Home / Themes / Enterprise Software '24: Cybersecurity Software

Enterprise Software '24: Cybersecurity Software (open on stockthemes)

Last updated

Theme thesis · 3/5 sections · Tickers 13 with notes · 10 pending

Loading chart…
Loading…

Bull / Bear Details has the investment thesis and bull/bear points. Overview is monitoring guidance (hiring, forums, second-order trends, search keywords, Google Trends, datasets).

Bull / Bear Details

Cybersecurity spending is accelerating as non-human AI identities and autonomous agentic workflows outnumber human endpoints, expanding corporate attack surface

Thesis

Cybersecurity spending is accelerating as non-human AI identities and autonomous agentic workflows outnumber human endpoints, expanding corporate attack surfaces. High-scale platforms are winning multi-product consolidation budgets, though near-term multiples face scrutiny from lengthened deal approval cycles and monetization lags on early AI security tooling.

Bull case

  • The rapid enterprise deployment of autonomous AI agents and microservices has multiplied non-human identities far beyond human employee headcounts. This dynamic structurally expands total addressable budgets into machine identity governance, runtime agent guardrails, and behavioral API inspection beyond legacy seat-based licensing models.

  • Enterprises are actively eliminating point-tool sprawl by consolidating onto unified Zero Trust and XDR architectures spanning endpoints, identities, cloud networks, and data resilience. This platformization drive accelerates multi-module contract expansions, supporting higher net revenue retention rates and yielding multi-year, multi-million-dollar commitments.

  • Heightened adversary velocity, automated vulnerability exploitation, and stringent global compliance frameworks—including DoD Zero Trust architecture mandates, the EU NIS2 Directive, and SEC disclosure requirements—render cyber defense a mandatory, non-discretionary boardroom priority insulated from broader corporate IT budget trims.

Bear case

  • While enterprise proof-of-concept pipelines for autonomous agent governance and AI threat defense are expanding, contract conversion remains gated by 6-to-12-month enterprise procurement cycles and nascent pricing models, creating an optical lag between elevated market expectations and realized ARR contribution.

  • Intense competitive bundling by hyperscalers and legacy platform providers continues to commoditize entry-level identity, email, and endpoint protection layers, exerting discounting pressure during vendor bake-offs and challenging standalone unit economics.

  • Macroeconomic scrutiny on software spend and persistent enterprise technical debt have lengthened approval timelines for complex, multi-year architecture overhauls, risking deployment friction and delayed implementation schedules across hybrid and multi-cloud environments.

Overview

Hiring Trend Watchpoints

High-performing cybersecurity operators are concentrating technical hiring on non-human identity security, agentic governance, AI-driven autonomous detection and response (e.g., automated SecOps and AIDR), and secure multi-cloud architectures. Organizations are prioritizing specialized security research engineers capable of countering machine-speed exploits over conventional frontline manual SOC tier-1 analysts, where automated workflows are substituting headcount. On the go-to-market side, top firms are retooling enterprise sales capacity toward platform enterprise licensing specialists and customer architecture engineers who can execute multi-module platformization agreements (such as Falcon Flex and Z-Flex bundles) across CISOs and Chief AI Officers. Watch for hiring freezes in core R&D or prolonged enterprise quota-carrier ramp delays as early warning indicators of execution friction, while expanding technical customer-success and platform-deployment roles confirm accelerating multi-product wallet share expansion.

Forum Watchlist

  • reddit — r/cybersecurityhigh

    Enterprise practitioner sentiment on platformization consolidation, agent deployment friction, and competitive bake-offs between major EDR/XDR vendors

  • reddit — r/netsechigh

    Technical teardowns of zero-day exploits, novel weaponization techniques, and bypass vulnerabilities in cloud access and reverse proxies

  • reddit — r/sysadminmedium

    Field reports on SASE cutover migrations, identity provider reliability, MFA bypasses, and cyber resilience backup restoration speeds

  • community — CISO Series / Cyberwire Communityhigh

    Executive budget allocation trends, platform fatigue vs best-of-breed debates, and board-level mandates surrounding AI agent governance

