-+ 0.00%
-+ 0.00%
-+ 0.00%

Have cybersecurity stocks gone too far? Bernstein: AI demand is still strong, but sector valuations are already at a high level. Palo Alto (PANW.US), Okta (OKTA.US), and SentinelOne (S.US) ratings have been lowered

智通财经·09/17/2026 15:41:23
语音播报

The Zhitong Finance App learned that Bernstein said in the latest US software industry report released on September 17 that demand for cybersecurity brought about by artificial intelligence continues to increase, and corporate security budgets and new contract models are also driving industry growth, but after experiencing a sharp rise since 2026, the valuation of the cybersecurity sector has expanded markedly, and most of the covered companies have now approached or even exceeded the reasonable valuation level estimated by the agency. Based on this, Bernstein downgraded the ratings of Palo Alto Networks (PANW.US), Okta (OKTA.US), and SentinelOne (S.US) to “neutral”. Currently, only Zscaler (ZS.US) among the companies covered still has significant room for upward valuation.

Bernstein pointed out that at the beginning of this year, it was strongly optimistic about the cybersecurity industry, and its core logic was the new security requirements brought about by AI. Subsequently, even though AI Labs launched its own cybersecurity products one after another, which once raised investors' concerns about the replacement of traditional security software companies, the agency maintained a positive judgment on the fundamentals of the industry.

As it turns out, the demand for cybersecurity continues to strengthen. Bernstein's mid-year Chief Information Security Officer (CISO) and Chief Information Officer (CIO) surveys showed a further improvement in demand signals, and the recent increase in discussions surrounding cybersecurity risks that may limit the development of AI laboratories has further improved investors' views on traditional cybersecurity companies.

The problem, however, is that the rate of increase in stock prices may have outpaced the improvement in fundamentals. Bernstein said that since the beginning of 2026, the cumulative increase in many cybersecurity stocks covered by it has reached about 100% or even higher, while the level of sector trading congestion has increased significantly.

AI continues to drive security spending, but valuations have clearly “rushed”

Bernstein believes that the current core paradox in the cybersecurity industry has changed: at the beginning of the year, the market was concerned about whether AI would bring opportunities or threats to traditional cybersecurity vendors. Now, as demand is gradually verified, the problems investors need to face have become. How much future growth has the current stock price actually taken into account?

The valuation analysis in the report shows that cybersecurity companies' EV/sales multiples for the next 12 months are generally higher than application software companies, and the valuation of some of these companies even exceeds that of consumer infrastructure software companies that are also enjoying the AI investment boom.

Take Cloudflare (NET.US) and CrowdStrike (CRWD.US) as an example. As of September 14, the two companies' corresponding EV/next 12 month sales multiples had reached about 36 times. Bernstein's regression analysis further shows that, with the exception of a few companies, there is a high correlation between the “40 rule” and valuation multiples, and currently most covered companies are close to or even higher than the reasonable valuation level corresponding to the model.

Notably, Bernstein's own growth forecasts for these companies have generally exceeded the Wall Street seller market's unanimous expectations, but even with these relatively optimistic revenue forecasts, it is still difficult for the agency to find sufficient room for growth from current valuations other than Zscaler.

In other words, Bernstein does not believe that the fundamentals of the cybersecurity industry are deteriorating; rather, he believes that the valuation premium given by the market to this sector has increased markedly, and the demand for future growth in stock prices has also risen.

Flex contracts become cybersecurity company's new growth engine

In addition to AI requirements, Bernstein specifically pointed out that a flexible contract model known as “Flex” is helping cybersecurity vendors accelerate revenue growth. The Flex contract can be understood as a model where the manufacturer provides the customer with a model similar to an “enterprise-level general license”, where the customer promises a certain amount of money in advance and can then flexibly use the manufacturer's different products and services within the scope of the contract amount.

The advantage of this model is that business customers don't have to predict exactly what cybersecurity products they will need in the future when they first make a purchase. As new security threats emerge, customers can quickly add additional products without having to go through the full purchasing and sales process again. For cybersecurity vendors, this also greatly reduces the difficulty of upselling and cross-selling to existing customers.

CrowdStrike is an important example of this model. Bernstein estimates that CrowdStrike's latest quarterly expansion and up-sales generated through FLEX contracts contributed an additional $30 million to $40 million in additional annual recurring revenue (ARR), more than would be possible with normal sales capacity alone.

This means that the growth of cybersecurity companies is not only due to the expansion of market demand, but the business model itself is also improving sales efficiency.

Despite strong AI demand, there is still a natural upper limit for cybersecurity growth

However, Bernstein believes that although the Flex contract can increase the growth rate, it is not enough to fully support the growth expectations implied by some cybersecurity stocks at present. The core reason is that there is an essential difference between network security software and infrastructure software that charges for usage, such as cloud computing and databases.

