Cybersecurity Stocks: What Is Inside the Cybersecurity Theme
Last updated July 2026
Short answer
The cybersecurity theme holds six stocks, layered by where in the attack surface each one sits: Fortinet (FTNT) and Cloudflare (NET) at the network and perimeter, CrowdStrike (CRWD) and SentinelOne (S) on endpoints and cloud workloads, Zscaler (ZS) in identity-driven secure access, and Palo Alto Networks (PANW) as the consolidated platform reaching into all three. A company qualifies when the majority of its revenue comes from protecting digital systems and is delivered largely as recurring subscription software. The layers do not stack politely: security buyers are collapsing point products into fewer platforms, so several of these names compete with each other directly rather than complementing each other. Walnut is not an investment adviser.
Most cybersecurity stock lists are a ranking. This one is a membership test. Below is every company in Walnut's cybersecurity theme, the part of the attack surface it defends, the specific reason it clears the inclusion test, and the caveat that comes with it. The layers matter more than the names, and one fact about them matters more than the rest: because buyers are consolidating onto fewer platforms, the layers are competing for the same budget rather than dividing it neatly. At the end, the well-known security names that are deliberately not in the theme, and the reason each one fails the test.
What makes a stock a cybersecurity stock?
The theme applies a two-part test. First, does the majority of revenue come from protecting digital systems, meaning endpoint, network, cloud, identity, or application security? Second, is it delivered largely through recurring subscription software rather than through one-off projects or contracted people?
Both halves do real work. The majority requirement is what keeps the largest technology companies out, even though several of them run enormous security businesses. The subscription software requirement is what keeps out the consulting and government services firms that sell security expertise by the hour. Drop either half and the theme stops describing a coherent set of businesses: without the first it fills with conglomerates, without the second it mixes software economics with services economics and the constituents stop behaving alike for any comparable reason.
The second structural choice is that the theme spans layers of the attack surface rather than picking one. That is not an aesthetic preference. Two security holdings that both defend the endpoint are one bet dressed as two, while a perimeter vendor and an access vendor are genuinely exposed to different outcomes, because the architectural argument between them is unresolved. For the general idea, see thematic investing.
The network and perimeter layer: the ground being re-taken
The oldest layer of security defends the boundary between a company's network and everything outside it, historically with firewalls sitting in a rack at the edge of a building. That model did not disappear when work moved to the cloud, it moved: the boundary is now the point where traffic enters an application rather than a campus, and the equipment defending it is increasingly a global network run by the vendor. This layer is where the theme's oldest revenue and its newest architecture sit side by side, which is exactly why two very different companies represent it.
Fortinet (FTNT)
Network security built around firewalls, with a very large installed base spanning enterprises and smaller businesses, and its own custom security silicon inside the appliances.
Why it is in the theme. Fortinet is in the theme because it is the clearest listed expression of the layer everyone else is trying to displace, and it is not going quietly. Its own security processors are the reason: purpose-built silicon lets it inspect traffic at a cost per unit that general-purpose software cannot easily match, which is a structural argument for the appliance rather than a nostalgic one. It also gives the theme exposure to the small and mid-market and to the industrial edge, where the cloud-delivered vendors have far less presence.
The caveat. Hardware-anchored revenue moves with refresh cycles, so demand can arrive in waves rather than smoothly, and the long-run question of whether appliances keep their share of the security budget is exactly the question the rest of the theme is betting against.
Cloudflare (NET)
A global edge network that sits in front of websites and applications, originally for content delivery and denial-of-service protection, now also selling web-application firewalls, zero-trust access, and developer platform services.
Why it is in the theme. Cloudflare qualifies because it is the same job as the perimeter layer done from a completely different place. Rather than selling a box to put at the edge of a customer's network, it operates the network the traffic already crosses, which means its security products are delivered by infrastructure it built for other reasons. That gives the theme a name whose security business rides on an asset with non-security uses, so it is not purely a security-budget story.
The caveat. It is the least pure of the six against the theme's own test, since a meaningful part of the business is performance, delivery, and developer services rather than protection, and it has carried one of the richer valuations in the group.
How this layer relates to the rest. Everything above depends on this layer only in the sense that traffic has to reach an application before anything else matters. What makes it interesting inside the theme is that it is the layer under the most pressure: the perimeter's budget is the pot that the endpoint and access vendors are trying to win, so strength here is often weakness somewhere else in the roster.
