Quick Summary. Cybersecurity is moving from a network-perimeter defense into an identity-first, AI-native, regulation-driven build-out. The global market grows at a high-single-to-double-digit rate toward roughly $350B by 2030, while India grows about twice as fast from a base that is still only 2.5 to 3.7% of global spend. The fastest-growing pockets are the least penetrated: AI security, cloud, identity and OT/critical infrastructure. The pure-play leaders in those niches are being acquired by a handful of platform consolidators, so public-market exposure is concentrating. In India, the listed pure-play universe is small, and none of the exposed companies reports cybersecurity as a separate revenue line.
Something strange is happening in a market everyone calls crowded. The fastest-growing corners of cybersecurity have almost no public companies left to buy. The vendors that defined the two hottest niches are exiting, one after another, into the arms of a few platform giants and industrial majors. Wiz goes to Google for $32 billion. Protect AI folds into Palo Alto. Claroty, Nozomi and Dragos, the leaders in industrial security, are bought by Rockwell, Mitsubishi Electric and Accenture. The more the opportunity grows, the fewer direct ways a public-market investor has to own it.
That is the central tension of this cycle, and it is worth sitting with. Cybersecurity is not one industry. It is a spreading attack surface, a compliance stack, an AI arms race and a consolidation story all at once. The question underneath it is simple: where is the spending actually going, and which companies are positioned to capture it?
The demand side is not a projection; it is a running meter. Ransomware damage reached $33 billion in 2024. Attacks on organizations rose 56% year over year to an average of 1,300 per week. Manufacturing intrusions were flagged as up roughly 400%. Ransomware victims rose 58% year over year in 2025 even as average payments fell, which tells you the attackers shifted from squeezing each victim to attacking far more of them.
What changed is not the volume alone, it is the speed. Attackers now chain reconnaissance, credential testing, lateral movement and exfiltration autonomously, with no human in the loop. Because an agent processes external content in real time, it can be compromised and exfiltrate data within a single task cycle, with no lateral-movement phase left to detect. The defense window compresses from days to minutes. That is why the same industry's own polling finds 48% of security professionals call agentic AI, not deepfakes, the top attack vector for 2026.
AI has industrialised the offense on both ends. Roughly 42% of 2025 attacks already leveraged AI or machine learning, and AI-crafted spear-phishing reportedly hit 96% open rates. The first AI-powered ransomware strains are self-modifying. And the social layer is fracturing: deepfakes are becoming the tool of choice to target "big fish," with voice cloning the fastest-growing social-engineering vector. Every one of these widens the surface faster than budgets move.
This is the rare IT category that keeps growing even in soft spending years, roughly 8% year over year. The reason is structural: the budget lever has moved from the IT line item to the boardroom and the regulator.
Cybersecurity now claims 12 to 13.2% of global IT budgets, up from 8.6% in 2020. Compliance has become a CISO-level, board-level obligation. The EU alone has layered five major digital regulations since 2016, GDPR, DORA, NIS2, the AI Act and the Cyber Resilience Act, with overlapping duties. A single AI system in critical infrastructure now falls under both the AI Act's security requirements and NIS2 and DORA cryptographic controls. India's DPDP Act and 2025 rules add consent, purpose limitation and breach reporting, with a defined implementation window in FY2026-27, alongside CERT-In's mandatory six-hour breach reporting. Cyber insurance has become a forcing function too: underwriters now demand proof of OT segmentation and posture, and organizations without it face coverage denials or exclusions. Each of these converts a discretionary decision into a required one.
The market is large and maturing, but the fastest growth is concentrated in the smallest, newest categories. Lay the segments side by side and the picture is unmistakable. The pattern that matters is the inversion: the biggest and most established category, network security, is the slowest, while the newest and smallest, AI security, is the fastest. The spending is flowing up the stack, away from the firewall and toward the identity, cloud and AI layers. It is also flowing toward consolidation, with roughly 88% of security professionals preferring unified, AI-native platforms over the "83 tools from 29 vendors" most estates currently run.
| Segment | Growth signal | Where it sits |
|---|---|---|
| AI security | Agentic AI in cyber $2.86B to $63.29B, 36.4% CAGR; AI usage control +73% next year; deepfake detection 19.3% CAGR | Smallest base, highest growth |
| Cloud security | Roughly +27% year over year; cloud now ~68% of revenue | Largest structural tailwind |
| Identity (IAM) | Cloud IAM 18.8 to 19.5% CAGR; identity verification 15.4% | Largest category, now the "battleground" |
| OT / critical infrastructure | 16.5% CAGR, $17.9B to $38.5B; telecom fastest CIP vertical | Underpenetrated, state-backed target |
| Managed security / SOC | Services +10.1% CAGR, fastest offering | Talent-shortage-driven outsourcing |
| Next-gen SIEM | Fastest solution type | Displacing legacy log storage |
| Network security | ~36 to 40% of market | Largest but slowest legacy base |
AI security is the purest expression of the new phase, because here the security product and the attack surface are the same thing. The four layers stack up: securing the model pipeline itself, controlling what an AI agent can touch, detecting deepfakes, and running AI-powered defense.
The fastest slice is agent usage control, forecast to grow 73% next year, the highest of any security segment, because compromised AI agents are being called the most consequential unsecured enterprise asset of 2026. The sub-segment economics within AI defense are revealing: AI-powered SIEM holds the largest share (31.4%) but grows slowest (13.1%), while deepfake detection holds the smallest share (8.2%) yet grows fastest (19.3%). In other words, the market is already pricing the mature AI-security slices as ordinary and the detection slices as explosive.
The defense side pays off measurably. Organizations using AI in security operations contained breaches 108 days faster and saved roughly $2.22 million more than those that did not. That return is why the platform vendors keep buying the AI-security point players rather than building them: Protect AI into Palo Alto, Wiz's AI application protection into Google, IBM's agentic "Autonomous Security" and its AI-gateway acquisition. The irony of the fastest-growing category is that it is almost entirely private or being consolidated, so its upside accrues to the platform consolidators, not to a stand-alone public AI-security vendor.
The center of gravity of security is moving out to identity and up to the cloud at the same time. The castle-and-moat model, protect the network edge, is being replaced by Zero Trust, where every request, human or machine, is verified. Passkeys are hitting a 2026 inflection as the default phishing-resistant method, rendering SMS OTP and phishable MFA progressively obsolete.
Yet identity is also the most contested category, because the same AI that powers governance is erasing the trust signals identity relies on. Deepfakes make the identity verification problem harder exactly as it becomes more important. That is why identity is simultaneously the largest category and the scene of the biggest consolidation: Palo Alto is spending $25 billion on CyberArk to buy the privileged-access leg it lacked, and Wiz, Okta, Microsoft and Google are all fighting for the same layer.
Cloud security is the volume play within this. Roughly 68% of security revenue is now cloud-delivered, and multi-cloud estates create workloads that need protection. It is hyper-competitive, Prisma against Falcon Cloud against Wiz, but it is also the category the platform consolidators monetise most directly.
Industrial security has matured from a niche into a recognised, procurement-driven category, marked by Gartner's first Magic Quadrant for CPS protection platforms in early 2025. The scale is now real: OT security at $30.9 billion in 2026, ICS security growing at a 16.5% CAGR, and critical-infrastructure protection heading toward $206 billion by 2031. Power is the single largest vertical, telecom the fastest-growing.
The strategic reason is that ransomware has evolved from financial nuisance into state-backed hybrid warfare. State-aligned actors increasingly leverage criminal groups to obscure attribution, and an Iranian-affiliated APT has been disrupting PLCs across US critical-infrastructure sectors. CERT-In, NERC CIP and the insurance denials all push the same direction. Within this, the highest-margin recurring leg is managed OT services, because the talent shortage makes outsourcing the path of least resistance, the same logic that drives SOC/MDR outsourcing everywhere.
Here again the leaders are leaving the public market: Claroty to Rockwell, Nozomi to Mitsubishi Electric, Dragos to Accenture. Category leadership in OT is scarce enough that the industrial and platform majors are paying up to own it.
