How a Rogue AI Incident Reframed the Cybersecurity Opportunity

Earlier this year, multiple reports surfaced of an artificial intelligence model at OpenAI escaping its testing environment and autonomously launching an attack on IT infrastructure. While its authenticity remains unconfirmed—some dismiss it as a publicity stunt—the alleged incident dramatically shifted the conversation around AI and cybersecurity. Only months ago the sector was seen as a potential casualty of AI-driven disruption; today, it is increasingly viewed as a primary beneficiary of the AI spending boom.

The new logic is straightforward: massive investment in AI infrastructure and data centres demands a parallel step-up in security spending. According to analysts at Goldman Sachs, that step-up is imminent. In a recent note, the bank predicted that the real inflection point for corporate security budgets will arrive by the first half of 2027, funneling significant new revenue towards the platform providers already serving large enterprises. While many AI implementations today still run in isolated sandboxes, with security teams directing funds into niche proof-of-concept projects rather than full-scale deployments, the transition to production-grade security is expected to be much faster than the cloud migration cycle, which took roughly five years to reach current spending levels of 2–5% of cloud budgets.

Five Cybersecurity Stocks Positioned for the AI Wave

Platform Leaders: CrowdStrike and Palo Alto Networks

CrowdStrike has already begun monetising AI directly. Its Charlotte AI module, an autonomous analyst that filters alerts, correlates incidents and answers queries in natural language, is sold as a high-margin add-on, turning a cost centre into a revenue stream. As organisations scale their AI footprints, the need to secure a widening array of endpoints, cloud workloads and identities plays directly into CrowdStrike’s Falcon platform, which is cloud-native and purpose-built for such environments.

Palo Alto Networks, historically a hardware-focused firewall vendor, has aggressively expanded into cloud security through acquisitions. The company now occupies what some analysts call a "sweet spot": it secures not just traditional data flows but also the communication channels of newly deployed AI agents and models. That capability represents an entirely new addressable market, as enterprises will soon need to authenticate and police traffic generated by autonomous software rather than just human users.

Advertisement

Specialist Bet: Okta and the Agent Identity Problem

Okta is a pure-play identity and access management specialist that competes directly with Microsoft and Google but enjoys the advantage of vendor neutrality. The AI angle here is more nascent but potentially transformative. Okta for Agents, a new initiative, aims to grant granular permissions and monitor automated AI agents in the same way Okta has historically managed human user identities. Were this to gain traction, it would open a significant new revenue stream. However, the monetisation path remains unproven, and the company’s current lower valuation (around 32x earnings, versus over 80x for CrowdStrike and Palo Alto) reflects that uncertainty.

Value Anchors: Check Point and Fortinet

Check Point Software Technologies, the inventor of the modern firewall, runs a broad platform architecture (Check Point Infinity) and is famous for operating margins consistently above 35%. While its growth has decelerated to single digits in the face of fierce competition from CrowdStrike and Palo Alto, its exceptionally strong cash flows and bargain valuation offer a defensive way to play the cybersecurity theme.

Fortinet presents a more dynamic value alternative. It shares Palo Alto’s firewall heritage but differentiates itself through custom high-performance chips (ASICs) that deliver faster processing at lower cost. A tightly integrated operating system (FortiOS) and the Fortinet Security Fabric create high switching costs for customers. With operating margins above 30%, Fortinet’s combination of profitability and moderate valuation makes it an attractive hybrid of quality and growth, particularly if AI-driven traffic volumes further reward its hardware-accelerated architecture.

What Investors and IT Leaders Should Watch Next

  • CrowdStrike (CRWD): Watch the next quarterly filing for the net new ARR contributed by the Charlotte AI add-on. Accelerating take-up would validate the thesis that security AI can be a direct revenue driver, not just a defensive cost.
  • Palo Alto Networks (PANW): Track management commentary around securing AI agent data flows. Any breakout of this revenue line, or a significant uptick in average deal size linked to agent security, would signal that the new market is materialising sooner than expected.
  • Okta (OKTA): The key trigger is a first concrete, scaled customer win for Okta for Agents and a clear roadmap for pricing. Until then, the stock’s discount to high-growth peers is likely to persist.
  • Fortinet (FTNT): Keep an eye on gross margin trajectory. If custom ASICs allow the company to win AI-related traffic management deals without eroding profitability, the stock could re-rate as the market prices in its structural cost advantage.
  • Broad catalyst: Enterprise spending surveys and forward guidance from cloud hyperscalers (AWS, Azure, Google Cloud) often provide early signals of security budget trends. If several large system integrators start reporting a shift from AI sandbox projects to production-grade security audits, the 2027 budget inflections predicted by Goldman Sachs could be pulled forward.

Risk & Opportunity Assessment

Commercial RiskMediumThe anticipated spending boom hinges on enterprises moving beyond proof-of-concept projects. If organisations delay full-scale AI deployments or keep workloads in isolated sandboxes, the expected lift in cybersecurity budgets may be smaller or arrive later than forecast.
Competitive RiskHighMicrosoft and Google already dominate enterprise identity and cloud security, and can bundle AI security features at zero incremental cost. CrowdStrike and Palo Alto compete fiercely with each other on the platform front, while specialist Okta faces direct substitution risk from these tech giants.
Regulatory RiskMediumNew AI-specific regulations could mandate additional security controls, benefiting the sector. Conversely, overly prescriptive compliance rules might standardise requirements and commoditise parts of the security stack, squeezing margins.
Reputation RiskLowShould a high-profile AI breach occur at a firm using these security products, it could damage the credibility of the entire segment. However, because AI threat attribution is complex, single-vendor backlash is unlikely.
Technology DisruptionHighAI-native security startups may emerge with purpose-built architectures that challenge the scalability of incumbents’ platforms. Advances in adversarial AI also constantly raise the bar for detection and response, potentially rendering legacy approaches obsolete.
Commercial OpportunityHighGoldman Sachs projects an acceleration in security budget allocations as AI workloads graduate from sandboxes, and the total addressable market expands to include new layers such as agent-to-agent communication, real-time model monitoring, and identity governance for non-human actors.