Closed-Source vs Open-Source AI Battle Rages On, Three Cybersecurity Stocks Soar 130%! Trillion-Dollar "Security Debt" in the AI Era Ignites an Upgrade Frenzy

Stock News
Yesterday

The rise of Meta Muse and OpenAI Astra is pushing AI from merely answering questions toward autonomously executing tasks, while also continuously driving cybersecurity to become a fundamental capability that enterprises must invest in simultaneously when scaling AI deployments. This is why a basket of cybersecurity stocks tracked by Wall Street financial giant Goldman Sachs has more than doubled since hitting a low on April 10. The Australian government disclosed on September 24 that an OpenAI research team, while using an internal model on June 18 to study public pharmaceutical expenditures, had its agent independently seek alternative pathways after repeatedly encountering access blocks, gaining unauthorized entry into certain areas of a Medicare statistical reporting portal. OpenAI did not notify Australian authorities until September 10, and the method and timing of the notification drew dissatisfaction from Australian Prime Minister Albanese. There is currently no evidence that personal information was affected, and the statistical portal is independent of patient information and the Medicare payment system; however, the incident has pushed agent permission boundaries, behavioral auditing, and incident notification mechanisms to the forefront of regulatory attention. The industrial significance of this event lies in the fact that security investment is becoming a prerequisite for scaling AI applications. Australia has established a cross-departmental investigative task force to examine government cyber defense, incident response, and legal arrangements; the Government Services Minister has also requested an assessment of whether the previously budgeted AUD 160 million cybersecurity infrastructure upgrade can be accelerated, and whether legacy portals can be migrated or decommissioned. Security vendors have also participated in frontier model incident handling: OpenAI previously disclosed in its Hugging Face incident review that it had collaborated with external advisors including CrowdStrike to investigate the scope and impact of the activity. From this, a very clear and concrete transmission path for cybersecurity demand expansion in the AI agent era can be observed: enhanced capabilities of frontier AI agents expand the scope of systems and operations that need protection; actual incidents expose control gaps, further driving procurement of security assessments, system overhauls, and continuous monitoring. Palo Alto Networks CEO Nikesh Arora previously pointed to approximately $1 trillion in "cybersecurity debt" during the company's earnings call on September 1, highlighting the potential renewal demand for modernizing legacy security architectures. He noted that approximately $1 trillion in pre-AI-era cybersecurity technology debt globally urgently needs modernization, emphasizing that roughly $1 trillion in global cybersecurity infrastructure is not yet prepared to handle AI threats, and this gap will bring long-term growth space for the industry. Capital markets have already reacted strongly to this shift. The cybersecurity stock basket tracked by Goldman Sachs has more than doubled since its April 10 low, with CrowdStrike, Palo Alto Networks, and Fortinet all rising more than 130% over the same period; since September 11, the last trading day before Anthropic CEO Amodei called for slowing the development of the most advanced models, the basket has gained another 19%. Another Wall Street financial giant, Bank of America, views cybersecurity as an important investment theme and supporting force in the AI era, while Bernstein focuses on whether revenue growth can meet the strong acceleration implied by stock prices. Current pricing divergence centers on commercialization intensity: how much of the new security demand can be converted into subscriptions, module purchases, and recurring revenue. CrowdStrike's forward P/E of over 170 times, Palo Alto Networks' 91 times, and Fortinet's 48 times make order fulfillment and earnings forecast upgrades important supports for future performance. Whether open-source AI wins or closed-source AI wins, cybersecurity boundaries must persist! From the underlying system architecture perspective, agent capabilities come from the collaboration between large models and execution environments: models generate plans, execution frameworks invoke browsers, code tools, databases, and business interfaces, CPUs handle task orchestration and tool execution, and memory and storage retain context, files, and operational states. As systems like Muse and Astra can handle longer and more complex tasks, the objects enterprises need to protect also expand to include agent identities, access credentials, tool connections, runtime environments, and cross-system data flows. Therefore, security controls must run throughout the execution process: who initiates operations, what permissions are used, which data is accessed, whether human approval is required, and whether anomalous behavior can be interrupted in a timely manner. Technical guidance from the Australian Signals Directorate explicitly points out that the execution framework connecting tools and business systems outside of large model/AI agent systems is an important position where organizations can directly implement permissions, monitoring, and governance. Based on this, cybersecurity belongs to a core beneficiary layer in the AI industry chain with strong "model-route neutrality." Regardless of whether enterprises adopt closed-source model APIs, self-deploy open-weight models, or call multiple models simultaneously, they all need to manage identity, permissions, data access, and execution behavior. Model upgrades or vendor switches will not eliminate these control needs; cross-cloud, cross-model deployments actually increase the value of unified governance. The Australian Signals Directorate also emphasizes that models can be replaced over time, while execution frameworks and their security governance ecosystems may become more enduring organizational capabilities. Specific products have already developed along this direction: Okta manages agents as independent non-human identities, providing short-term credentials, per-tool-call authorization, and auditing; SailPoint governs agent owners, permissions, and lifecycles through cross-cloud and cross-application connectors. Frontier model capabilities are also enhancing security vendors' own service capabilities. Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense on September 22, combining Anthropic's Claude Mythos 5, OpenAI's GPT-5.6-Cyber, and open-weight models, selecting models based on different tasks to continuously conduct security testing on web applications, APIs, cloud infrastructure, code repositories, and network assets, and providing remediation recommendations; this service is already offered on an annual subscription basis. The same wave of model progress both increases enterprise defense needs and helps security platforms expand detection coverage, shorten response times, and convert capability upgrades into chargeable continuous services. These developments provide concrete commercial cases for the argument that "regardless of which model route leads, security platforms have opportunities to participate in value distribution." On the performance front, CrowdStrike's fiscal 2027 second-quarter revenue for the period ending July 31 was approximately $1.471 billion, up 26% year-over-year; annual recurring revenue (ARR) reached $5.84 billion, up 25% year-over-year, with net new ARR for the quarter at $332.8 million, up 51% year-over-year. These figures indicate that security demand has already materialized in some vendors' new business, though that quarter preceded the new round of market enthusiasm brought by Muse and Astra in September. The growth mechanisms more worth tracking in the future are the expansion of non-human identity, cloud workloads, and AI application protection scope, driving customers to add security modules, expand subscription contracts, and deepen platform usage. The investment value of security vendors will increasingly depend on whether they can convert the enterprise need for "AI must run securely" into continuously growing recurring revenue and cash flow. Cybersecurity stocks are red-hot, but some investors are beginning to question whether the rally can be sustained long-term. In recent months, cybersecurity company stock prices have risen sharply, with investors betting that threats brought by the most frontier AI models will benefit these companies' businesses. However, some stocks have risen so much that investors are beginning to question whether they have overshot. As shown in the chart above, consumer inertia is gradually being broken, and concept stocks related to agentic AI have surged recently. The basket of cybersecurity stocks tracked by Goldman Sachs has more than doubled since hitting a low on April 10. Previously, Anthropic restricted the release of its Mythos AI model due to concerns that it could be used to launch cyberattacks. Since then, shares of CrowdStrike Holdings, Palo Alto Networks, and Fortinet have all risen more than 130%, ranking among the ten best-performing S&P 500 constituents over the same period. The rapid ascent has made these stocks among the most highly valued in the market. According to Bloomberg-compiled data, CrowdStrike's forward P/E exceeds 170 times, second only to Tesla in the S&P 500. Palo Alto Networks' stock trades at 91 times forward 12-month expected earnings, making it the fifth most expensive stock in the index. Fortinet's P/E of 48 times ranks 16th. As shown in the chart above, AI security concerns have driven a surge in cybersecurity software stocks; the chart shows changes since December 31, 2025. "If you're considering entering now, you must realize that the price you're paying already reflects expectations that everything will be perfect in the future," said Brad Long, Chief Investment Officer of Wealthspire, which manages approximately $593 billion in assets. "The tailwinds for cybersecurity are obvious, but if any signs of weakness emerge—if the AI capital expenditure cycle slows, or even if we simply stop seeing as many sophisticated AI attacks—their revenue growth could slow and stock prices could fall sharply." This rally contrasts sharply with the beginning of the year, when concerns about AI disrupting existing business models triggered indiscriminate selling across the software industry. As industry financial performance has been strong, such concerns for many software companies have eased, and recent successive warnings from within the AI industry about the severe threats this technology could pose have given investors another reason to buy cybersecurity stocks. Since September 11, Goldman Sachs' cybersecurity stock basket has risen 19%. September 11 was the last trading day before Anthropic CEO Dario Amodei called for slowing the development of the most advanced models. Today, the necessity of strengthening cybersecurity defenses is widely recognized; the question is whether these companies can achieve sufficient revenue and profit growth to meet the expectations implied by their eye-watering valuations. "The cybersecurity sector may have overshot," warned Bernstein analyst Peter Weed recently when downgrading Palo Alto Networks, Okta, and SentinelOne. In a September 17 report, he wrote that while real demand does exist in the sector, "sector stock prices appear to imply expectations that growth will accelerate enough to rival usage-based software businesses like hyperscale cloud services or databases." However, Weed noted that cybersecurity business growth may be constrained by practical factors such as customer employee headcount. Nevertheless, fundamentals appear to be moving in the right direction. At the end of August, CrowdStrike released better-than-expected revenue guidance, pushing shares up more than 20% the day after the earnings release, the largest single-day gain since 2019. "The 'Mythos moment' prompted broad market acceptance of the view that adopting AI requires security safeguards," CEO George Kurtz said in the earnings statement. "Every enterprise will run on AI, and securing AI is the largest market opportunity we have ever had." Several AI-enabled hacking attacks and AI agent intrusions have occurred this year, alarming cybersecurity experts and AI developers. On Thursday, Australian Prime Minister Anthony Albanese said that an OpenAI model breached a government website earlier this year, gaining unauthorized access to files on a site used for reporting medical statistics. In July, OpenAI said its AI model inadvertently breached Hugging Face. Last week, Google disclosed that its Gemini AI model had similarly penetrated three companies' systems during security testing. "We believe the market is increasingly pricing in a step-change rise in cyber risk, which supports both higher security spending and a more aggressive valuation framework for the entire sector," Bank of America analyst Tal Liani wrote in a September 18 report. In raising target prices for CrowdStrike, Okta, and SailPoint, he called cybersecurity "a major investment theme in the AI era and a key force supporting the development of the AI era." Post Oak Group Managing Director Josh Taves said that although cybersecurity stocks have risen substantially, valuation signals can also be misleading if growth exceeds expectations. "Given how much the cybersecurity sector has risen this year, I understand why people might view it more cautiously. But while I expect other types of software budgets to shrink as AI models take over work, security spending should remain strong or even increase," he said. "In such an environment, traditional valuation metrics are less applicable than before. With such a strong demand backdrop, investors are willing to pay higher prices."

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10