Hey everyone,
This is the second post in our Investing Themes series. The first was about owning the power and cooling behind AI. This one is about something I think gets less attention than it deserves: keeping all of it safe. Technology is changing faster than at almost any point in my lifetime, and every new layer of software, every new AI tool, and every new connected device is something that has to be defended. I believe cybersecurity is one of the most important themes of the next decade, and in this post I'll walk through why, how the industry fits together, and how I'd judge a security stock.
A quick heads up on how this post works: parts 1 to 6 are open to everyone. Parts 7 and 8, where I go through my three top picks and the risks, are free too, but you'll need to enter your email to unlock them. It takes about five seconds, costs nothing, and there's no password or credit card.
1. Why security matters more when technology moves fast
Every time computing takes a big step, whether it was the internet, the cloud, or mobile, the number of things an attacker can target grows faster than the number of defenders. Security is the part of the stack that always has to catch up.
The cost of failing is already large and rising. IBM's 2026 Cost of a Data Breach report puts the global average at $4.99 million per breach, up 12% in a year, and the U.S. average at $11.5 million. The FBI's Internet Crime Complaint Center logged about $20.9 billion in reported cybercrime losses in 2025, a 26% jump, with complaints passing one million in a single year for the first time. Those are only the losses people reported.
That is the heart of the theme: the problem scales with how much of the economy runs on software, and software keeps eating more of the economy.
2. AI is arming both sides
AI helps attackers write more convincing phishing emails, find weaknesses faster, and automate steps that used to need a skilled human. IBM's 2026 report found that about one in four malicious breaches was already AI-enabled, a 56% increase from the year before, and those breaches averaged about $6 million.
It also helps defenders. Security teams are buried in alerts, and AI can sort, summarize, and respond far faster than a person can. That's why so many of the biggest security companies now pitch themselves as AI-native: the attackers aren't slowing down, so the defense has to automate too. In practice, this is an arms race, and arms races tend to be good for the companies selling the defense, as long as they keep up.
3. The new attack surface: AI agents, models, and machine identities
Companies are now deploying AI assistants and autonomous agents that read data, call tools, and take actions on someone's behalf. Each one needs an identity, permissions, and monitoring, just like an employee does, except there can be thousands of them and they never log off.
- More identities to protect. Software agents, service accounts, and API keys now outnumber human logins in many companies.
- New ways to be tricked. AI systems can be manipulated through the text they read, so protecting the data and instructions flowing in and out of them is a new job.
- More data in more places. AI tools pull information from everywhere, which raises the stakes on who can see what.
None of this replaces the old problems: stolen passwords, unpatched software, and phishing. It adds to them. A bigger and messier surface is what keeps security budgets growing.
4. Why security spending tends to be resilient
- It's hard to cut. When a single breach can cost millions and damage a brand, security is one of the last budgets a company wants to trim.
- It's recurring. Most modern security is sold as a subscription, which means predictable revenue and customers who stay for years.
- Regulation and insurance push it. Disclosure rules and cyber-insurance requirements make baseline security close to mandatory.
- Platforms win share. Buying many separate tools is expensive and leaves gaps, so large customers increasingly want fewer vendors that cover more ground. That favors the biggest platforms.
"Resilient" doesn't mean "immune." We'll see in part 8 that growth can still slow and stocks can still fall hard.
5. The layers of security, and who plays where
The industry looks crowded until you split it into layers:
- Endpoint. Protecting laptops, phones, servers, and other devices where attacks usually land.
- Network and zero trust. Treating every connection as untrusted until it's verified, instead of trusting anything "inside" the company network.
- Identity. Making sure the right person or software agent has the right access, and nothing more.
- Cloud. Securing the apps and data that live in cloud platforms.
- Security operations. The control room: detecting threats across all the layers and responding quickly, increasingly with AI.
The three companies I picked each lead from a different starting point, an endpoint specialist, a broad platform, and a zero-trust network pioneer, and all of them are pushing into the other layers. That overlap is both the opportunity and the competition.
6. How I'd judge a cybersecurity stock
Security stocks often look expensive on the usual measures, so I lean on a different toolkit:
- ARR (annual recurring revenue) and net new ARR. How big the subscription base is and how much was added this quarter. Accelerating net new ARR is a strong signal.
- RPO (remaining performance obligations). Contracted revenue not yet recognized, a rough view of what's already locked in.
- Free cash flow and its margin. The cash left after running and investing in the business. Many security companies are cash machines even when reported profit is tiny.
- GAAP vs. non-GAAP profit. Non-GAAP numbers exclude items like stock-based pay and acquisition costs. They're useful, but the gap between the two matters, and it's why P/E can be "not meaningful."
- Organic vs. acquired growth. Growth bought through acquisitions is not the same as growth earned from existing customers.
- The price paid. Even a great business can be a poor investment at the wrong price. Our DCF course and P/E explainer help here.
7. My top three picks in the theme
Here are the three companies I'd put at the center of this theme. Each leads a different layer, and I've listed the numbers I check first. All figures are from early October 2026 and are in the slides below.
| CrowdStrike | Palo Alto | Zscaler | |
|---|---|---|---|
| Ticker | CRWD | PANW | ZS |
| Layer | Endpoint | Platform | Zero trust |
| Price | $272.67 | $406.76 | $201.80 |
| 1-year return | +119.9% | +91.3% | -33.9% |
| P/E | n/m | 1,017 | n/m |
| Market cap | $279.2B | $332.7B | $32.9B |
| Analyst target vs. price | -14% | -3% | +9% |
CrowdStrike (CRWD): guards every endpoint
An AI-native platform protecting devices, identities, and cloud workloads. Q2 brought a record $333M of net new ARR (up 51% from a year ago), and ending ARR reached $5.84B, up 25%. Falcon Flex, its bundle that lets customers add more modules, doubled to $2.29B of ARR (+101%). Q2 free cash flow was $377M, and the FY27 net new ARR growth guide was raised to 34%.
