Cybersecurity earnings are strong. The bigger opportunity may still lie ahead

Recent results from leading cybersecurity companies point to improving demand, even without a sharp post-Mythos surge in industry spending. We believe this leaves room for further growth as agentic AI, increasingly sophisticated cyber threats and IT/OT convergence drive a multi-year expansion in cybersecurity investment.

Joel Phua
Joel Phua11 Sep 2026Views
Cybersecurity earnings are strong. The bigger opportunity may still lie ahead
Cybersecurity players delivered strong second-quarter earnings, with Fortinet, Okta, CrowdStrike and Palo Alto Networks all exceeding expectations and raising guidance.
While there has been no sharp post-Mythos spending spike, cybersecurity spending is strengthening, leaving a larger growth opportunity ahead as enterprises progressively ramp up security investments.
Long-term growth drivers for the sector remain intact, including rising AI adoption, increasingly sophisticated cyber threats, agentic AI, IT/OT convergence and tighter regulatory requirements.
Platformisation is gaining traction as enterprises consolidate vendors, favouring integrated cybersecurity platforms such as CrowdStrike and Palo Alto Networks.
We remain positive on the cybersecurity industry and believe the BUG ETF remains attractively valued despite its strong performance. We reiterate our target price of USD 57, implying 41% upside from its 10 September closing price of USD 40.65.

The Global X Cybersecurity ETF (NASDAQ: BUG) has continued its ascent since our last update, rising as much as 26% to close at a high of USD 44.46 on 13 August, before pulling back.

In this article, we analyse the top four holdings of the BUG ETF and highlight why we remain positive on the cybersecurity industry.

Figure 1: BUG has delivered strong YTD performance of 33.5%


Cybersecurity leaders deliver strong earnings and raise guidance


Fortinet


Fortinet's second quarter revenue jumped 26% year-over-year to USD 2.05 billion, comfortably above market expectations of USD 1.88 billion. Product revenue was particularly strong, growing 52% year-over-year to USD 773 million, driven by robust FortiGate unit growth and higher average selling prices as customers shifted toward higher-performing models to prepare for increased network traffic. Importantly, management noted that it has not seen any excess customer inventory or pulled-forward spending ahead of expected price increases stemming from the global memory chip shortage. This suggests that top-line growth was driven by durable underlying demand rather than a temporary spike.

Total billings grew 33% year-over-year to USD 2.37 billion, accelerating from the prior quarter, led by Secure Networking (+34%) and Unified SASE (+35%) on robust demand for physical infrastructure and attached services. Security Operations billings rose 25% on strong upsell momentum as customers consolidate point solutions onto Fortinet's broader platform. Adjusted earnings per share (EPS) came in at USD 0.90, well above consensus of USD 0.75.

As it did in the previous quarter, management raised its fiscal 2026 outlook across revenue, billings and EPS.

Despite the broad-based beat and raised guidance, shares closed roughly flat the following day, likely reflecting an already elevated valuation heading into the results.

Table 1: Fortinet’s latest earnings

2QFY26

2QFY25

Beat/Miss vs Estimate

YoY change

Revenue

2,047.9

1,630.0

8.8%

25.6%

Net Income

606.3

440.1

24.3%

37.8%

Adjusted diluted earnings per Share

0.90

0.64

20.2%

40.6%

Source: Fortinet 2QFY26 Press Release, Bloomberg. Data as of 29 July 2026.

Figures are in USD millions except percentages and per share amounts. 

Okta

Okta’s second-quarter revenue grew 11% YoY to USD 805 million, above consensus estimates of USD 792.9 million. Adjusted diluted EPS came in at USD 1.05, above consensus of USD 0.97. Remaining performance obligations (RPO) increased 17% YoY, while current RPO growth, which reflects the portion of RPO expected to be recognised over the next 12 months, accelerated from 12% to 14%.

Performance was supported by broad-based strength across Okta’s core workforce and customer identity platforms, with large enterprise customers remaining an important growth driver. The number of customers generating more than USD 1 million in annual contract value (ACV) grew by over 20%. New products also continued to gain traction, accounting for approximately 30% of bookings, led by Okta Identity Governance.

