
Cybersecurity — Who Gets Paid When AI Agents Act
As of the September 14, 2026 US regular close. Seven-company research universe: $PANW, $CRWD, $ZS, $NTSK, $FTNT, $RBRK and $CVLT. House view: neutral; wait on a broad basket. Commvault is the first recovery valuation to investigate further, and Zscaler is the preferred cloud-access candidate. Neither ranking is a current buy recommendation.
Thesis
An AI agent that can read a document is useful. Give it credentials, permission to edit a database and the ability to call another application, and the security problem changes. The enterprise must decide what it may do, inspect what it sends, contain mistakes and restore operations when prevention fails. Those are recurring operating responsibilities. They give cybersecurity a credible claim on the next phase of AI spending, even when the underlying models become cheaper.
The investment question is who can charge for that work, defend the contract and grow value per share from today’s price. Four different security jobs do not automatically justify four holdings. I compare Palo Alto with CrowdStrike, Zscaler with Netskope, and Rubrik with Commvault before choosing an expression. Fortinet provides a profitable network reference. The comparison supports continued research, but it does not establish an attractive entry for the broad basket after the rally.
The investment case already has evidence beyond product announcements. Zscaler’s latest quarter grew ARR 20% excluding Red Canary. Palo Alto’s prior-quarter disclosure put NGS ARR growth at 28% excluding CyberArk and Chronosphere. Fortinet’s latest product revenue grew 52%. Rubrik’s subscription ARR grew 33%. These are different measurements, covering different periods, but together they show demand across cloud inspection, platforms, appliances and recovery. None identifies how much growth came specifically from AI. [$ZS results](https://www.sec.gov/Archives/edgar/data/1713683/000171368326000156/zs-07312026_991.htm), [$PANW Q3 call](https://investors.paloaltonetworks.com/static-files/ea18c9ae-cbe6-4b5d-aa7c-65a6b9aeb2e2), [$FTNT results](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000018/ftntq2-2026ex991.htm), [$RBRK results](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Reports-Second-Quarter-Fiscal-Year-2027-Financial-Results/default.aspx).
All valuation calculations use the same September 14 regular close: $PANW $373.94; $CRWD $235.38; $ZS $191.73; $NTSK $17.00; $FTNT $170.18; $RBRK $100.20; $CVLT $140.21. Prices were captured from Yahoo’s dated daily series. The price and options images below retain their separately labeled intraday captures; those image timestamps are not the valuation timestamp. [Dated market prices](https://finance.yahoo.com/quote/ZS/history/).
Backdrop
The budget opportunity has two parts. Companies can use AI to make their security teams more productive, and they must secure the AI systems their employees deploy. These can have opposite implications for a vendor. Automating investigations may reduce the price customers will pay for a stand-alone analyst tool. Adding governed workloads, identities or protected data may expand the units a platform can sell. A useful investment framework must trace both effects rather than multiply an assumed number of agents by today’s human-seat price.
There is no defensible need for a trillion-dollar market forecast here. The observable starting point is the installed enterprise security budget and the vendors’ current contracts. A large opportunity can emerge through wider deployment inside existing customers, additional modules, greater protected capacity or better retention. It can also be offset by bundles, free introductory products and lower unit pricing. I would underwrite incremental contract value before accepting a company’s broad addressable-market slide, especially when multiple vendors count the same cloud, identity and data-security dollars.
Zero trust provides an architectural foundation. The US National Institute of Standards and Technology describes an approach that does not grant implicit trust merely because a user or asset is on an internal network. Authentication and authorization precede access to a resource. For agents, that distinction is practical: a valid identity can still request an inappropriate action. My inference is that enterprises will need policies that remain meaningful as software operates on someone’s behalf, with narrower permissions and evidence of what happened. The institute does not endorse any stock or establish which vendor captures this spending. [the US National Institute of Standards and Technology Special Publication 800-207](https://csrc.nist.gov/pubs/sp/800/207/final).
The revenue bridge has four steps: more useful automated work; more activity within a vendor’s covered environment; a contract that meters or bundles that activity into additional paid value; and a gross profit contribution after inspection, storage and support costs. Failure at any step weakens the thesis. An agent that works entirely inside a hyperscaler’s native controls may produce little revenue for an independent provider. A customer on an unlimited bundle may create substantially more traffic before its next renewal produces another dollar.
