---
title: "From 'AI Disruption' to 'AI Catalyst': The Logic Behind Cybersecurity Stocks Has Shifted"
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/296218067.md"
description: "The market was initially concerned that AI would erode the competitive moats of cybersecurity firms. However, AI agents have now spawned more complex and rapid attacks, thereby expanding the corporate attack surface and forcing security capabilities to upgrade in tandem with AI deployment. Consequently, cybersecurity is evolving from a defensive expense into essential infrastructure for the large-scale implementation of AI. This shift has significantly boosted demand logic, sector valuations, and ETF performance, as the market reprices its growth prospects"
datetime: "2026-08-18T11:01:38.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/296218067.md)
  - [en](https://longbridge.com/en/news/296218067.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/296218067.md)
---

# From 'AI Disruption' to 'AI Catalyst': The Logic Behind Cybersecurity Stocks Has Shifted

Market perception of the relationship between AI and the cybersecurity industry is undergoing a significant shift.

In a deep-dive report released on August 18, Bank of America Securities pointed out that just a few months ago, the market was worried that AI would disrupt the business models of traditional cybersecurity vendors and weaken the moats of existing products and platforms. **However, with the rapid emergence of new attack vectors such as AI agents, the market has begun to realize that AI is expanding the corporate attack surface and driving up the speed and complexity of cyberattacks.**

This means the relationship between AI and cybersecurity is shifting from "disruptor" to "demand catalyst." **The deeper enterprises integrate AI applications, the higher the requirements become for security capabilities regarding identity, data, endpoints, and cloud environments. Cybersecurity is thus transforming from a potential victim of the AI wave into indispensable infrastructure for the large-scale adoption of AI.**

This change is already reflected in market performance. Over the past two months, CIBR rose by 16.1%, HACK surged by 38%, IVG gained 14.9%, while the S&P 500 Index rose by only 3.6% during the same period. Meanwhile, valuations in the cybersecurity sector have expanded significantly, indicating that capital is repricing the industry's growth prospects.

## AI Threats Are Reshaping Security Demand

Previously, market concerns about AI's impact on the cybersecurity industry stemmed from a simple logic: AI lowers technical barriers, which could help enterprises perform security tasks more efficiently but also allow attackers to launch attacks at lower costs, thereby undermining the value of traditional security products.

However, this logic is changing with the rapid development of Agentic AI. **AI agents can execute tasks across systems, autonomously discover vulnerabilities, and operate continuously with limited human supervision. The resulting "agent-driven attacks" are becoming a new type of risk that corporate CISOs are focusing on.**

Compared to traditional cyberattacks, AI-driven threats not only mean an expanded attack surface but also a simultaneous increase in attack speed and complexity. For enterprises, the wider the deployment of AI, the more identities, permissions, data, and workloads need to be managed. If security capabilities fail to upgrade in sync, the efficiency gains brought by AI could instead translate into new security risks.

Therefore, AI is forming a new closed loop of security demand: **AI expands the attack surface – attack complexity increases – enterprises increase security spending – security vendors benefit.**

## Cybersecurity Shifts from "Defensive Spending" to "AI Infrastructure"

A more significant change lies in the evolving role of cybersecurity.

Previously, cybersecurity was largely viewed as a defensive expense within enterprise IT budgets, making industry valuations susceptible to macroeconomic conditions and corporate IT budget cycles. But in the AI era, security is gradually becoming a prerequisite for enterprises to expand their AI applications.

Enterprises need to ensure that AI agents are properly authorized, control machine identities and access rights, protect data within AI workflows, and continuously monitor cloud environments, endpoints, and networks. In other words, **without sufficient security capabilities, it will be difficult for enterprises to truly scale their AI strategies.**

**This shifts the demand logic for cybersecurity from purely "risk prevention" to "safeguarding AI growth." As the scale of AI investment grows, the potential space for security spending may expand accordingly.**

## Sector Valuations Are Being Repriced

Changes in demand logic are already beginning to reflect in valuations. According to Bank of America data, the median EV/2027 Sales multiple for cybersecurity companies is currently around 5.8x, up from just 4.5x two months ago; the average valuation has expanded from 7.0x to 9.0x.

At the same time, cybersecurity ETFs have recently significantly outperformed the broader market, indicating that market capital is increasing its attention to this industry. **From a valuation perspective, the core of the sector's repricing is not just short-term performance improvement, but rather the market assigning higher growth certainty to cybersecurity.**

If AI continues to expand enterprises' digital assets, machine identities, and automated workflows, security demand will expand along with it. This means the long-term Total Addressable Market (TAM) of the cybersecurity industry is being redefined by AI.

## Valuation Expansion Still Requires Earnings Verification

However, the significant expansion in sector valuations also implies that the market's expectations for future growth have risen synchronously.

Bank of America believes that the current valuation of the cybersecurity software industry is in the range of approximately 5x to 10x EV/Sales. The valuation differences among companies essentially reflect their growth rates, ability to expand into new markets, and the certainty of their business models.

Therefore, the demand catalyzed by AI does not mean that all cybersecurity companies will receive the same degree of valuation premium. **Companies that can sustainably gain market recognition need to prove that AI not only brings new security risks but also translates into actual orders, ARR growth, and a larger serviceable market.**

This also means that the core focus of the industry will shift from "whether AI will disrupt cybersecurity" to "how much new demand AI can actually bring to cybersecurity."

### Related Stocks

- [CIBR.US](https://longbridge.com/en/quote/CIBR.US.md)
- [BUG.US](https://longbridge.com/en/quote/BUG.US.md)
- [HACK.US](https://longbridge.com/en/quote/HACK.US.md)
- [IHAK.US](https://longbridge.com/en/quote/IHAK.US.md)
- [PSWD.US](https://longbridge.com/en/quote/PSWD.US.md)
- [UCYB.US](https://longbridge.com/en/quote/UCYB.US.md)

## Related News & Research

- [This ETF, the IBD stock of the day, breaks out as cybersecurity stocks rebound](https://longbridge.com/en/news/294724047.md)
- [$130 Million Coldcard Hack Puts Cybersecurity ETFs on Investors' Radar](https://longbridge.com/en/news/294973830.md)
- [Batten down the hatches and allocate defensively because global liquidity has peaked, argues veteran strategist](https://longbridge.com/en/news/295919967.md)
- [Tariff winners - 3 stocks that could benefit from trade chaos](https://longbridge.com/en/news/296217003.md)
- [Alpha Compute Strengthens Executive Team To Scale Global Infrastructure Business | ALP Stock News](https://longbridge.com/en/news/296138890.md)