• Over the past six months, cybersecurity stocks have been soaring, with a key cybersecurity index outperforming a top AI-hardware heavy semiconductor benchmark. 
  • CrowdStirke’s latest results are just one of many examples where cybersecurity companies have seen rapid AI-driven growth. 
  • While many focus on AI-cyberattacks and rouge agents creating cybersecurity demand, an underdiscussed tailwind could actually be the industry’s larger long-term growth driver.

CrowdStrike is on a tear after the company posted an all-time high net new ARR of $333 million. The cybersecurity leader also saw its AI Detection and Response (AIDR) ARR triple in one quarter and boosted its FY2027 net new ARR growth guidance to 34% YoY, up a whopping 1,150 basis points from its initial outlook. Shares ultimately closed up 20.5% after the report—enough to mark CrowdStrike’s second-largest single-day gain ever, bested only by the 70.6% rise on its first trading day. CrowdStrike has now surged over 80% YTD, and over 130% in the last six months.

This incredibly strong performance is not unique to CrowdStrike. Over recent months, cybersecurity companies have been quietly posting some of the most impressive AI-driven growth rates. This includes the world’s largest cybersecurity pure-play not named CrowdStrike calling an AI security offering its fastest growing product ever. 

In the last six months, the Nasdaq CTA Cybersecurity Index is up approximately 55%. This solidly exceeds the AI-hardware heavy NYSE Semiconductor Index’s gain near 42%, indicating that cyber stocks are among the market’s largest second-order beneficiaries of AI adoption. 

As we recently covered in our article “How Autonomous Agent Risks Are Reshaping Cybersecurity Investing”, the alarming cybersecurity capabilities of frontier models are causing significant concern among AI labs, enterprises, governments, and the public at large. This is leading to notable momentum for cybersecurity stocks. 

Amid this, the majority of coverage on AI cybersecurity centers around stories of AI models going rogue and the surge in AI-enabled cyberattacks by malicious actors. While not unwarranted, this focus leaves out a substantial part of the AI-driven cybersecurity growth opportunity, and an underappreciated tailwind could actually be the larger long-term growth driver for the industry. 

AI Adoption Is Driving an Explosion in Data and Network Traffic

The use of AI agents is leading to a dramatic increase in data traffic compared to humans. As we noted in our newsletter on soaring token consumption, Cisco estimates that wide-area network traffic, which measures the traffic between end users and data centers, increases by 450% when performing tasks using AI agents compared to humans. 

As AI and agent usage increases, AI-driven traffic is rising rapidly. Private cybersecurity company HUMAN estimates that monthly volumes of AI-driven traffic increased by 187% in 2025. The firm also estimates that traffic from AI agents and agentic browsers increased 7,851% YoY, albeit off a very low base in 2024. Perhaps most interestingly, automated traffic, which includes AI traffic and traditional automation tools like search engine crawlers, grew 8X faster than human-generated traffic. 

We can see trends like this continuing in 2026. Edge cloud computing company Fastly says that from January to May 2026, AI traffic on its network increased by 30%, or 6.5X faster than human-generated traffic in the same period. Within this, the company says that traffic related to Anthropic’s Claude increased by 555%. 

AI Traffic Growth Could Soar for Years to Come

While this surge in AI-driven traffic is significant, Cisco argues that growth is still in the early stages. The company estimates that from 2026 to 2035, agentic AI will result in 9X enterprise traffic growth compared to just 2.5X growth without agentic AI, with agentic traffic overtaking non-agentic traffic in mid-2028. 

Line chart showing enterprise network traffic reaching nearly 1,000% growth by 2035 with agentic AI versus 250% without it.
The chart compares projected enterprise network traffic growth from 2025 to 2035 with and without agentic AI adoption. Enterprise network traffic with agentic AI is forecast to approach 1,000% growth by 2035, while traffic without agentic AI rises to roughly 250%. Agentic AI enterprise traffic is projected to grow rapidly throughout the period and become the primary driver of overall network traffic growth. The data suggests that AI agents could significantly increase enterprise data movement and network inspection requirements over the next decade.

