AI removes that difficulty. A capable model can now write a competent vulnerability scanner, draft detection rules, or triage alerts at a fraction of the cost of the old approach. Enterprises have noticed. When a company can point a general-purpose AI system at its own codebase to find bugs, the standalone tool that used to own that job is no longer indispensable. The feature did not get worse. It got commoditized.
This is the line I have been repeating to founders for two years: having a great product is no longer a differentiator; it is the default. AI is what finally made that true across the whole market. And it cuts both ways. It strips the easy premium off incumbents whose value was a single strong feature, which is why the markdowns are rational. It also undercuts the AI-native challengers, because the very thing that makes them fundable, the ability to ship a slick product fast, is the thing AI hands to their next ten competitors for free.
So the incumbent selling one feature and the startup selling one clever model are exposed to the same erosion. The difference is that the incumbent is being priced down toward that reality, and the startup is being priced up away from it.
What actually creates durable value in security now
If the product is the default, value migrates to everything around the product. That is not a soft claim. It is where the durable revenue multiples are already clustering.
| Source of advantage |
Moat before AI |
Moat in 2026 |
| Product velocity and features |
Strong |
Weak, now the default |
| Trust and track record |
Strong |
Stronger |
| Distribution and install base |
Strong |
Strong but contestable |
| Switching cost and integration depth |
Moderate |
Strong |
| Proprietary data and telemetry |
Moderate |
Strong |
| Clear position and category ownership |
Underrated |
Decisive |
The public names with premium multiples are the ones with two or more of the bottom rows: proprietary data, deep integration into how security teams already work, and a brand buyers trust enough to standardize on. Publicly traded companies trading at a discount tend to have a good product and little else that is hard to copy. That is the whole story of the multiple gap, and AI is widening it.
For a vendor, this is a positioning problem before it is a product problem. When buyers cannot separate you on features, they separate you on whether they understand what you are for and whether they believe you can be trusted with it. That is exactly what a positioning audit is designed to catch, which is why I pressure-test vendor messaging against the same seven dimensions a CISO uses to decide who makes the shortlist. If you are raising or defending a valuation, a competitor review against the real field, not the field in your deck, is the difference between a number you can hold and a number that unwinds at the next round.
What this means if you are building or funding a security company
The contrarian read is not that AI security is a bad bet. Demand is real, and the market is expanding, as the live funding and category data at mandos.io/data shows. The contrarian read is that current prices reward the wrong thing, and the correction will sort winners by durability rather than novelty. Here is how I would stress-test any position in this market.
- Assume product parity within eighteen months. If your entire pitch is that your model or scanner is better, ask what remains true after three competitors match it. If the answer is nothing, you have a feature, not a company.
- Underwrite the moat, not the demo. For any AI-native name at a 15x multiple, find the row in the table above that justifies it. Proprietary data, distribution, or switching cost. If it is only product velocity, you are paying incumbent-beating prices for the least defensible asset in the market.
- Watch trust, not just growth. In security, the buyer's downside from a bad vendor is asymmetric, so trust compounds and novelty decays. The names that survive the repricing will be the ones a CISO would renew without a bake-off.
- Treat positioning as a financial input. A vendor that cannot explain in one sentence what it is for will get commoditized faster, because buyers default to the option they understand. Clarity is now a valuation lever, which is the argument for taking the way I work with vendors seriously before the next raise, not after it.
The incumbents being marked down and the startups being marked up are answering the same question and getting graded on different curves. AI did not make security products worthless. It made them ordinary. What is scarce now is the trust, distribution, and clarity that AI cannot generate on demand, and that is where both the durable companies and the durable valuations will end up.
Frequently asked questions
Why are cybersecurity company valuations splitting in 2026?
Public security leaders trade at near 7.8 times revenue, while private AI-native startups command roughly 15.2 times revenue. Incumbent premiums are compressing as AI makes their products easier to replicate, while investors bid up AI-native challengers on the expectation of a land grab. The two moves pull the market apart.
Are AI-native security startups overvalued?
Many are priced on product velocity, and that is the one advantage AI erodes fastest. A startup raising at twice the public revenue multiple needs a moat beyond a clever model, because the model itself is becoming a commodity. Some will grow into their valuations through trust and distribution. Most are priced as if the hard part is already done.
Does AI help or hurt cybersecurity incumbents?
Both. AI lets incumbents ship faster on top of large install bases and proprietary data, which is real leverage. It also lets a general model do for near-zero what some point products used to charge for, which strips the premium off any vendor whose value was a single feature. The incumbents with deep integration and trust hold up. The ones selling a feature do not.
What actually creates a moat in cybersecurity now?
Trust, distribution, switching cost, and proprietary data. When a competent product is the default, buyers decide on whether they believe you, whether their peers use you, and how painful you are to remove. Positioning and evidence do more for durable value than another model benchmark.
What should security founders take from the funding surge?
Raising at an AI-native multiple raises the bar you have to clear, it does not lower it. Treat product parity as table stakes and compete on the things AI cannot copy: a sharp position, proof a buyer trusts, and integration that makes you hard to rip out.