Cybersecurity can be a real growth industry and still be a bad investment if a company has weak economics, fading customer expansion, or a stock price that already assumes perfection. The better way to analyze the sector is to stop treating “cybersecurity” as a single theme and start evaluating each company like a business: what it sells, how recurring the revenue is, how sticky the customers are, and whether growth is turning into durable cash generation.
NIST’s zero trust guidance helps explain why demand keeps shifting toward identity, cloud, endpoint, and access controls as organizations rely more on remote users and cloud-based assets. But that industry tailwind alone does not tell you which stocks deserve capital. (csrc.nist.gov)

Start with the company’s economic model, not the theme
The first question is simple: what kind of cyber company is this? Endpoint protection, identity, cloud security, network appliances, and security analytics all sit under the same broad label, but they can behave very differently. CrowdStrike’s model is heavily subscription-based SaaS, with subscription revenue recognized over contract terms that are generally one to three years. Fortinet, by contrast, still combines a large product business with an even larger service stream tied to subscriptions and support; in its 2025 annual report, Fortinet reported $2.22 billion in product revenue, $4.58 billion in service revenue, and an 80.5% total gross margin. Those are not small accounting details. They shape renewal visibility, sales cycles, and how resilient revenue may be in a slowdown. (sec.gov; sec.gov)
That is why a quick read of the revenue model matters more than breach headlines or product demos. A company that depends on multi-year subscriptions and cross-sells may deserve a very different valuation from one that needs periodic hardware refreshes or larger one-off deals to hit the same top-line growth. Neither model is automatically better, but they should not be priced as if they carry the same quality of revenue. (sec.gov)

A useful first-pass review only needs three checks
- Read the revenue note before you read the story. Ask how the company gets paid: ratable subscriptions, support contracts, appliance sales, professional services, or a mix. CrowdStrike says most subscription contracts are one to three years and mostly non-cancelable; Fortinet separately reports product and service revenue, which makes it easier to see how much of the business is recurring. (sec.gov)
- Check customer expansion and contract visibility together. ARR tells you the size of the installed recurring base. Remaining performance obligations and deferred revenue help show how much signed business is still waiting to be recognized. CrowdStrike reported ARR of about $5.25 billion and remaining performance obligations of about $9.0 billion as of January 31, 2026. Okta reported a dollar-based net retention rate of 106% as of January 31, 2026, which indicates existing customers still expanded spend, but not at the hyper-growth pace investors once paid peak multiples for. (sec.gov; sec.gov)
- Read margins alongside the growth rate, then finish with the risk factors. Fast revenue growth is less impressive if gross margin is deteriorating, sales expense keeps climbing faster than revenue, or cash flow depends mainly on advance billings rather than improving operating discipline. Then review management discussion and risk factors for reliance on one flagship product, channel-heavy distribution, acquisition dependence, customer concentration, or pricing pressure. The most useful risks are the ones that directly explain the trends you already saw in revenue, retention, and margins.

What separates durable cyber businesses from good stories
In cybersecurity, the strongest businesses usually show a pattern: customers stay, customers buy more, and the company can add new modules without wrecking margins. That is why retention matters so much. A vendor can land a customer once with strong marketing, but long-term value comes from becoming embedded in the customer’s stack. Okta’s filing explicitly ties part of its revenue growth to increased revenue from existing customers, while CrowdStrike’s ARR and remaining performance obligations show how a growing installed base can translate into future revenue visibility. (sec.gov)
There is also an important nuance here: the newest cloud-native name is not automatically the better investment. Mature vendors can look less exciting, yet their installed base, support renewals, and broader operating margins may make them sturdier businesses. Fortinet’s 2025 results are a good example of why investors should not dismiss a mixed hardware-and-services model out of hand; service revenue was the larger piece of the business, and gross margin remained above 80%. Sometimes the market rewards the cleaner story. Sometimes the stronger economics belong to the less fashionable model. (sec.gov)
A better company is not automatically a better stock. After the quality screen, compare valuation against growth, retention, margins, dilution, and debt. Paying a premium multiple for a cyber company with slowing expansion can still produce weak returns.
Compare two names like an owner, not a theme trader
A simple hypothetical makes the point. Imagine two cybersecurity companies both growing revenue 25%. Company A gets most of that growth from recurring subscriptions, keeps net retention above 100%, and holds margins steady as customers add products. Company B also grows 25%, but needs more one-time product deals, shows weaker renewal visibility, and keeps issuing stock heavily to maintain the sales engine. Those are not equally attractive businesses, even if the headline growth rate is identical.
The best cybersecurity investments usually combine four traits: a mission-critical product category, recurring revenue, evidence that existing customers expand over time, and management discipline that turns growth into durable economics. If a company only offers the first two, it may still be a real business, but not necessarily a great stock. Before buying any cyber name, spend 20 minutes in the latest annual report and make the company prove those four points.
References
- NIST SP 800-207: Zero Trust Architecture – https://csrc.nist.gov/pubs/sp/800/207/final
- CrowdStrike Holdings, Inc. Annual Report on Form 10-K for the fiscal year ended January 31, 2026 – https://www.sec.gov/Archives/edgar/data/1535527/000153552726000010/crwd-20260131.htm
- Okta, Inc. Annual Report on Form 10-K for the fiscal year ended January 31, 2026 – https://www.sec.gov/Archives/edgar/data/1660134/000166013426000020/okta-20260131.htm
- Fortinet, Inc. Annual Report on Form 10-K for the fiscal year ended December 31, 2025 – https://www.sec.gov/Archives/edgar/data/1262039/000126203926000007/ftnt-20251231.htm