The rapid expansion in data creation and transfer driven by AI usage expands the amount of data that can be exposed to attacks and the range of surfaces that can be targeted. As CrowdStrike’s CEO George Kurtz put it, “The world’s adoption of AI is rapidly expanding the attack surface, more models, more agents, more agentic applications, more data and with that, more identities, more permissions, more policies, more cyberattacks and more risk.” 

Palo Alto Networks’ CEO Nikesh Arora makes a similar point: “we’ve always maintained that as more traffic traverses networks, more inspection is needed.” 

These statements show that top cybersecurity executives see the increase in AI-enabled attacks and rogue agents as far from the only factors creating increased demand for their offerings. The general expansion in AI usage establishes its own risks that enterprises need to defend against, and that their platforms can provide a solution to. 

Cybersecurity stocks are emerging as key second-order beneficiaries of AI. Find out which names have the strongest setups in this week’s 1-hour webinar—and also see how we’re positioning for what comes next in the AI trade. Subscribe now to follow the I/O Fund, with 6 stocks already up more than 100% YTD

AI Adoption Creates Enterprise Risk Separate from Attacks

Importantly, the surge in AI-related traffic creates different cybersecurity risks compared to AI-driven cyberattacks. This comes as enterprises increasingly input their data into third-party generative AI tools, many of which may not be company-approved or may have low security standards. 

Notably, from January to mid-March 2025, Palo Alto saw a spike in GenAI-related data loss prevention (DLP) incidents. Over the period, GenAI-related DLP incidents as a percentage of total DLP incidents rose from approximately 2.5% to 14%, a more than 5X increase in just 2.5 months.

Line chart showing GenAI-related DLP incidents rising from about 2.5% in January 2025 to over 14% by mid-March.
The chart tracks GenAI-related data loss prevention (DLP) incidents as a percentage of all DLP incidents from January to March 2025. The share rises from approximately 2.5% in early January to more than 14% by mid-March, despite a temporary decline in early March. Overall, GenAI-related incidents increase more than fivefold over the period, indicating rapidly growing data security risks associated with enterprise adoption of generative AI tools.

This could have a twofold effect on cybersecurity demand. First, it could influence enterprises using AI tools to adopt DLP solutions that can detect and prevent GenAI-related incidents. Additionally, it could influence tool providers to improve their cybersecurity infrastructure as a competitive differentiator versus tools with weaker security. 

Furthermore, CrowdStrike notes that agent-triggered detection leads, or potential threats, are now tracking at 2.5X the rate of human-triggered leads. This indicates that agents are taking significantly more potentially risky actions than humans and increasing the number of threats that need to be investigated. 

CrowdStrike also suggests that enterprises could be significantly underestimating the number of agents operating in their organization. It notes one customer who counted 150 agents in its inventory, but CrowdStrike found the true count was over 3X higher at 500. Meanwhile, it found over 70 active agents at another customer that had not approved any agent usage. 

These data points lend weight to the thesis that increased AI traffic requires additional monitoring, showing that incidents and potential threats related to AI usage are spiking. At the same time, enterprises may not have a full understanding of the extent of their internal AI usage, and thus the risks it creates. 

AI Security Demand Is Expanding Across the Cybersecurity Industry

CrowdStrike’s AIDR ARR tripling in just one quarter is far from the only example of companies generating significant momentum for security solutions that address AI-related concerns. 

The market’s largest cybersecurity pure-play, Palo Alto Networks, discussed the growth of its Prisma AIRS platform in June, which secures AI agents, apps, models, and data. The company notes that Prisma AIRS is now its fastest-growing product ever. During the quarter, the product hit 300 customers, tripling its customer count versus fiscal Q2. Palo Alto says it has clear visibility into generating $100 million in product ARR “over the next couple of quarters”. 

Palo Alto also noted its network security business unit “delivered its most robust third-quarter performance in years,” underscoring the “mission-critical role of real-time network traffic inspection as enterprise-wide AI initiatives continue to transition to production.” 

