Technology and media (7 of 8)
Cybersecurity
In one minute
Companies sell software and services that stop criminals and spies from breaking into other companies' computers, stealing data or locking systems.
The big idea: Security spending is a risk decision: buyers pay to cut the chance and the cost of a very bad day, and regulators and insurers set the minimum. Most sellers are subscription software businesses with high gross margins and sticky customers. The battle among vendors is to become the customer's main platform, which drives large acquisitions.
- One unit, in numbers
- One mid-sized business customer of a security software vendor for one year: USD 120,000 comes in, and USD 58,000 (48%) is left after its own costs.What is left is the unit's contribution, before the costs of the whole company. See the worked example
- Typical margin
- Gross margin about 75 to 80 percent for software vendors; operating margins range from losses at fast growers to solid profits at mature platformsRoughly how much of every 100 of sales (or income) is left as profit after the running costs. More on margin
- Capital intensity
- LowLittle money is tied up in buildings, machines or stock, so growing is cheap. More on capital intensity
- The number to watch
- ARR (annual recurring revenue)The yearly value of all active subscriptions.
Ask this first in a case
Are we looking at a buyer of security or a seller, and if a seller, software or services?
The industry's other words are explained in Words to know (11).
On this page (17 sections)
How money is made
- Subscriptions priced per device, per user, per cloud workload or per volume of data.
- Selling more modules to existing customers (platform bundles), often with a discount for buying several.
- Hardware such as firewalls, sold with yearly support and threat-update subscriptions.
- Managed security: a monthly fee to watch and respond to threats around the clock.
- Consulting, testing and incident response, billed by the day or by the project.
Worked example: one unit
Unit economics means the money in and out for one unit of the business. Start from the revenue, take away the unit's own costs, and what is left is its contribution. More on unit economics
| Line | Amount | ShareShare of revenue |
|---|---|---|
| Subscription for endpoint, identity and cloud modules | USD 120,000 | 100% |
| Minus Cloud hosting and data processing | USD 16,000 | 13% |
| Minus Support and share of threat research | USD 10,000 | 8.3% |
| Minus Customer success and renewal sales | USD 12,000 | 10% |
| Minus Share of the USD 120,000 cost to win the customer, spread over an expected five-year life | USD 24,000 | 20% |
| What is left (contribution) | USD 58,000 | 48% |
Check: USD 120,000 minus USD 62,000 of costs leaves USD 58,000.
So what: Gross margin here is about 78 percent, in line with CrowdStrike's subscription gross margin, and the customer earns back its acquisition cost within its life. Retention and extra modules move this most: selling one more module at USD 30,000 adds far more than it costs, because hosting and support rise only a little.
Key measures(9)
Key measures (also called KPIs, key performance indicators) are the numbers people in this industry track. Ask for the first one or two early in a case.
ARR (annual recurring revenue)
The yearly value of all active subscriptions. Glossary: ARR (annual recurring revenue)
Typical: CrowdStrike about USD 5.84 billion at the end of July 2026, up 25 percent[7]
Net new ARR
ARR added in a period after churn; shows whether growth is speeding up or slowing.
Typical: CrowdStrike about USD 333 million in the quarter to July 2026[7]
Gross revenue retention
Share of last year's revenue kept, not counting upsell; high because security is hard to switch off.
Net revenue retention
Revenue from last year's customers now, after upsell and churn, divided by last year's. Glossary: Net revenue retention
Subscription gross margin
Subscription revenue minus the cost of delivering it, divided by that revenue.
Typical: about 78 percent at CrowdStrike[7]
Modules per customer
How many product categories each customer buys; the platform measure.
CAC payback
Months of gross profit needed to earn back the cost of winning a customer. Glossary: CAC payback
Cost of a breach
What a data breach costs the victim on average; the buyer's reason to spend.
Typical: about USD 4.99 million worldwide and about USD 11.5 million in the US in 2026[4]
Time to detect and contain
How long attackers stay inside before they are found and stopped; shorter means cheaper breaches.
First questions to ask
When a case lands in this industry, these questions get you to the numbers that matter.
- Are we looking at a buyer of security or a seller, and if a seller, software or services?
- For a seller: how does ARR move (new, expansion, churn), and what are gross and net retention?
- Which product categories do customers buy, and how often do we lose deals to bundled platforms?
- For a buyer: which rules and insurers set the minimum, and what is the expected loss in the worst likely scenario?
- Which region and sector: do local rules require in-country data or staff?
Value chain: where the margin sits
The value chain is the steps a product or service passes through, from the first supplier to the customer. Each step below shows how much of the value it keeps. More on value chains
Step 1: Threat research and detection data
Margin variesSecurity vendors' research teams, specialist intelligence firms and national agencies
More customers give more data to spot new attacks.
