Are cybersecurity stocks being "wrongly punished" by AI? Morgan Stanley sees a $220 billion opportunity
The narrative of AI impacting the cybersecurity sector is now being re-examined.
In the past few weeks, Anthropic launched Claude Code Security and announced that the Mythos AI model achieved a perfect score on its proprietary cybersecurity benchmark test, causing market panic over AI's potential disruption of the cybersecurity industry. Related stocks saw cumulative declines of around 25%.
However, Morgan Stanley stated in its latest report that this sell-off reflects a structural misjudgment of the threat posed by AI, rather than a real deterioration of fundamentals. Investors have underestimated the expansion of defensive demand driven by AI, while overestimating its disruptive impact on existing vendors. The incremental security opportunities brought by AI could reach $220 billion, multiple times more than the ~10% market share facing disruption risks, and the net size of the cybersecurity software market is expected to be about 10% higher than today.
Sector Decline of About 25%: Overestimated Fears
This round of sell-off was triggered by a series of announcements from AI-native companies. According to MarketWatch, Anthropic released Claude Code Security and the Mythos AI model achieved full marks in its proprietary cybersecurity benchmark, prompting concerns among investors that AI would severely erode the value of traditional cybersecurity solutions, triggering large-scale position reductions.
Morgan Stanley noted that some AI-native companies have begun establishing pre-release model cooperation with selected cybersecurity vendors, with Palo Alto Networks and CrowdStrike involved, aiming to build security "guardrails" together before models are officially rolled out. This move itself demonstrates that AI vendors view cybersecurity as a prerequisite for model scaling, rather than as a substitute.
Regarding disputes within the sector, Morgan Stanley indicated that long-term investors are generally optimistic, believing that AI reduces attack costs and increases attack frequency and complexity, which will continuously strengthen security budgets from the demand side. Hedge funds, however, are more pessimistic, questioning the long-term ability of traditional vendors to withstand competition from AI-native challengers.
Morgan Stanley believes that the current debate closely mirrors the historic narrative during the early days of cloud migration, such as "cloud vendors will replace the security industry." Ultimately, these worries were proven to be overblown.
$220 Billion in Incremental Opportunity Far Exceeds Disruptive Loss
Morgan Stanley estimates that the current cybersecurity market size is about $300 billion (including services), representing 6% to 7% of total IT budgets.
Disruption risk is mainly concentrated at the "preventive security" layer—tasks such as vulnerability management, application security testing, and cloud configuration management, which can be performed asynchronously and tolerate higher latency, making them relatively easy for AI models to enter. This segment covers about 10% of the overall market.
Meanwhile, incremental security demand driven by AI is rapidly taking shape. As enterprises deploy AI models, agents, and data pipelines at scale, protecting these new assets will generate considerable additional budgets. Morgan Stanley estimates that this new demand is enough to offset market loss, with the net size of the cybersecurity software market expanding about 10% compared to today.
Data from the attack side further reinforces the logic of demand: Currently, 80% to 90% of attacks are AI-generated, with attack costs approaching zero. This has not weakened the rationale for security spending; instead, it fundamentally strengthens the need for real-time detection, response, and identity security capabilities.
The Most Robust Defensive Barriers
Morgan Stanley divides the cybersecurity market into three tiers: preventive security, control point/boundary security, and runtime security. It emphasizes that the disruptive power of AI is highly unevenly distributed among these layers.
Runtime security is difficult to disrupt because, once AI models enter production environments, threats such as prompt injection, data leaks, and model abuse must be detected and handled in real time—they cannot be preemptively eliminated during development and training. Both control point and runtime security require low latency and deterministic response, which fundamentally conflicts with today’s probabilistic AI models. CrowdStrike, Palo Alto Networks, Okta, and SailPoint are leveraging this to extend their expertise in endpoint, network, and identity security to the AI layer, building dynamic execution "guardrails" around real-time AI systems.
The logic of cost is also significant. Morgan Stanley points out that using large language models to process high-frequency security tasks like email filtering or identity verification may incur computation costs several orders of magnitude higher than existing solutions.
Currently, email security and identity platforms are typically priced at single-digit dollars per user per month, handling hundreds of thousands or more events, resulting in a marginal cost of less than one cent per event. Running AI models based on tokens at equivalent scale would introduce significantly higher computing expenditures. Morgan Stanley believes that in the near term, AI is more likely to play an "enhancement" role in cost-sensitive, low-latency scenarios, rather than fully replacing existing architectures.
Non-Human Identity Becomes the Next Core Battleground
The rise of AI is elevating the strategic importance of identity security. With rapid growth in APIs, machine identities, and autonomous agents—so-called "Non-Human Identity" (NHI)—traditional user-centric identity management frameworks struggle to address new risks.
Morgan Stanley notes that AI-driven systems often operate with elevated privileges and can access sensitive data across distributed environments, dramatically expanding the attack surface for credential abuse, privilege escalation, and unintended access paths.
Identity security is evolving from simple "authentication" to real-time execution controls encompassing continuous verification, fine-grained access control, and full lifecycle management. As AI agents autonomously execute database queries, trigger workflows, and interact with external systems, identity becomes the primary mechanism for enforcing trust boundaries and policy controls.
