SaaS, now more broadly understood as cloud software, remains the category underpinning how modern enterprises operate – but the opportunity set within it is far from uniform, and AI is reshaping it unevenly. Within cloud software, we are focused on areas where we see structural demand, measurable ROI, and enduring differentiation. Our last edition examined frontier AI platforms and infrastructure, where model capability meets operational reality. This edition turns to cybersecurity, the area where we believe the stakes are rising fastest.
The threat landscape is expanding on every axis at once: AI-powered attacks, the proliferation of cloud and hybrid environments, regulatory mandates, and geopolitical tension have together pushed cyber risk to a boardroom-level concern. The complicating factor is that AI is both the biggest accelerant of those threats and the most promising vector for defense. The same capabilities that let attackers automate reconnaissance, develop exploits faster, and scale operations also let defenders detect, respond, and remediate at machine speed. This is not a temporary escalation – it is a structural reset in how enterprises must think about risk.
The most acute expression of that reset is the identity problem. Every AI agent an enterprise deploys is a non-human identity – carrying credentials, accessing systems, and executing actions without direct human involvement at each step. Most security stacks were built for a world of human users with static credentials and defined roles. Agentic AI breaks that model entirely. According to KPMG’s Cybersecurity Considerations 2026, non-human identities outnumber human users by more than 80-to-1 in the average enterprise – and most organizations lack the governance frameworks to manage them at that scale. Data compounds the challenge: as agents consume and act on sensitive information across multi-cloud environments, governing what they can reach is as consequential as governing the identities themselves.
We see durable tailwinds as organizations confront identity sprawl, API security gaps, cloud misconfigurations, and supply chain vulnerabilities – and security budgets remain among the most resilient line items in enterprise IT. Gartner forecasts global information security spending will reach $244B in 2026, growing 11.6% year-over-year. Budget scrutiny is rising in parallel; we believe that the durable winners are the categories tied to measurable risk reduction.
The M&A record shows that strategics are acting on the same thesis. Google completed its $32B acquisition of Wiz, and Palo Alto Networks announced a definitive agreement to acquire CyberArk at an equity value of ~$25B, establishing identity security as a core pillar of its platform strategy. The major platforms are consolidating around integrated, outcome-oriented security – validating the control points and raising the standard for enterprise security. But as they slowly absorb acquisitions, space reopens for focused independents. In cybersecurity, where complexity is structural and the cost of getting it wrong is existential, deep data advantages, ownership of a system of record, and regulatory entanglement are enduring moats that drive category leadership.