Step 2: Security software
Fat marginPalo Alto Networks, CrowdStrike, Microsoft, Fortinet, Zscaler, Check Point
Subscription gross margins of about 75 to 80 percent.
Step 3: Distribution and resale
Thin marginDistributors, resellers and cloud marketplaces
Step 4: Consulting, integration and managed security
Medium marginAccenture, Deloitte, IBM, TCS, Help AG, Ensign InfoSecurity
People-heavy; security services are about two fifths of all security spending.
Step 5: The customer's security team
Margin variesThe chief information security officer (CISO) and analysts
Sets the budget and chooses vendors.
Step 6: Incident response and cyber insurance
Margin variesIncident response firms and insurers
Insurers increasingly require basic controls before they cover a company.
Profit pool: who keeps the money
Where in the value chain the profit ends up, which is often not where most of the sales are. More on profit pools
Most profit sits with software vendors whose products are hard to remove, especially platforms that sell several categories to the same customer. Services firms earn thinner, people-based margins but benefit from the shortage of skilled analysts. Resellers earn the least.
Cost structure(4)
The main costs, each as a share of revenue (the money from sales).
- Cost of revenue (cloud hosting, data processing, support)
- about 20 to 25 percent (CrowdStrike: subscription gross margin about 78 percent, or 81 percent on its adjusted measure)[7]
- Sales and marketing
- about a third of revenue at the median SaaS firm, nearer half at fast-growing venture-backed ones (SaaS benchmarks)[8]
- Research and development
- about 23 percent in listed and about 34 percent in private SaaS firms (SaaS benchmarks)[8]
- Services firms: people
- the largest cost by far for consulting and managed security, which is why their margins are lower than software
Benchmarks(6)
Typical figures for the industry, to check a client's numbers against.
- Worldwide information security spending
- about USD 213 billion in 2025, forecast about USD 240 billion in 2026[1]
- Security software share of spending
- about half (about USD 106 billion of USD 213 billion in 2025)[1]
- Security services share of spending
- about two fifths (about USD 84 billion in 2025)[1]
- Security spending in India and MENA
- about USD 3.4 billion in India and about USD 4 billion in MENA in 2026[2]
- Breaches starting with exploited software flaws
- about 31 percent in the 2026 report, the top way in[6]
- Breaches involving ransomware
- about 48 percent in the 2026 report[6]
Typical cases(6)
Case prompts you might hear in this industry.
- A security software vendor's growth is slowing. Why, and what should it do?
- Should a single-product security vendor build a platform, partner, or sell itself?
- How much should a bank spend on cybersecurity, and on what?
- Should an Indian IT services firm enter managed security in the Gulf?
- A private equity fund wants to buy a cybersecurity software company. Is it a good investment?
- Should we move from per-device to platform pricing?
Common traps(5)
Mistakes candidates make in this industry, and what to do instead.
- Treating security as a pure IT cost. Frame it as a risk decision with an expected loss.
- Assuming more tools mean more safety. Many breaches come from basics such as unpatched software and missing multi-factor login.
- Forgetting people: tools need analysts to act on alerts, and skilled analysts are scarce.
- Ignoring regulation, which often sets the minimum spend and reporting deadlines (NIS2 in the EU, 6-hour reporting in India).
- In vendor cases, missing the threat of large platforms bundling a similar product at little extra cost.
What changed, 2024 to 2026(6)
Recent changes a case could turn on.
- Spending keeps growing about 10 to 13 percent a year: Gartner forecast about USD 213 billion in 2025 and about USD 240 billion in 2026.[1]
- Breaches got more expensive: the average cost reached a record USD 4.99 million in IBM's 2026 study, up about 12 percent.[4]
- Attackers shifted to software flaws: exploiting vulnerabilities became the top way into breaches, at about 31 percent, ahead of stolen passwords.[6]
- Platforms bought the pieces they lacked: Palo Alto Networks completed its roughly USD 25 billion purchase of CyberArk (identity) in February 2026.[11]
- Google completed its USD 32 billion purchase of Wiz (cloud security) in March 2026, its largest acquisition.[10]
- Concentration risk became visible: a faulty CrowdStrike update in July 2024 crashed about 8.5 million Windows devices, yet CrowdStrike's ARR still grew 25 percent to mid 2026.[9]
Players by region(6)
Well-known companies in each region. You do not need to learn them by heart; they help you picture the market.
