Cybersecurity’s Consolidation Era Has Arrived and AI Is Accelerating It
Artificial intelligence (AI) is poised to create one of the largest identity-management challenges enterprises have ever faced. For decades, cybersecurity programs were designed primarily around human users, with employees receiving credentials that determined what systems, applications, and data they could access.
But as companies deploy an increasingly large number of AI agents, they must manage a rapidly expanding universe of non-human identities, creating new security challenges. That shift could make identity security one of the most important areas of cybersecurity, and thus one of the most lucrative investment opportunities this decade.
To subscribe to the MalcolmOnMoney newsletter and receive more content like this, click here.
At the same time, the industry's largest vendors are racing to build comprehensive security platforms capable of protecting every layer of the technology stack. Palo Alto Networks, CrowdStrike, and Zscaler have spent years expanding beyond the products that originally made them successful, while many smaller cybersecurity firms remain focused on one or two specialized categories, potentially making them attractive acquisition targets as the industry continues to consolidate around a smaller number of platforms.
As AI changes the way human employees and agents interact with computer systems, the gap between product company and platform will become even more pronounced. At the same time, many cybersecurity companies that lack the scale to become dominant platforms on their own may become increasingly more valuable acquisition targets.
That does not mean that these smaller companies offer inferior technologies or have weaker businesses. It simply means that some companies that have spent years developing one of the best solutions in a particular category may be incredibly valuable to a larger competitor that would likely have to spend years developing a comparable product otherwise.
The challenge for smaller cybersecurity companies is that large corporations tend to want fewer vendors that can offer more solutions under one roof. From the perspective of the chief information security officer (CISO) or whoever manages the tech stack with respect to security, managing dozens of individual cybersecurity solutions means negotiating several contracts, integrating multiple systems, and monitoring incoming information from various sources. Thus, there is a growing incentive for CISOs to consolidate more of their cybersecurity spending with fewer vendors capable of protecting several parts of the technology stack simultaneously.
Okta, for example, has spent years building one of the industry's leading identity-security franchises. And while the company has expanded beyond its original offerings, identity remains the core of its business. By contrast, CrowdStrike has used a “land and expand” strategy to move well beyond its endpoint offering and now supplies its customers with dozens of modules they can tack on to their existing subscription—all within their flagship Falcon platform.
Sometimes that evolution means developing a new product internally. Other times, buying an existing company with proven technology and an established customer base is the faster route. And lately, the industry's largest players have demonstrated a willingness to write some very large checks to do exactly that.
Perhaps the clearest evidence of this trend is in Palo Alto Networks’ acquisition of CyberArk in February 2026. CyberArk built its reputation around identity security, particularly privileged access management which helps companies control who can access their most sensitive systems and information. Rather than spending years attempting to recreate those capabilities internally, Palo Alto agreed to acquire the company for approximately $25 billion.
The significance of this particular deal goes beyond simply adding another product to Palo Alto’s offering. With identity fast becoming one of the most important pieces of the cybersecurity puzzle, the emergence of AI agents could make CyberArk and its core competency considerably more valuable over time.
The acquisition of CyberArk also makes Okta one of the largest publicly traded identity-security companies. Its products have long helped enterprises manage employee access through processes like single sign-on, multifactor authentication, and identity governance. But the rise of AI agents could make those capabilities considerably more important.
Prior to the advent of agents powered by AI, corporate identity-security programs were almost entirely designed around humans in that an employee received credentials—a username and password—that determined which applications, databases, and files they were allowed to access. But as companies deploy more AI agents to perform work on behalf of employees, they will have to manage an entirely new classification of digital identities.
An agent might access a customer database, retrieve confidential information, update a record, communicate with another application, or initiate a transaction without requiring a human to approve each step. In order to do so, the agent needs permission, meaning it effectively needs an identity of its own. And as the number of those identities grows, so does the importance of controlling when and what they can access.
This could make Okta increasingly more valuable to a larger cybersecurity platform looking to strengthen its identity capabilities. Ironically, the company’s singular focus on identity—rather than operating a broader platform like Palo Alto or CrowdStrike—may be precisely what makes it attractive as an acquisition target. But the challenge is price. With Okta valued around $30 billion, an acquisition premium could push the cost toward $40 billion, putting it beyond the reach of all but a relatively small group of potential buyers.
Okta is unlikely to be the last company to find itself in this position. As Palo Alto, CrowdStrike, and Zscaler—not to mention the larger hyperscalers—race to build more comprehensive security platforms, there are still plenty of gaps they can fill by acquiring a company that already specializes in a particular area.
The next phase of growth across cybersecurity will likely be defined just as much by consolidation as innovation. The largest platforms will continue looking for ways to become broader, while many of the best product companies could soon become valuable acquisition targets.
For investors, this means some of the most interesting opportunities in the market may not necessarily be the companies capable of becoming the next Palo Alto Networks, Zscaler, or CrowdStrike. They may, rather, offer solutions valuable enough that one of those platforms eventually decides it would rather buy than build.
*************************
Malcolm Ethridge is the Managing Partner at Capital Area Planning Group, based in Washington, D.C. His areas of expertise include retirement planning, investment portfolio development, tax planning, insurance, equity compensation and other executive benefits.
To subscribe to the MalcolmOnMoney newsletter and receive more content like this, click here.
Disclosures:
The information provided is for educational and informational purposes only, does not constitute investment advice, and should not be relied upon as such. Be sure to consult with your tax and legal advisors before taking any action that could have tax and legal consequences.
Investments in securities and insurance products are:
NOT FDIC-INSURED | NOT BANK-GUARANTEED | MAY LOSE VALUE