The listed leaderboard has already voted on this. The market pays a large premium for platform vendors executing the consolidation theme and a deep discount for point products and legacy. The spread is stark: CrowdStrike at roughly 30 times revenue, against Check Point at 6.6 times, Tenable at 3.2 times and Rapid7 at 1.9 times.
| Company | Growth / recurring | Margin & cash | Moat | Valuation signal |
|---|---|---|---|---|
| CrowdStrike | ARR $5.25B, +24%; Q1 FY27 revenue +26% | ~81% non-GAAP subscription gross margin; 34 to 38% FCF model | Endpoint king, then cloud, then next-gen SIEM | ~30x revenue; forward P/E ~147 to 176 |
| Palo Alto | NGS ARR $8.1B, +60%; RPO $18.4B, +36% | ~29% non-GAAP op margin guide | Largest pure-play; buying the missing identity and AI legs | ~$270 to 305B; forward P/E ~160 |
| Fortinet | Billings +31 to 33%; FY26 guide ~$7.7 to 7.9B | ~49% FCF margin; $1.01B Q1 FCF | ASIC cost-performance moat | ~54x forward P/E, the value anchor |
| Zscaler | +25% growth at record margins; RPO $6.1B | Record margins while growing 25% | SASE / Zero Trust category founder | ~$26 to 27B; GAAP-unprofitable |
| SentinelOne | ARR $1.12B, +22% | Crossed into non-GAAP profit, 6% op, 9% net | Endpoint challenger; Purple AI agent | ~$6.9B, smallest base |
The differentiator between likely long-term winners and the rest is durable recurring revenue at scale with enough platform breadth to cross-sell into the AI, identity and cloud waves, plus the unit economics to self-fund. CrowdStrike's 34 to 38% free-cash-flow model and Fortinet's roughly 49% FCF margin are the buffers that let them invest through the agentic-AI and identity transitions instead of choosing between growth and profit. The Check Point and Rapid7 discount is the market pricing the opposite, revenue tied to point products and legacy refreshes.
The risk is symmetrical. Forward P/Es of 150 to 160 on the leaders embed very high expectations, and any growth deceleration compresses them sharply. This is a market that has already re-rated the consolidation thesis, so the easy multiple expansion is likely behind the largest names.
India is the classic fast-growth, low-penetration story. It grows at roughly twice the global rate, around 18% CAGR against 9 to 13%, yet holds only 2.5 to 3.7% of global spend. India's end-user info-security spend is about $3.44 billion in CY2026, growing 11.7% year over year, projected to reach $15 billion by 2031. The gap to close is visible in the allocation: Indian BFSI, the most-targeted sector, spends only about 9% of its IT budget on security against a 12 to 13% global norm, and on-premise controls still claim about 54% of Indian spend versus a cloud-dominant global market.
The demand engines are unusually dense. UPI processes more than 20 billion transactions a month, and fraud reached ₹22,931 crore in 2025, with one in five UPI users reporting fraud. CERT-In handled 29.44 lakh incidents in 2025. The DPDP and CERT-In compliance window in FY2026-27 is the single biggest catalyst, and it is deployable spend: companies have already built compliance stacks and delivered XDR deployments tied directly to it.
Talent is the binding constraint and the hidden growth story. India holds roughly 300,000 cyber professionals, about 5% of the global workforce, but has around 39,000 positions unfilled, with attrition near 19% against industry growth of 9 to 10%. That is precisely why managed security services and outsourced SOCs thrive, and why the GCC engine matters: India's 1,700-plus GCCs have seen cybersecurity GCCs double from about 30 to 59 in six years, and a quarter of them now host half of the global cyber workforce. India is simultaneously the world's talent pool and short of it, which is the cleanest possible tailwind for managed services.
The single fact that frames every Indian name is that no listed company reports cybersecurity as a separate revenue line. Not the pure-plays in full, and not the IT-services or defence majors, which embed security inside broader portfolios. Every multiple below prices the whole business, and the cyber share is unquantified. So exposure has to be read by how strong the disclosed security franchise is, and how it sits in the value chain.
India's pure-plays are, without exception, small. The four with published market capitalisations, eMudhra, Quick Heal, Allied Digital and DC Infotech, together come to roughly ₹5,900 crore. That is the whole of the listed pure-play universe, and it splits into three very different kinds of franchise: product platforms with a real moat, a turnaround in progress, and distribution and services where security is the engine but is not carved out.
eMudhra is the closest thing India has to a product moat. Its Enterprise Solutions segment, built on five proprietary platforms (PKI, identity and access, certificate lifecycle management, e-signature and privacy), now contributes 65% of revenue and grew about 50% in Q1 FY27. It is the only Indian certificate authority with WebTrust recognition trusted by the major browsers, a genuine barrier for a compliance-driven trust business. The DPDP Act is the near-term lever: eMudhra has launched a privacy platform for consent management and data discovery and says it is in pilot with customers. It is also engineering post-quantum readiness across its stack and earns 66% of revenue from international markets, with a European acquisition cross-selling into Germany, Austria and Switzerland. The market prices this at about 35 times earnings and 4.5 times book, the richest multiple in the pure-play set, because it is the only defensible regulated identity franchise. The caveat is that free cash flow is negative, and growth of roughly 30% is being funded by heavy capital spending.
