Protection Matters - Citrini Research
Citrini Research
SubscribeSign in
Protection Matters<br>Cybersecurity’s Winners and Losers
Citrini<br>Aug 07, 2026<br>∙ Paid
190
Share
Nuance has not been an especially strong suit of the AI Trade to date.<br>Ask anyone over the past two months about what the rise of agentic coding agents means for cybersecurity and they’ll likely tell you it’s going to result in an explosion of demand. And they’re probably right – after all, agentic AI coding getting better has correlated pretty much 1:1 with frightening cybersecurity breaches increasing in frequency.<br>That was distinctly not the case just six short months ago.<br>In Q1, we watched the market punish cybersecurity stocks so aggressively that we were left searching for adjectives to describe the phenomenon.<br>On January 24th , we found one:
Since then, the market has rewarded us for opting to go with the obvious (“In the immediate term, supercharged agentic hacking is probably a good thing for cybersecurity stocks”) instead of the convoluted (“Here’s my 40 point explanation, relying on 8 unique predictions about the future, as to why SaaS will broadly be fine”).
We dove deeper into the AI-related upside for cybersecurity names, such as Cloudflare (NET US) , in sections of Agentic Utilities in March. A couple weeks later, most of them went on a tear. And a tear that was resilient against the momentum bloodshed relative to AI infrastructure and semis.
Now, contrary to the days when cybersecurity was yet another baby in a whole lot of unwanted bathwater, shares of companies that can reasonably claim to defend you against the coming wave of frighteningly effective bad actors have outperformed.
But we don’t want to suffer from the market version of Gell-Mann Amnesia – you know the one, where you see a selloff and go “It’s crazy the market can get this dislocated and create such obvious mispricing” and then never wonder if the same observation would apply at any point during the rally.<br>So we’re going beyond just the agentic utility angle and determining who’s best insulated from AI risks, who can reap the most of the coming boom in security spending and who should be feeling a little… insecure.<br>Who’s Got Protection, Who Gets Screwed, in Cybersecurity
With security back in vogue, we believe the market has done a wholesale discounting of the fears that took the sector out of favor in the first place. While that’s mostly correct, in our view, we believe there’s a promising setup from here to go long still underappreciated AI/cyber winners (either AI for cybersecurity or cybersecurity against AI) and short participants of the rally that haven’t proven they’re actually resilient to the threat.<br>While it may not have been obvious to casual observers earlier in the year that immediate cybersecurity demand would be positively impacted by agentic AI improving, we’ve now crossed the Rubicon. Since agentic coding agents debuted, and with their continued improvements, weekly cyberattacks per organization have steadily risen (after a plateau in 2022-2023).
Anyone paying attention can see the trend.<br>OpenAI reported recently that its agents had escaped confinement, hacked Hugging Face, and tried to infect projects on GitHub. The agent exploited a “zero day” vulnerability in third-party software that had apparently not yet been discovered by any of the vulnerability management incumbents. It snuck past traditional cyber defenses and orchestrated a sophisticated campaign. It accessed the internet and hacked Hugging Face, an AI tools company with information the agent wanted.<br>In response to the news that OpenAI’s rogue agent had become a bad actor, Hugging Face announced that (due to guardrails), they were forced to fight back using a Chinese open-source model.<br>The properties and capabilities that made a Chinese open-source model the right tool for Hugging Face also make it a game-changer for would-be attackers. A new era of AI-enabled, semi- and fully-autonomous cyberattacks will only increase demand for the products of most leading public cybersecurity vendors.<br>Anthropic didn’t do much to quell any potential fears that this might have just been an isolated incident – announcing not one but three real-world incidents occurring in their cybersecurity evals. In summary:
It doesn’t stop there, either. Iranian cyberattackers breached American water systems. Hackers are stealing Bitcoin from cold storage crypto wallets.
It’s clear that there are enormous opportunities for most cybersecurity companies in the AI era. Customers are redirecting budgets toward IT security. At the same time, we’ve seen the wholesale threat of commoditization from AI loom.<br>Our view is that there will be a stark contrast between winners and losers in the space, and it doesn’t take much digging to figure out who they are.<br>Discerning Winners and Losers
Our thesis regarding the winners and losers is best summed up in three key points:<br>1) In the near term, AI will create a...