Hello Cyber Builders đ
Last month I wrote about the buy-versus-build question.
Building security tools is cheaper than ever. With AI coding agents, open APIs, and cloud-native platforms, a single skilled engineer can do the work of an entire team. The gap between buying and building has nearly vanished.
But that advantage goes both ways.
If itâs cheaper to build, itâs also easier to copy. The moat you built with code, APIs, or a polished product gets smaller every month.
So the real question isnât âwhat can we build?â
AI will help you build almost anything.
The real question is what you can build that stays hard to copy, even when everyone has the same AI.
Iâve mapped out six categories where defensibility still matters. Iâll dive into each one over the next few weeks. Before I do, I want your feedback on the list.
Hereâs the map.
AI generates code in seconds. It doesnât generate atoms!
A physical product takes up space. It gets installed, worn, certified, and integrated into real environments. Once itâs in a data center, hospital, or factory, replacing it means procurement, deployment, testing, and sometimes regulatory approval. No prompt will change that.
I used to sell hardware as CTO of a network security appliance company. The SaaS crowd thought it was boring. Someone once called me a sheet metal seller. But hardware sticks once customers have it. They see it, touch it, and get used to it, even if most of their time is in the admin UI.
In cybersecurity, this means hardware security modules, secure edge devices, trusted execution environments, and embedded security chips. The moat is not just the design. It is the manufacturing relationships, certification history, field reliability, and trust built through real deployments.
Hardware moats come from real-world iteration. They are hard to fake.
You can copy a productâs features. You canât copy its community.
A network gets more valuable as more people join, and harder to leave. In cybersecurity, think trusted threat intelligence sharing, practitioner communities, security marketplaces, or the reputation infrastructure vendors rely on.
I am one of the early investors at Crowdsec. The company sells a high-value signal: which IP is malicious. Their secret sauce is remarkable: they have built a network of hundreds of thousands of participants, who share who tried to âconnectâ (and failed) in the last hours. Using that network, Crowdsec detects malicious activities 7 to 60 days before any other Threat Intelligence company.
Network effects are great, but there is also a more subtle moat: attention. If practitioners spend their time on one platform, they are not spending it anywhere else. Here is the counterintuitive part. As AI makes content abundant and synthetic, real networks become harder to find. When anyone can generate a threat report in seconds, the trusted people who verify and curate become more valuable, not less.
Cryptography is almost uniquely resistant to AI commoditization.
âAlmost correctâ is catastrophic. A small implementation flaw in a zero-knowledge proof, a mistake in a post-quantum scheme, an error in a secure computation protocol â these donât produce a slightly worse product. They break the security model entirely.
That penalty creates a real barrier. You need mathematical depth, implementation expertise, formal verification, and external audits. AI can explain the theory and generate code. But it cannot guarantee correctness, which is the only thing that matters.
As AI agents spread, demand for cryptographic tools will grow: proof-of-humanhood, verifiable credentials, post-quantum infrastructure, privacy-preserving analytics. Companies that can build these reliably will have one of the strongest technical moats in technology.
The hardest thing to build isnât an agent. Itâs a trustworthy one. A set of agents that drive decisions, not just store information or prioritize it.
Connecting an LLM to tools is easy. Building a platform that works reliably in a complex enterprise environment with governance, auditability, domain expertise, compliance, and deep integration is not.
In cybersecurity, this means agents that scale threat investigation, automate remediation with clear constraints, drive detection engineering, or run incident response playbooks.
The moat is not the model. It is the context. It is the structured knowledge, curated workflows, governance layer, and institutional memory built from real deployments.
Anyone can demo an agent. Few can deploy one that works safely at 3 am without human supervision.
Some industries have been service-heavy because the work required expert judgment.
AI changes the economics. Tasks that used to take days of junior effort can now be done in hours, with experts supervising, validating, and handling the parts that need judgment.
This creates a new kind of company. It is not pure software and not traditional services. It is AI-native expert service delivery.
In cybersecurity, this means MDR built from scratch, AI-powered red teaming, and compliance operations at much larger scale. The moat is the mix of automation and accountability. The buyer does not care if a human, an agent, or a hybrid team did the work. They want the job done, with someone responsible for the result.
Every major technology shift creates a new security frontier.
Cloud created cloud security. SaaS created SSPM. Kubernetes created container security. AI is creating AI security, but that is not the only new frontier.
Autonomous agents, synthetic identity, post-quantum infrastructure, machine-to-machine commerce, digital biology, cyber-physical systems: each of these creates new threat models that donât yet have answers.
The companies that get there first do not just build the product. They define the category. They write the language. The early threat model they publish becomes the industry reference point. That is a moat that is almost impossible to remove.
Across all six, AI makes features into commodities. It does not commoditize trust, physical reality, networks, deep expertise, regulatory credibility, or operational execution.
The most defensible businesses in 2026 will own something AI cannot instantly copy, even when every competitor has the same models.
In the coming weeks, I will go in depth on each of these. This is not a VC thesis. It is the builderâs view: what to build, where the technical substance is, and what the moat looks like from the inside.
If you are building in one of these areas, or not at all đ, or think I am wrong about what belongs on the list, I would like to hear from you.
Laurent đ