What are the main business models in cybersecurity?

Last updated: 25 August 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

The main business models in cybersecurity are recurring software subscriptions, usage-based security, hardware plus services, managed security, threat intelligence, consumer subscriptions, consulting, channel-distributed security and cyber insurance. Today, recurring B2B software and platform models have the strongest economics overall.

The market is converging on recurring revenue without converging on one pricing unit. Users, identities, endpoints, workloads, data and compute can all be sensible billing anchors depending on what actually drives the customer’s attack surface.

That distinction is becoming more important than the technical category itself. Two cloud-security companies can both look like SaaS businesses while one expands with employee count and the other expands with telemetry, workloads or automated investigations.

Usage pricing is gaining ground, but pure consumption is unlikely to replace subscriptions across cybersecurity. Security teams need cost predictability, and vendors increasingly have their own compute costs to recover, which makes committed capacity plus overage a natural middle ground.

Hardware remains economically relevant when it creates a durable installed base. Fortinet shows how an appliance can be the first sale while higher-margin subscriptions and support become the larger long-term business.

Managed detection and response is trying to turn human security expertise into software-like economics. The key variable is not whether people are involved, but how many customers each analyst can support as automation handles more triage, investigation and remediation.

Consulting has almost the opposite profile. It can deepen customer relationships and generate useful product insight, but revenue still rises much more closely with skilled labor, which makes software-level margins difficult to reach.

Platform consolidation is changing the competitive bar for specialists. A point product no longer needs to be merely better; it often needs to be much better, uniquely informed by proprietary data, or neutral across ecosystems in a way a large platform cannot easily match.

Threat intelligence and cyber insurance show that valuable cybersecurity businesses can sit outside classic software. Both benefit from proprietary risk data that becomes more useful when it is continuously refreshed and embedded in real decisions.

The strongest pattern across the sector is expansion inside an existing customer. The best models let revenue rise as the customer adds employees, devices, modules, workloads, telemetry or broader outsourced coverage, without forcing the vendor to win the account again from zero.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

Why doesn’t cybersecurity have one obvious business model?

Cybersecurity currently spans several very different businesses, from high-margin cloud subscriptions to physical appliances, 24/7 managed security teams, threat-intelligence data and cyber insurance.

The size of the market helps explain why so many models coexist. Gartner expects worldwide information-security spending to reach roughly $244 billion in 2026, up 11.6% in constant currency. That money is spread across software, services and network security rather than flowing into one standard product.

Look at four large vendors and the differences become obvious. CrowdStrike generated $1.32 billion of subscription revenue in its latest reported quarter, against $1.39 billion of total revenue. Fortinet generated $773 million from products in its latest quarter while recurring security subscriptions and support contributed far more. Huntress sells security technology together with a human SOC that watches customers around the clock. Coalition sells insurance policies while using its own security technology to reduce the probability and cost of claims.

Even companies that all look like cloud-software vendors charge for different things. Okta can charge per user or identity. CrowdStrike can charge per endpoint. Cloud and SIEM products increasingly meter data or infrastructure usage. Microsoft meters some Security Copilot usage through Security Compute Units.

For us, the useful distinction is economic rather than technical. Endpoint security, identity security and cloud security tell us what problem a company solves. The business model tells us what the customer pays for, what makes that bill grow and how expensive it is for the vendor to deliver the service.

What are cybersecurity customers actually paying for today?

Cybersecurity customers usually pay according to whatever grows with their attack surface: users, devices, identities, workloads, data, compute or access to a managed security team.

Per-user pricing still makes a lot of sense for identity security. Okta's Workforce Identity plans, for example, are commonly priced according to the number of users being protected. Cloudflare also uses per-user pricing for parts of its Zero Trust offering.

Endpoint security follows the same logic with devices. CrowdStrike publishes per-device pricing for smaller Falcon customers. Huntress currently lists Managed EDR at $8.99 per endpoint per month for its 50-to-99-endpoint tier and Managed ITDR at $4.80 per licensed identity. A company adding 20% more laptops or employees can therefore generate roughly 20% more revenue for the security vendor even before buying another product.

Data-heavy security products work differently. SIEM systems may process logs from thousands of endpoints, firewalls, applications and cloud environments. The amount of security work can increase dramatically even when employee count stays flat, which makes usage or resource pricing more logical. AI security is pushing in the same direction because running automated investigations and security agents creates real compute costs.