Other notable cyber vendors such as Zscaler, F5, SentinelOne, and Okta have also outlined early AI-driven success. In their latest earnings calls, Zscaler said its AI Protect portfolio crossed $100 million in bookings over the last 12 months, while F5 noted that its number of AI security customers doubled in just one quarter. 

In June, SentinelOne said its Prompt Security product had “basically doubled” its ARR for two consecutive quarters, and nearly quadrupled since it was acquired a few quarters ago. In its August earnings call, the company said ARR from Prompt Security and its Purple AI products “continues to be in hypergrowth,” tripling YoY. The firm expects its AI security offerings to become its next +$100 million ARR category, with Prompt Security currently being its fastest-growing platform solution. 

Lastly, Okta showed early signs of AI security product adoption in its latest results, seeing a “real possibility” that these offerings become a material long-term growth driver. The company signed dozens of deals related to its Okta for AI Agents offering, including several million-dollar-plus deals. This includes a deal with a Fortune 50 healthcare firm, which did not know where its agents were, the access they had, and the tasks they could execute. This again underscores that the general deployment of AI in large enterprises is generating demand for cybersecurity vendor solutions. 

Observability Emerges as Another AI-Driven Growth Opportunity

Some cybersecurity vendors, such as Palo Alto, are also expanding their addressable market into related categories like observability, which involves monitoring the performance of AI systems and infrastructure. 

Its latest earnings show clear evidence of observability being a significant growth driver as the company gains traction with AI labs. In fiscal Q3, Palo Alto’s overall observability ARR eclipsed $300 million during the quarter, nearly doubling in less than a year. Palo Alto said it had surpassed $200 million in ARR with a leading frontier AI lab, which it expects to increase again next quarter. 

Notably, this customer relationship is approximately 86X larger than that of Palo Alto’s average ‘platformized’ customer, showing the drastically outsized demand it can generate from model developers. The company’s total Next-Generation-Security (NGS) ARR was $8.13 billion during the quarter. Palo Alto says 65%, or around $5.28 billion, of its total NGS ARR comes from its ‘platformized’ customers, or those that have reached certain ARR thresholds. 

With 2,280 platformized customers, the average ARR among this group is approximately $2.32 million, making $200 million 86X higher than the average, and representing 3.8% of total platformized NGS ARR. This demonstrates that very significant opportunities exist outside of just AI cybersecurity use cases, creating another growth vector for companies with adjacent offerings. 

Conclusion

In June, CrowdStrike said the release of Anthropic’s Mythos marked an inflection point for the cybersecurity industry. The company now says that inflection has transitioned into an acceleration, with Q2 being CrowdStrike’s “best quarter in company history.”  

While rogue models and AI-enabled attacks are in the headlines, the broader readthrough is that cybersecurity stocks are starting to see tailwinds from surging AI traffic and an expanding attack surface.  

There is a sizable list of cybersecurity stocks that could emerge as beneficiaries, but for investors, spotting a trend is only the first step. It’s easy to talk about potential AI winners, but it’s much harder to know when to enter, how large of an allocation to hold, and how to manage an evolving thesis as valuations shift. This is exactly where the I/O Fund can help. 

Paid subscribers get access to I/O Fund’s portfolio, plus 1-hour weekly webinars where we discuss which cybersecurity stocks we are eyeing for an entry, at what price levels, and at what allocations.  

The I/O Fund has consistently outperformed hedge funds, tech ETFs and competing portfolios, with a 326% five-year cumulative return—and that does not yet include the I/O Fund’s 2026 outperformance. This year alone, the portfolio has 16 stocks outperforming the Nasdaq-100, including 6 stocks up more than 100% YTD. 

Don’t Navigate the Volatility on Your Own. Subscribe Now. 

Please note: The I/O Fund conducts research and draws conclusions for the company’s portfolio. We then share that information with our readers and offer real-time trade notifications. This is not a guarantee of a stock’s performance and it is not financial advice. Please consult your personal financial advisor before buying any stock in the companies mentioned in this analysis. 

Leo Miller, AI and Semiconductor Investment Writer at I/O Fund, contributed to this analysis. 

Recommended Reading: