-shared, and resilient — which is why defensive demand is permanent.

The ecosystem is specialized and professionalized — developers, affiliates, IABs, negotiators, launderers — mirroring a legitimate software supply chain with revenue-sharing, "customer support," and SLAs.

2025–2026 economics

1H 2026 threat landscape in review

The first half of 2026 supports a strong cybersecurity demand environment into the second half of 2026 and beyond — the central conclusion of Wall Street research reviewing the period. The driver is a broad attack surface spanning on-premises, hybrid, multi-cloud, and now AI environments, combined with rising AI capability among attackers, including Chinese and open-source models closing the gap with frontier-model cyber capabilities. The half's events spanned supply-chain attacks, insider threats, software vulnerabilities, operational shutdowns, crypto theft, and geopolitically motivated operations, with AI playing a growing role on both the offensive and governance sides. Notable incidents grouped by theme:

Attacks with real-world operational impact. A provider of ignition-interlock devices (Intoxalock) was hit in March 2026, locking thousands of U.S. drivers out of starting their cars for over a week. A Massachusetts hospital system (Signature Healthcare Brockton) suffered an April 2026 ransomware attack that forced ambulance diversions and canceled chemotherapy appointments. Toy manufacturer Hasbro disclosed a March 2026 network intrusion that it expects to delay roughly $40–60M of Consumer Products revenue to the back half of the year, plus about $20M of one-time remediation operating expense in 2026. A North Dakota water-treatment plant serving about 80,000 people (Minot) suffered a March 2026 ransomware attack on its SCADA systems, running water operations manually for 16 hours.

AI-related incidents. In April 2026, an AI coding agent operating for software vendor PocketOS deleted the company's production database and backups in roughly nine seconds while attempting to resolve a credential mismatch, causing a 30-plus-hour outage; because the most recent backup was 90 days old, records were reconstructed manually from payment, email, and calendar data. Wall Street research also cited AI-lab data-governance failures, including reports that Anthropic inadvertently exposed unpublished internal files and, separately, a large volume of proprietary source code through human error rather than an external attack, and a report that a third-party contractor obtained unauthorized access to a preview model using existing credentials. The review noted these alongside its broader point that AI is increasingly both a target and a tool for attackers.

Geopolitically motivated operations. Combined cyber and physical operations were reported around the Venezuela conflict (a power-grid disruption in Caracas) and the Iran war (blackout-inducing electronic campaigns and retaliatory breaches on both sides). A China-aligned espionage group was reported to have breached at least 70 government agencies and critical-infrastructure organizations across 37 countries over 2025–2026 to collect geopolitical intelligence.

Attack vectors. Insider threat: a U.S. defense contractor (L3Harris) recorded a $35M loss after an employee sold trade secrets and exploit tools to foreign governments; the former employee was sentenced to over seven years and ordered to pay more than $10M in restitution. Supply chain: a web-hosting platform (Vercel) suffered an April 2026 OAuth supply-chain compromise exposing customer secrets, and the widely used Axios JavaScript library (100M+ weekly downloads) was briefly poisoned in March 2026 via a hijacked maintainer token. A severe Linux local-privilege-escalation vulnerability ("CopyFail") was disclosed in April 2026. A June 2026 credential-harvesting campaign ("FortiBleed") aggregated exposed credentials for roughly 74,000 Fortinet firewall URLs. The FBI disclosed a February 2026 breach of non-public surveillance-related data, and a healthcare-technology vendor (Xsolis) reported a January 2026 breach affecting nearly 1.4M patients.

Crypto. A North-Korea-linked group exfiltrated roughly $285M from Solana-based Drift Protocol in April 2026 after a months-long social-engineering operation; a separate January 2026 breach of Step Finance took about $40M and led to that platform's shutdown.

Financial consequences and enforcement. Comcast established a $117.5M settlement fund (April 2026) over a 2023 breach affecting ~31.6M customers; Flagstar Bank received preliminary approval for a $31.5M settlement over 2021 breaches; and China-based Hytera pleaded guilty to conspiracy charges tied to a trade-secret theft scheme, drawing a $50M criminal fine and $214M in restitution. On enforcement, individuals tied to the BlackCat ransomware group — including two ransomware negotiators who leaked clients' positions to attackers — were convicted in 2026, and several U.S. residents were sentenced for facilitating North Korea's "fake IT worker" scheme.