Fortinet adds another variation: customers can buy a physical appliance and then continue paying for security subscriptions and technical support for years.

We can group the main models fairly cleanly:

Business model What customers usually pay for Examples What tends to grow the bill
Seat or identity subscription Users or identities Okta, Cloudflare More employees, accounts and features
Endpoint subscription Devices and servers CrowdStrike, Huntress More endpoints and additional modules
Usage-based security Data, compute or resources Elastic, Microsoft Security Copilot More telemetry, workloads and automated security activity
Hardware plus subscriptions Appliance plus ongoing security services Fortinet New installations, renewals and service upgrades
Managed security Protected assets plus continuous monitoring Huntress, MDR providers More assets and broader outsourced coverage
Threat intelligence Access to proprietary intelligence and workflows Recorded Future More teams, integrations and intelligence products
Consumer security Individual or household subscription Norton, Avast, LifeLock More subscribers and broader bundles
Cyber insurance Premium tied to insured risk Coalition More policies, higher limits and additional security services
Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Is subscription revenue now the default cybersecurity business model?

Recurring subscription revenue clearly dominates modern cybersecurity software today, with several major public vendors generating around 95% or more of quarterly revenue from recurring or subscription products.

CrowdStrike's latest available results are particularly clean. The company generated $1.321 billion of subscription revenue from $1.386 billion of total revenue, about 95%. Annual recurring revenue reached $5.51 billion and grew 24% year over year.

Okta is even more concentrated. Its latest quarter produced $750 million in subscription revenue out of $765 million in total revenue, roughly 98%. Tenable reported that recurring revenue represented 95% of its latest quarterly revenue. Rapid7 generated $205 million of product revenue against $211 million of total revenue.

These companies sell different security products, yet their revenue structure has converged. Combining the latest quarterly numbers from CrowdStrike, Okta, Tenable and Rapid7 gives us a revenue pool of roughly $2.63 billion, of which about 96% comes from subscription or recurring revenue under the companies' respective definitions.

Security lends itself unusually well to recurring payments. Malware changes, vulnerabilities appear, identities are created, detection models need updating and customers expect security vendors to keep operating cloud infrastructure continuously. A customer cannot realistically buy today's threat detection and expect it to remain sufficient five years from now.

The interesting fight has moved elsewhere. Cybersecurity companies are now competing over what the recurring bill should follow: users, endpoints, assets, modules, data, compute or a broader platform commitment.

Company Latest reported quarterly revenue Subscription or recurring revenue Approximate recurring share
CrowdStrike $1.386B $1.321B subscription revenue 95%
Okta $765M $750M subscription revenue 98%
Tenable $268.5M 95% of revenue classified as recurring 95%
Rapid7 $210.9M $205.1M product revenue 97%

Is usage-based cybersecurity pricing really taking over?

Usage-based cybersecurity pricing is spreading quickly in SIEM, cloud security and AI security, although seat and endpoint subscriptions still make more sense for much of the industry.

The shift is easiest to understand in security analytics. Imagine two companies with 5,000 employees. One sends a relatively small amount of telemetry into its security platform. The other monitors huge cloud environments, stores enormous log volumes and runs automated investigations continuously. Charging both solely according to employee count would increasingly disconnect the vendor's revenue from both the customer's usage and the vendor's computing costs.

Elastic has long pushed resource-based pricing for its cloud products. Microsoft uses Security Compute Units for Security Copilot. Customer-identity products can also price partly according to monthly active users rather than employee seats. Similar consumption mechanics appear across cloud security, observability and security-data platforms.

AI should make this more common. A human security analyst might run a few investigations during a workday, while autonomous security agents can scan, correlate and investigate events continuously. The amount of machine work becomes economically meaningful, so charging only for the humans supervising the system starts to look increasingly arbitrary.

Pure consumption pricing has its own problem, though. Security teams do not want analysts switching off telemetry because they are worried about the bill. Unexpected cloud costs are annoying; unexpected security costs can actively change how much data a company decides to inspect.

Hybrid pricing therefore looks like the better fit in many of these categories: a committed subscription or capacity level gives the vendor predictable revenue, while usage above that level captures customers whose security workloads become much heavier.

Seat pricing should remain common in workforce identity, and endpoint pricing still fits endpoint protection well. Usage pricing is expanding alongside those models rather than wiping them out.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Are firewall companies still hardware businesses?

