Which parts of cybersecurity are still interesting?

In our cybersecurity market deck, you will find everything you need to understand the market
SUMMARY
Which parts of cybersecurity are still interesting? The best opportunities today are AI agent security, agentic identity, AI-native AppSec and autonomous exposure management, with OT security standing out as the strongest large opportunity outside AI.
The broad cybersecurity market is still healthy, but that no longer means every security category is attractive for a startup. Funding and M&A remain high while platform consolidation is making generic point products much harder to distribute.
The strongest openings appear where technology has created a new security decision that did not exist a few years ago. Agents acting across SaaS apps, coding systems installing packages, and software receiving temporary machine permissions are all examples.
AI security itself is already too broad and too crowded to be a useful startup thesis. The better opportunities sit at specific control points, especially where software is about to take an action that could have real consequences.
Agent security and non-human identity are increasingly converging. The interesting product is less about discovering that an agent exists and more about deciding what it may do, for how long, with which credentials, and under what conditions.
AI coding is also moving AppSec earlier in the workflow. Security products that only scan code after it is written may lose relevance as coding agents start choosing dependencies, running commands and changing infrastructure inside the development session itself.
Exposure management looks unusually attractive because the customer pain is already obvious. Enterprises have far more vulnerabilities than they can fix, while attackers are exploiting them faster, which makes proof of exploitability and automated remediation much more valuable than another prioritized list.
Data security remains important, but DSPM discovery is no longer the most interesting wedge. The next layer is deciding whether a user or agent should be allowed to access, move or use sensitive data in a particular context.
AI SOC automation can still produce valuable companies, but the distribution problem is tougher. CrowdStrike and Palo Alto Networks already control enormous telemetry sets and response mechanisms, so independent startups need to work across vendors or automate real actions rather than merely summarize alerts.
OT security is attractive for almost the opposite reason. Industrial environments are difficult, slow-moving and full of specialized systems, which makes the market harder to enter but also harder for generic software platforms to absorb quickly.
Post-quantum security looks slower than AI security but more durable than many mature categories. Standards and government deadlines are turning cryptographic discovery and migration into a real multi-year enterprise program rather than a theoretical future problem.
The clearest pattern across the most attractive categories is that security is moving closer to execution. The valuable layer increasingly sits at the moment a system must decide whether an agent can act, a dependency can install, a vulnerability can be exploited or a remediation can run.

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market
Can a new cybersecurity startup still break through today?
Yes. A new cybersecurity startup can still break through today, although broad point products have much worse odds than they did a few years ago.
Money is certainly still going into cybersecurity. Crunchbase counted $10.6 billion invested in security and privacy startups during the first half of 2026. The second quarter slowed by roughly 30% from the first, but funding remained at historically high levels. Cybersecurity M&A has been even busier: The Wall Street Journal counted 219 acquisitions in the first half of the year, putting the market on pace to beat the record 400 deals completed in 2025 if that rate continues.
The harder part is distribution. CrowdStrike's latest reported numbers show how much buying is moving toward platforms. Its customers using at least six Falcon modules reached 51%, up from 50% one quarter earlier and 49% two quarters earlier. Thirty-five percent now use seven or more modules, and 25% use eight or more. Falcon Flex accounts alone represented more than $1.9 billion of ARR, almost twice the level of a year earlier.
That changes what counts as an attractive startup opportunity. A company selling one more endpoint dashboard, cloud scanner or generic detection product has to persuade customers to add another vendor while CrowdStrike, Palo Alto Networks, Microsoft and others are offering the same buyer more functions under an existing contract.
The openings that still look good tend to appear where the underlying technology has changed enough to create a new security control point. AI agents, machine identities, AI-written software and autonomous remediation all fit that description. Mature categories where the customer already has three acceptable vendors generally do not.
| Market evidence | Latest useful figure | What we take from it |
|---|---|---|
| Cybersecurity startup funding | $10.6B in H1 2026 | Investors are still funding the sector heavily |
| Cybersecurity M&A | 219 deals in H1 2026 | Acquirers still have a strong appetite for new security technology |
| CrowdStrike customers using 6+ modules | 51% | Platform consolidation is getting stronger |
| CrowdStrike Falcon Flex ARR | $1.9B+ | Large vendors can cross-sell new security categories very quickly |
If you want more recent data on this point, please see our latest cybersecurity market report.
Why are new cybersecurity markets opening up again now?
AI is opening new cybersecurity markets because companies are giving software more access and more autonomy at the same time that attackers are getting faster.
