Companies are handing more of their work to AI. Every one of those AI tools needs access to company systems, and every one of them can be attacked.
Most investors are watching the first story. The second is where cybersecurity comes in.
What’s happening?
First, companies are starting to use AI agents.
An AI agent is software that carries out tasks by itself. It can open files, update customer records, and pass work to other systems without a person approving each step.
To do that, every agent needs access. Bank of America’s analysts pointed out this month that agents create new attack surfaces, new identities to manage, and new governance requirements. Each one adds to the security budget.
The second development is that AI models have started reaching systems they were never meant to touch.
In recent weeks, OpenAI, Anthropic, and Meta have each reported incidents where their AI models broke out of testing environments and attempted to hack other companies.
On Friday, 18 September, Google said its Gemini model had done the same. In May, during a hacking test run by an outside security firm called Irregular, Gemini accessed the systems of three real companies.
The model was never supposed to reach the internet. A bug in the test environment gave it access, and the fictional company it was told to target shared a name with a real one.
In one case, it guessed a password until it got in. In the other two, it used login details it found posted publicly online. It stopped each time once it realised the systems were real.
Not every model has. By Al Jazeera’s account, Anthropic’s Claude kept going after realising it was inside real companies.
None of this took advanced hacking. A guessed password and exposed login details were enough. That’s exactly the kind of gap cybersecurity companies are paid to close.
Attackers are using AI too. Gartner, a research firm that tracks technology spending, lists AI use by both companies and attackers as a key reason security spending keeps growing. As Okta’s chief executive said this month, “The threat actors are not pausing.”
Put these together, and the spending follows. Companies spent $193 billion on security in 2024. Gartner expects about $244 billion in 2026.
And this is where the stock market comes in.
By 18 September, CrowdStrike was up 108.7% for the year and Palo Alto Networks 101.91%.
The earlier incidents led Anthropic’s chief executive to call for the industry to slow the development of the most advanced AI models until they can be made safe. He published that essay on Saturday, 12 September. On the Monday that followed, CrowdStrike closed 13.8% higher at a record.
Why AI makes cybersecurity a bigger business

Think of every AI agent as a new employee who gets a key card on day one.
That card has to be issued, limited to the right doors, watched while it’s in use, and canceled when the job ends. A company that switches on a thousand agents has just handed out a thousand key cards.
Someone has to manage all of them. That’s the job cybersecurity companies are selling.
After all, most of these companies sell subscriptions. When a customer adds more agents, it may need more protection, and the subscription grows with it.
That’s why analysts watch a figure called annual recurring revenue. It’s the yearly value of the subscriptions a company has signed.
The recurring revenue CrowdStrike added was up 51% on a year earlier. Palo Alto’s recurring revenue from its newer security products grew 63%.
So the demand isn’t only a story. It’s showing up in the numbers.
Why this is more complicated than a normal growth story

Here’s the awkward part.
Security spending is forecast to grow about 12% this year. The leading stocks roughly doubled.
When you buy a growth stock, you’re mostly paying for what the company could earn years from now.
A price that doubles while spending grows 12% means investors have already paid for a lot of that future. If the growth arrives on schedule, that may be fine. If it arrives late, the price has room to fall.
And that room is wide. CrowdStrike’s lowest price over the past year was $85.68. Palo Alto’s was $139.57. Both trade far above those levels today.
Interest rates add a second layer.
The Federal Reserve, America’s central bank, sets the benchmark interest rate for the economy. On 16 September, it raised that rate to between 3.75% and 4%, its first increase since 2023. The median Fed official expects another hike this year.
When rates rise, safer investments such as government bonds pay more. That makes investors less willing to pay a high price today for profits that may only arrive years later.
Two days after the Fed’s decision, Bernstein downgraded Palo Alto, Okta, and SentinelOne. It argued that the sector’s roughly 100% gain this year had pushed valuations to or above fair value. CrowdStrike, Palo Alto, Okta, and SentinelOne each fell between 3% and 4% that day.
It’s not necessarily the AI story that’s wrong. It’s the possibility that the price has already run ahead of it.
Two mistakes to avoid
Don’t buy the story instead of the chart
The case for AI security is well documented. That doesn’t make the price right on any given day.
A strong story is exactly when traders loosen their rules. They buy because the reasoning feels solid, and the setup never actually triggered.
Don’t chase every AI headline
AI risk will keep making the news. Some headlines may lift these stocks, and some may knock them down.
A 13.8% jump and a 3% drop in the same week tell you about the mood. Neither tells you the trend.
Sort cybersecurity stocks into three groups