Price
$272.67
1-year return
+119.9%
P/E
n/m
Market cap
$279.2B
Watch out. It's priced for perfection: GAAP profit is near zero, the shares more than doubled in a year, and the average analyst target ($236) sits 14% below the price. The CEO has sold on seven dates since late June, and no insider has bought.
Palo Alto Networks (PANW): fights AI with a platform
Network, cloud, and security-operations tools in one platform. Next-gen security ARR grew 63% to $9.1B, helped by the CyberArk deal, and it added nearly $1B of net new security ARR in a single quarter. RPO passed $21B (up 34%). FY26 adjusted free cash flow was $4.4B (a 38.4% margin) with a target of 40% by FY28, and its AI security-operations product, XSIAM, topped $700M of ARR (+70%). FY27 revenue is guided to $14.1B to $14.2B.
Price
$406.76
1-year return
+91.3%
P/E
1,017
Market cap
$332.7B
Watch out. Growth is partly acquired, and FY27 security ARR is guided to just 22% to 23% growth. Q4 GAAP net loss was $282M, and the shares sit at a 52-week high with a P/E over 1,000 on GAAP profit. Insiders sold about $20.8M over 90 days and none bought. The average analyst target of $396 is 3% below the price.
Zscaler (ZS): locks down every connection
Zero trust security for users, apps, and AI traffic. Q4 revenue and ARR both grew 25%, with a record 24.3% non-GAAP operating margin. ARR reached $3.77B; excluding the Red Canary deal, ARR grew 20%. More than 950 customers now buy across users, branches, and cloud workloads, up from 700, and FY26 free cash flow was $779M.
Price
$201.80
1-year return
-33.9%
P/E
n/m
Market cap
$32.9B
Watch out. FY27 is guided to only about 17% growth (versus 25%), and free cash flow margin fell from 27% to 23% on heavy capex. The shares are down 34% in a year. That also makes it the one pick with analyst upside (an average target of $220, about 9% above the price) and the only one where insiders still own about 20%, though they have sold about $5.6M in three months.
Side by side
- CrowdStrike has the strongest momentum and accelerating growth, and the most priced-in expectations.
- Palo Alto is the biggest and most profitable on cash flow, but its growth is the most acquisition-assisted and its multiple on GAAP earnings is extreme.
- Zscaler is the contrarian one: the only stock of the three that is down over the year, with the market clearly worried about its slowing growth outlook.
8. The risks, and how I'd own it
- Valuation. CrowdStrike's shares more than doubled and Palo Alto's rose 91% in a year, and analysts' average targets for CrowdStrike and Palo Alto sit below today's price. Good news can already be in the stock.
- Slowing guidance. Both Zscaler's FY27 outlook (about 17% growth) and Palo Alto's security ARR guide (22% to 23%) are slower than recent results. In this industry, a slower outlook can hurt a stock even when the quarter was good.
- Acquired growth. Deals like CyberArk (Palo Alto) and Red Canary (Zscaler) boost the numbers, but integration is hard and organic growth is the cleaner signal. Zscaler's ARR grew 25% reported but 20% without Red Canary.
- Profit quality. Heavy stock-based pay and acquisition costs mean GAAP profit is thin or negative, so these stocks lean on free cash flow and non-GAAP numbers that you have to understand.
- Insider selling. All three show net selling and no open-market insider buying in the periods covered by the slides. It's common with stock-heavy pay, but it's still worth noticing.
- Competition and consolidation. These three are fighting each other, Microsoft, and a long list of startups. A platform winning share means others lose it.
- A major breach or outage. A security vendor's own failure can damage trust quickly, and one bad update can disrupt customers at huge scale.
- Theme concentration. Three stocks in one theme will often move together when the market punishes software.
How I'd think about owning it:
- Spread across layers, not three versions of the same bet.
- Size for volatility. The 52-week ranges here are huge (CrowdStrike from $86 to $274, Zscaler from $114 to $336), so decide in advance how big a swing you can stomach.
- Watch net new ARR, guidance, and free cash flow margin, not just the headline revenue.
- Consider a fund if you like the theme but not single-stock risk. Cybersecurity and broad software funds hold companies like these.
The bottom line: security demand is likely to keep growing as technology speeds up, but a strong theme doesn't make every stock in it a good buy at every price. That part is up to you.
More soon,
Learn to Love Money
NOT FINANCIAL ADVICE. This post is an educational opinion piece and is not a recommendation to buy, sell, or hold any security. Figures are from company filings and third-party data providers as of early October 2026 and change daily. Analyst targets are opinions, not guarantees. Do your own research or talk to a licensed advisor before investing. This post was prepared with AI assistance; see our AI Disclosure.
Sources
- IBM: Cost of a Data Breach Report (2026 figures via Security Boulevard)
- FBI IC3: 2025 Internet Crime Report (summary: CyberScoop)
- Company filings (SEC EDGAR, 8-K): CrowdStrike, Palo Alto Networks, Zscaler
- Insider trades, analyst ratings and price targets (MarketBeat): CrowdStrike, Palo Alto Networks, Zscaler
- Ownership and holdings (TipRanks): CrowdStrike, Palo Alto Networks, Zscaler
- Analyst consensus (S&P Global via StockAnalysis): CrowdStrike, Palo Alto Networks, Zscaler
- Price, P/E, market cap and 1-year charts: Apple Stocks (redrawn from screenshots).