CrowdStrike's latest Global Threat Report found that AI-enabled adversary activity rose 89% year over year. Average eCrime breakout time, meaning the time between an initial compromise and an attacker moving laterally, fell to 29 minutes. The fastest case CrowdStrike observed took 27 seconds.
That speed changes the value of many existing security workflows. A vulnerability that sits in a queue for three weeks, an identity review performed every quarter or an alert that waits an hour for an analyst can all become too slow.
Enterprise AI is also creating security problems inside companies rather than only helping attackers. Verizon's latest DBIR found frequent employee use of unapproved AI tools rising from 15% to 45% in one year. Third parties were involved in 48% of breaches, up 60% from the previous year's level. Meanwhile, agents are increasingly being connected to SaaS applications, source-code repositories, cloud systems and internal company data.
The result is a much broader set of software actors that can read information and take actions. Security products now have to answer questions such as which agent is acting, what credentials it has, which data it can read, which tool it wants to call and whether that action should be allowed.
These days, that is where much of the genuinely new cybersecurity surface is appearing.

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward
Is “AI security” already too crowded to build in?
Yes. “AI security” is already too crowded to be a useful startup category by itself.
Capital is pouring into the area from almost every direction. Alice recently raised $140 million and said it is approaching $100 million in ARR across AI trust, safety and security. Zenity raised $125 million for agent security. Obsidian Security raised $85 million at a $1.1 billion valuation. Geordie raised $30 million after reporting 1,300% ARR growth during the first five months of the year.
Large cybersecurity vendors are moving just as quickly. Palo Alto Networks spent $231 million on Koi to add security for agentic software running on endpoints and agreed to pay about $140 million for AI gateway company Portkey. CrowdStrike acquired Pangea for AI security. Akamai paid roughly $205 million for LayerX to bring browser-based AI controls into its zero-trust platform.
The category is already splitting into more specific markets: model security, AI red teaming, agent identity, runtime protection, AI gateways, browser controls, data governance and agent authorization.
For founders, “we secure enterprise AI” now sounds about as broad as “we secure the cloud.” A startup needs to own a specific decision that customers cannot easily hand to an existing platform.
We would much rather build around questions such as whether an agent should be allowed to send a payment, install a package, query a customer database or call an external tool. Those are concrete security decisions with clear consequences.
Is AI agent security the best cybersecurity market to enter now?
For a new cybersecurity company, AI agent security is our strongest bet today.
The recent financing activity is unusually concentrated. Zenity raised $125 million to secure autonomous agents in production. Obsidian Security raised another $85 million and reached a $1.1 billion valuation. Obsidian also disclosed that more than 100 customers now spend over $100,000 a year on its platform, while more than 14 spend over $1 million. That is useful evidence because it shows real enterprise budgets forming behind the category.
The products are also moving beyond simple prompt filtering. Zenity says it can understand an agent's intent and allow, modify or block actions. Obsidian watches agents interacting with third-party applications such as Salesforce, Slack, Snowflake and GitHub. Geordie focuses on agent security and governance across enterprise deployments.
The browser and API layers reinforce the same idea. CrowdStrike is buying browser-runtime technology because browsers increasingly sit between agents and enterprise applications. Akamai made the same move with LayerX. API-security companies such as Salt and Wallarm are extending into MCP and AI-agent traffic because agents become useful when they start calling tools.
These products are converging around one valuable control point: what an agent is allowed to do after it has been given access.
There is also fresh evidence that the problem can become more serious than a badly phrased chatbot response. Recent controlled experiments have shown autonomous agents interfering with other agents, exploiting weak authentication and taking unexpected actions when given enough authority. Once companies put similar systems into finance, engineering, customer support or IT, the security requirement moves much closer to privileged-access control.
The risk for startups is speed. Palo Alto Networks, CrowdStrike, Okta and other incumbents are already buying their way into agent security. A startup that only inventories agents will probably get compressed quickly.
The bigger opportunity is runtime enforcement across different agent frameworks, browsers, APIs and SaaS applications. If agents become a meaningful part of the workforce, companies will eventually need a place where their actions can be authorized, logged, restricted and revoked. That control layer is still up for grabs.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups
Is non-human identity becoming a real cybersecurity market?
Yes. Non-human identity is becoming a real cybersecurity market as AI agents turn an old service-account problem into a much bigger access-control problem.