  • community — Spiceworks Security Communitymedium

    Mid-market IT manager reactions to vendor licensing overhauls, appliance renewal costs, and firewall-to-SSE transitions

Industry Publications

  • Dark Reading (darkreading.com) — Comprehensive coverage of enterprise cyber threat vectors, incident response tactics, and cloud security architecture trends influencing CISO purchasing decisions.
  • BleepingComputer (bleepingcomputer.com) — Fastest-breaking reporting on active ransomware campaigns, zero-day vulnerabilities, extortion developments, and patch urgency across enterprise software.
  • SC Media (scmagazine.com) — In-depth focus on cybersecurity management, regulatory governance, identity security, and competitive platform comparative assessments.
  • Krebs on Security (krebsonsecurity.com) — High-impact investigative journalism uncovering systemic software supply-chain compromises, major corporate data breaches, and organized threat actor tactics.
  • CSO Online (csoonline.com) — Strategic analysis tailored for CISOs regarding enterprise risk quantification, board reporting, AI security policy, and vendor consolidation strategies.

Second Order Trends

A major second-order trend is the explosion of Non-Human and Autonomous Agent Identities. Software agents, microservice integrations, and automated pipelines now outnumber human employees inside enterprises by significant factors, turning machine identity governance (MIS), API privilege boundaries, and runtime agent guardrails into primary cyber growth segments rather than peripheral niche features. Concurrently, traditional disaster recovery has converged with core security into 'Cyber Resilience': organizations are shifting capital from passive data protection to active cyber recovery platforms that can programmatically clean, verify, and restore entire Active Directory and enterprise data estates within hours of an attack. Lastly, business models are decoupling from static per-seat metrics toward flexible enterprise credit draw-down pools, allowing customers to dynamically ingest telemetry, test emerging AI protection modules, and reallocate security spend across hybrid and multi-cloud footprints in real time.

Search Keywords Brand Product

  • Falcon platform
  • Prisma AIRS
  • Zero Trust Exchange
  • Netskope One
  • Rubrik Security Cloud
  • Singularity XDR
  • Identity Security Cloud
  • Cortex XSIAM
  • Cloudflare Zero Trust
  • FortiGate
  • Auth0
  • Agentic Fabric
  • Akamai Guardicore
  • Rubrik Agent Cloud
  • Prompt Security
  • Purple AI
  • Falcon Flex
  • BIG-IP
  • Norton 360
  • Varonis Data Security
  • cybersecurity software
  • Zero Trust architecture
  • SASE deployment
  • agentic AI security
  • extended detection and response
  • ransomware resilience
  • non-human identity security
  • cloud workload protection

Search Keywords Policy Regulatory

  • DoD Zero Trust mandate
  • EU NIS2 Directive
  • SEC cybersecurity disclosure rules
  • CISA binding operational directives
  • FedRAMP High authorization
  • EU AI Act compliance

Search Keywords Event Phrases

  • Black Hat USA
  • RSA Conference
  • DEF CON
  • Gartner Security & Risk Management Summit
  • CrowdStrike Fal.Con
  • Palo Alto Networks Ignite

Google Trend Product Category Intent

• Zero Trust software • EDR software • SASE solutions • cloud security platform • identity governance software • ransomware recovery tool

Google Trend Consumer Intent

• identity theft protection • antivirus software • dark web monitoring • password manager security • scam protection app

Google Trend Macro Policy Terms

• Zero Trust federal mandate • NIS2 compliance • CISA cybersecurity directives • SEC cyber disclosure rules

Economic Data Watch

1. Federal Reserve Bank of St. Louis (FRED) / U.S. Bureau of Economic Analysis (BEA) — National Income and Product Accounts (NIPA Table 5.6.5U)

Not in registryaccess=api

Metric/field FRED Series B985RC1Q027SBEA (Private fixed investment: Nonresidential: Intellectual property products: Software)

Cadence quarterly

Why it matters Directly tracks aggregate enterprise capital expenditures dedicated to software, providing the core macro indicator of enterprise IT software budget availability across cybersecurity platforms.