That distinction also explains why adoption and margins must be read together. Cloud-delivered security requires servers, memory, network capacity and engineering. Zscaler’s latest call described accelerated equipment purchases and elevated component costs; management expects capital spending to remain elevated in fiscal 2027. Rising traffic therefore creates both an opportunity to sell and a requirement to invest. The cash cost arrives whether the security vendor wins attractive incremental pricing or merely absorbs more activity under existing contracts. [$ZS Q4 call, CFO remarks at 28:44–29:39](https://no5neo61wycllmc1.public.blob.vercel-storage.com/earnings-transcripts-pdfs/ZS-2026-09-03-transcript-1788504693314-a247bf.pdf).
Mechanism
Consider an agent asked to prepare a customer renewal. It authenticates, reads an approved account record, searches internal documents and calls a billing application. The desired outcome is a draft proposal. The unwanted outcomes include disclosing another customer’s data, changing payment details or following instructions planted in a retrieved document. A network connection can be encrypted and correctly authenticated while the requested business action remains wrong. The security system needs enough context to distinguish those cases, and the application still needs its own authorization checks.
The first layer governs identity and privilege: which principal is acting, whose authority it carries and how much access it should receive. The second governs connections and content: which application or external service it may reach, and what information may leave. The third limits movement between systems and detects suspicious execution. Recovery is a separate responsibility. A clean, protected copy and a tested restoration sequence can reduce the damage after a destructive action; they cannot retroactively prevent stolen information from being disclosed.

The map is a functional example, not a purchasing sequence. One enterprise may combine several controls inside a platform; another may use a native cloud gateway plus independent recovery. Palo Alto overlaps with Zscaler and Fortinet, CrowdStrike competes for detection and response spending, and Commvault competes with Rubrik. The table below is the investment comparison; neither the diagram nor the number of layers assigns portfolio weights.
Zscaler’s agent-security announcement makes this concrete. Its AI Broker is designed to sit inline on agent communications, while AI Access Graph maps relationships between identities, applications and data. The announcement also extends controls to endpoint AI activity. These are vendor-described capabilities, not an independent efficacy test. The economic appeal is that an existing access platform can potentially add governance where enterprise traffic already passes. The coverage limit is equally important: routing, connectors, supported protocols and correctly configured policies determine which actions the platform can actually see. [Zscaler agent-security architecture](https://ir.zscaler.com/node/16276/pdf).

The illustrative policy allows an approved read and denies a database deletion and an external transfer. It is intentionally categorical, with no invented detection rate or latency benchmark. A production system has harder choices. Some tools expose broad permissions, some requests are encrypted beyond the inspection point, and legitimate workflows sometimes look unusual. A customer must balance control with availability. If false positives constantly interrupt useful work, employees will seek exceptions and the practical protection may shrink even while the dashboard reports wider deployment.
I see three sources of defensibility: integration into real workflows, accumulated security context, and reliable operation at scale. Writing a demonstration scanner does not reproduce those attributes. They are also not permanent monopolies. A platform must keep its integrations current, respond to new attack techniques and show that its operating cost remains tolerable. The advantage belongs to providers that can enforce useful decisions with enough reliability to remain in the workflow. Brand recognition alone is insufficient evidence, and a product launch alone is insufficient evidence of revenue.
Basket & Positioning
Selection starts with substitutes. A platform can have the strongest distribution and still demand too much future profit at its current price. A slower recovery vendor can offer a lower cash-flow hurdle without being the better product. I separate operating evidence from the price paid for it. Latest quarters below have different fiscal labels; ARR growth is reported unless the cell explicitly says organic.
Sources: [$PANW results](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-reports-fiscal-fourth-quarter-and-fiscal-10), [$ZS results](https://www.sec.gov/Archives/edgar/data/1713683/000171368326000156/zs-07312026_991.htm), [$FTNT results](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000018/ftntq2-2026ex991.htm), [$RBRK results](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Reports-Second-Quarter-Fiscal-Year-2027-Financial-Results/default.aspx), [$CRWD results](https://ir.crowdstrike.com/node/17376/pdf), [$NTSK results](https://www.netskope.com/press-releases/netskope-announces-strong-second-quarter-fiscal-2027-financial-results), [$CVLT results](https://ir.commvault.com/node/24406/html). Multiples use guidance midpoints detailed in Valuation. Quarterly and annual FCF are labeled and are not ranked as equal periods. Adjusted EPS, FCF and sales multiples answer different questions.
$ZS — monetizing activity beyond human seats
Zscaler connects authorized users and workloads to applications through a cloud security platform. Its investment appeal is the prospect of expanding from human access into branches, workloads, data and agents without having to win the customer from scratch each time. The fiscal 2026 filing describes a deployment across more than 200 public data centers, plus private sites, and says subscription and support supplied approximately 98% of annual revenue. Distribution and infrastructure are part of the product, not incidental expenses surrounding a software interface. [$ZS fiscal 2026 10-K](https://ir.zscaler.com/static-files/9c6b5564-b169-4f39-bff3-6281212488fe).
