Investors often treat cybersecurity as a single sector, but right now the industry is being remade by three linked forces — the economics of ransomware, the growth and retrenchment of cyber insurance, and the arrival o…
The ransomware cycle: demand shocks that ripple through buying
Ransomware assaults create sudden, visible loss events that push organizations into urgent spending. After a severe incident, boards and CISOs rapidly prioritize detection, backup, and response — often accelerating multi-year security roadmaps into near-term purchases. That spike in demand is real, but it's uneven: some enterprises only buy once they've been hit or after a peer has been compromised.
For vendors this means revenue can be lumpy and event-driven. Products that promise quick containment or easy restoration see short-term surges, while longer-term investments in architecture and identity often advance more slowly. When analyzing a security vendor’s topline, look for metrics that show whether growth is pull-forward spending or sustainable net-new business: annual contract value (ACV) growth, renewal rates, and multi-year deals versus one-time professional-services revenue.
Cyber insurance: underwriting today, controls tomorrow
Cyber insurance used to be a way to transfer residual risk. Insurers, hit by rising claim frequency and severity, tightened underwriting: higher premiums, stricter proof-of-controls, and lower coverage for certain threats. That pressure forces companies to implement specific security controls and to document their maturity.
For vendors, cyber insurance has become an interesting channel influence. Security products that provide measurable telemetry and compliance evidence — endpoint detection with audit trails, SIEM/XDR platforms with immutable logs, or managed detection services that offer SLA-backed reporting — can be easier for insured customers to justify. The dynamic shifts some purchasing decisions from ‘nice-to-have’ to ‘required for coverage,’ changing the addressable market for certain types of tools.
AI-based detection: higher efficacy, different costs
AI and ML models are improving detection speed and reducing false positives, which addresses a chronic problem for security teams: alert fatigue. Better signal-to-noise lets smaller teams operate securely and can reduce the need for large, expensive security operations centers (SOCs). That improves the value proposition for vendors offering automated detection and response.
But AI brings new economics. Models require labeled data, ongoing retraining, and significant compute. Vendors delivering cloud-based AI detection face rising infrastructure costs that can pressure gross margins unless they pass costs to customers or differentiate sufficiently to command higher ASPs. Investors should watch metrics like gross margin trends, customer acquisition cost (CAC) payback, and how companies describe model maintenance expenses and data partnerships.
How buying cycles and product models intersect: subscriptions, services, and retention
Security vendors have been moving to subscription and managed-service models for years, which smooths revenue but also raises the bar for retention. With subscription pricing, durable growth comes from net retention (expansions minus churn). The shifts discussed above — insurance-driven buy requirements, ransomware-driven pull-forwards, and AI-enabled efficiency — all affect retention differently.
Expect three patterns: 1) vendors that deliver essential telemetry tied to compliance or insurance requirements can see sticky recurring revenue; 2) vendors that sell tactical, one-off remediation or forensic services may get high short-term revenue but lower retention; 3) companies that successfully package AI detection as a managed outcome (reliable alerting plus response) are best positioned to expand accounts because they replace costly human labor and provide measurable ROI.
What to watch on earnings days and updates
When companies report, focus beyond headline growth. Look for commentary on customer acquisition trends post-major incidents, renewal and net retention rates, changes in average contract duration, and disclosure about model-related infrastructure costs. Management tone on the frequency of RFPs tied to insurance requirements or regulatory inquiries is also telling — it signals whether demand has structural backing or is cyclical.
Also monitor product-mix shifts. Are more customers buying bundled managed detection and response (MDR) or just point tools? Bundles often lift lifetime value but can hide margin pressure if they require heavy human involvement. Clear disclosure on gross margins, professional services as a percent of revenue, and ARR composition will tell you whether growth is scaling profitably.
The Bottom Line
Cybersecurity today is less about standalone software boxes and more about outcomes: demonstrable detection, documented controls, and an ability to reduce operational burden. Ransomware events, tighter cyber insurance, and AI-driven automation are reshaping demand and vendor economics. Read quarterly reports with an eye on retention, product mix, and model-related costs to separate transient spikes from sustainable growth.
Want ideas like this every week?
Join the free Breakout Brief — the setups, sectors and signals we are watching.