Signal to watch Sustained positive QoQ annualized growth indicates supportive software spending environments; deceleration signals budget scrutiny and lengthened procurement cycles.

Confidence: high

2. U.S. Bureau of Labor Statistics (BLS) — Current Employment Statistics (CES)

Matched (medium)lab_headcount · access=api

Metric/field BLS Series CES6054150001 (All Employees: Computer Systems Design and Related Services)

Cadence monthly

Why it matters Measures payroll headcount trends across IT consulting, cybersecurity engineering, and systems implementation services critical for deploying Zero Trust, SASE, and identity platforms.

Signal to watch MoM payroll expansion confirms strong deployment velocity and implementation capacity; net contraction indicates IT budget freezes and delayed enterprise security rollout schedules.

Confidence: high

3. U.S. Bureau of Labor Statistics (BLS) — Producer Price Index (PPI)

Not in registryaccess=api

Metric/field BLS Series PCU511210511210 (Producer Price Index by Industry: Software Publishers)

Cadence monthly

Why it matters Gauges pricing power and contract renewal inflation across enterprise software vendors, reflecting whether cybersecurity platforms can sustain net price realization and module upsell pricing.

Signal to watch Index trajectory above core PPI indicates durable pricing power and vendor consolidation leverage; deceleration signals pricing pressure and enterprise discount concessions.

Confidence: high

4. U.S. Department of the Treasury / USAspending.gov — Federal Contract Awards Database

Not in registryaccess=api

Metric/field Award Obligations for Product Service Code D310 (IT and Telecom - Cyber Security and Data Backup) and PSC 7A21 (IT and Telecom - Business Application Software)

Cadence quarterly

Why it matters Quantifies actual federal contract obligations for commercial security and cyber-resilience software, directly indicating conversion velocity for public-sector-certified vendors.

Signal to watch Sequential growth in federal obligation dollars confirms execution of federal Zero Trust mandates; obligation pauses or continuing resolution stagnation indicate delayed federal deal closings.

Confidence: high

5. U.S. Securities and Exchange Commission (SEC) — EDGAR Filings Database

Not in registry

Metric/field Monthly count of Form 8-K filings submitted under Item 1.05 (Material Cybersecurity Incidents)

Cadence monthly

Why it matters Mandatory disclosures of material breaches under SEC rules elevate corporate risk urgency and board oversight, acting as an ongoing catalyst for enterprise-wide cyber-resilience spending.

Signal to watch Sustained elevation or cluster spikes in material disclosures drive acute board-level demand for immediate security architecture overhauls and automated defense platforms.

Confidence: medium

Free Alt Data Watch

1. Cybersecurity and Infrastructure Security Agency (CISA) — Known Exploited Vulnerabilities (KEV) Catalog

Not in registry

Metric/field Monthly additions count of CVE IDs in the CISA KEV JSON feed (cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

Cadence weekly

Why it matters Catalog of vulnerabilities actively exploited in the wild driving mandatory enterprise remediation, directly fueling demand for exposure management and vulnerability prioritization.

Signal to watch Sharp increases in monthly active exploit additions signal heightened adversary activity, accelerating procurement of exposure management and endpoint detection platforms.

Confidence: high

2. National Institute of Standards and Technology (NIST) — National Vulnerability Database (NVD) CVE API 2.0

Not in registry

Metric/field Monthly count of published CVEs with CVSS v3.1 baseScore >= 9.0 (metrics.cvssMetricV31.cvssData.baseScore)

Cadence monthly

Why it matters Measures the rate of newly disclosed critical software flaws that bypass legacy perimeter controls, driving migration toward cloud-native Zero Trust and XDR architectures.

Signal to watch Upward trajectory in critical severity vulnerabilities broadens enterprise attack surfaces and reinforces defensive consolidation toward unified security platforms.

Confidence: high

3. Cloudflare — Cloudflare Radar API

Not in registry

Metric/field Global share of mitigated malicious HTTP and layer 7 DDoS traffic (radar/attacks/layer7/summary/mitigated_requests_percentage)

Cadence weekly

Why it matters Provides real-time visibility into global malicious web traffic, bot scraping, and distributed denial-of-service pressure across global edge networks.

