Cybersecurity stocks surge as AI fear reshapes the market

The AI story took a sharp turn this week. Instead of focusing only on productivity, chip demand and the next wave of AI infrastructure, investors started asking a different question: what happens when increasingly powerful AI systems become a bigger security risk?

That shift helped push major cybersecurity stocks higher, even as some of the biggest names in AI infrastructure faced pressure.

A strong week for cybersecurity

Cybersecurity stocks had a standout week as concerns around AI safety and autonomous systems created fresh interest in companies that protect enterprise networks, identities and data.

According to the source material:

  • CrowdStrike gained about 15% from Monday through the week
  • SailPoint also gained about 15%
  • Palo Alto Networks rose about 10%
  • Okta added about 9%
  • The First Trust Nasdaq Cybersecurity ETF gained about 5%

The gains came despite a pullback on Friday, showing just how quickly investor attention moved toward cybersecurity during the week.

The move was not simply about one company’s earnings report or a new product launch. It was closely connected to the broader conversation around AI risks, autonomous agents and the growing attack surface created by AI adoption.

AI’s next problem: security

The biggest change in the market narrative was the growing recognition that AI can create risks as quickly as it creates opportunities.

Anthropic CEO Dario Amodei called for greater caution around the pace of AI development, arguing that risk prevention needs time to keep up with advances in model capabilities.

OpenAI CEO Sam Altman subsequently expressed agreement with the need for caution and added his own warnings about the potential consequences of increasingly powerful AI systems.

Salesforce CEO Marc Benioff also weighed in, arguing that the technology industry needs to take the AI safety moment seriously and avoid repeating some of the problems associated with social media.

These warnings helped change the conversation for investors.

The question was no longer simply:

How much economic value can AI create?

It became:

How much security spending will be required as AI becomes embedded across businesses?

Why cybersecurity companies could benefit

The logic behind the market move is relatively straightforward.

As businesses deploy more AI systems, they also have to protect:

  • Corporate identities
  • Sensitive data
  • Cloud infrastructure
  • AI agents
  • Enterprise applications
  • Networks and endpoints
  • Access permissions
  • Automated workflows

The expansion of AI agents makes this particularly important.

Traditional chatbots generally respond to prompts. More advanced agentic AI systems can perform multi-step tasks, interact with databases and access different enterprise systems.

That creates more potential points of exposure.

For cybersecurity companies, that could translate into increased demand for tools that monitor identities, detect threats and protect networks.

Okta CEO Todd McKinnon highlighted this issue directly, saying that threat actors are also using AI and are not slowing down. His argument is that companies have to keep track of an increasingly complicated identity environment as more work moves through AI systems.

CrowdStrike sits at the centre of the debate

CrowdStrike has become one of the most closely watched names in the AI cybersecurity discussion.

The company has been expanding its platform while positioning cybersecurity as an important part of the AI era.

Its recent numbers show why investors are paying attention.

According to the material provided:

  • Annual recurring revenue grew 25%
  • Net new ARR grew 55% in the fiscal second quarter
  • Net new ARR reached a record $333 million
  • Next-generation SIEM ending ARR increased 60% to $695 million

At the same time, the numbers also show why expectations are becoming important.

The company guided net new ARR to between $343 million and $347 million, representing growth of roughly 29% to 31%. That would be slower than the 55% growth recorded in the previous quarter.

That creates a key question for investors: can CrowdStrike continue delivering growth quickly enough to justify the expectations built into its valuation?

Palo Alto Networks has a different setup

Palo Alto Networks also benefited from the cybersecurity rally.

The company was reported to be up around 10% for the week, while its Next-Generation Security ARR growth was cited at 63%.

Its broader platform strategy gives it exposure across several parts of enterprise security, while the growth of AI creates additional demand for protecting cloud environments, networks and applications.

The source material also highlights a significant difference in valuation between CrowdStrike and Palo Alto Networks.

CrowdStrike was cited at a forward P/E of roughly 192x, compared with around 90x for Palo Alto Networks.

That does not determine what either stock will do next, but it does show that investors are assigning very different valuations to the two businesses.

The bigger market rotation

The cybersecurity rally also fits into a broader shift in technology markets.

Investors had spent much of the AI boom concentrating on:

chips → data centres → hyperscalers → AI infrastructure

This week, part of that attention moved toward:

security → identity → networks → AI risk protection

That does not necessarily mean investors have abandoned AI hardware or infrastructure.

Instead, the week’s moves suggest that investors are beginning to think about the second-order effects of AI adoption.

If companies deploy more AI, they may also need to spend more on securing those systems.

That creates a different investment narrative around the technology cycle.

The autonomous AI challenge

One of the most important themes is the rise of autonomous AI agents.

AI agents are designed to do more than answer questions. They can potentially interact with enterprise systems, retrieve information, execute workflows and make decisions across multiple steps.

That creates efficiency opportunities, but it also increases the number of systems that need to be secured.

A compromised AI agent could potentially have access to far more information and systems than a traditional application.

That makes identity management and access controls increasingly important.

The source material specifically points to CrowdStrike’s Falcon ecosystem, Palo Alto’s platform strategy and Zscaler’s zero-trust approach as examples of cybersecurity platforms positioned around this changing environment.

But the rally comes with expectations

The week’s gains also raise an important distinction.

A cybersecurity stock can rise because its long-term business opportunity is improving. But that does not automatically mean the stock price will continue rising.

When expectations become very high, companies have to keep delivering strong growth.

CrowdStrike’s valuation is one example of that tension.

The material cites the company trading above the consensus analyst price target, while Palo Alto Networks was described as trading below its consensus target at the time of the article.

These figures can change quickly with stock prices and analyst updates, so they should be viewed as a snapshot rather than a permanent valuation difference.

What investors will be watching next

The AI security narrative is likely to face a more important test when companies report their actual business results.

For CrowdStrike, the next earnings report was identified as a key validation point.

For Palo Alto Networks, investors will also be watching whether strong security demand translates into sustained revenue and ARR growth.

The important question is whether this week’s rally represents:

  • A temporary rotation into cybersecurity
  • A longer-term reassessment of AI-related security spending
  • Or a combination of both

The answer will depend less on headlines and more on what companies report in bookings, ARR, revenue growth and customer spending.

The bigger takeaway

This week’s market action highlights an important shift in how investors are thinking about AI.

The AI story is no longer only about who builds the most powerful models or sells the most chips.

It is increasingly about the infrastructure required to make AI usable at scale, including security, identity, access control and risk management.

That creates a new layer in the AI investment story.

The companies building AI systems may capture one part of the spending cycle.

The companies protecting those systems could capture another.

For cybersecurity investors, the opportunity is closely tied to whether AI adoption creates a sustained increase in security requirements.

For the broader technology market, the week’s moves show that AI risk itself is becoming an investable theme.