Recent transactions make the change hard to dismiss. Oasis Security raised $120 million earlier this year after reporting that new ARR had grown fivefold over the previous year. A few months later, Cyera agreed to acquire Oasis in a deal valued at roughly $1 billion.
Okta has also agreed to acquire Permiso Security, which protects human, machine and agentic identities across cloud environments. NewCore came out of stealth with $66 million to build an identity platform where AI agents have their own lifecycle, permissions and revocation mechanisms rather than borrowing credentials designed for software services or human employees.
The interesting part goes beyond counting machine identities. Companies have already had service accounts, API keys, workloads and certificates for years. AI agents make the problem harder because their behavior can change from one task to the next. An agent might need temporary access to Salesforce, then a database, then a payment tool, with each action depending on what happened earlier in the workflow.
Static permissions become awkward in that environment.
This makes dynamic authorization especially interesting: short-lived credentials, just-in-time access, limits on which tools an agent can use, approval thresholds for sensitive actions and immediate revocation when behavior changes.
Large platforms are already buying identity technology. Discovery alone will be hard to defend as a standalone company. The stronger position is owning the authorization decision itself.
Is data security still interesting after the DSPM boom?
Data security is still very interesting, but the fresh opportunity has moved beyond finding sensitive data in cloud storage.
Cyera shows how much value customers and investors still see in the category. The company recently raised $600 million at a $12 billion valuation, twice its valuation from roughly a year earlier and four times its valuation over an 18-month period. Cyera says it has now shipped more than 100 capabilities across DSPM, DLP, privacy, identity and agentic security.
That expansion tells us more than the valuation does. DSPM started largely around discovering sensitive data, classifying it and showing companies where it was exposed. The leading company in the category is now pushing into identity, behavior, DLP and agent controls because knowing where data sits only solves part of the problem.
AI makes the next question much more valuable: who or what is allowed to use the data?
An AI assistant may have permission to search customer records but no reason to export thousands of them. A coding agent may need access to one repository without needing the company's entire source-code estate. An HR agent may need employee information while being blocked from salary records for some tasks.
The proposed $1 billion Cyera-Oasis deal fits that direction. Data context and identity context are starting to come together because an enterprise needs both before it can decide whether an agent should be allowed to perform an action.
We would avoid another generic DSPM product that mainly produces an inventory of sensitive files. The more attractive opportunity currently sits around data authorization for AI: understanding what data an agent can reach, why it is accessing it, what it intends to do next and whether that use should be allowed.

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity
Is AI coding creating a new AppSec market?
Yes. AI coding is creating a new AppSec market because security now has to intervene while agents are writing and executing software.
Traditional application security assumes a fairly predictable sequence. A developer writes code, commits it, pushes it through CI, runs security checks and eventually deploys it. Coding agents can collapse several of those steps into one session. They can write code, add dependencies, modify configuration files, run terminal commands and interact with cloud environments while pursuing a task.
That creates a new security checkpoint inside the agent workflow itself.
Endor Labs is a good example of where the category is moving. The company raised $93 million while expanding beyond software-composition analysis into broader application and supply-chain security. Its package-firewall approach can stop risky or malicious dependencies before they reach developer environments, which becomes more useful when an agent rather than a human chooses the package.
Semgrep has also pushed its security tooling directly into AI development environments such as Claude Code and Cursor so that vulnerabilities can be caught while code is being generated. Palo Alto Networks' Koi acquisition attacks the problem from the endpoint side by tracking agentic software, plugins and other code that can bypass traditional installation controls.
Software supply-chain security belongs inside this same opportunity. Verizon found third parties involved in 48% of breaches in its latest dataset, while AI coding makes it easier to introduce dependencies at much higher speed. A security product therefore needs to know where a package came from, whether the agent actually needs it, what the package can execute and whether it should be allowed onto the machine.
The most interesting startup here would sit between the coding agent and the development environment. It would understand proposed code, packages, secrets, commands and infrastructure changes before execution.
Another scanner that runs after the code has already been written feels much less interesting.
If you want more recent data on this point, please see our latest cybersecurity market report.
Is exposure management one of the best cybersecurity opportunities now?
Yes. Exposure management has become one of the strongest cybersecurity opportunities because companies are drowning in vulnerabilities while attackers are exploiting them faster.
Verizon's latest DBIR found that vulnerability exploitation accounted for 31% of breaches, making it the leading initial access vector for the first time in the report's 19-year history. Verizon also found that only 26% of critical vulnerabilities in CISA's Known Exploited Vulnerabilities catalog had been fully remediated in the environments it studied, with a median remediation time of 43 days.