Signal to watch Elevated malicious traffic and bot mitigation percentages validate enterprise necessity for advanced edge security, API protection, and web application firewalls.

Confidence: high

4. GitHub Archive / Google BigQuery — GH Archive (githubarchive.day.*)

Not in registry

Metric/field Aggregate monthly WatchEvent and ForkEvent counts across top open-source security repositories (e.g., wazuh/wazuh, falcosecurity/falco, osquery/osquery)

Cadence monthly

Why it matters Tracks open-source developer activity and engineering community focus on security primitives, runtime security, and observability, foreshadowing commercial software adoption trends.

Signal to watch Accelerating star and fork counts indicate emerging developer-driven security standards and runtime security architecture transitions.

Confidence: medium

5. Google Trends — Search Interest Over Time

Not in registry

Metric/field Weekly normalized search volume index (0-100) for query topic composite 'Zero Trust' + 'SASE' + 'Identity Governance' (worldwide)

Cadence weekly

Why it matters Captures broader commercial and practitioner search interest in next-generation cybersecurity architectures, serving as a top-of-funnel brand awareness indicator for category leaders.

Signal to watch Consistent upward trends indicate broadening market education and accelerating consideration stages for cloud-native security frameworks.

Confidence: medium

Paid Alt Data Watch

1. Revelio Labs — Enterprise Workforce Intelligence and Job Postings Dataset

Not in registryaccess=file

Metric/field Active enterprise job postings count mentioning 'Zero Trust Architecture', 'SASE', 'CrowdStrike Falcon', 'Zscaler ZPA', or 'Palo Alto Prisma' (job_postings.skills_required)

Cadence monthly

Why it matters Measures enterprise hiring commitments for specialized cybersecurity skill sets, serving as an operational leading indicator for enterprise platform implementation and module deployment.

Signal to watch Persistent growth in enterprise job postings specifying platform-specific competencies indicates active multi-year software expansion and low shelfware risk.

Confidence: high

2. Gartner — Gartner Market Databook & IT Spending Forecast

Matchedgartner_it_spending_market_forecasts · access=file · map_only

Metric/field Worldwide Security and Risk Management Software Spending Forecast and Constant-Currency Growth Rate (USD Billions)

Cadence irregular

Why it matters The benchmark macro enterprise software spending guide used by institutional investors to gauge institutional security budget resiliency relative to overall IT budgets.

Signal to watch Upward adjustments in forecast growth confirm budget priority protection; downward revisions highlight broad corporate IT spend curtailment.

Confidence: high

3. HG Insights — Technology Intelligence & Install Base Platform

Not in registry

Metric/field Global 2000 enterprise install counts and competitive replacement events for next-generation firewalls, SASE, and identity governance (product_install_count, displacement_flag)

Cadence monthly

Why it matters Directly tracks enterprise vendor consolidation and competitive displacements between legacy point appliances and modern integrated platforms.

Signal to watch Net positive vendor replacement rates toward leading cybersecurity platforms substantiate the theme's core platformization thesis.

Confidence: high

4. Similarweb — Enterprise Digital Intelligence Platform

Matchedsimilarweb_digital_marketing_referral_intelligence · access=file · map_only

Metric/field Monthly unique visitors and session duration on enterprise customer administrative portals (e.g., falcon.crowdstrike.com, admin.okta.com, *.zscaler.net, portal.rubrik.com)

Cadence irregular

Why it matters Provides ongoing, high-frequency telemetry on enterprise customer platform engagement, seat utilization, and administrator activity without waiting for quarterly reports.

Signal to watch Consistent MoM growth in active portal sessions points to healthy gross retention and expanding multi-module usage across deployed seats.

Confidence: high

5. Visible Alpha — Consensus Estimates & Segment Revisions Database

Not in registry

Metric/field Consensus Next-Generation Security (NGS) ARR for PANW, Ending ARR for CRWD, and Net New Subscription ARR for RBRK and SAIL

Cadence monthly

Why it matters Tracks sell-side revision breadth and consensus model adjustments for core recurring revenue KPIs across bellwether cybersecurity platforms.

