UBS said cybersecurity stocks have climbed sharply since April and now trade above their COVID-era valuation peaks, leaving the sector with less room for disappointment in the third quarter. In its U.S. software report published on Sept. 28, 2026, the bank said the group is trading at 62x market-cap-weighted enterprise value to next-12-month free cash flow and 15x enterprise value to next-12-month revenue, above the pandemic peaks of 59.1x and 14.9x.

According to UBS, investor expectations have been pushed higher by rising attention on AI security incidents, but company fundamentals have not accelerated at the same pace. That, in the bank’s view, means Q3 results will need to beat by a wider margin to support current valuations.
UBS says fundamentals have not kept pace with the rerating
Roger Boyd of UBS said that, aside from CrowdStrike (CRWD), Fortinet (FTNT), Palo Alto Networks (PANW) and Qualys (QLYS), most vendors did not show accelerating revenue and billings growth in the second quarter. Third-quarter guidance, he wrote, was broadly muted.
UBS said cybersecurity stocks, excluding those four companies, have risen an average of 62% since the April 7 release of Mythos. If the sector does not deliver broader upside in Q3, the bank said that could reinforce the view that large platforms are capturing incremental AI security budgets. A small miss from CRWD or PANW in Q3 could also weigh on the whole group.
The report added that cybersecurity lagged software in the first four months of 2026 because frontier labs were introducing dedicated cyber models, vulnerability discovery systems, code security products and agent defense frameworks that appeared to compete with incumbent vendors. Since April, after frontier labs established controlled access programs with cybersecurity companies and the AI threat environment kept changing, cybersecurity stocks have doubled and outperformed the software index. UBS said the underlying fundamentals, however, remain relatively unchanged.
Three debates UBS is watching
UBS highlighted three central debates for the sector. First, whether Q3 needs a broader tailwind across the industry; the bank said yes. Second, whether concerns about competition from frontier labs will re-emerge; UBS said those labs are at least likely to keep expanding their cybersecurity capabilities. Third, what role infrastructure vendors will play in AI security; UBS said moves by Microsoft, ServiceNow and Nvidia could intensify that discussion.
Frontier labs are expanding in cyber
UBS said cybersecurity has become a much more visible focus area for frontier labs in 2026. OpenAI has introduced GPT-6 Astra, which Preparedness Framework v2 designated as the first model at the “critical” level for cybersecurity capability, as well as GPT-5.6 Sol, GPT-5.5 Cyber and the Daybreak Blue controlled access program.
Greg Brockman said OpenAI is using Astra-level capabilities to protect its internal infrastructure. UBS also pointed to OpenAI DevDay 2026 on Sept. 29 as the next likely venue for additional cyber-related announcements.
Anthropic has launched Claude Code Security, a preview of Claude Mythos, Project Glasswing and the Cyber Verification Program. Google has released Big Sleep, Gemini 3.5/3.8 Flash Cyber, AVDH and Fairwind, with more than 650 partners. Microsoft AI has introduced MAI-Cyber-1-Flash, MDASH and Project Perception. Meta has rolled out CyberSecEval. xAI has introduced Grok 4.7 and Grok for Security Teams.
UBS said these offerings overlap more directly with the existing cybersecurity stack. Vulnerability discovery, code review, exploit reasoning, investigation, triage, detection engineering, prioritization and remediation are increasingly tasks that frontier models or cyber-specific models can handle.

Infrastructure vendors are moving into the security stack
Nvidia launched the Open Secure AI Alliance in July with more than 35 technology and cybersecurity partners, according to the report. ServiceNow has been expanding its cybersecurity business through the acquisitions of Armis and Veza. Microsoft continues to broaden its AI security suite, while Nvidia is building an AI security platform around OpenShell and Sentry.
UBS described OpenShell as an open-source secure runtime for AI agents, and Sentry as a DPU-based platform for real-time segmentation and response. At launch, OpenShell integrated with CrowdStrike, Palo Alto Networks, Cisco and Jfrog. Its design places policy enforcement, sandboxing and access control outside the agent inference loop, creating a security layer that the model itself cannot bypass. UBS said multiple customers have described using OpenShell or other open-source frameworks to build or customize secure multi-agent environments.
The bank added that infrastructure vendors have not historically been especially successful when security is an add-on, but the competitive narrative is getting louder because of how the market is viewing their scale. UBS argued that model capability is not the same as enterprise security ownership. Models may identify vulnerabilities, investigate alerts and recommend actions, but they do not independently own enterprise telemetry, identity systems, policy infrastructure, enforcement points or operating responsibility. The more relevant distinction, in UBS’s view, is between security analytics and security control. Frontier labs are likely to stay focused on analytics, with limited ability to execute runtime security. Vendors whose value proposition is centered on analytics face growing pressure.
Governance demand is shaping security budgets
UBS said comments from frontier lab leaders about “slowing the frontier” have made customers more cautious, but its checks do not show a broad slowdown in enterprise AI adoption. Instead, customers are paying more attention to sandboxing, observability, authorization, model choice, agent monitoring and data controls while continuing to deploy AI.
Across several surveys, UBS found that AI security is increasingly being budgeted together with AI deployment rather than as a separate initiative. Customers said stronger models create more governance requirements, not less security spending. They are discussing agent identity, authorization, data protection, observability and human-in-the-loop controls more often, while continuing to use AI for security work.
Partner feedback pointed to identity security as the top priority, followed by governance, then adjacent areas such as data security posture management, data loss prevention and data access governance. UBS said it expects investment in those categories to increase.
How UBS is framing the sector
UBS said its preferred way to think about positioning in cybersecurity comes down to three points: valuations are already above pandemic peaks and Q3 will need stronger beats to support them; competition narratives involving frontier labs and infrastructure providers could return, putting more pressure on analytics-led vendors; and enterprise governance needs are pushing security budgets to merge with AI deployment budgets, supporting spending in identity, governance and data security.
This article is a整理 and interpretation by Chaoxiang Research of a third-party broker research report from UBS Group dated Sept. 28, 2026, combined with public market information. Any ratings, target prices, earnings forecasts and related judgments cited in the piece are the views of the broker’s analysts and represent only the stance of their institution, not Chaoxiang Research, and do not constitute investment advice.
Markets carry risk, and decisions should be made independently. This article should not be used as the basis for buying or selling any security.

