The Lighthouse · Member Report

Structural investment themes

Cybersecurity:
The New Business Staple

Why an enduring need still requires careful stock selection.

The investment framework

An essential need is the beginning of the analysis.

  1. 01 · The need

    Protection

    Does the customer need it again next year?

  2. 02 · The business

    Durability

    Can this provider keep earning the customer's trust and money?

  3. 03 · The investment

    Price

    Do realistic expectations leave room for a satisfactory return?

A framework for reading the sector, not a forecast or a ranking of companies.

Executive summary

Every era has its basics. For households, those include food, shelter, and the ability to protect what they own. For businesses, they include electricity, communications, reliable records, and the ability to keep operating.

As those records, payments, communications, and customer relationships move online, protection has to move with them. Cybersecurity increasingly belongs in the same conversation as the other expenses that make a business possible.

That is the investment idea behind this report: cybersecurity may be developing some of the demand characteristics we associate with staples. The need repeats. Letting protection lapse can be expensive. A purchase made last year does not eliminate the need to maintain it this year.

But the investment conclusion requires another step. Persistent demand for protection does not guarantee persistent profits for every supplier. Nor does it make any share price reasonable.

Cybersecurity can have staple-like demand while its stocks retain the risks of competitive technology businesses. The opportunity is to identify companies that convert necessary protection into durable customer relationships, sound cash generation, and value for each share owned.

When protection becomes part of the operating budget

Imagine a business opening its doors tomorrow. The lights work, the staff arrive, and the products are ready. But employees cannot access their accounts, customer records are unavailable, or payments cannot be processed. Much of the business is effectively closed even though the building is intact.

That is why cybersecurity belongs in a discussion about business continuity. It is broader than antivirus software. It includes controlling access, protecting devices and data, detecting trouble, responding to incidents, and restoring operations.

The Federal Trade Commission's small-business guidance uses the NIST Cybersecurity Framework's six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It also emphasizes supplier risks and incident planning. This is a management responsibility extending beyond the IT department. The framework itself is voluntary; it is not a universal purchasing mandate. FTC business guidance

There is spending evidence behind this shift. In its July 2025 forecast, Gartner projected worldwide information-security spending of approximately $240 billion in 2026, compared with approximately $213 billion projected for 2025. Gartner estimated 12.5% growth, while noting that some organizations were cautious about new security purchases. These are dated forecasts, not completed 2026 results. Gartner spending forecast

Our interpretation is that security is becoming a recurring operating requirement. That does not make every budget recession-proof. A customer can keep protecting its business while negotiating harder, delaying an upgrade, or replacing several products with one contract.

What Coca-Cola teaches—and where the comparison ends

Warren Buffett's Coca-Cola investment offers a useful way into the subject. Coca-Cola dates to 1886, giving the brand roughly 140 years of history. In Berkshire Hathaway's 2022 shareholder letter, Buffett described how the annual cash dividends Berkshire received from Coke grew from $75 million in 1994 to $704 million in 2022. Coca-Cola history, Berkshire's 2022 letter

The useful lesson is the value of repeat demand and a business that can translate it into cash over many years. People buy a drink, consume it, and eventually buy another. Security customers also face a recurring need, although they are buying continuing protection rather than another bottle.

Coca-Cola is not a literal survival necessity. Its relevance here is habitual consumption and business durability. Likewise, calling cybersecurity a business staple describes a demand pattern; it does not reclassify technology shares as consumer-staples stocks.

There is also a major difference. A security provider must keep adapting to new threats, new systems, and competing products. Customer trust matters, but trust has to be supported by continuing technical performance. A familiar brand alone cannot keep a product effective.

The Buffett-inspired question is therefore: which providers can turn a recurring need into enduring economics? This comparison is our analytical lens, not a claim that Buffett endorses cybersecurity stocks.

AI adds another layer of responsibility

The current relevance extends beyond a familiar warning that more activity is moving online. Businesses are also introducing software agents that can take actions, access information, and use other systems.

In its February 2026 cybersecurity outlook, Gartner identified AI-agent oversight and identity management as important challenges. It also described AI's potential to improve security investigations while introducing new staffing, governance, and cost considerations. Gartner's 2026 cybersecurity trends

For investors, this suggests additional work around deciding what each person or software agent may access, monitoring that activity, and limiting mistakes. But greater complexity is not automatically greater profit. Automation could help suppliers serve customers more efficiently; it could also make some existing features cheaper and easier to reproduce.

The evidence to watch is whether customers pay for useful protection and whether providers deliver it economically. An AI label is not enough.

Quantum readiness adds work before the threat arrives

Quantum computing introduces a different challenge. A sufficiently capable quantum computer could undermine widely used public-key cryptography, including systems used to establish secure connections and verify digital signatures. The timing is uncertain; this is not a claim that today's quantum machines can already break those systems at scale.

Preparation cannot simply wait for that day. NIST finalized its first three post-quantum cryptography standards in 2024 and encourages organizations to begin the transition. It also explains the risk of encrypted information being collected now for possible decryption later. Data that must remain confidential for many years deserves particular attention. NIST's post-quantum overview

The practical work includes finding where vulnerable cryptography is used, coordinating with suppliers, testing replacements, and planning migrations without disrupting operations. This is a transition in how systems are protected, not a forecast that all encryption will suddenly fail. NIST migration project

For investors, the implication is that the work of protection keeps changing. AI and quantum readiness can create additional demand for expertise, but neither guarantees a revenue windfall for every cybersecurity company. Some of that work may be delivered through existing software, consulting, or infrastructure providers.

A specialty that ordinary IT support cannot cover alone

Keeping computers running and defending an organization against evolving threats are related responsibilities, but they require different depths of expertise. Identity design, incident response, continuous monitoring, and cryptographic migration are not tasks to hand casually to whoever also fixes the office printer.

The UK's National Cyber Security Centre notes that many small and medium-sized businesses use managed service providers for IT and cybersecurity. Its guidance also stresses careful provider selection and secure configuration: hiring a specialist does not remove the customer's responsibilities. NCSC provider guidance

Some organizations can build strong internal security teams. Others need outside specialists, managed services, or a combination of internal oversight and external tools. The point is not that every business must outsource everything. It is that specialist expertise must be available somewhere in the arrangement.

That helps explain why cybersecurity may remain a recurring expense. Customers are paying for continuing competence as well as software. For suppliers, the test is whether they can deliver that competence reliably and profitably. Outsourcing also creates dependence on the provider, making its own security and reliability part of the customer's risk assessment.

Three tests between necessity and shareholder returns

Three tests between necessity and shareholder returns
Test The question Evidence that matters
The need Does protection remain important to the customer? Ongoing use, renewals, and a clear role in keeping operations safe.
The business Can this provider retain customers and earn attractive returns? Retention, pricing discipline, reliability, margins, and cash generation.
The investment Does the price leave room for a satisfactory outcome? Realistic growth assumptions, valuation, dilution, and downside scenarios.

A convincing answer to the first question does not settle the next two. This is where an appealing sector story must become company research.

In a subscription business, examine annual recurring revenue, or ARR, where disclosed. ARR is a company-defined measure of recurring revenue at a point in time; it is not the same as recognized revenue or cash received. Compare definitions and separate growth from acquisitions from growth in the existing business.

Retention deserves similar care. Keeping customers is different from persuading existing customers to spend more. A provider can report strong expansion among large clients while struggling to win new accounts. Read the measures together rather than relying on a single headline percentage.

Cash flow also needs interpretation. Advance customer payments can lift near-term operating cash flow. Stock compensation can support reported cash generation while diluting owners. Watch cash flow per diluted share, the share count, and whether repurchases actually reduce dilution.

Do cybersecurity companies pay dividends?

