Newsletter · · Ashutosh Agarwal
Cyber Broke Away as Record Highs Land the Same Day IBM Cratered - Cybersecurity - Week of July 21, 2026
Cybersecurity for the week of July 21, 2026. Cyber stocks printed record highs on the very day IBM cratered on weak software demand, a mainstream wealth desk called cyber the most durable enterprise spend, and a top cyber VC warned the private market is pricing a story well ahead of numbers while autonomous hacking went from one lab's weapon to a commodity.
Cybersecurity
Week of July 21, 2026: Cyber Broke Away as Record Highs Land the Same Day IBM Cratered
TL;DR
- This was the week the market stopped treating "software" as one thing. On Monday, July 14, IBM plunged after telling shareholders that clients were distracted by "rapidly evolving industry-wide cybersecurity concerns" and were redirecting dollars elsewhere. The same afternoon, cybersecurity stocks printed fresh record highs (CrowdStrike up 10%, Palo Alto up 6%, Fortinet at an all-time high, Okta at a 52-week high) and the broad software index actually closed green. As CNBC's Josh Brown put it on the Halftime Report, the market is "getting smarter" and will now "stop speaking of software monolithically."
- The bull case got a heavyweight endorsement. On CNBC's Fast Money (July 17), Citi Wealth's head of portfolio strategy J.P. Coviello called cybersecurity "the most durable area of enterprise spend that's likely to continue for the next five to ten years," noting it has "already doubled over the past 15 [years] as a percentage of enterprise spend." His preferred way to play it: "the bigger platforms."
- But a top cyber venture investor threw cold water on the froth. On the Resilient Cyber podcast (July 16), Foundation Capital's Sid Trivedi said today's sky-high private valuations are "certainly a market pricing a story well ahead of numbers", which he called "always dangerous games." He walked through this year's giant deals (Palo Alto's $25B CyberArk buy, Alphabet's $32B Wiz close) and the AI-security startups raising at prices "close to the revenue," and warned that the last batch of cyber unicorns from 2021–2022 are now being sold "for a significantly smaller" sum than the capital that went into them.
- The demand catalyst everyone hyped last week, Anthropic's "Mythos" AI hacker, quietly lost its exclusivity. Multiple podcasts this week argued the ability to auto-discover and exploit software flaws is now commoditized: China's models are "just as good, if not better," OpenAI shipped its own version, and a NIST mathematician published a formal proof that you literally cannot "guardrail your way out" of the problem. The takeaway for investors: the threat is real and permanent, but it's no longer one company's magic.
The single biggest thing that happened: cyber officially split off from the software wreck
For most of this year the fear hanging over software has been simple, that AI would let companies build their own tools and stop paying big vendors. That fear had a brutal, public confirmation this week, and it made the cyber divergence impossible to miss.
IBM was the cautionary tale. On the July 14 Halftime Report, the panel dug into why IBM cratered: the CEO's letter to shareholders blamed, in part, clients being "distracted with rapidly evolving industry-wide cybersecurity concerns" and, separately, deals that didn't close because customers were "directing those dollars elsewhere." One host summed up the gut-punch: this was "one of the most pessimistic, pitch-black announcements about software demand that we've heard yet."
And yet cyber ripped to records on the same day. As the host ticked through it: "that means that they were spending in cybersecurity, which is why CrowdStrike... is up 10%, why Palo Alto is up 6%, and why Fortinet's up 3%." Fortinet hit a record high; Okta a 52-week high. The software ETF (IGV) closed green even as IBM blew up, something the panel said would have been impossible two months ago, when "they would have hit all these cyber stocks along with IBM."
Josh Brown made the sharpest point of the week about what this means:
"The market is differentiating. It's getting smarter... I expect the market to stop speaking of software monolithically and to start thinking about the various categories within the software space as their own individual stories, that are differently either benefited or put at a disadvantage due to AI."
