The Business of Cyber Security

The consolidation life cycle — where each category sits

Where a category sits on the consolidation life cycle — not just what it does — determines how value is captured and who captures it. Every category runs the same arc: a new threat opens a pool (nascent), startups rush in (early/fragmenting), demand migrates fast and a few leaders pull away (mid/filling, hot), the field hardens (late/oligopoly), and the function is absorbed into the platforms (aggregated). At the edge, point products win, and the play is to build a moat or sell into scarcity; in the hot middle, the contest is for category leadership; at the mature end, competition is on distribution, not novelty. The same growth rate means different things at different stages. (This chart mirrors Book Ch. 7 — The Landscape, Category by Category.)

Identity (IAM / PAM / IGA / machine identity / ITDR)

Cloud security (CNAPP / CSPM / CWPP / DSPM)

Security operations (SIEM / SOAR / TIP / autonomous SOC)

Endpoint (EPP / EDR / XDR)

Network & SASE/SSE/ZTNA

Application & software-supply-chain security

Data security (DLP / DSPM / encryption / resilience)

OT / ICS / IoT security

GRC / TPRM / compliance automation

Exposure management (VM / ASM / BAS / PTaaS)

AI security (security for AI)

Email & collaboration security


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.