Cybersecurity covers several very different businesses. Before you add any of them to your watchlist, work out which job each one does.
The companies named below are examples to help you sort. They are not recommendations.
Group 1: Device protection
These companies protect the computers and servers where attacks actually land. CrowdStrike and SentinelOne are examples.
CrowdStrike runs threat hunting, AI-powered risk analysis, and automated breach response on one platform.
Check where these names sit in your screener’s relative strength columns. The best-known stock in a group isn’t always the strongest one this month.
Group 2: Identity
These companies decide who is allowed into a system, and increasingly, which AI agent. Okta and SailPoint are examples.
This is the group most directly tied to the key card problem. If your screener keeps surfacing identity names, that tells you where money is flowing inside the theme.
Group 3: Network and cloud
These companies control the traffic moving between people, apps, and cloud systems. Palo Alto Networks, Zscaler, and Fortinet are examples.
Cloud security has been a main driver of the fastest-growing part of security spending. Palo Alto is the broadest of these and still isn’t a pure play, so it may not move in step with the rest.
Compare each stock to a cybersecurity ETF such as CIBR as well as to the S&P 500. If a stock is weaker than its own sector, the theme isn’t carrying it.
Many traders own a cybersecurity stock without knowing which of these jobs it does. That’s often where the confusion starts when the group moves unevenly.
Let the chart make the decision
Here’s the good news: you don’t need a view on AI to trade this theme. Pull up the weekly chart for every cybersecurity stock on your list, and let it answer the question for you.
If the trend is still up, the market hasn’t decided that the valuation worries are serious enough to change it. Momentum still needs to confirm on your own rules before anything happens.
If the weekly trend has broken down, the story stops mattering. At that point, it’s a matter of exiting according to the rules or checking that the stop loss is sitting where it should be.
What if the signal doesn’t work?
Plenty of them won’t, and the system is built for that. A signal isn’t a forecast. It marks a point where the rules say a defined risk is worth taking.
Some of those trades run for months, some stall, and some stop out within a week. What stays the same is the loss you accepted before entering, because that was set by the stop. It doesn’t change according to how convincing the story behind the stock is.
So the useful question isn’t whether the method is right about AI. It’s whether the rules are followed in the cases where it isn’t. Below are two CrowdStrike signals, one that ran and one that didn’t.
CrowdStrike Holdings Inc (Position Weekly)

On CrowdStrike’s weekly chart, the Position Weekly candle flipped from red to blue in early May 2026. In this strategy, the color change is the entry signal.
The High of the flip week was about 132. The system places a buy-stop slightly above that High, so the entry mark was near 132. The stop shown at the flip was around 113.
Price traded through the mark, so a fill would have occurred on strength rather than on a break of support. While the weekly candle remained blue, the position stayed open. That period covers the same stretch of the chart where the larger advance appears.
The example is about process, not prediction. A red-to-blue flip sets the mark; a buy-stop above the flip-week High defines entry; the weekly color governs whether the trade stays open or is exited later.
CrowdStrike Holdings Inc (Position Daily)

This Position Daily example sits inside the larger Position Weekly advance on CrowdStrike, shown in the first chart. It is one of the smaller daily swings within that same overall move, not a separate theme.
On the daily chart, a long was marked around the 190 area in mid-2026. Entry followed the same buy-stop rule: a mark slightly above the signal bar’s High, with a stop set by the system. Price filled near 190. The move did not hold. The exit also came near 190, so the trade finished roughly flat rather than as a large winner.
Even while a weekly trend is intact, not every daily signal produces a sustained advance. Some setups fail or break even. The process still defines where to enter, where to exit, and when the trade is over without rewriting the rules after the fact.
What to watch between now and 01 December
The Fed meeting on 27 and 28 October
The decision lands at 2 a.m. Singapore time on Thursday, 29 October. Another hike could add pressure on growth stocks. A pause could ease it.
CrowdStrike and Palo Alto earnings
CrowdStrike reports on 25 November and Palo Alto on 1 December.
Watch these two even if you don’t own either. Between them, they cover device protection and network and cloud, and the rest of the group tends to move with them.
Their recurring revenue is also where the spending story gets tested. Gartner’s forecast is a forecast. Recurring revenue is money customers have already committed.
Strong growth could support the case that AI spending is reaching these companies. A slowdown could bring the valuation question back.
Neither of them covers identity. If you hold an identity name, check its own reporting date.
The weekly trend of the stocks on your list
Don’t focus only on how far a stock has risen. What matters is whether the trend is still intact.
Sort your stocks. Know which job each one does. Then let the chart tell you when something has genuinely changed.
You don’t need an opinion on the future of AI when your trading rules already tell you what to do.
If this article helped you understand the market, the next step is seeing how to put that knowledge to work.
Watch my 3-step trading process LIVE: find promising stocks, plan when to buy and sell, and decide how much to risk before placing a trade.
It’s the same approach I’ve used to trade systematically and generate monthly returns over the past five years. Click the banner below to learn more.







