Cybersecurity will get more expensive

On August 26, OpenAI published a 38-page post-mortem of the Hugging Face incident, followed by a call for collective action on cyber defense co-signed by 126 companies on August 27.

The same day, CrowdStrike's stock closed up 20%, its best day ever, and Okta's stock grew by 29% after both reported quarterly results. The First Trust NASDAQ Cybersecurity ETF (CIBR) closed up 7.6%. Palo Alto Networks rose 12.8%, SailPoint 12.2%, Rubrik 11.3%, and Zscaler 10.0%.

I decided to look closer at these coincidences to understand the implications for the cybersecurity industry and real businesses.

CrowdStrike's CEO credits the Mythos moment for driving business growth and calls securing AI "the largest market opportunity in our history," because "AI is driving more cyberattacks. AI is driving more cyber spending." CrowdStrike recorded $333 million in net new ARR (51% YoY), while increasing subscription gross margin to 81% (+1%).

Okta's CEO similarly appreciates AI agents that need a trusted identity. Okta's revenue is up 11%, and margin is also up by 6 points to 28%.

Now let's take a look at what OpenAI and others proposed in the letter. It outlines four major objectives to reduce cybersecurity risks stemming from AI-enabled cyberattacks becoming far more widespread and sophisticated.

ObjectiveVerbatim
1. Every organization"Make cyber defense an immediate leadership priority" and meet it "with the urgency and coordination of an incident that takes precedence over everything except critical business operations."
"Use capable, lower-cost models for broad coverage, and apply frontier capabilities to the hardest problems."
2. Cybersecurity companies and technology partners"Help lead the response to defend against sustained AI-enabled attacks, including testing defenses continuously against frontier cyber capabilities."
"Make AI-powered defense accessible and deployable for critical-infrastructure operators."
3. Governments"Fund cyber defense, starting with essential services that lack the staff or budget to act."
"Expedite the expansion of trusted access programs."
4. Frontier AI companies"Provide responsible model access, significant funding, training, and hands-on support."
"Ensure agentic identities are traceable and accountable."

It essentially declares that defenses must be AI-powered and that cybersecurity spend must be prioritized and supported at every level. The buyers are told to buy and upgrade. The sellers are enthusiastic about building and selling more. The labs and the hardware makers are celebrating the metering of cybersecurity, with more token spend ahead.

Who signed the letter? 72% of the 126 signatories directly or indirectly benefit from the proposal. Exactly one signer, General Motors, represents what we can call the real-world industry that the authors are so eager to protect.

126 companies that signed the letter.
126 companies that signed the letter.

With these facts in hand, there's no need for a crystal ball to predict that the cost of cybersecurity will go up for real-world businesses. But what exactly will drive the budgets' growth?

  • Application security. The engineering budget that is already exploding because of tokens spent on agents writing software will go up at least 2-3x more to secure the written code through threat modeling and code review done by the model itself. The existing AppSec budgets in the security organization will go up too, as metered consumption stacks on top of per-seat licenses. Both expenses will grow along with the volume of code written by AI.
  • Agent identity. Each deployed agent requires an identity, and machine identities already outnumber humans 109 to 1. The vendors spent $2.9 billion acquiring agent-identity startups in 2026 alone, led by Oasis to Cyera for about $1 billion, SGNL to CrowdStrike for $740 million, and Astrix to Cisco for $400 million. These investments must be recouped.
  • Agent monitoring and oversight will become a new line in security budgets and will also grow existing EDR budgets. A monitor powered by an AI model that watches agents' actions is essentially adding a second inference bill on top of the agent's own.
  • Every cybersecurity renewal includes an AI add-on. As the vendors are told to strengthen "existing tools with AI," they are happy to add metered services on top of the existing per-seat license fees. For example, Microsoft Security Copilot is billed in Security Compute Units provisioned by the hour, about $4 per SCU per hour on top of the Microsoft 365 seats.
  • Vulnerability management. The letter tells organizations to "use capable, lower-cost models for broad coverage, and apply frontier capabilities to the hardest problems." We know that small models work best for narrow tasks and require a specialized harness to be effective. So scanning with off-the-shelf Codex or Claude Code means using a frontier model, at $30 to $50 per million output tokens.
  • SOC and incident response. Agent-driven incidents are forensically dense. OpenAI mentioned that reconstructing one of them required over 7 billion logs and millions of GPU hours of its own models' time. OpenAI's advice to defenders is to invest in defensive agents so incident response can scale, which means the SOC line grows with an inference bill for net new triage and investigation.
  • Compliance with the EU AI Act for companies doing business in the EU and the emerging AI regulations at the state level, like the Colorado AI Act, will also contribute to ballooning cybersecurity budgets.

My take

  1. The letter says AI makes security "faster, cheaper and better." But we know that you can pick only two, and cheaper is not one of them.
  2. AI promises great productivity gains, but also brings a significant increase in risk management and compliance costs. We don't have enough good data yet to estimate the risk-adjusted return on AI, but our recent finding that securing AI-written code may cost up to 5 times as much as writing it invites thorough research on the topic.
  3. Who will foot the bill for the hospitals, water utilities, and local governments that the signers care so deeply about? None of them signed the letter that tells governments, read taxpayers, to fund them.
  4. The OpenAI-Hugging Face incident and the attacks on the Mexican government continue confirming the cybersecurity truth that basic hygiene is the most effective mechanism for preventing cyberattacks. However, with the AI spiral, it's sadly becoming extremely unpopular. It's not making net new money, and it's boring. The network segmentation project you did, aligning the IT teams and factory managers, balancing security and not paralyzing the work, is not presentable at the next conference sponsored by the AI security vendors.

Sources:

  1. The Hugging Face incident and the road ahead (OpenAI)
  2. A call for collective action on cyber defense (OpenAI)
  3. Okta announces second quarter fiscal year 2027 financial results, exhibit 99.1 to Form 8-K filed August 26, 2026 (SEC EDGAR)
  4. CrowdStrike reports second quarter fiscal year 2027 financial results (CrowdStrike)
  5. Historical quotes for CRWD, OKTA, PANW, SAIL, RBRK, ZS and CIBR, closes of August 26 and 27, 2026 (Nasdaq)
  6. The 'Breaking' News: the OpenAI-Hugging Face incident, Black Hat USA briefing, August 5, 2026 (OpenAI)
  7. 2026 Identity Security Landscape, chapter one (Palo Alto Networks)
  8. One platform to secure the agentic enterprise, the Oasis Security acquisition (Cyera)
  9. CrowdStrike to acquire SGNL to transform identity security for the AI era (CrowdStrike)
  10. Cisco announces intent to acquire Astrix Security (Cisco)
  11. Microsoft Security Copilot Security Compute Units and capacity (Microsoft Learn)