Key Points
The cybersecurity sector underperformed in 2025
The cybersecurity sector, as measured by the Global X Cybersecurity ETF (NASDAQ: BUG) underperformed in 2025, returning -5.1% (in USD terms). This came on the back of a challenging macro environment with companies being more cautious about IT spending. According to IANS 2025–2026 Security Budget Benchmark Report, security budget grew just 4% in 2025, down from 8% in 2024.
The underperformance of BUG in 2025 was further compounded by the sharp decline in Fortinet’s share price, one of the fund’s largest and most influential holdings. Following its August 2025 earnings release, Fortinet’s stock plummeted over 22% in a single session after the company disclosed that its highly anticipated firewall refresh cycle contributed less to revenue growth than investors had expected. The stock remained largely flat for the remainder of the year.
Year-to-date, as of 20 February, BUG has declined a further 16.1%. Cybersecurity stocks have sold off alongside the broader software sector, as investors grow increasingly concerned that AI-native companies could undermine their competitive advantages and business models. For instance, Anthropic recently launched new plug-ins for its Claude AI agent that can handle a range of administrative tasks, along with a security feature that can scan entire codebases for vulnerabilities and suggest targeted fixes for developers to review. These advancements have heightened fears that AI platforms may begin competing directly with traditional software and cybersecurity providers.
Related article: SaaSpocalypse: Software stocks crash on AI disruption fears – But is the market overreacting?
Figure 1: Cybersecurity stocks have underperformed the broader US market
Positive long-term outlook, with uneven growth across the sector
We remain positive on the cybersecurity sector over the long term, as both the volume and sophistication of cyber threats continue to rise. Data from Check Point Research shows that global cyberattacks are escalating, with organisations experiencing an average of 2,090 attacks per week in January 2026, up 17% year-on-year.
Threat actors are increasingly leveraging AI to sharpen and scale their operations. Generative AI tools, for example, help criminals create convincing phishing emails (fake emails designed to steal information), deepfake impersonations (AI-generated fake videos or voices), and automated hacking programs. This has driven up both the frequency and effectiveness of attacks.
At the same time, the rapid adoption of AI within enterprises is expanding the attack surface. When businesses integrate generative or agentic AI (AI systems that can act more independently) into their workflows, they may expose themselves to problems such as:
· Prompt injection attacks: tricking AI systems into giving away sensitive information or performing unintended actions
· Data leakage: confidential data being exposed unintentionally
· Excessive system access: AI tools having more access to company systems than they should
As organisations accelerate digitalisation and AI deployment, many remain underprepared for these emerging risks, with defensive capabilities struggling to keep pace with an increasingly complex threat landscape. This gap underlines the structural need for sustained, long-term investment in cybersecurity solutions.
Adding to this pressure, an increasingly fragmented geopolitical environment has seen state-sponsored attacks targeting critical infrastructure, corporations, and financial systems, reinforcing cybersecurity as a strategic imperative rather than a discretionary IT expense.
Building on this, we believe cybersecurity stocks are relatively insulated from AI-driven disruption. Unlike broader software companies, the technical complexity and mission-critical nature of cybersecurity solutions make it difficult for enterprises to replace established products. Security breaches carry catastrophic financial, reputational, and legal consequences, and organisations cannot simply code their own cybersecurity software using large language models without taking on significant risk. At the same time, many leading cybersecurity firms are actively leveraging AI to strengthen their solutions by improving detection, response, and automation to address the growing scale and complexity of cyber threats, thereby reinforcing rather than undermining their market position.
That said, while the cybersecurity sector is structurally well-positioned and relatively insulated from AI disruption, near-term growth may be moderated by corporate budget constraints. Security spending is expected to expand only modestly in 2026, with 56% of organisations surveyed by UBS Evidence Lab anticipating 1–5% growth, 23% expecting increases of 6% or more, and 18% projecting no change. As budgets come under pressure, investors should focus on companies with exposure to higher-priority spending areas and those well-placed to benefit from ongoing vendor consolidation.
Focus on cloud, identity, and AI security solutions
According to the UBS Evidence Lab survey, Chief Information Security Officers rank cloud security and identity security as their top priorities for additional spending.
Figure 2: Budget expectations by segment

Source: UBS Evidence Lab. Data as of November 2025.
Cloud security remains the fastest growing cybersecurity segment, with Gartner expecting 30% growth in 2026. As organisations invest in AI infrastructure and increasingly migrate their data and applications to the cloud, cloud is an important and expanding risk surface which needs protection against. Companies with cloud security solutions include SentinelOne, Zscaler, CrowdStrike and Palo Alto Networks.
Identity security is another segment receiving significant attention, driven by the rapid growth of machine identities, which expands the attack surface. According to CyberArk, machine identities outnumber human identities by 82 to 1 in 2025, presenting organisations with the dual challenge of verifying human users while managing and securing a rapidly expanding population of non-human identities. This creates a growing need for identity solutions that can detect compromised credentials, govern privileged access, and prevent sophisticated spoofing attacks (where attackers impersonate legitimate users to gain unauthorised access). Leading companies with exposure to this theme include SailPoint, Okta, CrowdStrike, Palo Alto Networks, and CyberArk (soon to be acquired by Palo Alto Networks).
Besides cloud and identity security, cybersecurity providers offering AI-powered solutions are poised for strong growth. AI not only helps tackle the increasing complexity of cyber threats but also addresses the shortage of skilled professionals, with an estimated 4.8 million unfilled cybersecurity roles globally. These solutions can automate security operations (SecOps), accelerate threat detection, reduce mean-time-to-response (MTTR), and enhance analyst capabilities, effectively narrowing the talent gap. Tools like CrowdStrike’s Charlotte AI showcase how AI can triage and investigate threats more quickly and efficiently, improving overall security outcomes. Companies best positioned to benefit from this trend include CrowdStrike, Palo Alto Networks, and SailPoint, all of which are integrating AI into their platforms to meet growing enterprise demand.
Preference for platform leaders
Vendor consolidation, also known as platformisation, remains a key structural trend within the cybersecurity industry. In the past, companies often bought separate “best-of-breed” tools for different needs, such as identity protection, endpoint security, and cloud security. Now, many companies prefer to use a single, integrated platform that covers multiple security functions in one system. This helps to simplify vendor management, lower operational complexity, and reduce costs.
Beyond cost efficiencies, integrated platforms can also deliver stronger security outcomes. By consolidating data from across an organisation into a single environment, these platforms can detect threats more accurately and respond more quickly. As more customers adopt them, the amount and diversity of data grow, further improving detection capabilities. This creates a virtuous cycle: better security attracts more customers, whose data in turn strengthens the platform, gradually building a durable competitive advantage.
Leading vendors are accelerating this strategy through targeted acquisitions to expand product breadth and close capability gaps. For instance, Palo Alto’s upcoming acquisition of CyberArk will enhance its identity security capabilities and strengthens its position as a comprehensive platform provider. Other examples of platform leaders include CrowdStrike, Fortinet, and Zscaler.
We expect platform leaders to continue gaining market share as customers consolidate spending with fewer, larger vendors. In an environment of constrained IT budgets, companies offering broad, integrated platforms are better positioned to capture a larger share of customer spending and potentially outgrow the broader cybersecurity market.
Overall, we favour platform vendors with meaningful exposure to high-priority spending areas such as cloud, identity, and AI security, as they are well positioned to benefit from both ongoing vendor consolidation and mission-critical security spending. Examples include Palo Alto Networks and CrowdStrike, both of which combine broad platform capabilities with strong exposure to these key growth segments.
The cybersecurity sector offers an attractive upside
Investing in individual cybersecurity names can offer higher upside, but it also entails greater volatility. Companies that fail to meet earnings or revenue expectations may experience sharp price declines, as illustrated by Fortinet last year amid elevated growth expectations. For investors seeking exposure to this high-growth sector with a lower risk appetite, a diversified ETF such as BUG, which holds 30 cybersecurity companies, may provide more a stable return profile.
More aggressive investors, however, may find BUG less appealing, as individual index constituents are capped at 6% at each semi-annual rebalancing, potentially limiting upside if platform leaders capture a disproportionate share of growth.
In any case, the recent selloff in cybersecurity stocks presents an appealing entry point for investors. Applying a fair price-to-earnings multiple of 35x to projected 2027 earnings for the Indxx Cybersecurity Index, we estimate a target price of USD 50 for BUG, implying roughly 95% upside from its closing price of 25.6 USD on 20 February 2026.