The growing use of AI by organisations, alongside increasingly sophisticated AI-enabled threats, is heightening security concerns and prompting customers to accelerate infrastructure modernisation. Management noted that discussions around securing AI are increasingly expanding into broader identity modernisation initiatives, supporting demand for Okta’s identity solutions.

Management raised FY2027 guidance for revenue, diluted EPS and free cash flow, reflecting continued strength in demand and execution.

Okta’s share price surged 28.6% the day after the earnings release, likely reflecting investors’ growing confidence that the company is well positioned to benefit from the adoption of agentic identity security.

Table 2: Okta’s latest earnings

2QFY2Y

2QFY26

Beat/Miss vs Estimate

YoY change

Revenue

805.0

728.0

1.5%

10.6%

Net Income

194.0

169.0

9.3%

14.8%

Adjusted diluted earnings per Share

1.05

0.91

8.8%

15.4%

Source: Okta 2QFY27 Press Release, Bloomberg. Data as of 26 August 2026.

Figures are in USD millions except percentages and per share amounts. 

Crowdstrike

CrowdStrike delivered a strong fiscal second quarter, reporting revenue of USD 1.47 billion, up 26% year-over-year and ahead of consensus expectations of USD 1.44 billion. Annual recurring revenue increased 25% to USD 5.84 billion, while net new ARR accelerated 51% year-over-year to USD 333 million, exceeding the high end of management’s guidance.

The core endpoint business accelerated for the fourth consecutive quarter, as customers increasingly look to secure the growing AI attack surface, particularly as agentic AI activity expands across endpoints. Non-endpoint solutions, including Cloud Security, Next-Gen SIEM and Identity Security, also saw strong growth, with combined ARR increasing 39% year-over-year. Falcon Flex, CrowdStrike’s flexible licensing model providing access to its full security portfolio through a pre-negotiated commitment, continues to support platform consolidation and drive revenue, with average ending ARR increasing by more than 40% when customers convert from standard subscriptions.

Adjusted EPS came in at USD 0.31, ahead of consensus expectations of USD 0.29. Management raised its FY2027 guidance across revenue, ARR and EPS, supported by strong second quarter performance and a strengthening post-Mythos demand environment, which is driving increased investment in cybersecurity modernisation.

Shares surged 20.5% following the results, as investors responded positively to the strong results and improved growth outlook.

Table 3: CrowdStrike’s latest earnings

2QFY27

2QFY26

Beat/Miss vs Estimate

YoY change

Revenue

1,470.9

1,169.0

2.2%

25.8%

Net Income

5.3

-70.2

-78.9%

-

Adjusted diluted earnings per Share

0.31

0.23

6.4%

34.8%

Source: CrowdStrike 2QFY27 Press Release, Bloomberg. Data as of 26 August 2026.

Figures are in USD millions except percentages and per share amounts. 

Palo Alto Networks

Palo Alto Networks’ fiscal fourth-quarter 2026 revenue grew 34% YoY to USD 3.41 billion, above consensus estimates of USD 3.35 billion. Next-Generation Security (NGS) ARR, which covers Palo Alto Networks’ product, subscription and support offerings excluding hardware and legacy offerings, increased 63% YoY to USD 9.10 billion, while remaining performance obligations (RPO) rose 34% to USD 21.2 billion.

Management attributed the strong performance to growing customer urgency to strengthen cybersecurity defences as AI reshapes the security landscape, alongside continued adoption of its platformisation strategy. Palo Alto Networks added approximately 220 net new platformisations in Q4, with net revenue retention (NRR) for its platformised customer cohort exceeding 120%, highlighting strong customer retention and expansion. Adjusted earnings per share of USD 1.02 also exceeded consensus estimates of USD 0.98.

Despite the strong results, shares fell 9.3% the day after earnings, possibly reflecting concerns over weakening gross margins. Full-year gross margin declined 60 basis points to 75.8%, as revenue continued to shift towards faster-growing SaaS offerings that have yet to reach gross margin maturity. Management also expects cloud hosting costs to grow faster than revenue in fiscal 2027.