Signal to watch Positive net estimate revision momentum signifies outperforming ARR pipeline execution; negative revisions warn of sales execution drag or extended sales cycle friction.

Confidence: high

Prediction Market Watch

Theme Plain English
Enterprise Software '24: Cybersecurity Software captures vendors protecting corporate digital infrastructure across endpoints, identities, cloud networks, and data. As enterprise perimeters dissolve and autonomous AI agents proliferate alongside human employees, cybersecurity has transitioned from disconnected point tools toward unified Zero Trust platforms and active cyber resilience. Constituents deliver mission-critical software for threat detection, identity governance, secure edge connectivity, and rapid ransomware recovery, insulating enterprises against increasingly automated and sophisticated cyber threats.
Upcoming Catalysts34 rows
Catalyst IDEstimated TimingEstimated Date StartEstimated Date EndCatalystWhy It MattersTicker Or Theme SpecificTranscript DateSource TypeCatalyst Source
FFIV_1794269fbeginning in fiscal year 20272026-10-012026-12-31F5 anticipates an inflection in software revenue growth, leading to a higher growth rate beginning in fiscal year 2027.This signals a positive shift in a key revenue segment, driven by strong consumption rates and a larger renewal base, which could improve long-term revenue and profitability outlook.Ticker2026-04-28earnings_transcriptFFIV (ticker)
AKAM_b3c6671cfourth quarter of 20262026-10-012026-12-31A 4-year, roughly $200 million Cloud Infrastructure Services contract with a major U.S. tech company, largely for Akamai Inference Cloud; revenue recognition expected to start in Q4 2026.Significant multi-year AI compute win that expands Inference Cloud adoption and provides a measurable revenue ramp starting in late 2026.Ticker2026-02-19AKAM (ticker)
OKTA_d12671c1over the next several quarters and several years2026-08-012029-05-28Okta's AI agent products (Okta for AI Agents and Auth0 for AI Agents) begin to materially contribute to revenue by converting the large pipeline into significant deals.Successful conversion of the AI agent pipeline into substantial revenue would validate Okta's AI strategy, unlock a new growth vector, and materially impact future results and valuation. Failure to convert could dampen investor enthusiasm.Ticker2026-05-28earnings_transcriptOKTA (ticker)
OKTA_8f3fc8a9For the full year FY '272026-02-012027-01-31Okta's full-year FY'27 financial results, including total revenue growth, non-GAAP operating margin, and free cash flow margin, against provided guidance.Performance relative to full-year guidance will significantly influence investor perception of the company's growth trajectory and profitability, impacting valuation.Ticker2026-05-28earnings_transcriptOKTA (ticker)
OKTA_dfecb446FY '27 free cash flow margin guidance includes about a 1 point impact2026-02-012027-01-31Realization of a ~1 point impact on FY'27 free cash flow margin due to lower interest income from the stock repurchase program and cash settlement of convertible notes.This event directly affects the company's profitability metrics and capital allocation efficiency, influencing investor sentiment on financial management.Ticker2026-05-28earnings_transcriptOKTA (ticker)
OKTA_3d23c33acontinue to see increased retention and increased productivity2026-05-012027-01-31Continued improvement in sales force productivity and retention, leading to stronger go-to-market execution and increased bookings.Enhanced sales efficiency directly impacts bookings, revenue growth, and overall profitability, signaling effective go-to-market strategy and potentially leading to upside in future guidance.Ticker2026-05-28earnings_transcriptOKTA (ticker)
PANW_e63f94a0through Q1 of fiscal 272026-09-012026-10-31The tail end of a large LLM customer's migration to Chronosphere from an incumbent vendor will be completed.This event will conclude a significant migration that benefited Q4 FY26 ARR and impacted Q1 FY27 seasonality, providing clearer visibility into Chronosphere's organic growth moving forward.Ticker2026-09-01earnings_transcriptPANW (ticker)