Table 2: Projections for the Indxx Cybersecurity Index
|
IBUGT Index |
2024 |
2025E |
2026E |
2027E |
|
Earnings Per Share (EPS) |
66.5 |
78.4 |
86.5 |
99.2 |
|
Earnings Growth YoY |
73.3% |
17.9% |
10.3% |
14.8% |
|
PE Ratio (X) |
26.7 |
22.7 |
20.6 |
17.9 |
|
Target Price for Index (based on a fair PE of 35X) |
3,473 |
|||
|
Upside Potential |
95.4% |
|||
|
Target Price for ETF (USD) |
50 |
|||
|
Source: Bloomberg Finance L.P., iFAST Compilations. Data as of 20 February 2026 |
||||
Figure 3: Share prices are driven by earnings growth in the long run

Declaration:
This research report was prepared with the assistance of artificial intelligence (AI) tools. iFAST Financial Pte Ltd does not rely exclusively on AI for content generation; the content of this report – including all investment theses, ratings, price targets and conclusions – has been independently reviewed and verified by the research analyst(s) to ensure accuracy and professional integrity.
For specific disclosure, at the time of publication of this report, IFPL (via its connected and associated entities) holds a NIL position in the abovementioned securities. The analyst who produced this report holds a position in Fortinet.
All materials and contents found in this site are strictly for general circulation and informational purposes only and should not be considered as an offer, or solicitation, to deal in any of the funds or products found/identified in this site. While iFAST Financial Pte Ltd ("IFPL") has tried to provide accurate and timely information, there may be inadvertent delays, omissions, technical or factual inaccuracies and typographical errors. Any opinion or estimate contained in this report is made on a general basis and neither IFPL nor any of its servants or agents have given any consideration to nor have they or any of them made any investigation of the investment objective, financial situation or particular need of any user or reader, any specific person or group of persons. You should consider carefully if the products you are going to purchase are suitable for your investment objective, investment experience, risk tolerance and other personal circumstances. If you are uncertain about the suitability of the investment product, please seek advice from a financial adviser, before making a decision to purchase the investment product. Past performance is not indicative of future performance. The value of the investment products and the income from them may fall as well as rise. Opinions expressed herein are subject to change without notice. In respect of any matters arising from, or in connection with the said research analyses or research reports, recipients of the report are to contact IFPL at 10 Collyer Quay, #26-01 Ocean Financial Centre Building, Singapore 049315, or by telephone at +65 6557 2853. Where the report contains research analyses or research reports from a foreign research house and if the recipient of such research analyses or research reports is not an accredited investor, expert investor, institutional investor or an ex-accredited investor, IFPL accepts legal responsibility for the contents of such analyses or reports to such persons only to the extent as required by law. Please note that only certain security(ies) herein are available to all investors, while the rest are only available for certain persons to invest in, such as Accredited Investors (as defined in the Securities and Futures Act) or one who invests at least S$200,000 (or its equivalent currency) per transaction. To qualify as an Accredited Investor, one needs to submit a declaration form and certain relevant supporting documents, according to iFAST’s prevailing policies and procedures.
Please read our full disclaimers on the website at ( https://secure.fundsupermart.com/fsmone/policies/328125/investment-account-terms-&-conditions).
iFAST Financial Pte Ltd (IFPL) (registered address: 10 Collyer Quay #26-01 Ocean Financial Centre Singapore 049315, Telephone: 6557 2000) holds the Financial Advisers Licence issued by the Monetary Authority of Singapore ('MAS') to conduct regulated activities of advising on securities, marketing of collective investment schemes and arranging of any contract of insurance in respect of life policies, other than a contract of reinsurance and the Capital Markets Services Licence issued by the MAS to conduct regulated activities of dealing in securities and providing custodial services for securities. While IFPL has made every effort to ensure the independence of the report's contents, IFPL's nature of business is such that IFPL and its connected and associated entities together with their respective directors, officers and staff may be involved in providing dealing or investment-related services in the abovementioned securities, and have taken or may take positions in the securities mentioned in this report, and may also act as the principal for any buy or sell trades.