Fortinet shows that firewall vendors can still sell a lot of hardware while making most of their money from recurring services attached to that installed base.

Fortinet's latest quarter produced $2.05 billion of revenue. Product revenue reached $773 million after growing 52% year over year, so hardware is hardly disappearing. Yet products represented only about 38% of total revenue. The remaining roughly 62% came from services, including security subscriptions and technical support.

The margin difference is even more interesting. Fortinet reported a product gross margin of 69.8%, while its service gross margin reached 86.6%. The appliance gets Fortinet into the customer's network. Subscriptions and support then monetize that position repeatedly.

That combination can be extremely powerful. A firewall deployed across hundreds of branches may remain part of the customer's infrastructure for years. During that time the customer can renew threat protection, support, cloud services and other security capabilities.

Fortinet also reminds us why hardware still has drawbacks. Physical products bring component costs, inventory, manufacturing and supply-chain exposure into the model. Memory prices and product mix can move margins in ways that barely affect a pure cloud-security company.

The current numbers make the structure pretty clear: modern firewall vendors can use hardware as the entry point into a much larger recurring-services relationship.

Fortinet latest quarter Revenue Share of total revenue Gross margin
Products $773M 38% 69.8%
Services ~$1.28B 62% 86.6%
Total $2.05B 100%

How does managed detection and response make money without becoming consulting?

MDR companies make money by combining security software with a 24/7 security team, then using automation to serve many customers without adding analysts at the same rate as revenue.

Huntress gives us a very concrete example. Its Managed EDR currently starts at $8.99 per endpoint per month in its published 50-to-99-endpoint tier. That price includes both the technology and continuous detection and response from Huntress's SOC. Managed ITDR follows a similar model for identities.

Customers are effectively outsourcing part of their security operations. That is attractive because many companies can afford endpoint software but cannot recruit and run a strong security operations center every hour of every day.

The model has grown well beyond small MSP customers. Large security vendors are building and buying managed-security capabilities too. CrowdStrike continues to expand Falcon Complete and its newer agentic MDR offerings. Zscaler acquired Red Canary, one of the better-known independent MDR providers, bringing managed detection directly into a much larger security platform.

The economics depend heavily on automation. An old-style managed security provider that needs twice as many analysts when revenue doubles behaves much like an outsourcing company. An MDR platform that automates triage, investigation and remediation can let the same analyst supervise far more customers.

AI could improve that leverage quite sharply. Security agents can already collect context, prioritize alerts and perform parts of an investigation before a human becomes involved. If that works reliably at scale, MDR companies can sell a human-backed security outcome while gradually reducing the amount of human work required per customer.

That is why MDR is one of the more interesting hybrid models in cybersecurity right now. The customer buys an ongoing service, while the vendor keeps trying to make delivery look more like software.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Can cybersecurity consulting ever scale like software?

Cybersecurity consulting can produce a valuable business, but today's public-company numbers show how difficult it is for project-based human work to match the economics of security software.

CrowdStrike makes the comparison unusually easy because it reports both businesses. In its latest quarter, subscription gross margin was 78% on a GAAP basis. Professional-services gross margin was 17%. Professional services generated only about $65 million of CrowdStrike's $1.39 billion in revenue.

That gap comes from a basic constraint: experienced incident responders, penetration testers and security consultants have limited hours. Serving another hundred consulting clients usually requires more people. Serving another hundred software customers might require almost no proportional increase in headcount.

Okta is moving in the same direction strategically. The company says its current fiscal-year guidance includes roughly a one-percentage-point revenue headwind from deliberately shifting more professional-services work to partners. Okta would rather let external firms handle more implementation work while Okta keeps the higher-leverage software revenue.

Consulting can still be strategically useful. Incident-response teams see real attacks at close range. Penetration testers uncover weaknesses that can improve products. Consultants also create trusted relationships with senior security buyers.

We would treat consulting as a strong supporting business for many security companies, particularly where expertise is scarce. Building the whole company around billable human hours is a much tougher path to software-like margins.

If you want more recent data on this point, please see our latest cybersecurity market report.

Why are cybersecurity platforms winning so many deals now?

Cybersecurity platforms are gaining ground because large customers can buy more security from vendors they already trust, and the latest adoption figures show that consolidation is moving beyond marketing slogans.