PANW_0f12077fcoming architectural uplift and shift, opportunity in coming years2026-07-012029-02-17Launch and customer adoption of Palo Alto Networks' 'next-generation trust subscription' and quantum security capabilities, leveraging Venafi and other integrations, to prepare customers for the post-quantum era.This addresses a critical long-term security challenge and represents a new product ramp and market opportunity. Successful execution could establish PANW as a leader in post-quantum security, driving new revenue streams and competitive differentiation.Ticker2026-02-17earnings_transcriptPANW (ticker)
PANW_938fece8by fiscal 20302026-06-022030-07-31Palo Alto Networks surpassing 4,000 total platformized customers.This long-term strategic goal is a primary driver for achieving the $20 billion NGS ARR target, indicating deep customer architectural commitments and sustained revenue growth.Ticker2026-06-02earnings_transcriptPANW (ticker)
PANW_812901a6next 4 months. We think we'll get there before the end of this calendar year.2026-06-022026-12-31Completion of the migration of CyberArk's critical back-end systems to common Palo Alto Networks systems.Successful integration of back-end systems is crucial for realizing synergy targets and improving profitability, reinforcing confidence in the M&A strategy.Ticker2026-06-02earnings_transcriptPANW (ticker)
PANW_c161f490early days, yet to be built, a bit patient2026-07-012028-02-17The scaling of enterprise AI adoption and associated traffic volumes translating into substantial revenue generation from PANW's AI security products like Prisma AIRS, AgentiX, and future Koi integrations.This represents a major future growth driver. Faster-than-expected adoption and monetization could significantly boost PANW's long-term revenue and valuation, while delays or underperformance could negatively impact growth prospects.Ticker2026-02-17earnings_transcriptPANW (ticker)
PANW_47914d06second half of the year2026-07-012026-12-31Successful integration of CyberArk and Chronosphere acquisitions, including aligning go-to-market engines, account planning, sales incentives, and product innovation roadmaps.Crucial for realizing strategic value, synergies, and financial benefits (ARR, revenue, profitability) from these significant acquisitions. Failure could lead to disruption, missed targets, and negative investor sentiment.Ticker2026-02-17earnings_transcriptPANW (ticker)
PANW_61404065ongoing trend2026-02-172027-02-17Enterprises moving beyond AI experimentation to integrate foundational models into real workflows, leading to a demand for more consistent and consolidated security stacks.This trend directly supports Palo Alto Networks' platformization strategy, potentially accelerating sales of integrated security solutions (SASE, XSIAM, AI security) and improving net retention rates, impacting revenue growth and market share.Ticker2026-02-17earnings_transcriptPANW (ticker)
S_abee4b06Once fully implemented, we expect this action to result in approximately $45 million in annualized cost savings.2026-08-012027-07-31Realization of approximately $45 million in annualized cost savings from SentinelOne's workforce optimization initiative, following a one-time restructuring charge in Q2 FY27.These savings are expected to provide financial flexibility, allow reinvestment in key growth areas, and contribute to significant operating margin expansion, positively impacting profitability and shareholder value.Ticker2026-05-28earnings_transcriptS (ticker)
SAIL_3990b418for fiscal year 20272026-06-112027-01-31Progress and acceleration of on-premise to SaaS migrations, specifically achieving or exceeding the 10% migration target for the $350 million on-prem ARR base in FY27.Successful and accelerated SaaS migrations, especially with the 2-3x ARR uplift, would significantly boost SailPoint's SaaS ARR, revenue, and profitability, validating its cloud-first strategy and driving long-term value.Ticker2026-06-09earnings_transcriptSAIL (ticker)
SAIL_00a0ee05FY '27 and beyond2026-02-012029-01-31Migration of existing perpetual and term license customers (representing approximately $350 million in ARR) to SailPoint's Identity Security Cloud.This represents a significant and durable growth tailwind with a potential 2 to 3 times ARR uplift upon migration, contributing substantially to long-term ARR expansion.Ticker2026-03-18earnings_transcriptSAIL (ticker)