The latest quarter, reported September 3 for the period ended July 31, produced $898.2 million of revenue and $3.771 billion of ARR. Excluding Red Canary, ARR was $3.630 billion and grew 20%; net new ARR grew 17%. The distinction matters because acquisition-driven growth does not demonstrate faster demand in the original business. The constructive signal is the acceleration in organic net additions, while the caution is that the fiscal 2027 total ARR guide implies roughly 17% growth. I would not assume that a 25% reported exit rate continues automatically. [$ZS Q4 results](https://www.sec.gov/Archives/edgar/data/1713683/000171368326000156/zs-07312026_991.htm).
The CFO’s call commentary provides a more useful AI monetization indicator than transaction volume: non-seat-based metered offerings represented approximately 30% of new and upsell annual contract value in both the quarter and year. ARR associated with those offerings more than doubled. This is not a disclosure that 30% of total revenue comes from AI, nor that every agent generates a new seat. It does show that the commercial model is broadening beyond employees. I would track this mix alongside organic net additions and the conversion of large commitments into revenue. [$ZS Q4 transcript, 21:27–22:40](https://no5neo61wycllmc1.public.blob.vercel-storage.com/earnings-transcripts-pdfs/ZS-2026-09-03-transcript-1788504693314-a247bf.pdf).
The cash comparison is less flattering than the adjusted operating margin. Fiscal 2026 operating cash flow was $1.130 billion; free cash flow was $779.1 million, versus a GAAP net loss of $63.2 million. The approximately $351 million difference between operating cash and free cash covered capital expenditure and internal-use software. Noncash compensation and working-capital timing help explain why cash generation can coexist with accounting losses. That cash is valuable, but it should not be mistaken for profit available to shareholders without dilution or reinvestment. [$ZS cash-flow statement and reconciliation](https://www.sec.gov/Archives/edgar/data/1713683/000171368326000156/zs-07312026_991.htm).
At $191.73, the midpoint of FY2027 adjusted EPS guidance ($4.88) implies 39.3× earnings. That is the lowest forward adjusted P/E among the four profitable-on-an-adjusted-basis platform/network comparisons here. It is still a premium requiring durable contract growth. The reverse test below quantifies how much per-share progress is needed if the exit multiple falls to 30×.
Revenue and margin trajectory
Zscaler is the basket’s clearest example of why the long history and the latest quarter belong together. Annual revenue has more than tripled since fiscal 2022, and GAAP operating losses have narrowed sharply relative to sales. Yet the business has not completed that transition to annual GAAP operating profitability. A buyer can reasonably believe that scale will close the gap, but should also recognize that adjusted earnings exclude costs that matter to ownership economics. The following series uses rounded GAAP operating margins and reported revenue, not a synthetic organic history.
$PANW — a larger platform with a larger integration bill
Palo Alto offers the broadest platform expression in this basket. Its CyberArk acquisition closed on February 11, adding identity security to an existing network and security-operations footprint. The approximately $25 billion figure was the announced equity value of a cash-and-stock agreement, not a $25 billion cash payment. The original terms were $45 in cash and 2.2005 $PANW shares per CyberArk share. The attraction is the ability to sell additional protection into an established enterprise customer base; the obligation is to earn a return on the capital and shares used to acquire it. [Transaction terms](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-announces-agreement-to-acquire-cyberark--the-identity-security-leader), [closing announcement](https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era).
The September 1 release supersedes the $3.0 billion quarter in the August thread. Q4 revenue reached $3.41 billion, up 34%, and NGS ARR reached $9.10 billion, up 63%. Q4 GAAP operating income was $172 million, versus approximately $1.0 billion on an adjusted basis, and GAAP net income was negative. The fiscal 2027 revenue guide is $14.10–14.20 billion. These numbers establish the new scale of the combined company; they do not describe organic growth in the original Palo Alto business. [$PANW Q4 results](https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-reports-fiscal-fourth-quarter-and-fiscal-10).
The more revealing detail is inside the platform disclosures. Management said Prisma AI Runtime Security exceeded $100 million of ARR, while the acquired identity business, now called Idira, grew fiscal 2026 revenue 21% on a pro forma basis. The call also disclosed a nine-figure contribution to Q4 net new ARR from a large customer migrating to Chronosphere. That migration should not be extrapolated as a normal quarterly addition. I want the next reports to show broad customer expansion after that unusually large contribution rolls through the comparison. [$PANW Q4 transcript](https://investors.paloaltonetworks.com/static-files/b6d9916f-f4ab-4b43-8457-2d345aaa0a47).