The endpoint and cloud workload layer: the agent on the machine
If an attacker gets past the network, the next place to catch them is on the machine itself. This layer puts software directly on laptops, servers, and cloud workloads, watches behaviour rather than matching known signatures, and reports back to a cloud brain that correlates what it sees across every customer. It became the centre of gravity in modern security for a structural reason: the agent is already installed everywhere, which makes it the cheapest place from which to sell the next product. That is the mechanism behind most of the consolidation described further down this page.
CrowdStrike Holdings (CRWD)
The Falcon platform, a cloud-delivered endpoint detection and response product that has expanded into cloud workload protection, identity protection, and security operations, all sold as modules on the same agent.
Why it is in the theme. CrowdStrike is in the theme as the purest expression of the consolidation argument. It sells a single lightweight agent and then monetises it repeatedly, which is why its story is usually told in modules adopted per customer rather than in products sold. Anyone holding the theme to express the view that security budgets concentrate into fewer, larger platforms is holding CrowdStrike whether they intended to or not, because it is the name where that mechanic is most visible.
The caveat. It carries a premium software valuation that assumes years of continued module expansion, and its 2024 update-related outage was a reminder that a vendor with an agent on every machine also carries an unusually large operational blast radius.
SentinelOne (S)
The Singularity platform, an AI-driven autonomous endpoint and extended-detection product that acts on threats on the device rather than waiting for a cloud round trip, sold to enterprises and through managed service providers.
Why it is in the theme. SentinelOne is in the theme for a reason worth being blunt about: it is the direct competitor to another constituent, not a complement to it. It qualifies because the endpoint layer is contested and holding only the incumbent is a bet that the contest is already over. It also represents the smaller, faster-growing end of the security market and the managed-service channel, which is a different route to market from the direct enterprise sale that dominates the rest of the roster.
The caveat. This is the smallest and most volatile holding in the theme, its path to sustained profitability is less mature than the platform leaders', and it competes head-on with a much larger vendor in the same layer. Holding both is deliberate exposure to the fight, not diversification within it.
How this layer relates to the rest. This layer is the theme's expansion engine. It does not sit neatly above the network layer so much as reach across it, because a vendor with an agent on every machine can add cloud posture, identity protection, and security operations without asking the customer to deploy anything new. It is also the layer where two of the theme's constituents compete most directly with each other.
The identity and access layer: the perimeter that replaced the perimeter
When applications live in someone else's data centre and staff work from anywhere, the only boundary left is the decision about who is allowed to reach what. This layer answers that question continuously: verifying the user and the device, then brokering a connection to one specific application rather than admitting anyone to the network as a whole. It is the layer that grew fastest as the network perimeter dissolved, and it is also the layer most exposed to being absorbed, because every platform vendor wants access control to be a feature of their suite rather than someone else's product.
Zscaler (ZS)
Cloud-delivered secure access, routing enterprise traffic through its own global network and connecting verified users to individual applications rather than placing them on the corporate network.
Why it is in the theme. Zscaler is in the theme because it is the cleanest listed way to hold the architectural shift itself rather than a product category. Its whole business assumes that the appliance at the edge of the building is going away, which makes it the structural opposite of the theme's network-layer holding. That opposition is the point: the theme deliberately owns both sides of an unresolved architectural argument rather than picking the winner in advance.
The caveat. It trades on continued growth, and the capability it sells is precisely the one the broadest platform vendors are bundling into larger deals, so the competitive threat comes from inside this theme as much as from outside it.
How this layer relates to the rest. This layer is where the theme's competitive tension is sharpest. Its zero-trust access sits directly on top of the traffic the network layer used to own, so growth here often comes out of the perimeter budget, and the platform layer below is selling a competing version of the same capability inside a bundle. Note also what the theme does not hold: there is no standalone identity-management specialist in the roster, which is a deliberate call explained in the exclusions.
The consolidated platform layer: the vendor trying to absorb the other three
The last layer is not a part of the attack surface at all. It is a commercial strategy: sell the customer network security, cloud security, and security operations as one integrated suite, on one contract, and displace the point products in each category. Security buyers have real reasons to want this, because dozens of separate tools are expensive to run and leave gaps between them, and a vendor that can land one product and expand into ten captures a growing share of a budget it already sits inside. This layer exists in the theme to represent the consolidation trend directly rather than only through its effects on everyone else.
Palo Alto Networks (PANW)
The broadest security vendor in the theme, spanning network firewalls, cloud security, and security operations, sold increasingly as a bundled platform rather than as separate products.