A list of 50,000 vulnerabilities is not particularly useful when an attacker can move through an environment in minutes. Security teams need to know which vulnerabilities can actually be reached and exploited, then fix those first.
Horizon3.ai is currently showing what that can look like commercially. The company raised $250 million at a valuation above $2 billion after reporting 120% ARR growth and more than 7,000 customers. Its valuation roughly tripled from the $650 million level reported a little over a year earlier. Horizon3 uses autonomous penetration testing to attack customer environments and prove which weaknesses are exploitable.
Oligo Security provides another angle. It recently raised $60 million, bringing total funding to $140 million, after reporting 300% year-over-year ARR growth. Instead of treating every vulnerable software library as equally dangerous, Oligo watches what code is actually executing and can block exploitation at runtime.
These companies attack the same bottleneck from opposite sides. Horizon3 tries to prove which exposures an attacker can use. Oligo watches which vulnerable code can actually be exploited in production.
The category becomes especially attractive when remediation enters the loop. A system that identifies a real attack path, proposes the fix, applies it safely and then attacks the environment again to verify the result could turn vulnerability management from a backlog into a continuous automated process.
| Company | Recent financing | Useful evidence | What looks attractive |
|---|---|---|---|
| Horizon3.ai | $250M | 120% ARR growth, 7,000+ customers | Autonomous attack validation |
| Oligo Security | $60M | 300% YoY ARR growth | Runtime exploitability and blocking |
| Broader market | Vulnerabilities cause 31% of breaches | Remediation still takes weeks | Automation can remove a real operational bottleneck |

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups
Can an AI SOC startup still beat CrowdStrike and Palo Alto Networks?
An AI SOC startup can still become valuable today, but this is a tougher market than agent security or exposure management because CrowdStrike and Palo Alto Networks already own huge amounts of security data.
The demand is real. Mate Security recently raised $35 million only months after emerging from stealth, bringing its total funding above $50 million. Torq raised $140 million at a $1.2 billion valuation around AI-driven security operations and automation. Other young companies are building autonomous analysts that investigate alerts, collect evidence and respond without waiting for a person to work through every step.
The incumbent numbers show why we are more cautious here. CrowdStrike's Next-Gen SIEM passed $600 million in ARR in its latest reported quarter. Palo Alto Networks' XSIAM had already crossed $500 million in ARR, and more than one-third of XSIAM customers had enabled its AgentiX capabilities by the previous quarter.
Those platforms begin with an advantage that an independent AI analyst cannot easily reproduce: they already have endpoint events, identity data, threat intelligence, cloud telemetry and mechanisms for taking action.
A startup therefore needs to do something more valuable than summarizing alerts or writing investigation notes. The better products can investigate across multiple vendors, query external systems, collect evidence, disable accounts, isolate devices, change configurations and leave an auditable trail of what the agent did.
Cross-platform automation may be the best wedge precisely because most large companies still use security products from several vendors.
We like the AI SOC less than agent security because incumbents are stronger here. We still like autonomous response when the startup can genuinely remove hours of analyst work rather than merely make the existing console easier to use.
Is OT security the best cybersecurity opportunity outside AI?
OT security is probably the strongest large cybersecurity opportunity today that does not depend on the AI-agent boom.
Accenture recently made a very large bet on the category. It agreed to acquire a majority stake in Dragos along with runZero and NetRise in transactions representing about $4.18 billion of enterprise value. Accenture said the three companies were expected to produce roughly $208 million of combined ARR growing around 53% year over year.
Those numbers imply an enterprise-value-to-ARR multiple of roughly 20 times, which is striking for a part of cybersecurity that used to receive far less attention than cloud or endpoint security.
The underlying systems also give startups some protection from easy platform bundling. Factories, utilities, industrial equipment, embedded devices and other operational environments use specialized hardware, old software, proprietary protocols and systems that may stay in production for decades. Security teams often cannot reboot, replace or patch them the same way they would a laptop.
NetRise focuses on firmware and software-component risk. runZero finds assets across complicated networks. Dragos protects industrial environments and investigates OT threats. Accenture bringing those pieces together shows how much work still exists between simply finding an industrial asset and keeping it secure throughout its life.
OT also has a clear downside. Selling to power companies, manufacturers and critical-infrastructure operators usually takes more domain knowledge and patience than selling another SaaS security tool to a technology company.