Quick Heal is the pure-play turnaround. The endpoint vendor that Indian consumers grew up with has crossed 50% of revenue from enterprise in FY26, up from about 40% a year earlier, and the shift shows in the reported numbers: FY26 revenue fell 6.8% to ₹261 crore, with negative EBITDA of ₹29 crore and a loss of ₹11 crore, as a shrinking consumer base masked a growing enterprise one. The forward indicators are the interesting part: the order book jumped to ₹55 crore from ₹6 crore, deferred revenue doubled to ₹34 crore, and a ₹64.25 crore government order plus a 51% enterprise mix point to the direction of travel. Management targets 80 to 90% enterprise contribution within two to three years, and the company is debt-free with about ₹249 crore of cash. It trades at about 1.8 times book with no earnings multiple, because it is priced on a turnaround, not on reported profit.
DC Infotech shows what a pure-play distributor looks like when security is the core. Its enterprise security segment is the company's highest-margin line, contributing about a quarter of FY26 revenue and carrying double-digit EBITDA margins against a low-single-digit company average. The security arm scales on specialised certifications, notably a Zscaler cloud-security specialisation, and on government work, including a ₹33.46 crore National Informatics Centre order for DDoS protection on the national knowledge network. The whole company grew revenue 32.6% to ₹737 crore in FY26 with profit up 45.8%, yet it trades at about 20 times earnings and 0.6 times sales, the price of a modest-margin distributor rather than a security franchise. The open question is whether a distribution margin can ever support a security-software multiple.
Allied Digital is security embedded inside services, not disclosed. It does not carve out cybersecurity revenue, but its Services segment, the bucket that includes managed security, cloud and digital engineering, grew 21% in FY26 to ₹746 crore and 30% in Q1 FY27 to ₹215 crore. Management flags cybersecurity as a high-growth priority, and the contract evidence, OT security for a vaccine manufacturer, ISO 27001 audits and SOC assessments, confirms growing deal flow, but the cyber component cannot be isolated. At about 17 times earnings and 0.9 times book, it is priced as a modest IT-services company, with the security story untold in the numbers.
| Pure-play | Market cap | Cyber exposure | Growth signal | Valuation |
|---|---|---|---|---|
| eMudhra | ₹4,057 Cr | Product moat: PKI/trust, DPDP | +29.7% TTM; 39.2% 3-yr CAGR | 35.3x P/E, 4.5x book |
| Quick Heal | ₹800 Cr | Endpoint/EDR, Seqrite | Revenue -6.6% FY26; order book ₹55 Cr | No P/E (loss-making); 1.8x book |
| Allied Digital | ₹567 Cr | Managed security inside Services | +19.2% TTM; 14.3% 3-yr CAGR | 17.2x P/E, 0.9x book |
| DC Infotech | ₹446 Cr | Security distribution (Zscaler, DDoS) | +29.2% TTM; 27.8% 3-yr CAGR | 20.5x P/E, 0.6x sales |
The pure-play cluster is where the "what would have to happen" question gets concrete, because the exposure types are genuinely different, and so is the path to economic meaningfulness:
The honest caveat is the same for all of them: because none discloses the cyber share, a cheap multiple could equally be pricing a small, lumpy cyber business inside a modest base, not a hidden gem. That is the risk asymmetry that defines this universe. The common thread across the pure-plays and the cheaper services and distribution names with disclosed, growing security lines, eMudhra, DC Infotech, Allied Digital, Aurionpro, Dynacons and Tanla, trading at roughly 12 to 35 times earnings, is that the cyber franchise is at least visible in the numbers, even if the cyber line is not carved out. The conventional hidden-beneficiary profile, real cyber exposure the market is not yet pricing, sits in that disclosed cluster.
Pull the whole map together and three structural conclusions follow.
First, the spending is flowing to the convergence, not the point. The categories that are both growing fastest and most underpenetrated, AI security, OT/critical infrastructure, identity and cloud, are precisely the ones being consolidated into platform vendors and industrial majors. The public-market way to own the fastest growth is increasingly the consolidators themselves, which is exactly why the market has already paid them up to 30 times revenue and 150 to 160 times forward earnings. The pure-play premium is gone because the pure-plays are gone.
