newsfilter.io
Interview, Fireside Chat

Cybersecurity Deals Surge Amid Rising Attacks

  • Cybersecurity investment totaled over $30 billion last year, characterizing the sector as highly funded despite rising geopolitical tensions and slowing economic growth.
  • Global cyber-related losses are projected to rise from $6 trillion in the prior year to over $10 trillion by 2025, representing a compound annual growth rate (CAGR) of over 20%.
  • Defensive spending is forecasted to exceed $100 billion by 2025 as organizations attempt to mitigate the expanding attack surface.
  • The attack surface has shifted from centralized data centers to diversified endpoints including mobile, web, cloud, SaaS, IoT, and OT, complicating defense strategies.
  • Organized crime groups, rather than nation-states, currently drive the majority of cyber attacks, with the group Conti generating an estimated $180 million in revenue against $6 million in expenses last year.
  • Geopolitical risks remain elevated due to potential Russian cyber warfare responses to sanctions, prompting Western governments to advise a "shields up" posture for all companies.
  • Defenders face a structural disadvantage where attackers only need one successful breach while defenders must succeed 100% of the time.
  • Innovation is accelerating in cloud security and software development life cycle integration, aiming to provide real-time runtime protection for software as it is built.
  • Market consolidation is a primary trend, with cybersecurity M&A volume reaching $70 billion in 2021, a fourfold increase from 2020.
  • Large cloud providers are expected to grow inorganically to acquire protection mechanisms, while financial sponsors are increasingly active due to the sector's resilient and durable business models.
  • Goldman Sachs Asset Management is shifting investment focus to earlier-stage companies (including Series B) with low revenue but proven teams to navigate high valuations of established "platform" companies.
  • Key investment themes include AI and ML applications, cybersecurity stack simplification, cloud/SaaS security, identity management, and DevSecOps.
  • The regulatory landscape is tightening, with the SEC mandating security incident disclosures for public companies and the NIST framework expanding into critical industries like utilities and manufacturing.
  • Market fragmentation is significant, with approximately 2,000 security vendors present at RSA, driving demand for solutions that simplify the security stack for enterprises.
  • Managed Security Service Providers (MSSPs) are gaining importance in addressing the global shortage of cybersecurity professionals and enabling smaller businesses to manage complex defense postures.
  • Investors are prioritizing companies that can grow into comprehensive security platforms over those offering isolated "better mousetrap" technologies that may become obsolete.