Back Bankinfosecurity How Recent Cyber Earnings Show Growth Alone No Longer Pays
Agentic AI , Artificial Intelligence & Machine Learning , -Generation Technologies & Secure Development
Aggressive growth didn't translate into higher stock prices in the most recent quarter for many of the industry's most prominent cybersecurity and technology vendors.
See Also: Inside the 2026 Cyber Workforce: Key Trends, Talent Gaps, Strategic Shifts and the AI Revolution
Seven of eight high-profile vendors recorded year-over-year sales growth of at least 25% for their cyber or tech business in the fiscal quarter that ended June 30 or July 31, with only Cisco's security business lagging with a 14% growth rate. But investors weren't impressed, with only CrowdStrike and Amazon recording stock price gains above 2% since announcing earnings while five other vendors have seen their stock fall.
While Fortinet and Cloudflare have essentially treaded water since announcing earnings - with less than 2% movement in their stock prices - others haven't fared as well, with Zscaler seeing its stock drop more than 5% and Palo Alto Networks, Cisco and Rubrik recording stock price drops approaching or exceeding double digits.
More profitable companies have fared better in the market, with all three companies recording stock price gains since announcing earnings reporting net income on a GAAP basis, although CrowdStrike made just $5 million last quarter. Conversely, four of the five companies with post-earnings stock price drops reported a GAAP net loss last quarter, with only Cisco making money and seeing its stock tumble.
Similarly, vendors growing year-over-year headcount most aggressively fared worse on the stock front, with four of the five biggest headcount growers recording stock price drops. CrowdStrike, who grew its staff by 16.5%, is the lone exception. Of the three least-aggressive vendors on the headcount front, two saw their stock prices increase. Only Cisco saw both its headcount and post-earnings stock price fall.
Below is a look at how eight prominent cyber and technology vendors have fared since announcing earnings in recent weeks, with a deep dive into how CEOs at these companies see artificial intelligence reshaping enterprise infrastructure and security:
Attempting to Live Up to Lofty Expectations
Why Frontier Models Are Becoming Commoditized
Frontier models are becoming increasingly comparable in overall capability, making price, performance and specialization more important differentiators, Amazon CEO Andy Jassy told investors. Organizations are moving away from the assumption that a single dominant model will handle every workload, with businesses increasingly choosing different models based on cost, performance and individual use cases (see: Amazon: Custom Frontier Model Can Cut Costs, Target Niches ).
"Within the few years, you're going to have at least a half dozen models that are comparably good to each other," Jassy told investors. "They'll all be in Bedrock, and one of them will be ours."
AI workloads require greater bandwidth, lower latency and more efficient links between increasingly distributed computing resources, which Cisco CEO Chuck Robbins said is driving a multiyear, multibillion-dollar networking supercycle. Issues with token costs, sensitive data and data sovereignty are making on-premises and hybrid architectures increasingly attractive compared to cloud-based AI providers (see: Fortinet Sees On-Prem SASE Market Outpacing Cloud ).
"Even for SASE three years ago, we only focused on SASE for service providers," Fortinet CEO Ken Xie told investors. "Now we see they're all starting to come back with all this sovereign SASE, private SASE and on-premise solution is huge. That's the reason I say it's two to three times larger than the cloud-only based SASE."
AI agents and applications are generating substantial traffic within enterprises and data centers, which Xie said makes routing all traffic to cloud security infrastructure increasingly inefficient. The proliferation of open-source, open-weight and specialized AI models means organizations must secure not only AI applications but also the agents, identities, models, data and infrastructure supporting them (see: Palo Alto: Security Debt Exposes Firms to AI-Powered Attacks ).
"Each new deployment adds more infrastructure to fortify and more sensitive data to protect," Palo Alto Networks CEO Nikesh Arora told investors. "The surface area requiring platformized protection is expanding dramatically."
When Will the Bill for Technical Debt Become Due?
Years of deferred infrastructure upgrades have left organizations exposed just as AI gives attackers greater capabilities, Arora said. Agent security is bringing identity resilience, data protection, runtime monitoring and recovery closer together, and Rubrik CEO Bipul Sinha said enterprises need to identify sanctioned and unsanctioned agents and determine what data and tools they can access (see: Rubrik: Firms Want Joint Agent Identity, Visibility, Recovery ).
"Identity has become the weakest link in cyberattacks," Sinha told investors. "And once these attackers get in, lots of times, they actually destroy identity systems or do a ransom or encrypt the identity system or have long-term persistence in the identity system, and that became their host to attack other places."
Enterprises increasingly need real-time visibility into what agents access, where they communicate, what they execute and how much they spend, according to CrowdStrike CEO George Kurtz. He said CrowdStrike is applying a token-based consumption model to AI detection and response through Falcon Flex, giving organizations visibility into security use and AI spending (see: CrowdStrike Flex Model Adapts Deals to Evolving AI Threats ).
"You have to understand at runtime what the agents are actually doing, whether that's in a sandbox or if those agents are running essentially on your computer or your laptop," Kurtz said. "You have to understand the exposures that you have."
Non-human traffic has already surpassed human traffic earlier than Cloudflare expected, and if current trends continue, CEO Matthew Prince said non-human traffic could become 1,000 times greater than human traffic within five years. Palo Alto Networks CEO Arora envisions agents eventually handling complex product migrations and security configuration while humans primarily validate their actions (see: Cloudflare Rides Surge in Bot Traffic and AI Workloads ).
"Humans will be a rounding error on the internet, not because human traffic goes down, but that's just how fast we're seeing non-human traffic grow," Prince told investors. "If we're going to have 1,000 times as much traffic online, we've got to get a lot more efficient."
Artificial Intelligence & Machine Learning
-Generation Technologies & Secure Development
Executive Editor, Business, ISMG
Novinson is responsible for covering the vendor and technology landscape. Prior to joining ISMG, he spent four and a half years covering all the major cybersecurity vendors at CRN, with a focus on their programs and offerings for IT service providers. He was recognized for his breaking news coverage of the August 2019 coordinated ransomware attack against local governments in Texas as well as for his continued reporting around the SolarWinds hack in late 2020 and early 2021.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