Some do. Others retain their earnings and cash to support operations and growth. That distinction matters for readers who associate the word staple with reliable dividend income.

The following examples illustrate different payout policies. They are not recommendations, rankings, or a complete sector list. Policies were checked on August 28, 2026.

Illustrative cash dividend policies — checked August 28, 2026
Company Cash dividend position What it illustrates
Palo Alto Networks (PANW) Its investor FAQ says it does not intend to declare or pay cash dividends in the foreseeable future. Company FAQ An essential product category need not produce current shareholder income.
CrowdStrike (CRWD) Its fiscal 2026 annual filing says it has never paid cash dividends and does not expect to pay them in the foreseeable future. Annual filing A recurring-revenue thesis can depend on future business growth and share-price appreciation.
Gen Digital (GEN) Its August 2026 results announcement declared a quarterly cash dividend of $0.125 per share, payable September 9, 2026, to shareholders of record on August 17. Company announcement Dividend-paying exposure exists, but its business mix still needs separate analysis.

Gen's brands include Norton, Avast, and LifeLock, alongside financial-wellness offerings such as MoneyLion. That makes it a different business mix from enterprise security providers, rather than a like-for-like dividend substitute. Gen's business description

A dividend is a capital-allocation choice, not proof of safety. Investors still need to examine debt, cash coverage, reinvestment needs, and the purchase price. Conversely, the absence of a dividend is not a defect if retained capital is invested productively. Future payments are not guaranteed.

The need follows us home

The same idea extends to personal life. Email, bank access, family photographs, identity information, and work accounts can all depend on digital systems. Protecting them is an ordinary household responsibility, even when the technology feels complicated.

CISA's published Secure Our World guidance emphasizes four practical habits: recognizing phishing, using strong passwords and a password manager, enabling multifactor authentication, and updating software. CISA's published guidance

The investment qualification is that a need for protection is not automatically a need for another paid subscription. Some protections are built into devices, operating systems, or existing services; others depend on behavior. Consumer providers must demonstrate why their additional service is useful enough to retain paying customers.

This creates two related research paths: business protection and household protection. They address a common need, but customer budgets, distribution, retention, and willingness to pay may differ substantially.

The risks inside an essential industry

The first is competition. Customers may want fewer tools and simpler administration. A broader provider may win a larger contract while a specialist loses its place in the budget. Alternatively, a specialist may retain customers because its protection is materially better. Consolidation can change who receives the spending without eliminating the need.

The second is reliability. On July 19, 2024, a defective CrowdStrike content update for Windows caused an outage. CrowdStrike stated that the incident was not a cyberattack. The example matters because a supplier responsible for protection can itself become a source of operational disruption. It is a historical risk example, not a judgment about the company's current investment value. CrowdStrike's incident statement

The third is valuation. Consider a deliberately simplified illustration: a business earns $1 per share and trades at 60 times earnings, giving a $60 share price. Earnings then rise 25% to $1.25, but investors will pay only 40 times earnings. The resulting price is $50, a decline of about 16.7%, despite the earnings growth.

Those figures describe no actual company. They show why a correct business thesis can still produce a disappointing investment. Dividends, taxes, and other factors are excluded from the illustration.

Finally, do not confuse a protective product with a defensive stock. A cybersecurity provider may reduce a customer's operating risk while its own shares remain sensitive to interest rates, growth expectations, execution, and market sentiment.

What would strengthen—or weaken—the thesis?

Evidence to monitor — research questions, not company ratings
Area to monitor Evidence that strengthens the case Evidence that weakens the case
Customer demand Renewals remain healthy and customers pay for continued protection. Contracts are renewed only after concessions or customers cut deployment.
Competitive position Products remain useful, trusted, and difficult to replace. Comparable protection is bundled elsewhere at a lower incremental cost.
Growth quality Existing-business growth and customer expansion support reported results. Acquisitions, promotions, or changing metric definitions obscure performance.
Owner economics Cash generation per diluted share improves alongside sustainable margins. Dilution, debt, or customer incentives absorb the benefits of revenue growth.
Reliability Providers show disciplined testing, response, and recovery practices. Repeated operational failures damage trust or impose material costs.
Price and expectations The investment works under reasonable growth and margin assumptions. The price requires nearly flawless execution for many years.

