Hello Cyber Builders đź––
In Part 1, I went deep on the physical moats: hardware, networks, and cryptography.
The argument there was that these categories survive because they depend on something AI cannot instantly replicate — physical reality, accumulated trust, and mathematical correctness. You can’t prompt your way to a FIPS 140-3 certification. You can’t generate an authentic practitioner community. You can’t guarantee cryptographic correctness with a foundation model.
Today, I want to talk about three more domains where AI cannot copy what you offer, because these are not just about code.
These are a different story from Part 1.
In Part 1, AI is the threat to the moat. Is AI able to replicate the trust you put in hardware, a network effect, or a crypto algorithm? No.
In Part 2, AI is a tool for building. The question is: how do you use AI to build something bigger than just software? Smartly.
What truly sets an AI-native security company apart from an LLM wrapper isn’t the technology—it’s the strategy. The key is understanding what accumulates value over time, what becomes increasingly difficult for competitors to replicate, and what the market can’t simply purchase from another provider using the same AI model.
I like quick, back-of-the-envelope math. It shows if something actually works.
The average enterprise Security Operations Center processes 1000+ distinct security alerts per day. Those alerts come from an average of 30+ fragmented security tools. The average analyst can spend about 40 minutes manually investigating the context and business intent behind a single alert.
Run the numbers. It just doesn’t add up.
This is not an alert problem. It is an architecture problem. The Security Information and Event Management (SIEM) platform — which has served as the centerpiece of enterprise security operations for 20 years — was designed as a database. A very expensive, very powerful database that ingests logs, matches rules, and generates tickets.
If you approach it theoretically, using best practices and practitioner guidance documents, you’ll hear that you need to have a “log tank,” a central place to put all your logs. When the volume was manageable, this worked. The “best practice” was applicable. But when hybrid cloud environments scaled, when machine identities proliferated, when data ingestion volumes reached petabytes — the SIEM initial paradigm collapsed under its own architectural weight and cost structure.
As we said, as we described, as explained: Many security operations are flooded by data, information, and alerts. And where I think AI won’t change the game yet is in transforming this flood of data into meaningful action and decision. This is what Andreessen Horowitz, the VC firm, calls a system of intelligence.
This means you don’t just build software and call it done. You layer in content, data collection, and refinement to make decisions and take action.
In the SOC example, this means using your context—your security graph context—feeding it to the agent or AI you’re using, and then building and taking decisions. Is this a false positive alarm? Something you can discard safely? Or is it something very important you should escalate to your best analyst in the room? That’s a system of intelligence.
All security operations can leverage a System of Intelligence. Take identity: Does this access request look very similar to the hundreds of other access requests we’ve already provided to this user and their team, given their profile? Or is it something very bizarre—because normally, a financial analyst doesn’t get access to the customer database?
So, when you move from just collecting data and building workflows to actually triaging, deciding, and acting, you get a system of intelligence. Here, AI won’t change everything overnight. It can learn what an analyst does, but only if you give it the right context, content, policies, and best practices from your security tool. That’s what leads to real decisions and actions.
On this, I’m not alone. Anton Chuvakin—former Gartner analyst, Google security leader, and now Head of Product Management at Cisco Security—wrote a very interesting blog post recently. He said that your SIEM won’t be “vibe-coded” soon, and other products won’t be “vibe-die” soon because they’re mostly code and policy that the customer already owns. The policy is already commoditized.
But in many other segments, that context is not yet easy to reconcile. There is no one central threat graph publicly available. And that’s not something a company can build by itself.
For example, CTI takes people: a threat research team. It takes data collection from the dark web, from customer networks, from the intelligence community. It takes a lot of effort. Then you can use your best AI on top of it.
Today, AI itself can’t replicate this. All things are going to change—we don’t know. We’ve seen that over the last two years, the best AI labs have moved from very interesting language models to AI capable of aggregating large amounts of knowledge. And in the weights of these AI models, all those best practices are already integrated. They don’t need extra context to analyze code and find vulnerabilities in source code.
But security is more than that. We’ll see if this changes or improves over time.
Here is the standard venture capital taxonomy of security companies.
Software: high margins, scales with customers not headcount, recurring revenue, multiple on ARR. The dream.
Services: lower margins, scales with headcount, project-based revenue, multiple on EBITDA. The compromise.
Every cybersecurity investor wants to back software. Every experienced security practitioner knows that services firms are still doing some of the most important security work — because it requires expert judgment that hasn’t scaled until now.
