The Business of Cyber Security

Threat as a Leading Indicator

The threat economy's central use to a corp-dev practitioner is as a leading indicator: the attacker's choice of tactic in one year points to the defender's budget the next, and the defender's budget points to the acquisition currency the year after. Threat is the leading indicator of defensive demand, and defensive demand is the leading indicator of M&A. The lag is real and roughly knowable, which is what makes it useful. When Akira began mass-exploiting SonicWall VPNs, that was also an early read on exposure-management and VPN-replacement budgets, and therefore on which assets would become acquisition targets and which acquirers would need them. The sections below formalize that transmission, quantify the lag, and turn reading the threat tape into a repeatable origination discipline.

The transmission: tactic → budget → deal

The threat tape leads the deal tape — with a roughly knowable lag Tactic shift → budget reallocation → consolidation, each link lagging the last 1 · Threat tape leak sites · IAB prices · CVE exploitation · IC3 losses leads by ~12–24 mo 2 · Defensive budget CISO spend reallocation · vendor ARR/NRR inflection leads by ~6–18 mo 3 · M&A / valuation platform acquires the category; multiples re-rate the realized deal The origination window act on stage 1–2; the market prices it at stage 3 by stage 3 the premium is already in the price Lags illustrative, drawn from category case histories. Exhibit: The Business of Cyber Security.
The edge is not in observing stage 3 (everyone reads deal announcements) — it is in acting at stage 1–2, when the threat tape and early ARR inflections are visible but the consolidation premium has not yet been priced. See [Valuation](12-valuation-benchmarks.md) and [Deals](11-ma-deals-comps.md).

The mechanism is causal, not coincidental. A new attacker tactic creates incident losses → losses force CISO budget reallocation toward the controls that would have stopped it → reallocation shows up as ARR growth and NRR inflection at the vendors selling those controls → growth and strategic necessity pull in platform acquirers, who pay a control premium → the deal re-rates the comp set for the whole sub-segment. Each arrow has a lag, and the lags compound: by the time a category is the subject of a billion-dollar acquisition, the underlying threat signal that justified it was visible 18–36 months earlier on the leak-site trackers and the IC3 loss tables.

The evidence: 2025 tactics already point at the next deals

The five CH-H pages each produced a dated, public threat signal. Read forward, each one is a budget — and therefore a deal — forecast:

2025 threat signal (source) The budget it forces The M&A it predicts
Stolen credentials the #1 ransomware entry vector; 54% of victims had prior infostealer logs (DBIR; 15b) Identity, MFA, ITDR, machine identity, session protection The identity wave — Palo Alto–CyberArk (03a)
Akira mass-exploiting edge/VPN devices (15a) Exposure management, CTEM, attack-surface, VPN replacement CTEM consolidation (03k); SASE (03d)
Cl0p supply-chain single-point compromise (15a) AppSec, software-supply-chain, third-party risk AppSec/SSCM (03f); GRC/TPRM (03i)
Double-extortion + data theft standard (15a) Immutable backup/recovery; EDR/XDR; MDR Rubrik/Cohesity scale; MDR roll-ups (04b)
BEC $3.046B, AI-nexus losses rising (IC3 2025; 15d) Behavioral email security; deepfake/voice auth Email re-platforming (03j); verification white space
OT/cyber-physical targeting (Volt Typhoon; 15c) OT/ICS visibility and segmentation ServiceNow–Armis ~$7.75B (announced Dec 2025, completed Apr 20 2026; 03h)
Crypto laundering / sanctions rails $104B (15e) Blockchain analytics, crypto compliance Chainalysis/TRM/Elliptic vertical

The ServiceNow–Armis line is the cleanest worked example of the full transmission: nation-state and ransomware attention to operational technology and cyber-physical systems built through 2023–2025 (stage 1) → enterprise and critical-infrastructure OT-security budgets inflected (stage 2) → a platform paid ~$7.75B to own asset-visibility-plus-risk across IT/OT/medical devices (stage 3, completed Apr 20, 2026). The threat signal led the deal by years; the deal merely confirmed what the threat tape had been saying.

The instruments to watch

Reading the tape requires knowing which gauges lead and which lag. The leading, attacker-side instruments move first and carry more weight than the lagging, market-side ones that only confirm:

These cross with the market-side confirmation instruments — vendor ARR/NRR by category (02a), public multiples by sub-segment (12b), and the deal log (11) — to locate the position in the lag. When the threat instruments are elevated and the market instruments are quiet, the origination window is open. When both are loud, the premium is already priced.

Falsifiable bear case

The threat-as-leading-indicator framework is powerful but conditional. (1) The lag may be too noisy to trade. Budgets respond to many forces (compliance, board pressure, macro IT spend) beyond threat; if threat explains only a minority of the variance in category spend, the "signal" is too weak to underwrite a thesis on its own. (2) Defense can decouple from specific tactics. As platforms consolidate, budget increasingly flows to platforms rather than to the point category a given tactic implies — so a threat signal pointing at "exposure management" may simply accrue to the incumbent platform's bundle, not to a fundable standalone (03m). (3) AI could collapse the lag. If both attack and defense accelerate, the 12–24-month origination window compresses toward zero, and the informational edge erodes — the signal becomes efficient. The bear case is not "threat doesn't drive demand"; it is "the tradeable lag between signal and price narrows or gets absorbed by platforms" — which would shift the edge from category selection to platform selection.

/ angle

It reframes diligence. For any target, the question becomes: which threat instrument is the demand under this company's ARR, and is that instrument accelerating or decaying? A target riding a decaying tactic is a value trap; one riding an accelerating tactic with an un-priced multiple is the mandate. That test ties CH-H directly to commercial due diligence (34).


Sources: Chainalysis — 2026 Crypto Crime Report introduction · FBI — 2025 Internet Crime Report (IC3) · ServiceNow — completes Armis acquisition (Apr 2026) · ITPro — ServiceNow wraps up $7.75B Armis acquisition · DeepStrike — stealer log statistics 2025 (DBIR 54% figure)


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.