Table 4: Palo Alto Network’s latest earnings

4QFY26

4QFY25

Beat/Miss vs Estimate

YoY change

Revenue

3,410.0

2,536.3

1.7%

34.4%

Net Income

853.0

673.0

4.7%

26.7%

Adjusted diluted earnings per Share

1.02

0.95

4.3%

7.4%

Source: Palo Alto Networks 4QFY26 Press Release, Bloomberg. Data as of 1 September 2026.

Figures are in USD millions except percentages and per share amounts. 

Cybersecurity spending is ramping up, with long-term growth drivers intact

The launch of Mythos in April has catalysed greater board-level attention towards cybersecurity, with management teams increasingly treating security as an urgent business priority. This heightened urgency is beginning to translate into higher cybersecurity spending, contributing to strong second-quarter results across cybersecurity players.

That said, we do not believe there has been a large, sudden inflection in cybersecurity spending following Mythos. Rather, the strong results reflect an incremental increase in spending as companies reassess their security needs. Palo Alto Networks CEO Nikesh Arora noted that enterprises need time to assess their security needs and evaluate the changes required before deploying cybersecurity solutions, with deployments potentially taking one to three years. Companies are also balancing cybersecurity investments against other AI initiatives, including AI-enabled customer support, large language model deployment and AI coding tools.

This gradual adoption is also evident in Okta's outlook. The company expects AI-related contributions to remain small and immaterial in FY27, but sees potential for them to become more meaningful from FY28 onwards. A recent McKinsey Global Survey on the state of AI similarly found that while the adoption of AI tools continues to increase, the use of agentic AI remains at a very early stage compared with AI chatbots. This suggests there is still considerable runway for AI adoption and, consequently, cybersecurity spending to expand as organisations move towards more advanced AI applications.

Figure 2: Adoption of AI agents remains at an early stage


Looking ahead, we remain positive on the long-term outlook for cybersecurity. AI-powered cyber threats are likely to be an increasingly important driver of demand, as threat actors use AI to automate vulnerability discovery and launch faster, more sophisticated attacks. This increases the need for more advanced security solutions and faster threat detection and response.

Rising adoption of agentic AI further expands the cybersecurity attack surface. Unlike traditional AI applications that respond to individual human prompts, autonomous agents can operate continuously in the background, creating a growing number of machine identities with their own access that organisations will need to secure. The increasing autonomy and capabilities of AI agents also raise the risk that they could operate beyond their intended boundaries, with Anthropic, OpenAI and Meta Platforms recently disclosing instances where their models escaped testing environments, accessed the open internet and carried out attacks against real-world systems.

Beyond AI, IT and operational technology (OT) convergence is opening up new areas of cybersecurity demand. Industrial and utility environments that were historically isolated from corporate IT networks are becoming increasingly connected, creating new vulnerabilities that organisations need to secure. Meanwhile, persistent threats against critical infrastructure and tighter regulatory and compliance requirements, including Europe's NIS2 framework, are providing additional impetus for companies to strengthen their security infrastructure.

Taken together, these factors point to a multi-year expansion in the cybersecurity opportunity. With industry spending still ramping up, we believe the stronger growth opportunity lies ahead as AI adoption expands and enterprises accelerate security modernisation. This underpins our earnings growth projections for the Global X Cybersecurity ETF (BUG), with EPS growth expected to accelerate from 2026 through 2028 as cybersecurity spending ramps up. We maintain our target price of USD 57, implying approximately 41% upside from its closing price on 10 September 2026.

For investors with a higher risk appetite seeking single-stock exposure, we continue to favour platform leaders such as CrowdStrike and Palo Alto Networks. Both are well positioned to benefit from ongoing vendor consolidation as enterprises seek to reduce complexity by working with fewer cybersecurity providers. More importantly, as AI-powered threats operate at machine speed, fragmented security solutions may struggle to respond quickly enough when data is spread across disconnected platforms. This should further support the advantage and broader customer preference for integrated security platforms that can coordinate protection across the enterprise and respond rapidly to threats.