Palo Alto Networks is probably the clearest example. In its latest reported quarter, Next-Generation Security ARR reached $8.1 billion, up 60% year over year, although acquisitions including CyberArk and Chronosphere contributed materially to that growth. The company counted roughly 2,280 platformizations across its largest customers.

More importantly, around 65% of Palo Alto's Next-Generation Security ARR now comes from platformized customers. Those customers show roughly 120% net retention, meaning the cohort is collectively spending about 20% more than a year earlier before new customers are added.

CrowdStrike is seeing the same behavior from another starting point. At the end of its previous fiscal year, 50% of eligible subscription customers used six or more Falcon modules, 34% used seven or more and 24% used eight or more. Endpoint protection can become the entry point for identity, cloud security, SIEM, data protection or managed response.

Microsoft makes this competitive pressure even stronger. Security can sit inside a much larger Microsoft relationship covering Microsoft 365, Azure, Windows, Entra, Intune and other products. An independent security vendor may therefore be competing against something the customer already owns or can add through an existing enterprise agreement.

Platform selling has a simple economic advantage. Winning a completely new Fortune 500 account is slow and expensive. Selling an additional security module to a customer already running several of your products avoids much of that friction.

Customers also have a reason to cooperate. Running dozens of security products creates duplicated data, overlapping agents, separate contracts and another integration every time a tool is added. Consolidating onto a smaller number of strong platforms can genuinely reduce that operational mess.

Specialists still have room, but being slightly better is becoming a weak pitch. A new point product increasingly needs to solve an important problem much better than the module already available from CrowdStrike, Palo Alto Networks, Microsoft or another incumbent platform.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Can a specialist cybersecurity company still beat the big platforms?

Specialist cybersecurity companies can still build major businesses today, but the bar has risen: a narrow product needs unusually good technology, proprietary data or a problem that large platforms still handle poorly.

Tenable is a useful example. Its latest quarterly revenue grew 8.6% to $268.5 million, and the company now serves more than 40,000 customers. It has stayed relevant by expanding vulnerability management into a broader exposure-management platform rather than remaining a single vulnerability scanner.

Rapid7 shows the tougher side of the same market. Its latest quarterly revenue fell 1.5%, while ARR declined 2% to $824 million. Rapid7's new management is explicitly narrowing the company's focus around detection and response and exposure management. Adding more and more loosely connected security products has not automatically produced platform economics.

Threat intelligence offers another route for specialists. Recorded Future grew into a company serving more than 1,900 customers across 75 countries, including more than half of the Fortune 100, before Mastercard agreed to acquire it for $2.65 billion. Proprietary intelligence was valuable enough to command a multi-billion-dollar price even with much larger security platforms already in the market.

There are also categories where neutrality matters. Some customers want an identity provider that works across Microsoft, Google, AWS and many SaaS applications. Others want security products that monitor several competing clouds without favoring one infrastructure stack. Independence can itself become part of the product.

We would not bet on the death of specialist cybersecurity. We would be much more skeptical of specialists whose entire pitch is a modestly better dashboard or another variation of functionality already bundled into a major platform.

If you want more recent data on this point, please see our latest cybersecurity market report.

How do threat-intelligence companies actually make money?

Threat-intelligence companies sell continuous access to proprietary data about attackers, malware, infrastructure and emerging threats, usually through recurring enterprise contracts rather than one-off reports.

Recorded Future shows how valuable that model can become. Before Mastercard's $2.65 billion acquisition agreement, Recorded Future had more than 1,900 clients across 75 countries, including governments in 45 countries and more than half of the Fortune 100.

The customer is paying for a dataset that keeps changing. An intelligence platform collects domains, IP addresses, malware activity, dark-web information, criminal discussions, geopolitical events and other indicators, then turns those raw observations into something security teams can search or feed into their own systems.

That creates a different kind of recurring value from endpoint software. Yesterday's threat intelligence loses usefulness quickly, so customers need the feed to keep updating. Historical data can also become more valuable over time because it helps analysts connect a new attacker or piece of infrastructure with older activity.

The strongest intelligence vendors also integrate their data into SIEM, EDR, identity and fraud systems. Customers then use the intelligence automatically rather than logging into a separate portal every morning.

Mastercard's acquisition of Recorded Future is especially telling. Threat intelligence can support cybersecurity, payments and fraud decisions at the same time. Proprietary security data becomes far more valuable when it sits inside a system making millions of risk decisions.