Why it is in the theme. Palo Alto Networks is in the theme because it is the only constituent that is present in every layer above, which makes it the theme's hedge against its own structure. If consolidation is the dominant force in security spending, the vendor executing it most aggressively should capture the value, and that outcome would come partly at the expense of the specialists held beside it. Including it means the theme is not implicitly betting that point products win.
The caveat. Bundling to win platform deals can suppress near-term billings even when the strategy is working, so the reported numbers and the strategic progress can point in different directions for a while. It is also the constituent most exposed to the largest software vendors, who can bundle security into agreements customers already sign.
How this layer relates to the rest. This layer is in tension with all three above it by design. It competes with the network layer in firewalls, with the endpoint layer in workload protection and security operations, and with the access layer in zero-trust connectivity. Holding it alongside the others is not stacking complements, it is holding both the consolidator and the specialists it is trying to consolidate, which is a coherent position only if you understand that is what you are doing.
How the layers hold together
In most themes the layers form a chain: one supplies the next, and weakness at the bottom eventually shows up at the top. Cybersecurity does not work that way, and pretending it does is the most common mistake in reading a roster like this. The layers here are competing for the same budget.
The reason is platform consolidation. A large organisation historically ran dozens of separate security products, which was expensive to operate and left gaps between tools that no one owned. The response has been to buy more capabilities from fewer vendors, and that changes the competitive geometry completely. A vendor already installed on every laptop can sell cloud workload protection without a new deployment. A vendor already inspecting every packet can add access control. A vendor already selling the firewall can bundle the endpoint agent into the renewal. Expansion sideways into a neighbouring layer is cheaper than winning a new customer, so every layer is being entered from the layers next to it.
The practical consequence for this roster is worth stating plainly. CrowdStrike and SentinelOne are not complements, they are direct competitors for the same endpoint deals. Palo Alto Networks competes with Fortinet in firewalls, with both endpoint names in workload protection and security operations, and with Zscaler in secure access. Fortinet and Zscaler represent opposite answers to the question of whether security belongs in an appliance or in a cloud network. Only Cloudflare sits somewhat outside the fight, because a meaningful part of its business is performance and delivery rather than protection.
That is a coherent position, but it is a specific one. Holding all six is a bet that security spending keeps growing and that you would rather own the argument than pick its winner. It is not the same thing as owning six companies that need each other to succeed, and a theme that looks diversified because it holds six tickers can still behave like one bet on high-growth security software when sentiment turns. Understanding which of those two you are holding is more useful than any ranking of the six.
Who is not in the theme, and why
A membership test is only credible if it excludes things. These are the names people most often expect to find here, and the specific reason each one does not qualify.
- Microsoft. It runs one of the largest security businesses in the world and is the single biggest competitive threat to several constituents, because it can bundle endpoint and identity protection into agreements customers already sign. It still fails the test, which asks for the majority of revenue to come from protecting digital systems. Security is a large line inside a far larger company, so it appears in the cloud computing theme instead.
- Okta. The marquee identity and access management specialist, and the one exclusion here that is about roster construction rather than a failed test. The theme expresses the identity layer through the access and platform vendors that are absorbing it, which is the same consolidation logic the rest of the roster rests on. That is a debatable call, not a disqualification, and Okta is covered in the companion roundup.
- Cisco. A serious security vendor with a large portfolio assembled over years of acquisitions, but the majority of its revenue comes from networking hardware and infrastructure. The test asks what most of the money comes from, not whether the company sells security, and by that reading Cisco is a networking company with a security division.
- Broadcom and similar acquirers of security assets. Enterprise security products can end up owned by semiconductor and infrastructure-software conglomerates, where they are run for cash inside a much larger portfolio. The revenue-majority test excludes them for the same reason it excludes Microsoft, and the exposure you would actually be buying is the parent company's capital allocation rather than the security market.
- Cyber consulting and government services firms. They deliver real security work, but they deliver it as contracted people rather than as recurring subscription software, which is the second half of the theme's criteria. Their economics are billable hours and contract awards, so they do not behave like the software names beside them even when the underlying demand driver is identical.
The Microsoft case is the one worth dwelling on, because the exclusion is technically correct and strategically uncomfortable at the same time. It fails a revenue-majority test cleanly and belongs in the cloud computing theme, where its exposure is the thesis rather than a division. But the consolidation pressure described above does not only come from inside this roster. It also comes from a vendor that can add security to a contract the customer was going to sign anyway, and no pure-play theme can hold that risk directly. Naming it is more useful than pretending the roster is complete.