He also gave a jaw-dropping reminder of how far CrowdStrike has come. It just did a 4-for-1 stock split; unsplit, "it would be over $800." He recalled buying it "at $350 at a time when people were saying, oh no, AI is basically the death knell of every software company. That narrative turned out to be so incredibly wrong in the case of the cybersecurity stocks." He called it "one of the biggest winners... for the overall S&P 500 of all time."
There was a real second-order idea buried in that segment worth flagging: pricing power is shifting away from legacy software toward whoever customers actually can't live without. Brown argued IBM's missed deals partly reflect companies "pushing back after 15 years of having to say yes to every price increase", pointing at Salesforce and Adobe renewals that used to be automatic ("thank you very much for this golf outing") and no longer are. IBM's slide actually began the prior week on news that Starbucks is "actively looking to cut IBM and Microsoft out of some of the things that they're being paid for." His warning: "I honestly don't think it stops with IBM." Cyber, so far, sits on the winning side of that power shift: its software is the stuff nobody dares rip out.
The bull case, from a mainstream money manager: "the most durable area of enterprise spend"
If Monday was the price action, Friday was the thesis. On CNBC's Fast Money (July 17), Citi Wealth's J.P. Coviello explained why he started buying into cyber "a couple months ago," after the software valuation compression earlier in the year scared people off the whole group.
His reasoning is the cleanest articulation yet of the "agents force more security spend" argument, in plain language:
"When you have agents working alongside humans, you need password authentication. You need broader authentication. You need border control of what agents are able to access with respect to IP within a company. So for us, we see it as the most durable area of enterprise spend that's likely to continue for the next five to ten years. It's already doubled over the past 15 as a percentage of enterprise spend."
His conclusion, "we're very optimistic here for the bigger platforms", matters because it's a wealth-management desk telling high-net-worth clients to buy the megacap security names, not a niche security commentator. That's the "narrative to real money" progression this newsletter has been tracking, continuing.
One useful caveat from the same show, courtesy of Karen Finerman, for anyone tempted to extrapolate the whole market's AI-driven earnings: she noted that of the roughly 28% earnings growth in Q1, "something like 12% of it was Alphabet, Amazon and NVIDIA marking up their portfolios for... their equity stakes in Anthropic and OpenAI." In other words, a chunk of the "AI boom" earnings is accounting gains on private stakes, not operating cash. Good discipline to keep in mind.
The counterweight: a top cyber VC says the private market is "pricing a story well ahead of numbers"
The most valuable hour of the week for investors was on Resilient Cyber (July 16), where host Chris Hughes interviewed Sid Trivedi of Foundation Capital, a firm that's invested for 30+ years and is usually the first or second money into a cyber startup. He was refreshingly blunt about how hot things have gotten, and where the risk sits.
On valuations. Asked directly whether today's prices reflect what customers actually pay, Trivedi didn't hedge: "It's certainly a market pricing a story well ahead of numbers. And I think that those are always dangerous games." He pointed to the "AI SOC" category (software that automates a security operations center) as the poster child, citing three deals: "7AI... raised like the largest Series A on record," "Torq... crossed a billion-dollar valuation," and "ExaForce... raised a massive raise in the same category." His explanation: investors who made fortunes on the blistering zero-to-$100M-ARR pace of AI coding tools are betting the same explosive growth will happen in security, but he thinks cyber is structurally slower because "we are... in an industry that focuses on reducing risk," selling to risk-averse buyers who "want to get all the boxes checked before they go and purchase."
The sobering history lesson. He warned this rhymes with 2021–2022 (the cheap-money "ZIRP era"): "When you look at those unicorns today, three, four years on, you're already seeing several of them being acquired for a significantly smaller... end result than even the amount of capital that went into those companies. Forget about... the valuation." His advice to founders, and the implicit warning to late-stage investors, is that "one of the easiest unfortunate ways to destroy a company is to have a down round," which spooks employees, customers, and existing backers all at once.