That makes threat intelligence one of cybersecurity's clearest data-subscription businesses, although the best intelligence companies increasingly want their data embedded in broader security workflows.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

How do consumer cybersecurity companies still make money?

Consumer cybersecurity still supports a very large subscription business, but companies are making more money by expanding beyond basic antivirus into identity, privacy, scams and broader digital protection.

Gen Digital owns Norton, Avast and LifeLock, which makes it one of the best windows into this model. Gen's latest quarter generated $1.336 billion of total revenue. Its Cyber Safety Platform alone contributed $846 million.

There is an interesting detail underneath that headline. Cyber Safety revenue was $869 million in the comparable quarter a year earlier, so the core cyber-safety business actually declined slightly. Gen's overall growth came from a broader portfolio that now includes identity and financial-wellness products.

That says quite a lot about consumer cybersecurity today. Antivirus by itself is a mature category. Windows, macOS, smartphones and browsers already include substantial security features, which makes it harder to convince consumers to pay simply for malware scanning.

Companies such as Gen therefore try to increase the value of each subscriber through bundles covering identity theft, VPNs, privacy, scam protection and other services. LifeLock is a good example of how cybersecurity can extend into identity monitoring and financial protection.

Distribution is also different from enterprise security. Consumers can subscribe directly online, so brand, digital marketing, renewal rates and cross-selling have more influence on economics than enterprise sales teams. Gen still generated $273 million of its latest quarterly revenue through partners, showing that telecoms, retailers and other channels remain useful too.

Consumer cybersecurity is alive and commercially significant, but the product being sold these days is increasingly “protect my digital life” rather than simply “install antivirus on my computer.”

Is cyber insurance becoming a real cybersecurity business model?

Cyber insurance is becoming a genuine cybersecurity business because companies such as Coalition now combine insurance premiums with continuous security monitoring, risk data and incident response.

Coalition has more than 100,000 policyholders, giving it a large dataset connecting real security weaknesses with actual financial losses. Its 2026 Cyber Claims Report found that 64% of closed claims from 2025 resulted in no out-of-pocket loss for the policyholder. Among ransomware claims, 70% involved both encryption and data exfiltration.

The recent Allianz deal pushes this model much further. Allianz Commercial agreed to transition its standalone commercial cyber-insurance business to Coalition through a long-term global partnership. Coalition will take primary responsibility for areas including pricing, product development, risk mitigation and claims management, while Allianz contributes insurance capacity and global distribution.

That arrangement gives Coalition an economic incentive that ordinary cybersecurity vendors do not have. Better security can directly reduce the claims it has to manage. If Coalition detects an exposed service, helps a policyholder close it and prevents a ransomware attack, the security product has improved the economics of the insurance book.

The same telemetry can also improve underwriting. Instead of judging a company only from a questionnaire filled out once a year, a cyber insurer can continuously observe parts of its external attack surface and incorporate that information into risk decisions.

Cyber insurance will remain smaller than the software market because the model also requires underwriting, insurance capacity, regulation and claims expertise. Still, Coalition and Allianz are showing how security technology and financial risk transfer can sit inside one business.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Why do cybersecurity resellers and MSPs still matter in a cloud market?

Cybersecurity vendors still depend heavily on resellers, MSPs and other partners because thousands of customers want someone else to choose, install and manage their security products.

Fortinet says substantially all of its revenue comes through channel partners such as distributors and resellers. Palo Alto Networks also generates substantially all of its revenue through channel partners. Those are multi-billion-dollar security companies, so the channel clearly survived the move from boxed software to cloud subscriptions.

The model is especially powerful among small and midsized companies. Huntress was built around MSP distribution. The MSP already manages the customer's Microsoft 365 environment, devices, backups and IT support, then adds Huntress security on top.

That arrangement lets several businesses make money from the same customer. The security vendor earns recurring software or managed-security revenue. The MSP adds its own monthly service fee. Distributors can sit between vendors and thousands of smaller partners.

Direct self-service still has a role. Cloudflare uses free and inexpensive plans to pull users into its ecosystem, while several security companies offer free trials or entry-level products. Those tactics reduce customer-acquisition friction, especially among developers and smaller organizations.

Once customers become larger, though, deployment, compliance reviews, procurement, integration and support get more complicated. Partners become useful again.