SAIL_5b8d747btowards the latter half of the year2026-07-012026-12-31Increased monetization and revenue contribution from SailPoint's Agentic Fabric and new AI-related offerings, leading to a more significant impact on financial results.A significant increase in AI-related revenue could materially impact SailPoint's top-line growth, potentially leading to raised guidance and positive investor sentiment, validating their AI strategy.Ticker2026-06-09earnings_transcriptSAIL (ticker)
SAIL_d9de4233FY '272026-02-012027-01-31SailPoint achieving 90% to 95% of net new ARR from its SaaS cloud platform.This is a key assumption in SailPoint's FY27 financial guidance, indicating successful execution of their SaaS-first strategy and strong customer adoption of cloud offerings, though it may temporarily impact reported revenue and operating margin.Ticker2026-03-18earnings_transcriptSAIL (ticker)
SAIL_d290eaf7FY '272026-02-012027-01-31Increased acquisition of new enterprise customers seeking foundational security in the AI era.This is expected to expand SailPoint's market share and contribute to new logo ARR, forming a critical part of their durable growth engine for FY27.Ticker2026-03-18earnings_transcriptSAIL (ticker)
SAIL_17f79095fiscal '27 this calendar '262026-02-012026-12-31Market validation of SailPoint's AI identity solutions and their ability to address customer needs for securing Agentic environments.Successful delivery and market proof will solidify SailPoint's competitive position as a leader in securing AI-powered enterprises, driving adoption of their emerging products and potentially leading to outperformance of guidance.Ticker2026-03-18earnings_transcriptSAIL (ticker)
SAIL_c2ec1062FY '272026-02-012027-01-31Acceleration of existing SailPoint customers' shift to SaaS and adoption of AI identity solutions (AIS, MIS, DAS).This strategy aims to deepen SailPoint's footprint within its customer base, driving SaaS ARR growth and leveraging flexible pricing models, which is a key component of their FY27 growth plan.Ticker2026-03-18earnings_transcriptSAIL (ticker)
SAIL_619b83f9as these regulatory pressures intensify2026-06-112027-06-11Intensification of regulatory pressures related to AI risk frameworks (Treasury, NIST) and legal mandates (EU AI Act).Increased regulatory scrutiny on AI governance and non-human identities could drive greater demand for SailPoint's identity security solutions, strengthening its competitive advantage and potentially accelerating adoption.Theme2026-06-09earnings_transcriptSAIL (ticker)
ZS_a5e0f27cQ42026-05-012027-04-30Higher capital expenditures in Q4 FY26 and fiscal year 2027 due to increasing memory, storage, and processor prices, impacting free cash flow margin.Increased CapEx will negatively impact free cash flow margin in Q4 FY26 and FY27, as reflected in the lowered free cash flow margin guidance for FY26. This could impact profitability and investor sentiment.Ticker2026-05-26earnings_transcriptZS (ticker)
ZS_8c7cb2dcin '272026-05-012027-04-30Rollout and customer uptake of the integrated SecOps solution, combining Zscaler's platform with Red Canary's capabilities.Successful uptake could drive further upsell and cross-sell opportunities, contributing to ARR growth. The uncertainty around the pace of uptake could impact the realization of this growth.Ticker2026-05-26earnings_transcriptZS (ticker)
ZS_494da17dan important part of our fiscal '27 plan2026-05-012027-04-30Execution and effectiveness of new initiatives to accelerate new logo acquisition, particularly in the mid-market enterprise segment and through channel partners.Improved new logo growth is a strategic focus and could significantly boost ARR and market share, offsetting the 'tempered view' currently incorporated into FY27 guidance. Failure to execute could further pressure growth.Ticker2026-05-26earnings_transcriptZS (ticker)
ZS_ab629f13will have impact in fiscal '272026-05-012027-04-30Accelerated enterprise adoption of AI and the emergence of powerful frontier AI models driving increased demand for Zscaler's Zero Trust security solutions.This represents a significant tailwind, potentially boosting pipeline, new logo wins, and upsells for Zscaler's AI Protect and Zero Trust solutions, positively impacting revenue and ARR growth.Theme2026-05-26earnings_transcriptZS (ticker)