Platformization is a useful operating lens, provided its definition travels with the chart. The presentation counts qualifying deployments across several platforms within the largest customers; one customer can contribute more than one platformization. The displayed retention figure excludes identity and observability where comparable history is unavailable. This prevents two mistaken conclusions: that the count represents distinct new customers, and that the retention statistic already demonstrates integration success across every acquired business. The slide is evidence of management’s chosen measure, not an independent estimate of market share. [$PANW presentation, slide 5](https://investors.paloaltonetworks.com/static-files/8864c425-7c5d-4471-85c9-cdbf9072cfe5).

At $373.94 and the FY2027 adjusted EPS guide midpoint of $4.175, the multiple is 89.6×. Palo Alto has disclosed paid AI Runtime business and broad distribution, but the acquisition-expanded platform needs to create per-share earnings after integration costs and additional shares. The broader platform is a business advantage to test, not a reason to ignore the purchase multiple.
What the platform mix reveals
The identity purchase has changed Palo Alto’s revenue composition, but it has not displaced the network business as the largest contributor. Using the company’s newly presented platform classifications, Network & AI Security supplied 68.4% of Q4 revenue and Cortex 17.2%; Idira supplied 9.9%, with other activities making up the remainder. Network & AI Security was 77.3% of fiscal 2025 revenue and 72.8% of fiscal 2026 revenue. Those annual comparisons include a changed acquisition perimeter, so the declining share does not mean the network business shrank.
$FTNT — profitable inspection capacity
Fortinet contributes a business with substantial current accounting profitability and a product position rooted in network infrastructure. Its combination of FortiGate appliances, FortiOS software and subscription services gives customers a way to enforce policy across distributed environments. Specialized silicon can make inspection more efficient, but the economic result depends on product mix, pricing, utilization and the service relationship that follows the sale. The thesis does not require every AI request to pass a Fortinet box. It requires enough customers to need more secure network capacity and to choose Fortinet when they buy it.
Q2 revenue was $2.05 billion, up 26%; product revenue was $773 million, up 52%. Products supplied about 38% of total revenue, versus roughly 31% a year earlier; services supplied about 62% of total revenue, versus roughly 69% previously. The seven-percentage-point shift shows that hardware contributed disproportionately to the acceleration. GAAP operating margin was 34%, compared with 38% adjusted. Operating cash flow of $1.04 billion converted into $966 million of free cash flow. Management’s full-year revenue range of $8.02–8.18 billion implies approximately 19% growth. This is stronger current profit evidence than a story resting entirely on a future agent-security module. [$FTNT Q2 results](https://www.sec.gov/Archives/edgar/data/1262039/000126203926000018/ftntq2-2026ex991.htm).
The counterargument is the cycle. Hardware orders can benefit from replacements, capacity upgrades and purchasing timing simultaneously. The next few quarters must distinguish a sustained expansion in the installed revenue base from an unusually favorable shipment period. The earnings presentation also shows that secure networking still accounts for most billings, with smaller contributions from unified cloud access and security operations. I would watch whether service growth and subscription adoption follow the appliance strength. A product spike without that follow-through would weaken the recurring-revenue argument. [$FTNT Q2 presentation](https://investor.fortinet.com/static-files/657dfcda-7367-4c36-8259-b0b43a535da1).
Fortinet’s latest price is about 49.5 times the midpoint of its $3.41–3.47 adjusted EPS guide. That is a premium multiple despite the hardware component. Its own history supplies a useful check: the house’s five-year, filing-date-aware series puts trailing GAAP P/E at approximately 60.1 times, versus a 56.9-times median, around the 55th percentile of observations. Being near a historical median does not make a stock cheap; it says that today’s premium is familiar in the sampled period. Different earnings definitions explain the gap between trailing GAAP and forward adjusted P/E.

$RBRK — recovery has to include the application
Rubrik’s place in the basket is easiest to understand after prevention fails. Restoring a file is useful; restoring a working business requires data, identity, configuration and dependencies to come back in the right sequence. The company’s autonomous business recovery announcement describes discovery of the application stack, protected recovery points and an orchestrated rebuild. These are claims about the product’s design. Customers still need realistic restoration tests, appropriate coverage and confidence that recovered systems are clean. A successful backup job is not proof that a complex business can restart on schedule. [Rubrik recovery architecture](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Introduces-Autonomous-Business-Recovery-Solution-for-Cloud-Applications/default.aspx).