For a team that understands those customers, that difficulty can become an advantage. Fewer startups can credibly enter the market, while the physical infrastructure cannot be replaced every time the software industry changes direction.
If you want more recent data on this point, please see our latest cybersecurity market report.

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors
Is post-quantum cybersecurity finally worth building in?
Yes. Post-quantum cybersecurity is finally becoming a real enterprise migration market, although it will move more slowly than AI security.
The timing has changed because organizations now have standards and deadlines rather than only a theoretical future threat. The US government has directed high-value federal systems toward post-quantum key-establishment migration by 2030 and digital-signature migration by 2031. Federal procurement rules are also moving toward post-quantum requirements.
Money is arriving behind that transition. Keyfactor recently announced more than $1 billion of strategic growth investment to expand its machine-identity, cryptographic-management and post-quantum business. The company already serves more than 2,500 customers and manages billions of machine identities.
At the startup end, QIZ Security raised a $17 million seed round to build cryptographic discovery and post-quantum migration software. QIZ says it has already worked with more than 100 organizations on quantum-safe readiness.
There is also a useful reality check in recent internet measurements. A study of more than 32,000 domains found that about 49% supported hybrid post-quantum key exchange, while roughly half still relied on classical key exchange. Hybrid post-quantum certificates were essentially absent in the sample. Migration is underway, but it is far from finished.
The startup opportunity sits in crypto-agility. Large companies often do not know every place where an old encryption algorithm, certificate or key-management system is embedded. Replacing those components can affect applications, devices, vendors and infrastructure that have been running for years.
A company that continuously discovers cryptography, maps dependencies, plans migration, automates replacement and proves compliance can solve a problem that will persist for years.
We rank post-quantum below agent security on immediate startup velocity. For durability, it looks much better than many mature security categories.
Which big cybersecurity markets are bad places for a new startup?
Generic endpoint security, SIEM, CNAPP, DSPM discovery, basic API discovery and standalone browser security all look much harder for a new startup today.
Endpoint security has brutal incumbent economics. CrowdStrike now has more than $5.5 billion of ARR and can sell additional security products through the same Falcon sensor and Flex contract. Microsoft already sits inside the enterprise software stack. Palo Alto Networks can connect endpoint protection with network, cloud and security operations.
SIEM is heading in the same direction. CrowdStrike has already built a $600 million-plus Next-Gen SIEM business, while Palo Alto Networks has taken XSIAM past the half-billion-dollar ARR mark. An independent entrant needs a dramatic technical or economic advantage to make customers move their security data again.
Generic CNAPP has also become difficult after Google's acquisition of Wiz and the expansion of Palo Alto Networks and CrowdStrike deeper into cloud security. There will still be new cloud-security companies, but a fresh startup needs a narrower wedge around something changing quickly, such as AI infrastructure, runtime behavior or machine identity.
DSPM discovery faces similar pressure from Cyera, Rubrik, Palo Alto Networks and other platforms. API discovery is being pulled into broader application-security stacks. Browser security has produced excellent outcomes, but CrowdStrike bought Seraphic, Akamai bought LayerX, Palo Alto Networks already owns Talon, and Island has raised enough money to build a major independent company.
Even a good market can be a poor place to start a company. The worst setup is a product that solves a known problem for a buyer who already owns an acceptable version inside a larger platform.
The more attractive categories today appear where customers have gained a new type of asset, identity or workflow that existing platforms were never built to control.

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market
Which parts of cybersecurity are still the most interesting today?
AI agent security, agentic identity, AI-native AppSec and autonomous exposure management are the four cybersecurity markets we would look at first today, with OT security as the strongest opportunity outside AI.
AI agent security comes first. Enterprises are already spending real money, startups are producing nine-figure rounds, and the core problem remains unsettled: how do we control software that can independently use credentials, access data and take actions across many applications?
Agentic identity sits immediately beside it. The opportunity becomes especially strong around authorization, short-lived permissions and revocation rather than another inventory of machine accounts.
AI-native AppSec ranks highly because the development workflow itself is changing. When coding agents can install packages, execute commands and alter infrastructure, the security layer needs to move into the agent session.
Autonomous exposure management also has unusually good evidence behind it. Verizon shows vulnerability exploitation becoming the leading breach entry point, while Horizon3.ai and Oligo are showing strong commercial growth around attack validation and runtime protection. We think automated remediation is the next important step.
Data security for AI remains attractive, especially around deciding what agents can read and transmit. AI SOC automation has real potential but faces much stronger incumbents. Post-quantum migration looks durable but slower. OT security combines strong growth with hard technical problems and remains our favorite non-AI category.
