Why U.S. cybersecurity stocks are rallying while China’s sector is still falling

Why U.S. cybersecurity stocks are rallying while China’s sector is still falling

N
News Editor
2026-09-21 13:22:09
Cybersecurity stocks in the U.S. and China have diverged sharply during this year’s AI trade. As of Aug. 31, the U.S.-listed cybersecurity ETF CIBR was up 40.36% for the year, while China’s CSI Information Security Theme Index was down 12.49% as of Sept. 18. The source article argues that the gap is not simply about who has stronger AI narratives. It comes from a deeper shift in how cybersecurity is funded and sold in the two markets. In the U.S., cybersecurity is increasingly treated as infrastructure tied to AI adoption. Gartner expects global information security spending to reach $244 billion in 2026, up 11.6%, while its Securing AI segment is projected to hit $2.835 billion in 2026 and $4.783 billion in 2027. That demand is already showing up in company results, including Fortinet and Palo Alto Networks. In China, by contrast, the digital security market has contracted for three straight years, according to 数世咨询, and many vendors still depend on traditional government and enterprise IT compliance budgets. The article also points to differences in business models. U.S. leaders such as Palo Alto Networks, CrowdStrike and Fortinet are building subscription-based platforms that can expand revenue per customer. Many Chinese vendors still rely on project-based sales, where security often trails spending on models, computing power, data governance and application development. The result, the article says, is that one market is earning from AI expansion, while the other is still earning from conventional IT construction.

U.S. and Chinese cybersecurity stocks have turned into two totally different trades in this year’s AI surge.

By Aug. 31, the U.S. cybersecurity ETF CIBR was up 40.36% for the year, beating the Nasdaq over the same stretch, and several names in the group had more than doubled. China? Almost the reverse. Zhipu has landed more than 1 billion yuan in cybersecurity-related orders, but the wider sector has stayed soft. As of Sept. 18, the CSI Information Security Theme Index was down 12.49% for the year.

So yes, that is a gap of more than 50 percentage points in less than a year.

The source article argues the core reason is simple: cybersecurity is becoming two different businesses in the two markets. In the U.S., it is starting to look like infrastructure that rises with AI usage, pulling in spending tied to AI growth. In China, cybersecurity revenue is still mostly stuck inside old government and enterprise IT compliance budgets, where it is treated more like a cost center.

Market size and demand are moving in different directions

The split shows up first in industry growth.

Gartner expects global information security spending to hit $244 billion in 2026, up 11.6% year over year. The fastest-growing piece, the article says, is demand created by AI. Gartner also tracks a category called Securing AI, covering AI application security, AI usage controls, AI governance platforms and AI Gateway products.

That market is expected to reach $2.835 billion in 2026, up 83%, and then climb to $4.783 billion in 2027, another 68.7% increase.

Put differently, AI has not just pushed U.S. companies to reshuffle existing security budgets. It has created brand-new security budgets. Every extra AI application can add another layer of demand, from model authorization to data security. More AI deployment. More security spending.

The article says you can already see that in company earnings.

Fortinet reported $2.05 billion in revenue in the second quarter, up 26% year over year. Billings were $2.37 billion, up 33%, and its GAAP operating margin was 34%.

Palo Alto Networks gave an even cleaner example. In the fourth quarter of fiscal 2026, its AI security product Prisma AIRS had topped $100 million in ARR after just four quarters on the market, making it the fastest-growing new product in the company’s history.

Chinese cybersecurity vendors, on the other hand, are working in a market that has already contracted for three straight years, the article said.

Data from Digital World Consulting showed that China’s digital security market reached 88.743 billion yuan in 2025, down 1.5% year over year. That was the third consecutive annual decline. The market was 98.12 billion yuan in 2022, then slipped 0.76% in 2023, 7.4% in 2024 and another 1.5% in 2025. Over three years, it shrank by nearly 10 billion yuan.

Qi An Xin said in its interim report that customers have broadly cut budgets and project delays are still showing up because of the macro environment and government fiscal conditions. It also said price competition is still fierce and, with limited budgets, customers are more and more inclined to maintain existing systems instead of launching new projects.

For the first half of the year, Qi An Xin posted revenue of 1.497 billion yuan, down 14.09%, and a net loss attributable to shareholders of 411 million yuan.

The article also says some Chinese companies have gotten a lift from AI, but that money has not always gone to security first.

Sangfor is one case. In the first half, the company reported revenue of 3.998 billion yuan, up 32.85%, and net profit attributable to shareholders of 231 million yuan, returning to profitability. But its fastest-growing business was not security. Revenue from cloud computing and AI infrastructure came to 2.212 billion yuan, up 58.6%, while cybersecurity revenue was 1.587 billion yuan, up 10.57%. The former made up 55.34% of total revenue, becoming the company’s main growth engine for the first time.