The latest quarter delivered $427.3 million of revenue, up 38%, and subscription ARR of $1.66 billion, up 33%. Cloud ARR grew 39%, but that figure includes migrations; adjusted net new cloud ARR grew 20% excluding specified migration effects. GAAP gross margin declined from 79.5% to 78.4%. Free cash flow was $65.7 million, and the company remained loss-making under GAAP. These results support strong demand while reminding us that cloud growth, normalized new business and shareholder earnings are separate questions. [Rubrik Q2 results](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Reports-Second-Quarter-Fiscal-Year-2027-Financial-Results/default.aspx).
Agent Cloud creates an adjacent opportunity, but its commercial maturity should be kept in proportion. On the Q2 call, management described more than fifteen customers and cited a retailer expanding from existing recovery products into agent governance. That is encouraging early adoption, not evidence that agent security already dominates revenue. I underwrite the recovery franchise first and treat broader agent governance as potential upside. The company must turn trials and initial production deployments into measurable recurring business while continuing to serve the recovery workloads that fund its expansion. [$RBRK Q2 call, 13:52–16:13](https://no5neo61wycllmc1.public.blob.vercel-storage.com/earnings-transcripts-pdfs/RBRK-2026-08-27-transcript-1787899655503-f5c052.pdf).
A September product release gives a concrete example of why the recovery problem becomes richer as data architectures change. Rubrik’s Apache Iceberg protection includes both data and table metadata, with catalog reconnection during restoration. That matters because a collection of saved objects is less useful if the application cannot interpret or query it. The announcement strengthens the product logic, though it does not quantify material near-term revenue. My test is whether expanding workload coverage increases protected capacity and customer spend without sacrificing cash conversion. [Iceberg protection, September 8](https://ir.rubrik.com/news-events/press-releases/news-details/2026/Rubrik-Launches-Lakehouse-Protection-with-Apache-Iceberg-Data-on-AWS/default.aspx).
At $100.20, the FY2027 guide’s 228 million weighted diluted shares imply a $22.85 billion equity-value proxy. Dividing by revenue guidance midpoint $1.689 billion gives 13.5× sales; dividing by FCF midpoint $328 million gives 69.7× cash flow. This uses guided weighted shares, not a verified current fully diluted capitalization. The Commvault comparison below tests whether Rubrik’s faster growth earns that cash-flow premium.
Management & Track Record
Palo Alto’s four-call sequence is a useful management scorecard. In Q1 fiscal 2026, leadership discussed expanding platform adoption before the two large acquisitions closed. In Q2, it laid out integration plans and explicitly explained that CyberArk’s ARR definition would be conformed to Palo Alto’s. In Q3, it separated the acquired contribution and gave a Q4 revenue range of $3.345–3.355 billion. Q4 reached $3.41 billion. That is a verifiable execution beat, but the changing business perimeter prevents a simple comparison of headline ARR growth across the entire year. [Q1 call](https://investors.paloaltonetworks.com/static-files/634119c3-7098-4d6e-8ae1-28bf28ac1e14), [Q2 call](https://investors.paloaltonetworks.com/static-files/16d1b661-d762-4918-b2c6-e3ed8bef4e32), [Q3 call](https://investors.paloaltonetworks.com/static-files/ea18c9ae-cbe6-4b5d-aa7c-65a6b9aeb2e2).
Nikesh Arora’s capital-allocation test is now larger than executing another small product acquisition. Shareholders need evidence that the expanded platform grows per-share earnings and cash, not merely the consolidated revenue base. Jay Chaudhry’s team at Zscaler has a different test: convert its architecture into faster organic additions while managing the infrastructure bill. Ken Xie’s Fortinet must convert strong hardware demand into a durable service relationship. Bipul Sinha’s Rubrik must expand recovery coverage and emerging agent products without allowing dilution and reinvestment to consume the benefits of growth. Their latest calls and releases establish these roles; the judgments are mine.
Same-role challengers — $CRWD, $NTSK and $CVLT
CrowdStrike is a serious platform alternative to Palo Alto. Q2 FY2027 revenue rose 26% to $1.471 billion, ARR reached $5.84 billion, and net new ARR rose 51% to $332.8 million. FCF was $377.4 million. The FY2027 guide calls for roughly $6.001 billion revenue and $1.255 adjusted EPS at the midpoints. Crucially, the release restates share and per-share figures for the July 2026 four-for-one split. The $235.38 close therefore implies 187.6× guided EPS; applying pre-split EPS would materially understate valuation. [CrowdStrike results](https://ir.crowdstrike.com/node/17376/pdf).
CrowdStrike’s first-half stock compensation was $674.6 million against $845.9 million FCF; Q2 GAAP operating margin remained about −2%. Falcon Flex demonstrates platform selling, but ARR at Flex-adopting customers is not incremental AI revenue. Compared with Palo Alto, CrowdStrike offers strong recurring-contract momentum and less dependence on a CyberArk-sized integration. The tradeoff is a much higher earnings hurdle. Neither gets selected solely because its product can secure agents. [CrowdStrike filing](https://www.sec.gov/Archives/edgar/data/1535527/000153552726000031/crwd-20260731.htm).
Netskope tests the Zscaler preference. Q2 FY2027 revenue grew 29% to $220.5 million and ARR grew 27% to $899 million. Its GAAP operating margin was −41%, adjusted margin −9%, and quarterly FCF −$29.8 million. FY2027 guidance implies about $890 million revenue and a 2% FCF margin. Using 415 million guided weighted shares gives 7.9× sales at $17.00. Faster growth comes with a much earlier cash-conversion stage; Zscaler remains the stronger current cash-generation choice. [Netskope results](https://www.netskope.com/press-releases/netskope-announces-strong-second-quarter-fiscal-2027-financial-results).
Netskope expensed $63.0 million of stock compensation in the quarter. IPO-related recognition affects the GAAP comparison, so the loss increase should not be read as equivalent deterioration in unit economics. Loss-period weighted shares also exclude anti-dilutive awards; the 415 million proxy is not a fully diluted ownership count. To displace Zscaler on this shortlist, Netskope needs a repeatable cash-margin trajectory and evidence that the sales discount survives dilution. [Netskope filing](https://www.sec.gov/Archives/edgar/data/2063196/000119312526380428/ntsk-20260731.htm).
Commvault changes the recovery comparison. Q1 FY2027 revenue rose 11% to $314.1 million; subscription ARR rose 22% to $1.054 billion. GAAP operating margin was 8.2%, FCF $51 million, and subscription net retention 114%. The full-year FCF guide midpoint is $255 million. At $140.21 and roughly 42 million guided diluted shares, the equity proxy is $5.89 billion, or 23.1× FCF versus Rubrik’s 69.7×. Rubrik grows faster; Commvault asks much less of future cash generation. That makes Commvault the first recovery valuation to investigate, not an automatic buy. [Commvault results](https://ir.commvault.com/node/24406/html).
The apparent discount needs an ownership and accounting check. Commvault’s quarter included $35.3 million stock compensation; subtracting that from the rounded $51 million FCF leaves about $15.7 million as a rough ownership-cost screen, not a reported metric or annual forecast. Term-license and SaaS revenue recognition differ, so revenue growth alone is an imperfect product comparison. Lower P/FCF does not settle renewal quality, recovery reliability or share dilution. [Commvault filing](https://www.sec.gov/Archives/edgar/data/1169561/000116956126000024/cvlt-20260630.htm).
What AI customers are actually paying for
A paid product can matter without being material to the whole company. The evidence ladder below separates a dollar disclosure from commercial proxies and product availability. “Unproven” means this research has not isolated incremental agent-security dollars; it does not mean the company has no such customers. A new SKU, a pilot or an AI label cannot be added to a revenue model as though it were a disclosed contract.
The relevant issuer results and transcript passages are cited in each company section. None of these disclosures establishes that each additional agent creates a separately billed seat. Palo Alto has the clearest product-level paid amount in this comparison; Zscaler’s non-seat contracts are a useful commercial bridge, but they also include non-AI workloads. The other companies need more specific disclosure before agent counts can drive our sales estimates.

Competition starts with the budget the customer already has
Microsoft can make the incremental price of an AI security feature appear small to an existing enterprise customer. Eligible Microsoft 365 E5/E7 subscriptions include Security Copilot capacity: 400 SCUs monthly per 1,000 paid licenses, capped at 10,000 SCUs. This is a bounded allowance, not unlimited free security. It puts pressure on standalone investigation software to prove an outcome beyond the included capacity and existing identity/security integration. [Microsoft capacity terms](https://learn.microsoft.com/en-us/copilot/security/security-copilot-inclusion).
AWS meters AgentCore Policy authorization requests while AgentCore Identity has no additional charge when used through Runtime or Gateway. Identity therefore can be bundled into infrastructure that already bills for other work. An independent control provider needs a reason to sit outside that stack: multi-cloud visibility, stronger policy, cross-application governance or lower total operating cost. “Every agent needs identity” alone does not identify the vendor paid. [AWS pricing and scope](https://aws.amazon.com/bedrock/agentcore/pricing/).