At a glance
The same six names, grouped by the layer of the attack surface they occupy rather than ranked, so the shape of the theme is visible at a glance.
| Ticker | Company | Layer | What it does |
|---|---|---|---|
| FTNT | Fortinet | The network and perimeter layer | Network security built around firewalls |
| NET | Cloudflare | The network and perimeter layer | A global edge network that sits in front of websites and applications |
| CRWD | CrowdStrike Holdings | The endpoint and cloud workload layer | The Falcon platform |
| S | SentinelOne | The endpoint and cloud workload layer | The Singularity platform |
| ZS | Zscaler | The identity and access layer | Cloud-delivered secure access |
| PANW | Palo Alto Networks | The consolidated platform layer | The broadest security vendor in the theme |
Of the 6, five are security-first businesses and one, Cloudflare, sells security on top of infrastructure built for performance and delivery. Two of them, CrowdStrike and SentinelOne, sit in the same layer on purpose.
How this differs from a cybersecurity ETF
The passive route is a fund, and it answers a different question. Dedicated cybersecurity funds exist in the broader market, though the proxies attached to this theme are the broad technology funds VGT and XLK, where the largest security names appear at small weights inside a much wider technology sector. That is real exposure, but it is diluted: most of what you own is not security, and the weights are set by an index rather than by you.
A theme inverts the trade. You know exactly which six names you own, which layer each one represents, and which two of them are competing with each other, and you accept that six names is a narrower roster than a fund holds. Neither is automatically better. The fund is the simpler instrument and spreads a competitive shock across more holdings, the theme is the more deliberate one and lets you decide how much of the appliance-versus-cloud argument you want to own. Plenty of people hold a broad fund as a core with a small thematic tilt beside it.
Turning the roster into a portfolio
A list of six names is an input, not a portfolio. What turns one into the other is structure: which layers you want exposure to, what weight each name carries, and whether the concentration you end up with was chosen or inherited.
- Decide the layer mix first, then the names. How much of the roster sits in the consolidated platform versus in the specialists changes the character of the position far more than swapping one endpoint vendor for another.
- Know where you are holding both sides of a fight. Owning CrowdStrike and SentinelOne together is exposure to the endpoint contest rather than diversification within it, and the same is true of Fortinet beside Zscaler. That can be deliberate, but it should be deliberate.
- Set target weights that sum to 100. Equal weighting across six names is a choice, and so is tilting toward the platform vendors. Both are defensible. Not deciding is what leaves you concentrated by accident after one name runs.
- Frame it against the S&P 500. A narrow thematic position should be judged against a broad benchmark, because the extra concentration has to be buying you something.
- Expect the roster to correlate. These are premium-multiple software companies with a shared customer budget, so they can fall together even when their competitive positions are diverging.
This is what Walnut is built for. You describe the thesis, the AI assistant proposes constituents and weights you can edit, the portfolio tracks as one performance line against the S&P 500, and you place trades you approve yourself at your own broker. Walnut is informational and does not tell you which stocks to buy.
For the companion view of which security names are most widely held and discussed, including the identity specialist this theme leaves out, see best cybersecurity stocks. For the wider category these subscription economics come from, see best software stocks.
The bottom line
The cybersecurity theme is six companies across four layers of the attack surface. Fortinet defends the perimeter from an appliance with its own silicon, Cloudflare defends it from a global edge network it already operates. CrowdStrike and SentinelOne fight over the agent on the machine. Zscaler represents the access layer that replaced the perimeter. Palo Alto Networks represents the commercial strategy of absorbing all three into one contract.
Read as a flat list of six security stocks, the theme looks like a spread across a durable spending category. Read as four layers being consolidated into fewer platforms, it is a position on an unresolved competitive fight in which some of the constituents win at each other's expense. The second reading is the accurate one, and it is the one worth deciding about. Nothing here is a recommendation, and Walnut is not an investment adviser.
Try Walnut on top of your broker
Connect any major US broker in a few clicks. Walnut adds AI research, portfolio building, and live portfolio answers, without changing where your money lives.
FAQ
What stocks are in the cybersecurity theme?
Six: CrowdStrike (CRWD) and SentinelOne (S) in endpoint and cloud workload protection, Fortinet (FTNT) and Cloudflare (NET) at the network and perimeter layer, Zscaler (ZS) in identity-driven secure access, and Palo Alto Networks (PANW) as the consolidated platform spanning all of them. The roster is organised by where in the attack surface each vendor sits, because that is what determines whether two holdings are the same bet or different ones.