AI changes the economics and creates a third category. It’s not software. It’s not classic services. It’s AI-native expert delivery. Now, five people with the right AI stack can do what used to take fifty—and still own the results.
AI is not replacing the second category because you’re adopting it at the core of your operation.
If you look at the security market—and here, you see the graph from Omdia, one of the growing analysts in the space—you’ll see that security is mostly 66% service and 33% product. Why? Because corporate security teams, mid-markets, IT teams, and SMBs don’t really know how to secure themselves.
Resources are scarce, and skills are hard to aggregate and maintain because it’s an ever-moving field. So most people go to service partners to stay at the top of security knowledge and access the resources they need—because it’s very hard to hire.
They’re also delegating managed services when they need 24/7 teams all over the globe to respond to incidents and alerts.
AI is shaking up this service market. I’d bet many will overhaul their services in the next five years. For customers, it’s a must-have, but it’s often hard to see the real value.
MSSPs are already engaged in a down-to-the-bottom price war because it’s hard for them to prove the value of the service they deliver. Paradoxically, they provide more value when the customer is under attack, and they can say, “Well, we are blocking things, etc.” than when nothing is happening. But when they deliver this, they’re losing money because they’re investing more and more resources in the case. And when nothing happens, they look for logs, create incidents and alerts, and that’s okay.
AI could be a real game-changer here. It can help scale and democratize services. You can do things you couldn’t before. You can personalize your service for each customer, not just send generic EDR alerts or GRC reports. You can deliver real context—business units, verticals, VIPs—whatever matters to the customer. That’s how you avoid being just another commodity and actually make money by scaling your service.
Second, you can do much more. If you’re running a SOC, you’re probably just doing alert management and log analysis. Very few SOCs offer personalized services, such as VIP monitoring or threat hunting for industry-specific threats. Using AI, you can do these kinds of things because you can automate and scale very advanced practices that you’re not able to do today—because they would consume too many people, and the value of your service wouldn’t be able to be charged back to the customer.
So, AI-native security services are how you use AI without getting commoditized by it in the next five years.
Cybersecurity Platforms!
A cybersecurity platform isn’t just a single piece of software or a collection of tools—it’s an integrated foundation that brings together diverse security functions, data, and workflows within a single ecosystem. Platforms unify detection, response, and management, making them more than the sum of their parts. Rather than solving a single problem, a platform is designed to address a broad set of security needs, allowing organizations to standardize how they defend against, monitor, and adapt to threats across their environments.
Platforms become powerful because they create network effects: new capabilities, integrations, or data sources make the whole system more valuable over time. This is why many of the most influential cybersecurity companies have evolved into platforms rather than just point solutions.
For a deeper dive into the 12 cybersecurity platforms that matter right now, check out my article: The 12 Cybersecurity Platforms That Actually Matter.
So would we live forever with these 12 cybersecurity platforms? For sure, not.
Every major technology shift creates a new security frontier.
Cloud created cloud security. SaaS created SSPM. Kubernetes created container security. Mobile created mobile security. Each time, the companies that got there first didn’t just build the product — they wrote the threat model, defined the vocabulary, and established the mental frame that the rest of the market adopted. That first-mover advantage is nearly impossible to dislodge even when incumbents copy the features.
That’s Cybersecurity is never static, because the threats themselves are constantly changing. Attackers adapt quickly, leveraging new vulnerabilities and sophisticated techniques to bypass traditional defenses.
Take AI by itself. It is opening up several new security frontiers at once. “AI Security” is about mastering the model’s security and explainability. But this is also about monitoring the “AI Agents” behaviors, identities, and access rights. It is also responding to a new class of AI-driven cyberattacks in which malicious actors develop their own “black hat” agents.
For Cyber Builders, what is the most important?
I would answer: To “own” the problem. To become a thought leader. To tell the story better than the other.
Eventually, build a technology that embraces the complexity of that new world. There are 100+ industrial protocols. There are 100+ agentic frameworks. There are thousands of new threat vectors and actors.
So, to build something new, one way is to pick a new domain and build a very specific visibility layer and detection rules for it. Ultimately, the right product (and platform!) doesn’t just defend against today’s risks—it lays the groundwork for securing whatever challenges tomorrow may bring.
That’s six categories across two posts: hardware, networks, and cryptography in Part 1; systems of intelligence, AI-native services, and frontier security today.
In Part 1, the moat holds because AI can’t reach it. In Part 2, AI is part of how you build it — but only if you understand what you’re actually accumulating, not just which model you’re calling.
If you’re building in one of these three categories — or if you see something I’ve missed — I’d like to hear from you.
Laurent đź’š