Table 5: Projections for the Indxx Cybersecurity Index

IBUGT Index

2025

2026E

2027E

2028E

Earnings Per Share (EPS)

78.4

87.7

99.0

114.6

Earnings Growth YoY

17.8%

11.8%

12.9%

15.7%

PE Ratio (X)

27.0

32.4

28.7

24.8

Target Price for Index (based on a fair PE of 35X)

4,011

Upside Potential

41.3%

Target Price for ETF (USD)

57

Source: Bloomberg Finance L.P., iFAST estimates.

Data as of 10 September 2026

Figure 3: Share prices are driven by earnings growth in the long run

Declaration:

This research report was prepared with the assistance of artificial intelligence (AI) tools. iFAST Financial Pte Ltd does not rely exclusively on AI for content generation; the content of this report – including all investment theses, ratings, price targets and conclusions – has been independently reviewed and verified by the research analyst(s) to ensure accuracy and professional integrity.

For specific disclosure, at the time of publication of this report, IFPL (via its connected and associated entities) holds a NIL position in the abovementioned securities. The analyst who produced this report holds a position in Fortinet, Palo Alto Networks and CrowdStrike. 


All materials and contents found in this site are strictly for general circulation and informational purposes only and should not be considered as an offer, or solicitation, to deal in any of the funds or products found/identified in this site. While iFAST Financial Pte Ltd ("IFPL") has tried to provide accurate and timely information, there may be inadvertent delays, omissions, technical or factual inaccuracies and typographical errors. Any opinion or estimate contained in this report is made on a general basis and neither IFPL nor any of its servants or agents have given any consideration to nor have they or any of them made any investigation of the investment objective, financial situation or particular need of any user or reader, any specific person or group of persons. You should consider carefully if the products you are going to purchase are suitable for your investment objective, investment experience, risk tolerance and other personal circumstances. If you are uncertain about the suitability of the investment product, please seek advice from a financial adviser, before making a decision to purchase the investment product. Past performance is not indicative of future performance. The value of the investment products and the income from them may fall as well as rise. Opinions expressed herein are subject to change without notice. In respect of any matters arising from, or in connection with the said research analyses or research reports, recipients of the report are to contact IFPL at 10 Collyer Quay, #26-01 Ocean Financial Centre Building, Singapore 049315, or by telephone at +65 6557 2853. Where the report contains research analyses or research reports from a foreign research house and if the recipient of such research analyses or research reports is not an accredited investor, expert investor, institutional investor or an ex-accredited investor, IFPL accepts legal responsibility for the contents of such analyses or reports to such persons only to the extent as required by law. Please note that only certain security(ies) herein are available to all investors, while the rest are only available for certain persons to invest in, such as Accredited Investors (as defined in the Securities and Futures Act) or one who invests at least S$200,000 (or its equivalent currency) per transaction. To qualify as an Accredited Investor, one needs to submit a declaration form and certain relevant supporting documents, according to iFAST’s prevailing policies and procedures.

Please read our full disclaimers on the website at ( https://fsm.global/sg/policies/328125/investment-account-terms-&-conditions).

iFAST Financial Pte Ltd (IFPL) (registered address: 10 Collyer Quay #26-01 Ocean Financial Centre Singapore 049315, Telephone: 6557 2000) holds the Financial Advisers Licence issued by the Monetary Authority of Singapore ('MAS') to conduct regulated activities of advising on securities, marketing of collective investment schemes and arranging of any contract of insurance in respect of life policies, other than a contract of reinsurance and the Capital Markets Services Licence issued by the MAS to conduct regulated activities of dealing in securities and providing custodial services for securities. While IFPL has made every effort to ensure the independence of the report's contents, IFPL's nature of business is such that IFPL and its connected and associated entities together with their respective directors, officers and staff may be involved in providing dealing or investment-related services in the abovementioned securities, and have taken or may take positions in the securities mentioned in this report, and may also act as the principal for any buy or sell trades.