The consolidation map. Trivedi laid out the M&A wave better than any banker note. Beyond the two blockbusters (Palo Alto's "$25 billion acquisition of CyberArk, very identity-centric," and "Alphabet finalizing their $32 billion acquisition of Wiz"), he flagged a structural shift he called the biggest change of the past year: the IT buyer and the security buyer are merging, and vendors are crossing the line in both directions:
- ServiceNow bought both Armis and Vesa late last year to push into security.
- Palo Alto bought Chronosphere (observability) after CyberArk, moving into IT infrastructure, in what he called "a very, very heavy year."
- Databricks announced "Lakewatch" and bought Panther (a security data/SIEM player).
- SailPoint (identity) acquired Entro to move further onto the security side.
His framing: buyers increasingly have a joint "CIO + CISO" role, and platforms are chasing that combined wallet. But, importantly for anyone assuming the giants take everything, he insisted best-of-breed "won't die," because cyber has too many niches for a handful of platforms to fully dominate.
What's a moat now that AI can copy your product? This is the question hanging over every software valuation, and his answer was specific. Enduring moats: proprietary data ("the more proprietary data you have that hasn't been released to the foundation model companies, the more value you can attain"), deep workflow context, integration depth into a customer's internal tools, and speed of innovation. Fading moats: slick UI/UX, per Trivedi, "if we look at companies like Wiz, it was all about creative design and UI. I think that is less of a moat today," because models can now generate good design, and because people increasingly talk to "a system of agents" instead of clicking buttons. That's a direct read on why data-rich incumbents (CrowdStrike's telemetry, Palo Alto's platform footprint) may defend margins better than pretty-dashboard challengers.
Programming note for the calendar: this all sets up Black Hat / "Hacker Summer Camp" in Las Vegas in early August, historically a catalyst-dense stretch for product launches and deal chatter. Trivedi (a Black Hat startup judge) and Hughes both flagged it as the next big event to watch.
Meet the new consensus on the threat: Mythos was never magic, and it's already everywhere
Last week's story was that Anthropic's "Mythos", an AI that autonomously finds and exploits software flaws, was the unique, named demand catalyst driving the whole trade. This week, the expert consensus deflated the "unique" part, which is actually more bullish for the sector (permanent demand) and more bearish for any single AI lab's "special sauce."
On the excellent Cybersecurity Today weekend episode (July 18), host David Shipley interviewed a working CISO whose company builds browser-isolation security. Two things stood out:
First, credit where due, with a wink: "Anthropic... created an amazing (we have to give props) the cybersecurity and AI marketing campaign of the year. The Academy Award goes to Anthropic, hands down." But on whether Mythos is actually one-of-a-kind: "There's plenty of other models. There's a gradient of capabilities. Yes, it does look like Mythos was a step up... but we've used other models and they all have some level of these capabilities." China's models are now "just as good, if not better, than Mythos," and "OpenAI came out with their version." The conclusion: autonomous vulnerability discovery "is going to be open source models... this is the new normal."
Second, the guest made the crucial point that finding flaws is only half of it: "it goes beyond finding vulnerabilities. It's actually about being able to leverage these vulnerabilities. Build exploits, chain exploits." The old comfort that a disclosed flaw takes "weeks for people to develop an exploit" no longer holds. He cited ESET researchers who fed a vulnerability's public documentation into an LLM and, "in about 15 minutes... for about a dollar's worth of AI expense... came up with working POC [proof-of-concept] code." He memorably described the whole software estate as needing an "EPA Superfund cleanup", decades of "bad code" that will take decades to harden.
The math backs this up, literally. A recurring theme this week was a formal proof that guardrails can't win. As the Cybersecurity Today daily show (July 17) explained, NIST senior scientist Apostol Vasilev published (in IEEE Security & Privacy) a proof, built on Kurt Gödel's 1931 incompleteness theorems, that "no finite set of AI guardrails can ever be universally robust against adversarial prompts." The practical answer, echoed by the CISO above, is that you can't rely on the AI lab's built-in "soft guardrails"; you need "hard guardrails" (an external framework that controls what an agent is allowed to touch) plus constant red-teaming and the assumption that something will get through.
And now the AI vendors are selling the shovels to break their own tools. The same show detailed OpenAI's new GPT-RED, "an AI whose entire job is to break other AIs", an automated red-teamer aimed at prompt-injection flaws in agentic systems, trained via self-play. Set loose on a real AI-powered vending machine from Andon Labs, it "talked the agent into cutting the price of anything over $100 down to $0.50," bought one at the discount, and canceled another customer's order. OpenAI fed the results back into training GPT-5.6, which it says now "fails six times less often on one of its hardest prompt injection benchmarks." The investment read: AI red-teaming is becoming a product category of its own.
Quantum: the clock got a name, a date, and a product to sell
Quantum kept sharpening from a vague worry into a dated, sellable event.
On CXOTalk (July 17), Palo Alto Networks' EVP of Network Security, Anand Oswald, gave the most product-specific quantum pitch yet, essentially Palo Alto's sales motion. The timeline he laid out: experts like Gartner and McKinsey estimate that "by end of this decade" a quantum computer could break today's encryption; the US government's CNSA 2.0 mandates "started to take effect in 2025"; algorithms like RSA and ECC will be "officially deprecated" by 2030 and "disallowed" by 2035 ("that's a hard stop"). Because a full cryptographic migration "can take between 5 to 10 years", and "a full cryptographic inventory alone can take... over a year", his message was "start now." What Palo Alto is selling into that fear: "14 new models of our next-generation firewall" built for the heavier processing of post-quantum cryptography, plus an "industry-first" tech called Cipher Translation that makes legacy apps "quantum-ready" just by routing their traffic through a Palo Alto firewall. He also flagged the "harvest now, decrypt later" risk: adversaries "already stealing encrypted data today" to crack once quantum arrives.
The timelines were independently corroborated elsewhere. On Macro Musings (July 20), Bitcoin Policy Institute's Sam Lyman cited a March Google paper showing the qubits needed to break Bitcoin's cryptography dropped from a prior estimate of "about 10 million qubits" to "as few as 500,000", but stressed the practical clock is still years out: "Google's own quantum deadline for their technology to become quantum resistant is 2029," and "the US government wants all of its agencies to be quantum resistant by the year 2035." And a primer episode, Science Friction (July 14), walked through the fundamentals: Shor's algorithm, the NIST post-quantum competition launched in 2016 with six winning algorithms selected in 2022, and "$750+ million" in annual US defense spending on quantum. The investment throughline: post-quantum migration is a multi-year, government-mandated refresh cycle, a tailwind for network-security vendors selling the hardware and the "crypto-agility."
The debate
Bull frame: Cyber has structurally decoupled from the rest of software: it's the line item nobody cuts, its pricing power is intact while legacy vendors lose theirs, and AI keeps expanding the attack surface (more agents, more code, more machine identities) while making attacks cheaper and faster. A mainstream wealth desk (Citi's Coviello) is now telling clients it's "the most durable" enterprise spend for 5–10 years and to own "the bigger platforms." Record highs across CrowdStrike, Palo Alto, Fortinet, and Okta say the market agrees.
Bear frame: Two cracks. First, valuation: a top cyber VC says the private market is "pricing a story well ahead of numbers," the AI-SOC darlings are raising far ahead of revenue, and the last unicorn class is being sold below the cash raised, a warning that public multiples this stretched leave no room for error. Second, the moat: if autonomous hacking is now a commodity (China, OpenAI, open-source models all matching Mythos) and a NIST proof says guardrails can never fully hold, then the value accrues to whoever owns proprietary data and deep integration, not necessarily whoever has the flashiest AI story. UI/UX, once a moat, is fading.