- Global
- Microsoft
- Palo Alto Networks
- CrowdStrike
- Cisco (with Splunk)
- Google (with Mandiant and Wiz)
- Fortinet
- United States
- Zscaler
- Okta
- Cloudflare
- SentinelOne
- Proofpoint
- Europe
- Thales (France)
- Sophos and Darktrace (UK)
- WithSecure (Finland, taken private in 2025)
- ESET (Slovakia)
- Middle East
- Check Point (Israel)
- Help AG (part of e&, UAE)
- CPX (UAE)
- sirar by stc (Saudi Arabia)
- India
- Quick Heal and Seqrite
- TCS, Infosys, Wipro and HCLTech (managed security)
- Southeast Asia
- Ensign InfoSecurity (Singapore)
- ST Engineering (Singapore)
Words to know(11)
Linked words have a fuller entry in the glossary.
- Ransomware
- Malicious software that locks or steals data until a payment is made.
- Phishing
- Fake messages that trick people into giving away passwords or access.
- Vulnerability
- A flaw in software that attackers can use until it is fixed (patched).
- Endpoint (EDR)
- Endpoint detection and response: software that watches laptops and servers for attacks.
- Identity and access management
- Tools that check who someone is and what they may reach.
- SIEM
- A system that gathers alerts and logs so analysts can spot attacks.
- SOC
- Security operations centre: the team that watches for and responds to attacks.
- MSSP
- Managed security service provider: a firm that runs security monitoring for customers.
- CISO
- Chief information security officer: the executive responsible for security.
- Platform consolidation
- Buying several security categories from one vendor instead of many.
- Expected loss
- The chance of an event in a year multiplied by what it would cost.
Business model patterns
The ways of making money this industry follows. Spot the pattern in a new industry and you already know the first questions to ask.
Sources(13)
Facts checked on . Worked examples are illustrative, shaped by these sources rather than one company's figures.
- 1.Gartner: worldwide end-user spending on information security to total USD 213 billion in 2025, with a table by segment to 2026 (July 2025, official press release) (opens in a new tab)
- 2.Gartner: information security spending in India to total USD 3.4 billion in 2026 (March 2026, official press release) (opens in a new tab)
- 3.Gartner: MENA end-user spending on information security to total USD 4 billion in 2026 (October 2025, official press release) (opens in a new tab)
- 4.IBM: Cost of a Data Breach Report 2026 (official report page) (opens in a new tab)
- 5.eSecurity Planet: IBM 2026 Cost of a Data Breach Report, key findings including the US average (opens in a new tab)
- 6.Verizon: 2026 Data Breach Investigations Report (official report page) (opens in a new tab)
- 7.CrowdStrike: second quarter fiscal year 2027 financial results, quarter ended 31 July 2026 (official) (opens in a new tab)
- 8.Benchmarkit: 2025 B2B SaaS Performance Metrics Benchmarks (2024 data, survey report) (opens in a new tab)
- 9.Microsoft: helping our customers through the CrowdStrike outage, 8.5 million Windows devices affected (July 2024, official blog) (opens in a new tab)
- 10.Cleary Gottlieb: Google completes USD 32 billion acquisition of Wiz (March 2026) (opens in a new tab)
- 11.CRN Asia: Palo Alto Networks completes USD 25 billion acquisition of CyberArk (February 2026) (opens in a new tab)
- 12.EUR-Lex: Directive (EU) 2022/2555 (NIS2) on a high common level of cybersecurity across the Union (official) (opens in a new tab)
- 13.CERT-In, Government of India: directions of 28 April 2022 on reporting cyber incidents within 6 hours (official) (opens in a new tab)
Go deeper and practise
Go deeper
The full lessons behind this brief, with sources and worked cases.
Same pattern elsewhere
Industries that make money in a similar way. What you learned here carries over.
- Media and entertainmentMedia companies make or buy films, shows, music, games and sport, then earn from them through subscriptions, advertising, sales and licences.Shares: Subscription, Network effects
- Software and SaaSCompanies write software once and rent it to businesses and people as a monthly or yearly subscription delivered over the internet.Shares: Subscription
- Data centres, cloud and AI computeCompanies build buildings full of computers, fill them with power and cooling, and rent out space or computing time to businesses, cloud users and AI labs.Shares: Subscription
- Telecom: mobile and fixed networksCompanies build mobile and broadband networks and charge people and businesses a monthly fee to use them for calls and data.Shares: Subscription
- Education and edtechSchools, universities, tutoring companies and learning apps teach people, paid for by governments, parents, employers or the learners themselves.Shares: Subscription
- Healthcare providers and payersHospitals, clinics and doctors who give care, and the governments and insurers who pay for it.Shares: Subscription