U.S. vendors are selling platforms, while many Chinese vendors still sell projects

The article says the business-model gap is widening right alongside the budget gap.

U.S. cybersecurity companies mainly sell subscriptions. A customer signs a contract, then keeps renewing. As AI applications multiply, new security needs can be added onto the same customer relationship. AI Gateway, AI application security, and identity and permission management for agents are all examples of demand that did not exist before.

At the same time, AI is making enterprise IT environments more tangled. That can push customers to cut down the number of vendors they use. The article says big players like Palo Alto, CrowdStrike and Fortinet are in position to absorb budgets that used to go to other security providers.

Palo Alto is framed as the clearest example. For years, the company has stressed “Platformization.” The idea: a large enterprise that once bought products from a dozen, or even dozens, of security vendors across network security, cloud security, SOC and identity security can gradually consolidate that spending onto one platform.

The article says the model is beginning to work. In the second quarter of fiscal 2026, Palo Alto had about 1,550 platformization customers, up 35% year over year. Those customers posted a net revenue retention rate of 119%. By the fourth quarter, that number had moved above 120%.

Meaning customers on the platform usually spend more in year two than they did in year one. The market is expanding, and the leaders are also pulling more revenue from each customer. That, the article says, is why the quality of growth at U.S. cybersecurity companies looks especially strong.

China has not shown the same pattern.

Many domestic cybersecurity companies still depend on project-based sales and can only pull from enterprise IT budgets, often with fairly low priority. The article gives the example of a local state-owned enterprise willing to spend tens of millions of yuan to build a large-model platform because it expects the system to enter real business workflows. It can process materials, analyze data, build knowledge bases and hand some manual work to agents. Those projects have clear use cases and can be approved as standalone initiatives.

Cybersecurity is different. It rarely produces business revenue directly. So in a new technology investment cycle, security demand usually trails production systems.

According to the article, China is in exactly that stage now. Many government and enterprise customers are still building their own large-model platforms. A big share of budgets is going first to models, computing power, data governance and application development. Security is part of the discussion, yes, but in most cases it is still only one piece of a broader project and has not yet formed a large standalone budget.

And in that process, traditional cybersecurity vendors are often just one supplier among many, able to capture only a small share of total project revenue. The article says that helps explain why Zhipu can lock in 1 billion yuan in orders while cybersecurity vendors struggle to reach revenue on the same scale.

Adding AI to products does not mean customers will pay more

The article says Chinese cybersecurity vendors are also using AI to upgrade products, including SOC, threat detection and security operations.

But putting AI into a product does not mean customers will automatically pay separately for it. A security system that used to sell for 1 million yuan may now come with large-model analysis features, yet customers may still treat that as an ordinary product upgrade.

That leaves vendors carrying higher research and development costs, while average selling prices do not necessarily rise at the same pace. At this stage, the article says, AI is first increasing costs for many Chinese cybersecurity companies rather than producing a big enough stream of new revenue.

Dedicated AI security products may be the real turning point

The article argues that the products most likely to change the industry are the ones built specifically to protect AI, including model access controls, data loss prevention, prompt attack protection and agent permission management.

But that demand depends on one thing first: AI has to move into production environments. These problems become painful enough only after large models are embedded in core enterprise operations. If a company’s AI use is still limited to occasional drafting work by employees, AI security is unlikely to become a standalone budget item.

That is another area where the U.S. market is moving faster, according to the article. Many U.S. companies have already put Copilot, coding agents and other AI applications into real production settings. As those systems get access to more enterprise data and internal systems, security becomes a prerequisite for deployment.

That is why AI security is gradually turning into an independent market in the U.S., while China has not fully reached that point yet.

The valuation gap reflects a change in economic function

The article says the real gap between the two markets comes from a change in what security does economically inside enterprises.

In the U.S., cybersecurity has shifted from a compliance cost into infrastructure that grows with AI usage. The more enterprises use AI, the more they spend on security, and the leading platforms can keep increasing revenue per customer.

In China, cybersecurity still sits mostly in the cost-center bucket. Customers buy it to satisfy compliance requirements and keep systems running. That puts a natural cap on budgets and makes it hard for spending to rise with AI usage.

One market is making money from AI expansion. The other is still making money from conventional IT construction. The article says that is the root reason valuations have split so sharply.

The piece was originally published by the WeChat public account "Silicon-Based Observation Pro" and written by Aqi.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.