Browser security, generic cloud security, traditional endpoint, SIEM and basic discovery products are much harder entry points now because large platforms have already claimed so much of the customer relationship.
Across the strongest categories, one pattern keeps coming back: security is moving closer to the moment an action happens. The valuable product increasingly decides whether an agent may access a file, whether a coding assistant may install a dependency, whether a vulnerability can really be exploited or whether an automated response should execute.
That is where we think cybersecurity still has the most room.
| Cybersecurity market | Our view today | What still looks open | Biggest problem |
|---|---|---|---|
| AI agent security | Very high | Runtime action control, policy, attribution, kill switches | Incumbents are moving quickly |
| Agentic and non-human identity | Very high | Dynamic authorization, temporary access, revocation | Discovery will become a platform feature |
| AI-native AppSec | Very high | Security inside coding-agent workflows | Existing AppSec vendors can move upstream |
| Autonomous exposure management | Very high | Attack validation, prioritization, automated remediation | Platforms will try to absorb the workflow |
| Data security for AI | High | Control over what agents can access and transmit | DSPM itself is already crowded |
| OT cybersecurity | High | Industrial asset, firmware, runtime and response security | Slower, harder enterprise sales |
| AI SOC automation | Medium-high | Cross-platform investigation and autonomous response | CrowdStrike and Palo Alto own massive telemetry sets |
| Post-quantum security | Medium-high | Crypto discovery, migration and crypto-agility | Adoption will take years |
| Browser security | Medium | New agent-runtime control points | Consolidation is already advanced |
| Generic cloud security / CNAPP | Low | Narrow AI-infrastructure wedges | Major platforms dominate |
| Generic endpoint / SIEM | Low | Major architectural breakthroughs only | Distribution heavily favors incumbents |
If you want more recent data on this point, please see our latest cybersecurity market report.
OUR METHODOLOGY
This analysis asks which parts of cybersecurity still offer meaningful room for a new company today. We compare categories across five main dimensions: how much the underlying security problem is changing, whether enterprise demand is visible, whether startups are showing commercial traction, where strategic buyers are placing capital, and how much incumbent platform power makes entry harder.
We prioritized recent evidence because cybersecurity markets can move quickly when enterprise architecture changes or when a large platform absorbs a once-independent category. The most useful evidence included financing rounds, acquisitions, ARR and customer disclosures, product expansion, platform adoption, threat and breach data, and standards or government migration deadlines.
We did not treat funding as proof of demand. Funding shows where investors are placing conviction, while revenue growth and customer-spend disclosures give stronger evidence that buyers are actually creating budgets. Acquisitions help show where established security companies see strategic value, and threat data helps test whether the underlying problem itself is becoming more important.
Platform adoption was treated as a separate constraint. A category can be large and growing while still being a poor startup market if customers already receive an acceptable version of the product through CrowdStrike, Palo Alto Networks, Microsoft or another incumbent platform.
The categories ranked highest when technical change, enterprise demand, commercial traction and remaining whitespace reinforced one another. We ranked categories lower when demand was real but the distribution advantage of existing platforms was already overwhelming.
We also distinguished between discovery and control. In several areas, including non-human identity, DSPM and agent security, discovery is increasingly likely to become a platform feature. The more defensible startup opportunities tend to sit closer to authorization, runtime enforcement, exploit validation, remediation or another decision that directly changes what a system is allowed to do.
Key sources used for this analysis include: CrowdStrike's Q1 FY2027 financial results, CrowdStrike's Q2 FY2027 results, the 2026 CrowdStrike Global Threat Report, Verizon's 2026 Data Breach Investigations Report, Zenity's $125 million financing announcement, Obsidian Security's Series D announcement, Cyera's $600 million financing announcement, Cyera on the Oasis Security acquisition, Okta on the Permiso Security acquisition agreement, Akamai on the LayerX acquisition, Horizon3.ai's Series E announcement, Torq's Series D announcement, Semgrep on Guardian for AI-generated code, Accenture on the Dragos, runZero and NetRise transactions, Keyfactor's $1 billion-plus strategic investment, NIST's post-quantum cryptography standards page, NCCoE's post-quantum migration project, and QIZ Security's $17 million seed announcement.

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time
Related blog posts
- Who are the top investors in cybersecurity?
Who is the author of this content?
NEW MARKET PITCH TEAM
We track new markets so founders and investors can move fasterWe build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.