Google completed its Wiz acquisition in March 2026 and describes continued multi-cloud support. That combines a cloud-security competitor with a hyperscaler’s distribution; it challenges the assumption that consolidation only benefits the listed pure plays. Private vendors also compete at the control point: Noma announced agent access and MCP-server policy controls. These are product and distribution facts, not proof that either wins every deployment. [Google/Wiz](https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz); [Noma announcement](https://noma.security/blog/noma-launches-agentic-access-control-to-govern-ai-agents-and-mcp-servers-across-the-enterprise).
The independent-vendor moat must show up at renewal: customers paying for wider coverage, reliable enforcement and recovery, or measurable operating savings after the bundle is considered. Native tools can also be a distribution channel, particularly for recovery products integrated into a cloud marketplace. The next research step is a deployment-and-renewal comparison, not an assumption that hyperscalers either eliminate or validate every specialist.
The short argument against vulnerability-management vendors deserves a narrower formulation. AI may make finding and explaining weaknesses cheaper, increasing competitive pressure on products that cannot convert findings into action. That does not establish that Tenable or Qualys only perform code review. Tenable’s current offering includes AI exposure discovery, access context and governance; Qualys documents an agent for validating exploitability and prioritizing remediation. A product announcement does not prove those capabilities beat competitors, but it directly challenges the assumption that incumbents will remain static while AI improves. [Tenable AI Exposure](https://www.tenable.com/press-releases/tenable-extends-exposure-management-to-AI-attack-surface), [Qualys Agent Val](https://docs.qualys.com/en/etm/latest/agentic_ai/agent_val.htm).
The latest financial evidence also complicates an immediate obsolescence thesis. Tenable grew Q2 revenue 8.6% and reached a positive 4.6% GAAP operating margin. Qualys grew revenue 11% and reported a 34% GAAP operating margin. Those growth rates are lower than the core basket’s, but they are not a collapse. My threshold for a short would be persistent deterioration in retention, pricing or competitive wins, confirmed by weaker guidance and a valuation that still assumes resilience. This memo does not have that full evidentiary package and therefore does not recommend a $TENB/$QLYS short overlay. [Tenable Q2](https://investors.tenable.com/news-releases/news-release-details/tenable-announces-second-quarter-2026-financial-results), [Qualys Q2](https://www.sec.gov/Archives/edgar/data/1107843/000110784326000034/qlys-20260804xex991.htm).
Risks & What Breaks It
The most direct risk is that AI activity rises faster than paid security revenue. Customers may negotiate broad bundles, use native cloud controls, or demand lower prices as vendors automate their own work. That would produce impressive transaction statistics with disappointing net additions. I would downgrade the thesis if the next two reporting cycles show continued product promotion but slowing underlying demand, especially if sales incentives, free periods or acquisitions are needed to preserve headline growth. A longer runway is not a sufficient explanation for repeated deterioration in the measures already disclosed.
A second risk is operational concentration. Customers consolidate vendors to simplify their environment, but a widely deployed security platform can itself become an availability dependency. A bad update, outage, configuration error or compromised control system can impair the customer’s business. Recovery vendors face a related test: backups must be isolated enough to survive the incident, and restoration must work at the application level. These risks support layered architecture, but they can also limit how much of the stack a customer will entrust to one company.
A third risk is that higher cost absorbs the incremental opportunity. More encrypted traffic can require greater inspection capacity; more protected data requires storage; broader products require engineering and support. Stock-based compensation can fund expansion while diluting owners. Acquisition accounting can widen the gap between adjusted profit and GAAP results. I would therefore evaluate revenue per share, free cash flow per share and operating margins together. A rising cash-flow total can be less impressive when the share count rises alongside it or when the company adds back recurring economic costs.
Finally, the stocks can disappoint even if the businesses execute. Today’s rally raises the earnings hurdle, and the four names remain exposed to a common change in risk appetite. Slower growth, higher interest rates or a rotation away from premium software could compress multiples across the basket at once. Options walls offer no protection against that repricing. A measured allocation, staggered entry points and explicit valuation limits are more useful than assuming cybersecurity spending is immune to the price investors pay for it.
Price Setup
The following four price/options pairs document the original operating case studies. Their intraday capture times remain on the images. The seven-company valuation tables use the common regular close stated above. Options concentrations aggregate expirations and can change; they do not supply the earnings or cash-flow hurdle. The newly compared names are research alternatives, with no proposed trade or technical-entry call.
$ZS

$ZS: the captured call wall is $200 and put wall $160. These identify contract concentration; the investment question remains organic contract growth and per-share economics.

$PANW

$PANW: the captured call wall is $380 and put wall $300. The lower strike is far from the reference close and is not a tight risk limit.