Where I land this week: Still constructive on the sector, but the debate has clearly matured from "is cyber the AI trade?" (settled: yes) to "what am I paying, and what actually defends the margin?" The most important new information wasn't another CEO cheerleading: it was a disciplined early-stage investor telling his own founders to take lower valuations, and a working CISO explaining that the scary AI weapon is already everywhere and can't be perfectly fenced. That's a healthier, more durable bull case than last week's hype, but it argues for owning the data-rich platforms (and demanding the numbers back it up) rather than chasing the priciest private stories. The caveats remain: no big platform printed fresh quarterly numbers this week, and the real test is the August earnings season.
Stocks and companies in play
- CrowdStrike (CRWD): The week's clearest winner: up 10% on July 14 to records, fresh off a 4-for-1 split, described by Josh Brown as one of the S&P 500's biggest winners "of all time." Bull: rich proprietary telemetry (a durable moat per the Foundation Capital framework) and single-platform design. Bear: the most expensive name in software, priced for perfection. Watch: August print.
- Palo Alto Networks (PANW): Up 6% to records, and the most active on the news flow: closing the $25B CyberArk identity deal plus a Chronosphere observability move (per Foundation Capital), pushing hard on quantum-readiness (14 new firewall models + "Cipher Translation," per its EVP on CXOTalk), and named as an incident-response partner on the Jaguar Land Rover investigation. Bull: broadest platform for the "consolidate onto a few vendors" thesis. Bear: heavy acquisition spend to digest; watch integration and organic growth.
- Fortinet (FTNT): Hit an all-time high on July 14. Rode the same "cyber decouples from software" wave; no fresh company-specific catalyst this week.
- Okta (OKTA): 52-week high on July 14. Identity is the single most-repeated defensive priority across this week's threat episodes (agents inherit human credentials; least-privilege and just-in-time access are the fix), keeping Okta squarely in the agent-security basket.
- CyberArk (CYBR): Now inside Palo Alto via the $25B deal, its machine/identity franchise is exactly the agent-security turf everyone is chasing, but it's no longer a standalone bet.
- IBM: The negative tell of the week: cratered on soft software demand and lost deals to redirected budgets, with a host warning "it doesn't stop with IBM." A read on where pricing power is not.
- Datadog (DDOG): Cited again on the Halftime Report as a software name "working remarkably well" because of its cloud-infrastructure/observability focus, a reminder that "security-adjacent" infra software is catching some of the same flows.
- Progress Software (PRGS): Flagged on Cybersecurity Headlines (July 17): it urged ShareFile customers to shut down storage-zone controllers over a high-severity path-traversal zero-day (patched; CVE pending). A reputational/liability watch item.
- Private names to know: In AI-SOC: 7AI (largest Series A "on record"), Torq (crossed $1B), ExaForce (large raise), all cited as examples of prices running ahead of revenue. Anthropic valued at a "$300–600 billion" pre-money range and Sierra at "$15 billion" per the SaaStr podcast (July 15), context for how frothy the broader AI-software funding market is.
Read-throughs
- Anthropic (private): Still the epicenter of the demand narrative, but this week the message flipped from "Anthropic has a unique weapon" to "Anthropic ran the best marketing campaign; the capability is now everywhere." For investors, that reduces single-lab dependency risk and reinforces that the sector, not any one model, is the durable beneficiary.
- Identity is the whole ballgame: Across The Audit (July 18) and Business of Tech (July 14), the consistent expert message is that AI hasn't changed the entry point (phishing and over-permissioned credentials are still how attackers get in and move sideways) and that Mythos-style tools now chain together "low and medium" flaws nobody bothered patching. Concretely bullish for identity/least-privilege/just-in-time access (Okta, CyberArk, SailPoint). A telling product datapoint: 1Password launched an "agentic mode" that lets Claude log into services per-session without ever seeing the password: "identity is the new perimeter," now for agents too.