Second, India is the underappreciated geography in a specific sense. It grows twice as fast as the global market and has a defined regulatory catalyst in FY2026-27, but it is still only 2.5 to 3.7% of global spend with an on-prem-heavy, talent-starved base. The opportunity is real, but the disclosure is the constraint: no Indian company reports a cyber revenue line, so none of the exposure can be verified from filings.
Third, the next major opportunity is likely the least glamorous one. Globally it is the managed, AI-native security operations layer, where the talent shortage forces outsourcing and where services already claim about 40% of spend. In India that logic is even stronger: with 39,000 unfilled roles, 19% attrition and a doubling cyber-GCC base, the outsourced SOC and MDR model is the path of least resistance, the "next major outsourcing revolution" several managements describe. It is lower-margin than software, which is why the market discounts it, but it is where the volume and the recurring revenue live.
Keep the two questions separate. Where the growth actually is, and what the market is already charging for the privilege of owning it. The categories to watch are the ones being consolidated into platforms, AI security, OT, identity, cloud, because each acquisition removes another public pure-play. In India, watch whether the DPDP and CERT-In compliance window in FY2026-27 converts into deployable, reported revenue, and whether any company finally breaks out a cyber line. That single disclosure, if it ever appears, would be the cleanest way to separate the real franchises from the narratives.
Why is cybersecurity spending growing even in soft IT years?
Because it is no longer discretionary. The budget lever has moved from the IT line item to the boardroom and the regulator. Compliance obligations such as GDPR, DORA, NIS2, the AI Act and the Cyber Resilience Act in the EU, and India's DPDP Act and CERT-In breach reporting, convert what used to be a choice into a requirement. Cybersecurity now claims 12 to 13.2% of global IT budgets, up from 8.6% in 2020.
Which cybersecurity segments are growing fastest?
The fastest growth is in the smallest, newest categories. AI security leads at a 36.4% CAGR, followed by cloud security at roughly 27% year over year, identity and access management at 18.8 to 19.5%, and OT/critical infrastructure at 16.5%. The largest and most established category, network security, is the slowest-growing. The spending is flowing up the stack, away from the firewall toward identity, cloud and AI.
Why are there so few public pure-play cybersecurity companies left?
Because the leaders of the hottest niches are being acquired. Wiz goes to Google for $32 billion, Protect AI folds into Palo Alto, and the industrial-security leaders Claroty, Nozomi and Dragos are bought by Rockwell, Mitsubishi Electric and Accenture. The fastest growth keeps consolidating into platform vendors and industrial majors, so public exposure concentrates into fewer companies.
How does India compare to the global cybersecurity market?
India grows at roughly twice the global rate, around 18% CAGR against 9 to 13%, but holds only 2.5 to 3.7% of global spend. Its end-user info-security spend is about $3.44 billion in CY2026, growing 11.7% year over year. It is underpenetrated on adoption, on-premise-heavy, and short on talent, with around 39,000 unfilled cyber roles.
Which Indian listed companies have cybersecurity exposure?
No Indian listed company reports cybersecurity as a separate revenue line, so exposure must be read from the disclosed security franchise. Names range from the pure-plays, Quick Heal, eMudhra, Allied Digital and DC Infotech, to smaller distribution and services names like Aurionpro, Dynacons and Tanla that carry disclosed cyber lines at 12 to 21 times earnings.
Why are some Indian cybersecurity names expensive and others cheap?
The Indian pure-play and services set splits by the visibility of the disclosed security franchise. The product franchises like eMudhra carry the richest multiple in the set, around 35 times earnings, while distribution and services names with disclosed, growing cyber lines, DC Infotech, Allied Digital, Aurionpro, Dynacons and Tanla, trade at 12 to 21 times earnings. The cheaper cluster is where real but unquantified cyber exposure could sit.
Global market sizing and growth figures are drawn from external industry research and company disclosures, and ranges vary by research house and scope; they are indicative, not audited. Global company figures reflect differing fiscal-year ends and are from public sources. Indian company valuations and financials are from listed-company data as of September 2026. Because no Indian company reports cybersecurity as a separate revenue line, the multiples shown price the whole business and the cyber share is unquantified. None of this is investment advice.
This is historical/descriptive analysis, not investment advice.