TD Cowen analyst Shaul Eyal also points out that every AI platform requires credentials for each agent, and Okta plus SailPoint remain the only pure-play publicly listed identity security providers, thus possessing scarce value.
Platform Integration and Flexible Pricing as Core Barriers
Morgan Stanley believes that top cybersecurity companies in the AI era should possess three core attributes: a clear roadmap for agent security and rapid AI product release capability; a flexible consumption-based pricing framework (such as CrowdStrike’s Falcon Flex), lowering friction for clients deploying new capabilities; and an overall value proposition grounded in runtime execution, proprietary data advantages, and cost efficiency.
From a budget perspective, Morgan Stanley expects funds to shift from fragmented, point solutions towards integrated platforms. In the long run, continuous expansion of attack surfaces will make cybersecurity the most defensive priority in IT spending for enterprises—CIO surveys from Morgan Stanley indicate that cybersecurity software is the least likely IT project category to be cut.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
NEAR Loses Critical $5 Level After Brutal $20M Long Squeeze: More Pain Ahead?
If US Treasury yields continue to rise, what will Washington do next?
The Treasury has maintained liquidity by increasing the issuance of short-term Treasury bills and conducting small-scale buybacks. Some advocate for reducing expenditures to address the debt burden. Political constraints tilt the risk toward inflation, which harms bondholders' interests. Karen Brettell, Reuters, October 5 - The cost of borrowing for the U.S. government is rising, while it has almost exhausted straightforward ways to control those costs. Long-term Treasury yields are now near their highest levels in two decades, and the causes don't appear to be temporary. Washington is issuing large amounts of government debt to cover a fiscal deficit that shows no signs of shrinking. Inflation is cooling only slowly. Moreover, while the real estate and automotive sectors are struggling, the artificial intelligence investment boom is keeping the economy robust enough to prevent interest rates from falling. As a result, with over $40 trillion in debt, annual interest payments alone amount to around $1 trillion. Washington has options, from relying more on short-term borrowing to, in the most extreme case, having the Federal Reserve cap long-term yields. The more policymakers resort to such measures, the higher the risk of fueling inflation, potentially causing more pain for bondholders in the future. Torsten Slok, Chief Economist at Apollo Global Management, noted that for every $5 the government collects in taxes, $1 goes to service the debt. "That's a very, very high number, and it's only going to grow." U.S. President Donald Trump said in a September 28 interview with Time magazine that debt can be repaid through economic growth or inflation. But if these methods fail, the Treasury has other options ranging from moderate to radical. At present, the Treasury is increasingly relying on issuing short-term bills and conducting small-scale buybacks of old debt to help boost market liquidity. In a worse scenario, the next step would require Fed intervention. One method is large-scale purchases of long-term bonds, akin to 1961's "Operation Twist", another is directly capping long-term yields—a measure not used by the U.S. since World War II. The more aggressive the measures, the more they can suppress rates, but also the greater the risk of spurring inflation. “We are getting to a point where it's clear the government is uncomfortable with current rate levels," said Jeffrey Gundlach, CEO of DoubleLine Capital, at a recent investment event. Operation Twist Historically, the next escalation would likely be a full-scale reactivation of "Operation Twist." Launched in 1961, this strategy involved selling short-term Treasuries and purchasing long-term ones to flatten the yield curve. Implementing a substantial twist would require the Fed's assistance, but the Fed may stand pat unless there is an obvious financial emergency. Slok said that without the Fed's balance sheet, the Treasury has very limited tools for lowering rates. However, Fed Chair Kevin Warsh has criticized holding large amounts of government debt and other securities, arguing that massive bond buying blurs the line between monetary policy and government debt management. He has called for a new agreement between the Treasury and the Fed, under which the Fed Chair and Treasury Secretary would communicate publicly about the Fed's balance sheet and the Treasury’s debt issuance plans. Yield Curve Control If Operation Twist–style purchases don't work, the next move would be explicit yield curve control. In this scenario, the central bank commits to buying an unlimited amount of government debt to keep long-term rates under a set cap. From 1942 until the 1951 Treasury-Fed Accord, the Fed capped long-term Treasury yields at 2.5% to help fund WWII and the postwar recovery. The Bank of Japan implemented a version of this policy from 2016 to 2024. By artificially lowering rates, yield curve control can ease the political pressure of fiscal deficits. But it only works as long as investors aren't worried about being repaid with dollars devalued by inflation. Once that confidence is shaken, bond-buying meant to suppress rates only fuels the inflation it's designed to conceal. Veronique de Rugy, Senior Research Fellow at the Mercatus Center at George Mason University, said that ultimately, the only way to solve the debt problem is by cutting expenditures. “Congress needs to implement fiscal consolidation—in other words, austerity. The Fed cannot do this alone.” Divergent Paths John Higgins, Chief Economic Advisor at Capital Economics, notes that since World War II, the U.S. has only significantly reduced its debt-to-GDP ratio twice, but bondholders' experiences differed substantially each time. After the war, the debt-to-GDP ratio fell from about 106% in 1946 to 23% in 1974, while the 10-year Treasury yield climbed from 2.2% to 7.5%. In the 1990s, the ratio declined from 48% to 32%, and yields fell as well. What made the difference? After WWII, restr