Channel strategy is best seen as a multiplier on the core cybersecurity business model. A strong subscription product distributed through thousands of MSPs can reach customers that would never support the economics of a direct enterprise sales force.

Which cybersecurity business models look strongest today?

The strongest cybersecurity businesses today combine recurring revenue with automatic customer expansion, high software leverage and enough product breadth to sell more to customers that already trust them.

Recurring B2B security software sits at the center. CrowdStrike, Okta, Tenable and Rapid7 currently generate roughly 95% to 98% of revenue from recurring or subscription products under their respective reporting definitions. As seen above, combining their latest reported quarters puts the recurring share at roughly 96%.

Within that huge recurring market, three versions stand out.

Seat and endpoint subscriptions remain excellent when the number of users or devices naturally expands. Consumption pricing looks increasingly attractive where data, cloud infrastructure and AI-driven security work grow faster than headcount. Platform contracts can be even stronger because the vendor captures several security budgets inside one customer relationship.

The Fortinet model also remains powerful. As seen above, hardware gives Fortinet a durable position inside customer networks, while the higher-margin service business now produces most of its revenue. It carries more physical-product complexity than pure SaaS, but the subscription attach makes the economics much better than a normal hardware company.

MDR can become another strong model if automation keeps reducing the amount of analyst time needed per customer. Threat intelligence can support attractive data-subscription economics when the information is proprietary and deeply integrated into customer workflows.

Consulting sits further down our ranking because adding revenue still requires a lot of additional human work. Consumer cybersecurity remains substantial but increasingly needs bundles beyond antivirus to grow. Cyber insurance is promising and strategically interesting, although underwriting makes it a much more specialized business.

The biggest change across cybersecurity is how much these models are starting to overlap. CrowdStrike can sell software, threat intelligence and managed response. Palo Alto Networks spans network, cloud, identity, observability and security operations. Fortinet combines appliances with subscriptions. Coalition combines security technology with insurance.

That convergence points to a fairly direct conclusion. Cybersecurity has several main business models, but the companies with the best economics are increasingly trying to become the recurring security layer around a customer's entire digital environment. The more users, machines, data and security problems that flow through that layer, the larger the customer can become without the vendor having to win the account again from scratch.

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

OUR METHODOLOGY

This analysis looks at what makes a cybersecurity business model economically attractive today. We compare the main models through the questions that matter most: what customers pay for, what makes that spending expand, how recurring the revenue is, how expensive the service is to deliver, and whether the vendor can grow inside an existing customer relationship.

We did not start with a preferred model. Cybersecurity spans software subscriptions, hardware, managed services, proprietary data, consulting, consumer products and insurance, and several large companies now combine more than one of those businesses.

We prioritized recent, directly observable evidence: quarterly revenue mix, annual recurring revenue, gross margins, retention, module adoption, published pricing, customer counts, acquisition terms and strategic changes. Where companies use different definitions of recurring or subscription revenue, we use those figures to illuminate the underlying economics rather than treating them as perfectly standardized accounting categories.

Comparisons are used selectively. The point is not to create a mechanical ranking of vendors, but to isolate the economic differences between models—for example, recurring software versus project-based services, hardware revenue versus attached services, or platform expansion versus a standalone point product.

The pricing discussion relies on direct vendor evidence where possible, including CrowdStrike's endpoint pricing, Huntress's Managed EDR and ITDR pricing, and Microsoft's Security Copilot consumption framework. The broader market view is anchored by Gartner's 2026 information-security spending forecast.

Key sources used for this analysis include: Gartner's 2026 information-security forecast, CrowdStrike's Q1 FY2027 results, Okta's Q1 FY2027 results, Tenable's Q2 2026 results, Rapid7's Q2 2026 results, Fortinet's Q2 2026 results, CrowdStrike Falcon pricing, Huntress pricing, Microsoft's Security Copilot and Sentinel pricing material, Palo Alto Networks' Q3 FY2026 results, CrowdStrike's FY2026 module-adoption disclosure, CrowdStrike's newer module-adoption disclosure, Mastercard's Recorded Future acquisition announcement, Gen Digital's Q1 FY2027 results, Coalition's 2026 Cyber Claims Report, and Zscaler's filing covering the Red Canary acquisition.

No single metric determines the conclusion. We aggregate the evidence across revenue quality, natural expansion, delivery leverage and strategic position, giving more weight to recent, direct and economically relevant data than to broad category labels or marketing claims.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog