In the age of AI, cybersecurity is not a defense cost.
It is being redefined as an essential infrastructure industry that manages new attack surfaces and new identities (agents) created by AI. As generative AI and agentic AI accelerate the speed at which they write code, find vulnerabilities, and automate penetration paths, the demand for using the same AI for detection, prediction, and blocking also structurally increases. This is why Jensen Huang identified cybersecurity as “AI’s next killer market.” If AI creates the problems, then AI must also solve them.
Looking at market forecasts, overall information security spending is already on a major growth trajectory. Gartner estimates global information security spending to be around $240 billion to $249 billion in 2026, continuing double-digit growth thereafter to expand to approximately $320 billion to $370 billion by 2029-2030. Among these, the security market directly integrated with AI is growing even more steeply. Although the scope varies by research firm, scenarios repeatedly show it starting from $25 billion to $43 billion in 2026 and growing to around $50 billion to $100 billion by 2030-2031. The compound annual growth rate is generally in the 15-25% range. A more significant qualitative change is 'preemptive security.' Gartner estimates that preemptive security, which accounted for only 5% of IT security spending in 2024, will make up about half by 2030. This is based on the judgment that a model of detection and response alone cannot keep up with the accelerated attack speed compressed by AI. The background for this is the forecast that documented software vulnerabilities (CVEs) will increase from approximately 270,000 currently to nearly 1 million by 2030.
The Korean market is heading in the same direction, but policy and geopolitics play a stronger role. The domestic cybersecurity market is projected to exceed approximately 4 trillion won by 2026, with some forecasts suggesting it could grow to around 18 trillion won by 2030. Some surveys also predict that the total security market (physical + cyber) will surpass 10 trillion won by 2026. Demand is being driven by cyber threats from North Korea, regulations on public and critical infrastructure, the introduction of generative AI after the easing of network separation, and the transition to Post-Quantum Cryptography (PQC) promoted by the National Intelligence Service (reflecting public evaluation → mandatory implementation of some algorithms by 2029). The government has also set a direction to grow the information security industry by 2030 and foster AI security unicorns. In other words, Korea is both a consumer market for global AI security platforms and a market with unique demands related to data sovereignty, public procurement, and cryptographic transitions.
The investment strategy should be a combination of structural demand, platform transformation, and valuation discipline, rather than theme-following.
First, a long-term perspective is necessary. Cybersecurity is one of the few industries where demand remains strong even if the AI boom succeeds, fails, or if regulatory and accident risks increase. This is because as the attack surface expands, defense budgets increase, and as talent shortages worsen, demand for automation (agentic SOC, XDR, SOAR) grows. However, periods of sharp stock price surges, like the AI risk headlines in September 2026, are repeated. Rather than chasing such rallies, a strategy of investing in installments over 3-5 year periods is more realistic.
Second, it is better to focus on platforms, identity, and proactive defense rather than standalone security products. Every time an AI agent is created, new accounts, permissions, activity logs, and data access paths are generated. Therefore, platform companies that provide a single console view of endpoints, clouds, and networks, and identity companies that manage human, machine, and AI agent identities, are structurally advantageous. Zero Trust, SASE, data security (DSPM), and cyber resilience (backup, ransomware recovery) follow the same trend.
Third, it is practical for Korean investors to divide their investments into global and domestic. Global leaders dominate technology standards and large customers, but their valuations are already high. Domestic companies have local momentum such as public, financial, network separation relaxation, and PQC, but their scale and global competitiveness are challenges. Global exposure can be diversified through individual stocks and baskets such as HACK, CIBR, or domestically listed TIGER Global Cybersecurity ETF.
Fourth, risks must be clearly identified. After major stocks like CrowdStrike and Palo Alto rose sharply in 2026, expectations are already largely reflected in the price. Variables include failed M&As during platform integration, AI features not meeting actual effectiveness, regulatory fragmentation (different AI and data rules in the US, Europe, and China), and market share erosion by traditional firewall companies. Domestic small and medium-sized stocks often experience severe thematic fluctuations and have poor earnings visibility. Therefore, it is safer to stratify the portfolio, with 40-60% in core platforms, 20-30% in domestic policy beneficiaries, and 10-20% in satellite small/medium-sized and thematic stocks.
Potential companies have different roles.
Globally, CrowdStrike (CRWD) is the closest to the purest expression of the AI security theme. Based on its cloud-native endpoint and XDR Falcon platform, it is expanding into SOC automation and agent security, and the company itself believes it can grow its TAM to $325 billion by 2030. It is also the stock that has reacted most sensitively to the recent AI risk debate. Palo Alto Networks (PANW) is closest to perfection in terms of scale and product breadth. It aims to integrate network, cloud, and security operations into a platform, and by adding identity (CyberArk acquisition), it seeks to bring human, machine, and AI agent identities into one axis. While its growth rate and market dominance are strong, it already commands a high premium. Fortinet (FTNT) stands out in terms of relative value and profitability. It simultaneously leverages hardware-based performance advantages and SASE expansion, making it less burdensome compared to high-growth software. Zscaler (ZS) is a leading player in zero-trust and cloud access control, which makes logical sense as AI workloads and distributed access increase. Other auxiliary candidates include SentinelOne (AI-native endpoint), Okta/SailPoint (agent identity), Cloudflare (edge/traffic security), and Rubrik (cyber resilience).
In Korea, AhnLab (053800) is essentially the core. On September 16, 2026, it officially announced its transformation into an 'AI-native security platform company,' pledging to invest 100 billion won in AI over three years and setting targets of 1 trillion won in sales and a 30% global share by 2035. It boasts 13 security-specific AI models, over 2.5 PB of security data, and achievements in reducing SOC work hours. Its market capitalization is approximately 630 billion to 650 billion won, and its PER is around 13x, which is less burdensome than global high-growth stocks, and it also offers dividends. The key is whether its declarations translate into actual SaaS and global sales, and whether M&A will create synergy. With an established base in public and large enterprises, it is in a position to be the first to benefit if domestic AI security budgets increase.
SoftCamp (258790) is different. It started with document DRM and document-centric security, and is now moving towards Zero Trust and Remote Browser Isolation (RBI). As network separation was relaxed and public institutions began to use generative AI, SoftCamp put forward its N2SF strategy and SHIELDGate, which states, "Open AI, but isolate threats." This method involves running external AI and SaaS only in an isolated remote browser and transmitting only the screen. Its market capitalization is around 30 billion won, making it a small to medium-sized company with high volatility, but it directly addresses the unique domestic demands for document security, increased collaboration, and relaxed network separation. While the company's turnaround to profitability and revenue recovery are positive, competition with large platforms and low liquidity are risks.
그다음 층으로는 이글루코퍼레이션(보안관제·SIEM·AI SOC), 라온시큐어(인증·모바일·아이덴티티), 지니언스(네트워크 접근통제), 파수(문서·데이터 보안), SGA솔루션즈 등이 있다. 이들은 개별적으로는 글로벌 플랫폼을 이기기 어렵지만, 공공 조달, 금융권 규제, PQC 전환, AI 보안관제 국책 과제에서는 존재감이 있다. 다만 시총이 작고 테마 장세에 민감하므로 핵심이 아니라 위성으로 두는 편이 맞다.
Cybersecurity stocks in the AI era are less a bet on "how quickly AI gets smarter" and more a bet on how many systems and privileges AI will have. As attacks become automated, defense budgets don't decrease, and as agents increase, the demand for identity, privilege, log, and data control grows. Therefore, in the mid-to-long term, a basket of global platform leaders and domestic policy/sovereignty beneficiaries is the most explanatory. However, in periods where a theme ignites instantly, like the second half of 2026, prices run first. The core of prediction is not "will it rise," but rather identifying which companies actually convert AI attack surfaces into product sales. This article is an analysis summarizing market structure and company positioning, not a buy recommendation. Individual stocks require separate checks on performance, orders, valuation, and liquidity.