$FTNT

$FTNT: the captured call wall is $170 and put wall $155. The $170 concentration is near the closing price, not a guaranteed ceiling.

$RBRK

$RBRK: the captured call wall is $100 and put wall $102. The put wall is above the $100.20 regular close; describing it as support below spot would be wrong.

Valuation & House View
This is a comparative return-hurdle screen, not an intrinsic-value model or a set of price targets. I ask what per-share earnings or FCF must become to earn a 12% annual price return over three years, before dividends, fees and taxes. The hurdle is a house screening assumption, not a forecast. The equation is: required future metric per share = today’s price × 1.12³ ÷ exit multiple. Required annual growth compares that result with the guided annual starting metric. Fiscal year-ends differ; these are three-year economic transitions from each guided base, not synchronized calendar-quarter forecasts.
The disclosed anchors are annual adjusted EPS midpoints of $4.175 for $PANW (FY27), $4.88 for $ZS (FY27), $3.44 for $FTNT (CY26), and $1.255 for $CRWD (FY27, split-adjusted). For recovery, guided FCF divided by guided weighted diluted shares gives $1.439 for $RBRK ($328m/228m) and $6.071 for $CVLT ($255m/42m). Netskope’s guide implies only about $0.043 FCF per weighted share ($890m revenue × 2% margin /415m). These share proxies are not current fully diluted market capitalizations. Sources are the linked results in the comparison table; the attached issuer presentation also supplies Palo Alto’s guidance.
What today’s price requires
I show 30×/40×/60× adjusted earnings and 20×/30×/40× FCF as sensitivity ranges. These are disclosed stress assumptions, not estimated fair multiples. Today’s adjusted earnings peers span 39.3× to 187.6×; carrying the highest premium forward would decide the answer before the business does. The Fortinet historical chart uses trailing GAAP earnings and therefore cannot calibrate these forward adjusted exits. Comparable historical adjusted series for all seven names have not been established here. A lower exit makes execution do more of the work.
Cells show the required annual EPS growth over three years. Zscaler needs 22.5% at a 30× exit or 11.3% at 40×. Palo Alto needs 46.5% at 40×, and CrowdStrike 87.5%; even a 60× exit asks CrowdStrike for 63.8%. Those are arithmetic requirements, not forecasts of failure or success. An investor keeping a much higher terminal premium can obtain a different answer, but that premium is then a central investment assumption.
Recovery and the cost of growing cash flow
At a common 30× FCF exit, Rubrik needs 48.3% annual FCF-per-share growth; Commvault needs 2.6%. At a stricter 20× exit, Commvault’s requirement rises to 17.5%. That sensitivity is why “cheaper” is a research lead rather than a completed buy case. Netskope’s tiny positive guided cash base makes its growth percentage unstable: at 30×, the same return requires about $330m FCF after three years with flat shares. If revenue grows 25% annually from $890m, the required exit FCF margin is about 19%, versus the current 2% guide. Both revenue growth and margin expansion are assumptions.
Ownership matters. The tables require per-share growth. With 3% annual share growth, Rubrik’s 48.3% per-share cash hurdle becomes about 52.8% total FCF growth; Commvault’s 2.6% becomes 5.7%. These are dilution sensitivities, not share forecasts. Conversely, buybacks can improve per-share results, but use cash and cannot also be counted as an additional cash distribution in this price-return test. Adjusted EPS excludes costs that GAAP recognizes; reported FCF adds back stock compensation. Neither should be mistaken for an ownership-cost-free return.
House view — wait, with a narrower research order
I would not initiate a broad cybersecurity basket on the evidence and September 14 prices in this memo. The theme is credible, but paid agent revenue is often unquantified and several valuations require substantial per-share growth or persistent premium multiples. Commvault comes first for a recovery cash-flow and renewal investigation; Zscaler comes first for cloud-access economics. Palo Alto, Fortinet and Rubrik remain operating watch candidates. CrowdStrike’s commercial strength merits coverage, but its price imposes the highest earnings hurdle; Netskope needs proof of cash conversion. None of those rankings establishes an entry price. A buy case requires a fuller audited cash-flow model, comparable renewal evidence and a defensible margin of safety.
These are analyst review thresholds, not management promises or automatic trading triggers. A price decline also lowers the required-growth hurdle even if estimates are unchanged. Recheck by November 20, 2026, and earlier on earnings, material acquisitions, a major outage or revised commercial pricing. The weakest shared assumption is that incremental agent activity becomes incremental profitable spending for independent vendors after bundled alternatives and ownership costs. That assumption must improve before the house view becomes a buy.