- Healthcare cyber, spend is normalizing into consolidation: On Data Book (July 15), Clearwater president Baxter Lee said the post-2024-breach spending surge is over; cash-strapped hospitals are now doing "tool and vendor consolidation... to get more bang for the buck." Healthcare remains "the most targeted industry for close to a decade," with the "highest average ransom payment of any industry at $1.1 million" last year, and he flagged a shift toward disruption-motivated nation-state attacks (citing a device-wiping attack that "wiped out" 200,000 devices and exfiltrated 50 terabytes). Read-through: budgets favor platform consolidators over point tools, the same theme as the enterprise market.
- Breaches are hitting real revenue lines: Per Cybersecurity Today (July 20): Coca-Cola suspended US production at its Fairlife dairy unit after a ransomware attack (disclosed in an SEC filing), Fairlife crossed $1B in annual retail sales in 2022 and just got a $650M expansion commitment in March. Abbott Laboratories is juggling two unrelated breaches (Shiny Hunters claims 30M+ customer rows via a vishing attack on a Microsoft SSO account). And Microsoft shipped a record 570 Patch Tuesday fixes (with at least two zero-days under active exploitation) while warning that its own AI-driven bug-hunting means "heavier patch loads every month." Rising real-world damage is the demand engine; watch the SEC's push to move companies from quarterly to twice-yearly reporting (200,000+ public comments), which would change how fast these disclosures surface.
- Regulatory clock, mixed signals: The government's CMMC (Cybersecurity Maturity Model Certification) program for defense contractors was delayed again (Cybersecurity Headlines), a near-term headwind for compliance-driven spend among the ~80,000 affected companies, even as the quantum mandate (RSA deprecated 2030, disallowed 2035) creates a hard, dated refresh cycle pulling the other way.
What changed vs last week
Last week the story was that cyber had become Wall Street's favorite AI trade, powered by a single named catalyst (Mythos), a CEO on CNBC (Nikesh Arora), and Cramer ranking cyber the #1 CIO priority. This week the trade did something more durable, it decoupled, and the conversation grew up.
- From "cyber is the trade" to "cyber broke away from software." Last week was narrative and CEO conviction. This week was tape confirmation: cyber printed record highs (CRWD +10%, PANW +6%, FTNT all-time high, OKTA 52-week high) on the exact day IBM cratered on weak software demand, the cleanest proof yet that the market now prices security separately from the rest of software.
- The catalyst got demystified. Last week Mythos was the singular, almost mythical weapon. This week the expert consensus was that it's "a step up" but no longer unique: China matched it, OpenAI shipped its own, and it's heading to open source. More bullish for the sector's permanent demand; more bearish for any bet on one lab's exclusivity.
- A serious valuation warning entered the chat, from the buy side of private cyber. Last week's caution was about extreme public multiples and one startup's brutal unit economics. This week a veteran cyber VC (Foundation Capital's Sid Trivedi) said the private market is "pricing a story well ahead of numbers," named the frothiest deals (7AI, Torq, ExaForce), and reminded everyone that 2021-era unicorns are now selling below the cash they raised. That's a more credible bear signal than a valuation screen.
- The moat question got a concrete answer. New this week: proprietary data + integration depth + speed = durable; UI/UX = fading (even Wiz's famed design is "less of a moat today"). That reframes which incumbents deserve the premium: the data-rich ones.
- Guidance replaced by proof on guardrails. Last week the worry was qualitative ("AI makes attacks cheaper"). This week there's a formal NIST/Gödel proof that guardrails can never be complete, cementing "assume breach, contain the blast, red-team forever" as the permanent operating model, and turning AI red-teaming (OpenAI's GPT-RED) into its own emerging category.
- Quantum went from a warning to a sales motion. Last week it was France's ANSSI procurement deadline. This week Palo Alto put actual products behind it (14 quantum-ready firewalls + Cipher Translation) with hard NIST dates (RSA out by 2030/2035), turning quantum from a slide into a multi-year, mandated refresh cycle.