Industrial ransomware, Q2 2026

Industrial organizations are the segment where ransomware volume and operational consequence are most directly linked, and the quarterly count is one of the few consistently measured series in the threat economy. Dragos recorded 1,140 ransomware incidents affecting industrial organizations worldwide in Q2 2026, a 12% increase over the previous quarter, with manufacturing accounting for 747 of them — roughly two-thirds of the total (Dragos, Q2 2026).

The composition matters more than the count. Disruption continued to arrive through IT, ERP and virtualization systems, and Dragos found no cases in which attackers directly manipulated industrial control systems. Operational impact is therefore still being produced by ordinary enterprise ransomware reaching systems that industrial operations depend on, not by adversaries acquiring and using process-level capability. That distinction bears on how OT security demand should be read: the near-term budget driver is segmentation, visibility and recovery across the IT/OT boundary rather than defense against process manipulation, which remains the domain of state pre-positioning (15c) rather than of criminal monetization. See OT/ICS Security.

July 2026 edge-appliance exploitation cluster

Three concurrent exploitation waves against internet-facing enterprise infrastructure ran through July 2026, together illustrating the edge appliance and on-premises server as the dominant non-phishing entry path into corporate networks:

The cluster echoes the July-2025 ToolShell SharePoint wave and the 2024–25 Ivanti and Fortinet episodes: security and connectivity appliances themselves are recurring points of entry, and the most prolific ransomware group of 1H 2026 (Qilin, above) now runs edge-appliance exploitation as an initial-access motion alongside its affiliate phishing. The pattern sustains demand for exposure management and validation (03k), attack-surface reduction, and the patch-speed economics discussed in AI Security.

Why the criminal cyber economy exists

The criminal cyber economy is a rational market, driven by incentives that favor attackers:

  1. Asymmetric economics. An attacker needs one success; a defender must stop every attempt. Tooling (RaaS kits, IAB access) is cheap and reusable; the payoff (a single ransom or wire fraud) can be enormous. ROI is extreme.
  2. Low cost of entry, high specialization. The supply chain (developers, affiliates, brokers, launderers) lets low-skill actors participate by renting capability — exactly like SaaS lowered the barrier to building software.
  3. Cryptocurrency enabled scalable payment & laundering. Pseudonymous, borderless value transfer made monetization and cash-out viable at scale.
  4. Near-impunity / jurisdictional arbitrage. Many operators sit in jurisdictions that won't extradite or that tolerate (or direct) attacks on adversaries. Enforcement is slow and cross-border.
  5. A vast, soft attack surface. Cloud, SaaS, remote work, IoT/OT, and supply chains expand the target set faster than defenses mature.
  6. State sponsorship & blurred lines. Some governments run, fund, or shelter criminal groups, blending espionage, revenue, and deniable coercion (see Sovereign).

In short: demand exists because crime pays, capability is rentable, money moves anonymously, and accountability is weak. Every one of these conditions also guarantees durable, growing demand for defense — the economic engine under the entire security industry.

Red, blue, and purple teams

Because attackers hold the structural advantage described above, defenders rely on continuous testing that emulates an adversary rather than on passive controls. This is the origin of team-based security operations:

Team Role Mindset
Red team Offensive — simulate real attackers (pen-test, adversary emulation, social engineering) to find what actually breaks "Think like the attacker"
Blue team Defensive — detect, respond, harden; run the SOC, monitoring, IR "Defend and recover"
Purple team The feedback loop — red and blue working together so every attack technique becomes a new detection "Attack to improve defense"

Why they exist: real-world adversaries are the only honest test of a defense. Red teams expose gaps before criminals do; blue teams turn those findings into controls; purple teaming institutionalizes the loop. This dynamic is itself a market — it powers the offensive-security/PTaaS, BAS, and MDR sub-segments (Pentera, Cymulate, Cobalt, Synack, NetSPI, Bishop Fox — see Service Providers) and is increasingly productized into continuous, automated, and now AI-driven testing.

Why the threat economy maps to M&A demand

Every threat maps to a control the CISO must fund — the threat→control→budget logic that turns a headline breach into a board-approved line item. Acquirers read the same map forward as a deal pipeline (below). The linkages:

Cyber insurance linkage: Ransomware economics drive the cyber-insurance market (Coalition, At-Bay, Corvus/Travelers, Resilience), which is itself consolidating and overlaps with security vendors — a deal-adjacent space to monitor.

Sensitivity note: this describes the criminal economy at a market-structure level for defensive and investment-analysis purposes only.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.