品
Logo
Corea든 Korea든, 품격은 이름보다 먼저다
Whatever the name—Corea or Korea—dignity comes first.
Whatever the name—Corea or Korea—dignity comes first.
Now
지금
751 Diaspora
Heritage
유산
Humanity
인문
Mirengsi
未冷尸
Politics
정치
Media
언론
Thumbnail
젠슨 황이 사이버보안을 “AI의 다음 핵심 시장”으로 지목한 이유
category-icon

돈經濟

칼럼
panda_Lee

Cybersecurity Stocks in the AI Era: Structure Before Prediction

Views
0
2026. 09. 23
  • Cybersecurity in the AI era is being redefined from merely a defense cost to an essential infrastructure industry managing new AI-driven attacks and identities.
  • As generative AI and agentic AI accelerate attack speeds, the structural demand for AI-based security solutions for detection, prediction, and blocking will drive market growth.
  • The Korean market, in particular, is seeing accelerated growth in the AI security market due to unique geopolitical and policy factors like North Korean threats, public institution regulations, and relaxed network separation, emerging as both a global consumer market and one with distinct demands.
  • When investing in AI security, it's crucial to consider platform transitions, companies with proactive defense capabilities, and diversified investments based on structural demand in both domestic and international markets from a long-term perspective, while being wary of thematic short-term fluctuations.
  • Globally, CrowdStrike and Palo Alto Networks are leading AI security platforms, and domestically, AhnLab is expected to play a pivotal role by transitioning to an AI-native security platform.
In the age of AI, cybersecurity is not a defense cost.
It is being redefined as an essential infrastructure industry that manages new attack surfaces and new identities (agents) created by AI. As generative AI and agentic AI accelerate the speed at which they write code, find vulnerabilities, and automate penetration paths, the demand for using the same AI for detection, prediction, and blocking also structurally increases. This is why Jensen Huang identified cybersecurity as “AI’s next killer market.” If AI creates the problems, then AI must also solve them.
 
Looking at market forecasts, overall information security spending is already on a major growth trajectory. Gartner estimates global information security spending to be around $240 billion to $249 billion in 2026, continuing double-digit growth thereafter to expand to approximately $320 billion to $370 billion by 2029-2030. Among these, the security market directly integrated with AI is growing even more steeply. Although the scope varies by research firm, scenarios repeatedly show it starting from $25 billion to $43 billion in 2026 and growing to around $50 billion to $100 billion by 2030-2031. The compound annual growth rate is generally in the 15-25% range. A more significant qualitative change is 'preemptive security.' Gartner estimates that preemptive security, which accounted for only 5% of IT security spending in 2024, will make up about half by 2030. This is based on the judgment that a model of detection and response alone cannot keep up with the accelerated attack speed compressed by AI. The background for this is the forecast that documented software vulnerabilities (CVEs) will increase from approximately 270,000 currently to nearly 1 million by 2030.
 
The Korean market is heading in the same direction, but policy and geopolitics play a stronger role. The domestic cybersecurity market is projected to exceed approximately 4 trillion won by 2026, with some forecasts suggesting it could grow to around 18 trillion won by 2030. Some surveys also predict that the total security market (physical + cyber) will surpass 10 trillion won by 2026. Demand is being driven by cyber threats from North Korea, regulations on public and critical infrastructure, the introduction of generative AI after the easing of network separation, and the transition to Post-Quantum Cryptography (PQC) promoted by the National Intelligence Service (reflecting public evaluation → mandatory implementation of some algorithms by 2029). The government has also set a direction to grow the information security industry by 2030 and foster AI security unicorns. In other words, Korea is both a consumer market for global AI security platforms and a market with unique demands related to data sovereignty, public procurement, and cryptographic transitions.
 
The investment strategy should be a combination of structural demand, platform transformation, and valuation discipline, rather than theme-following.
First, a long-term perspective is necessary. Cybersecurity is one of the few industries where demand remains strong even if the AI boom succeeds, fails, or if regulatory and accident risks increase. This is because as the attack surface expands, defense budgets increase, and as talent shortages worsen, demand for automation (agentic SOC, XDR, SOAR) grows. However, periods of sharp stock price surges, like the AI risk headlines in September 2026, are repeated. Rather than chasing such rallies, a strategy of investing in installments over 3-5 year periods is more realistic.
 
Second, it is better to focus on platforms, identity, and proactive defense rather than standalone security products. Every time an AI agent is created, new accounts, permissions, activity logs, and data access paths are generated. Therefore, platform companies that provide a single console view of endpoints, clouds, and networks, and identity companies that manage human, machine, and AI agent identities, are structurally advantageous. Zero Trust, SASE, data security (DSPM), and cyber resilience (backup, ransomware recovery) follow the same trend.
 
Third, it is practical for Korean investors to divide their investments into global and domestic. Global leaders dominate technology standards and large customers, but their valuations are already high. Domestic companies have local momentum such as public, financial, network separation relaxation, and PQC, but their scale and global competitiveness are challenges. Global exposure can be diversified through individual stocks and baskets such as HACK, CIBR, or domestically listed TIGER Global Cybersecurity ETF.
 
Fourth, risks must be clearly identified. After major stocks like CrowdStrike and Palo Alto rose sharply in 2026, expectations are already largely reflected in the price. Variables include failed M&As during platform integration, AI features not meeting actual effectiveness, regulatory fragmentation (different AI and data rules in the US, Europe, and China), and market share erosion by traditional firewall companies. Domestic small and medium-sized stocks often experience severe thematic fluctuations and have poor earnings visibility. Therefore, it is safer to stratify the portfolio, with 40-60% in core platforms, 20-30% in domestic policy beneficiaries, and 10-20% in satellite small/medium-sized and thematic stocks.
 
Potential companies have different roles.
Globally, CrowdStrike (CRWD) is the closest to the purest expression of the AI security theme. Based on its cloud-native endpoint and XDR Falcon platform, it is expanding into SOC automation and agent security, and the company itself believes it can grow its TAM to $325 billion by 2030. It is also the stock that has reacted most sensitively to the recent AI risk debate. Palo Alto Networks (PANW) is closest to perfection in terms of scale and product breadth. It aims to integrate network, cloud, and security operations into a platform, and by adding identity (CyberArk acquisition), it seeks to bring human, machine, and AI agent identities into one axis. While its growth rate and market dominance are strong, it already commands a high premium. Fortinet (FTNT) stands out in terms of relative value and profitability. It simultaneously leverages hardware-based performance advantages and SASE expansion, making it less burdensome compared to high-growth software. Zscaler (ZS) is a leading player in zero-trust and cloud access control, which makes logical sense as AI workloads and distributed access increase. Other auxiliary candidates include SentinelOne (AI-native endpoint), Okta/SailPoint (agent identity), Cloudflare (edge/traffic security), and Rubrik (cyber resilience).
 
In Korea, AhnLab (053800) is essentially the core. On September 16, 2026, it officially announced its transformation into an 'AI-native security platform company,' pledging to invest 100 billion won in AI over three years and setting targets of 1 trillion won in sales and a 30% global share by 2035. It boasts 13 security-specific AI models, over 2.5 PB of security data, and achievements in reducing SOC work hours. Its market capitalization is approximately 630 billion to 650 billion won, and its PER is around 13x, which is less burdensome than global high-growth stocks, and it also offers dividends. The key is whether its declarations translate into actual SaaS and global sales, and whether M&A will create synergy. With an established base in public and large enterprises, it is in a position to be the first to benefit if domestic AI security budgets increase.
 
SoftCamp (258790) is different. It started with document DRM and document-centric security, and is now moving towards Zero Trust and Remote Browser Isolation (RBI). As network separation was relaxed and public institutions began to use generative AI, SoftCamp put forward its N2SF strategy and SHIELDGate, which states, "Open AI, but isolate threats." This method involves running external AI and SaaS only in an isolated remote browser and transmitting only the screen. Its market capitalization is around 30 billion won, making it a small to medium-sized company with high volatility, but it directly addresses the unique domestic demands for document security, increased collaboration, and relaxed network separation. While the company's turnaround to profitability and revenue recovery are positive, competition with large platforms and low liquidity are risks.
 
그다음 층으로는 이글루코퍼레이션(보안관제·SIEM·AI SOC), 라온시큐어(인증·모바일·아이덴티티), 지니언스(네트워크 접근통제), 파수(문서·데이터 보안), SGA솔루션즈 등이 있다. 이들은 개별적으로는 글로벌 플랫폼을 이기기 어렵지만, 공공 조달, 금융권 규제, PQC 전환, AI 보안관제 국책 과제에서는 존재감이 있다. 다만 시총이 작고 테마 장세에 민감하므로 핵심이 아니라 위성으로 두는 편이 맞다.
 
Cybersecurity stocks in the AI era are less a bet on "how quickly AI gets smarter" and more a bet on how many systems and privileges AI will have. As attacks become automated, defense budgets don't decrease, and as agents increase, the demand for identity, privilege, log, and data control grows. Therefore, in the mid-to-long term, a basket of global platform leaders and domestic policy/sovereignty beneficiaries is the most explanatory. However, in periods where a theme ignites instantly, like the second half of 2026, prices run first. The core of prediction is not "will it rise," but rather identifying which companies actually convert AI attack surfaces into product sales. This article is an analysis summarizing market structure and company positioning, not a buy recommendation. Individual stocks require separate checks on performance, orders, valuation, and liquidity.

댓글
( 0 / 500 )
manhee
7
AI 보안을 단순한 테마주로 보지 않고 공격면 확대→신원·권한 관리→플랫폼 통합이라는 구조로 설명한 점이 인상적입니다. 결국 중요한 것은 AI라는 이름을 붙였느냐가 아니라 실제 보안 수요를 매출과 이익으로 연결할 수 있는 기업인지겠지요.
( 0 / 500 )
모란
8
사이버보안은 AI가 발전할수록 오히려 필요성이 커지는 산업이라는 설명에 공감합니다. 특히 AI 에이전트가 늘어나면 사람뿐 아니라 머신과 에이전트의 신원·권한까지 관리해야 한다는 관점이 핵심인 것 같습니다.
( 0 / 500 )
Tech84
6
글로벌 기업과 국내 기업을 같은 기준으로 단순 비교하지 않고 플랫폼, 아이덴티티, 제로트러스트, PQC, 공공조달 등 각각의 역할을 나눠 본 점이 좋습니다. 국내 보안주는 정책 수혜만 볼 것이 아니라 실제 기술력과 실적 전환 여부를 함께 봐야겠습니다.
( 0 / 500 )
auto70
5
결국 ‘어떤 종목이 오를까’보다 ‘AI 시대에 어떤 보안 문제가 새롭게 생기는가’를 먼저 봐야 한다는 글의 결론이 설득력 있습니다. 특히 선제 방어와 AI 에이전트 보안은 앞으로 보안산업의 중요한 축이 될 가능성이 있어 보입니다.
( 0 / 500 )
baro6
5
사이버보안주는 AI라는 키워드만 붙으면 급등하는 테마 영역과 실제 산업의 구조적 성장 영역을 구분할 필요가 있겠습니다. 시장 규모보다 더 중요한 것은 각 기업이 AI 보안 수요를 실제 제품과 반복 매출로 얼마나 전환하고 있는지라는 지적에 주목하게 됩니다.
( 0 / 500 )
최광호
4
사이버보안을 방어 비용으로만 보면 이 산업의 변화를 놓치기 쉽습니다. AI가 기업의 업무 시스템 깊숙이 들어갈수록 보안은 선택적 투자가 아니라 AI 활용 자체를 가능하게 하는 기본 인프라가 된다는 설명이 와닿습니다.
( 0 / 500 )
Pink6
3
특히 ‘사람의 신원’에서 ‘사람·머신·AI 에이전트의 신원’으로 보안의 대상이 확대된다는 부분이 핵심이라고 봅니다. AI 에이전트가 권한을 갖는 순간부터 누가 무엇에 접근했는지를 통제하는 문제가 훨씬 중요해질 것 같습니다.
( 0 / 500 )
crown
3
국내 보안업체를 바라볼 때도 단순히 정부 정책 수혜주라는 접근에서 벗어날 필요가 있겠습니다. 공공시장이라는 안정적인 기반 위에서 자체 기술과 SaaS 매출, 해외 진출까지 만들어낼 수 있는지가 장기적인 차이를 만들 것 같습니다.
( 0 / 500 )
철우
1
좋은 투자 분석은 오를 종목을 찍는 것이 아니라 산업의 돈이 어디로 이동하는지를 보여주는 것이라고 생각합니다. 이 글은 AI 보안이라는 큰 흐름 속에서 플랫폼·아이덴티티·제로트러스트·복원력으로 수요가 어떻게 분화되는지를 보여준다는 점에서 참고할 만합니다
( 0 / 500 )
신고내용

신고내용을 선택해주세요
회원비난/비하/욕설글 및 댓글도배성 게시물저작권 침해/불법자료 유출허위사실유포개인정보 유출.사생활 침해무단광고/홍보음란물 및 도박 불법 광고물범죄행위 관련 글불법행위 관련 소개물품 판매 및 사기글악성코드 및 스파이웨어 유포기타 사유 및 운영진 판단
ID
PasswordShow password
비밀번호를 잊으셨나요?

Sign in with Google
열린국회정보한국매니페스토실천본부열려라국회국회입법예고참여연대참여연대

All information provided by us is free of charge and is for the public good.

ⓒ 2022. P-UM.netRSS