These are research questions, not scores assigned to the companies mentioned. A broad spending trend should be checked against the evidence at each business.

Why we wrote this: participate without needing one permanent winner

The computer industry of the 1980s and 1990s offers a useful reminder. An investor could believe that computers would become essential without knowing which companies would capture the greatest lasting value. Familiar names such as IBM, Microsoft, and Wang represented different parts of that changing market, not interchangeable investments. Wang became a well-known office-computing supplier and filed for bankruptcy in 1992. The need for computing continued. Computer History Museum

Cybersecurity invites a similar distinction. The need may endure, while products, leadership, and profit pools change. Recognizing a long-term theme does not require declaring today's most visible company its permanent winner.

Our view is that a modest allocation to cybersecurity can merit long-term consideration within an otherwise diversified portfolio. This is a general investment perspective, not a prescribed allocation or an assertion that the sector is suitable for every reader. The starting point is the investor's existing holdings, tolerance for losses, time horizon, and the prices available.

One way to express that view is through several carefully researched businesses rather than a single stock. A sector fund is another route to examine, subject to its holdings, concentration, costs, and overlap with investments already owned. Neither approach guarantees that the eventual winners will be included or that their returns will offset the losers. The SEC's investor guidance cautions that a narrowly focused fund does not, by itself, provide broad diversification. Investor.gov diversification guidance

The discipline has two levels: limit any one company's role, and limit the industry's combined role in the overall portfolio. Owning several cybersecurity companies may spread company-specific risk, but those shares can still fall together. An investor already holding substantial technology exposure might increase concentration by adding them.

It is useful to be precise about hedging. A small position limits how much that holding can hurt the portfolio; diversification spreads exposure. A hedge is designed to offset a particular risk. Simply owning cybersecurity shares does not hedge a market decline—or compensate an investor for a cyberattack.

Agility means reviewing the evidence and being willing to change holdings when the business case changes. It does not require reacting to every headline. Retention, competitive position, reliability, valuation, and portfolio weights offer more useful review points. Rebalancing can keep a successful theme from quietly becoming an oversized bet, with trading costs and taxes considered before changes.

The reason to study this industry is the possibility of enduring demand and growth. The reason to remain diversified and agile is that enduring demand does not identify the winners in advance.

The Lighthouse view

Some of the most interesting investment themes begin when an expense stops feeling optional. Cybersecurity increasingly fits that description as businesses and households put more of their working lives online.

The analogy with staples helps us recognize the recurring need. The differences remind us to study the suppliers carefully. Protection must be renewed, products must keep improving, and the benefits must reach shareholders after competition, costs, dilution, and the price paid.

Rising share prices can draw attention to the theme, but they are not the foundation of this report. We have not used a selected stock rally as proof, assigned price targets, or presumed that today's leaders will remain tomorrow's winners.

The need for cybersecurity may endure for decades. The investment opportunity belongs to businesses that can keep earning their place in that future—and to investors who pay a sensible price for them.

Sources and editorial notes

Research cutoff: August 28, 2026. August 2026 is the issue month. The investment framework, portfolio perspective, and analogies are WealthVelocity's interpretation; forecasts, historical events, and payout policies are attributed above. No portfolio percentage is prescribed, and describing a view as opinion does not remove the need to assess risk and suitability.

Informational research only; not personalized investment advice or a recommendation to buy or sell any security. All investments carry risk, including loss of principal. Forecasts, company policies, and market conditions can change. Examples are illustrative and do not establish suitability for any reader.

The Lighthouse

Keep the thesis. Keep testing it.

Explore more reports on changing conditions, evidence, and investment judgment.

Explore Reports