For hyperscale cloud service providers or database platforms, consumption can theoretically continue to expand rapidly as customer computing, data, and AI workloads increase, so revenue has a strong usage-driven effect.

Cybersecurity products, on the other hand, have a more obvious ceiling on natural growth. For example, AI pushes companies to focus on increasing investment in fields such as SSE/SASE, terminal security, observability, and communication and email security. Demand is usually linked to the number of employees or terminal devices in the enterprise, and the growth rate of these indicators is relatively stable. In contrast, cybersecurity and cloud security are more correlated with computing usage, so they have more obvious consumption-based growth attributes.

Using CrowdStrike as an example, Bernstein pointed out that after removing the influence of the easier year-on-year base, its “real” new ARR growth rate was in the high 20% range. As the Flex contract gradually enters a year-on-year base, its overall growth may eventually approach a high 20% range rather than the 40% or more growth level that current valuations seem to imply. The bank believes that strong demand and business model innovation are real, but they are not necessarily sufficient to meet the high growth expectations that have been taken into account in current stock prices.

Palo Alto, Okta, and SentinelOne downgraded

Based on the latest valuation model, Bernstein drastically raised the valuation multiples of cybersecurity companies and raised the target prices of several companies accordingly, but at the same time, the investment ratings of three of these companies were lowered.

Specifically, Palo Alto Networks' target price was raised from $253 to $351, but the rating was lowered from “outperforming the market” to “neutral”; Okta's target price was raised from $143 to $174, and the rating was also downgraded to “neutral”; and SentinelOne's target price was raised from $21 to $25, but the rating was also downgraded to “neutral.”

Bernstein said that all three companies were previously considered “too cheap,” but after experiencing revaluation in the past quarter, the current stock price has basically returned to a reasonable level compared to their updated industry valuation model, so the risk-to-benefit ratio is no longer as attractive as before.

Meanwhile, the ratings for CrowdStrike, Cloudflare, Fortinet (FTNT.US), and Zscaler remained unchanged.

However, Bernstein is particularly cautious about CrowdStrike's current valuation. The agency pointed out that CrowdStrike's current transaction valuation is significantly higher than the level corresponding to the industry regression model, while Palo Alto is relatively close to the model valuation. Both companies are benefiting from the growing demand for cybersecurity brought about by AI, so the valuation gap is likely to gradually narrow in the long run.

SentinelOne's potential merger and acquisition value draws attention

Despite downgrading SentinelOne's ratings, Bernstein sees the company as an attractive potential strategic acquisition target within its coverage area.

According to the report, SentinelOne may become a potential merger and acquisition target for AI laboratories, hyperscale cloud computing companies, and even other large cybersecurity vendors, including Anthropic, Google's parent company Alphabet (GOOGL.US), and Palo Alto Networks.

However, this view is Bernstein's judgment on the degree of potential strategic compatibility, and does not mean that the relevant companies are in the process of acquisition negotiations.

For Okta, Bernstein believes that the biggest potential upside variable in the future may come from AI agent infrastructure.

As AI agents begin to access enterprise applications, databases, and other digital resources on behalf of users, the importance of authentication and rights management is expected to increase, which may create new requirements for Okta. However, Bernstein also stressed that at present, it is still difficult to determine when AI agents will actually mature on a large scale and achieve commercial deployment, and it is also unclear how to price related products and the scale of final demand.

Maintaining Zscaler's “outperforming the market” rating sales transformation has entered a critical stage

Among the cybersecurity companies covered by Bernstein this time, Zscaler is a special one.

The report shows that Zscaler closed at $191.58 on September 16, while Bernstein raised its target price sharply from $224 to $298 and maintained an “outperforming market” rating. In contrast, the stock prices of Palo Alto, Cloudflare, CrowdStrike, Okta, and Fortinet were all higher than Bernstein's updated target prices at the time.

Bernstein believes that the main reason for Zscaler's previous growth slowdown was not that the product lost competitiveness, but rather that the company actively adjusted its sales strategy, gradually shifting from a transactional sales model that mainly relied on new customers in the past to a model that focused more on long-term customer relationships, up-selling, and cross-selling.

This three-year sales transformation is now in its final stages. Zscaler's net revenue retention rate (NRR) for the full year of FY2026 remained at 115%, and the company expects the existing sales pipeline to support FY2027 to continue to maintain this level. According to the latest quarterly data, the trend of declining contributions from new customers appears to have stopped. Bernstein expects that if this indicator stabilizes or even improves again, the company's revenue growth rate is also expected to stabilize.

Meanwhile, despite Zscaler's pressure from competitors such as Cloudflare, there is still considerable market space for large enterprises to migrate from traditional web security and VPN to modern SSE/SASE architectures.