What makes a company a cybersecurity stock?
The test this theme applies has two halves: the majority of revenue must come from protecting digital systems, covering endpoint, network, cloud, identity, or application security, and it must be delivered largely through recurring subscription software. The first half excludes large technology companies with significant security divisions. The second half excludes consulting and government services firms that sell security as contracted labour rather than as software.
How do the layers of the cybersecurity theme relate to each other?
Less neatly than in most themes, and that is the useful thing to understand. The network layer defends the boundary traffic crosses, the endpoint layer defends the machine if something gets through, and the access layer decides who reaches which application. But security buyers are collapsing point products into fewer platforms, so vendors are expanding sideways into each other's layers rather than staying in their own. The layers compete as much as they stack.
What is platform consolidation in cybersecurity?
Companies historically bought dozens of separate security products from different vendors, which was expensive to operate and left gaps between the tools. Consolidation is the shift toward buying many capabilities from one integrated vendor instead. It favours vendors that already sit inside the customer, because landing one product and expanding into several more is cheaper than winning a new account, and it is why scale matters so much in this part of software.
Are the stocks in the cybersecurity theme competitors?
Several of them are, directly. CrowdStrike and SentinelOne compete for the same endpoint deals. Palo Alto Networks competes with Fortinet in firewalls, with the endpoint names in workload protection and security operations, and with Zscaler in secure access. Owning the roster is therefore not a set of complements; it is deliberate exposure to an unresolved competitive fight, which is a different position from a theme whose members depend on each other.
Why is Microsoft not in the cybersecurity theme?
Because the majority of its revenue does not come from security, which is what the inclusion test asks. That is a technical exclusion with a real consequence: Microsoft is one of the largest security vendors in the world and can bundle endpoint and identity protection into agreements customers already sign, so the most significant competitive pressure on this theme comes from a company the theme cannot hold. Microsoft appears in the cloud computing theme instead.
Why is there no identity management specialist in the theme?
The theme expresses the identity layer through Zscaler's secure access and through the platform vendors adding identity protection to products they already sell, rather than through a standalone identity management vendor. That follows the consolidation logic the rest of the roster rests on, but it is a judgement call rather than a rule, and Okta is the obvious name a different construction would include. The companion roundup covers it.
What is the difference between CrowdStrike and Palo Alto Networks?
They arrive at the same destination from opposite directions. CrowdStrike started with an agent on the endpoint and expanded outward into cloud, identity, and security operations, monetising software it had already deployed. Palo Alto Networks started in network security and assembled a broad suite across network, cloud, and operations, selling it as one bundled platform. Both are pursuing consolidation; they differ in what they already own inside the customer.
What is the difference between this theme and a cybersecurity ETF?
Dedicated cybersecurity funds exist in the broader market, but the proxies attached to this theme are the broad technology funds VGT and XLK, where security names sit at small weights alongside a lot of unrelated technology. The fund route gives breadth and one ticket at weights you do not set. The theme gives a stated inclusion test, a named roster, and weights you choose, across a narrower set of companies. Neither is automatically better.
What are the risks of holding the cybersecurity theme?
Four sit across the roster. The leaders carry premium software valuations that assume years of continued growth. The names correlate, so a roster that looks diversified can behave like one bet on high-growth software. Consolidation means one constituent winning can be another losing. And a security incident at a vendor itself, as distinct from at its customers, is a risk specific to this sector that has already affected names in the group.
Can I build a cybersecurity portfolio in Walnut?
Yes. You describe the thesis, for example security across network, endpoint, access, and the consolidated platforms, and Walnut's AI assistant proposes constituents and target weights that you edit. You connect your own brokerage, the portfolio tracks as one performance line you can compare against the S&P 500, and you approve every order yourself at your broker. Walnut is informational and is not an investment adviser.
Is Walnut an investment adviser?
No. Walnut is informational and is not an investment adviser. This page describes which companies fit the cybersecurity theme and why, which is research context rather than a recommendation. Walnut does not tell you to buy, sell, or hold anything, and every trade needs your approval at your own broker.
Walnut is informational and is not an investment adviser. Theme membership is descriptive, not a recommendation. Cybersecurity is a fast-moving, highly competitive category; product portfolios, competitive positions, segment mix, and theme constituents change over time, so verify current details before deciding. Nothing on this page is a recommendation to buy, sell, or hold any security.
Invest in this theme
Cybersecurity
Protecting networks, identities, and cloud workloads: subscription security platforms benefiting from consolidation and resilient budgets.