ZS_86551063short term2026-05-012027-04-30Resolution of sales leadership transitions and their impact on sales execution and growth trajectory.The departure of two sales leaders and the ongoing transition could disrupt sales execution, potentially impacting net new ARR growth and overall revenue. Management has already taken a 'prudent approach' to guidance due to this uncertainty.Ticker2026-05-26earnings_transcriptZS (ticker)
NTSK_0e0d279asecond half of the year2026-11-012027-04-30Netskope expects net new ARR to accelerate in the second half of fiscal year 2027, driven by the ramping productivity of its sales representatives and strong demand for its new AI security products.This acceleration is crucial for validating the company's growth strategy, demonstrating the successful monetization of its AI-native platform, and addressing concerns about recent net new ARR performance.Ticker2026-06-03earnings_transcriptNTSK (ticker)
NTSK_6b3148eeback half of the year2026-11-012027-04-30Netskope anticipates a return to positive quarterly free cash flow in the back half of fiscal year 2027, following Q1 FY27 being the low watermark of its transition to annual billing.Achieving positive quarterly free cash flow demonstrates improved financial health and operational efficiency, aligning with management's full-year guidance and strengthening investor confidence.Ticker2026-06-03earnings_transcriptNTSK (ticker)
NET_b838626cDecember 2, 20262026-12-022026-12-02Effective date for full compliance with transparency obligations under the EU AI Act for artificially generated content.This regulatory action will drive demand for tools that ensure machine-readable marking and compliance for AI-generated content, impacting Cloudflare's generative AI offerings and those serving EU customers, potentially increasing adoption of its security and developer platforms.Theme2026-08-06earnings_transcriptNET (ticker)
FFIV_012e8c34end of software support date in our Q2 of '272027-01-012027-03-31End of software support for F5's iSeries appliances, which is expected to drive acceleration of customer refresh activity to rSeries products.This milestone is anticipated to accelerate the iSeries to rSeries refresh cycle, significantly boosting F5's hardware revenue and reinforcing its 'refresh plus' growth dynamic.Ticker2026-07-27earnings_transcriptFFIV (ticker)
SAIL_d38c2ceaby fiscal year-end2027-01-012027-01-31Achievement or overachievement of the $100 million AI-driven ARR target for fiscal year 2027.This milestone would validate the strong adoption and monetization of SailPoint's AI-driven solutions, reinforcing the bull thesis and potentially leading to upward revisions in future guidance.Ticker2026-09-09earnings_transcriptSAIL (ticker)
PANW_ce29122ain approximately 12 to 18 months.2027-06-022027-12-02Stock-based compensation (SBC) as a percentage of revenue returning to pre-acquisition levels.A reduction in SBC as a percentage of revenue would positively impact GAAP profitability and could improve investor sentiment regarding the dilutive effects of recent acquisitions.Ticker2026-06-02earnings_transcriptPANW (ticker)
PANW_02994241within the next 12 to 18 months.2027-06-022027-12-02CyberArk's profitability profile converging with Palo Alto Networks' overall profitability.This milestone is key to achieving Palo Alto Networks' target of a 40% free cash flow margin by fiscal 2028, signaling successful M&A integration and improved financial efficiency.Ticker2026-06-02earnings_transcriptPANW (ticker)

Constituents

  • — F5, Inc.
  • — Akamai Technologies, Inc.
  • — CrowdStrike Holdings, Inc.
  • GENT3
    — Gen Digital Inc.
  • NETT3
    — Cloudflare, Inc.
  • — Netskope, Inc. Class A Common Stock
  • — Okta, Inc.
  • — Palo Alto Networks, Inc.
  • — Rubrik, Inc.
  • ST3
    — SentinelOne, Inc.
  • — SailPoint, Inc.
  • — Varonis Systems, Inc.
  • ZST3
    — Zscaler, Inc.
  • 4704.TT3
    · no notes yet
  • CHKPT3
    · no notes yet
  • CVLTT3
    · no notes yet
  • FSECURE.HET3
    · no notes yet
  • FTNTT3
    · no notes yet
  • QLYST3
    · no notes yet
  • RDWRT3
    · no notes yet
  • RPDT3
    · no notes yet
  • TENBT3
    · no notes yet
  • YUBICO.STT3
    · no notes yet