Bernstein Flags Valuation Concerns in Cybersecurity Sector Despite Strong AI Demand, Downgrades Palo Alto, Okta and SentinelOne

Stock News
Yesterday

Bernstein's latest US software industry report suggests that while AI-driven demand for cybersecurity remains robust, the sector's valuations have expanded significantly following a substantial rally since early 2026. The firm notes that enterprise security budgets and new contract structures continue to fuel growth, yet most covered companies are now trading at or above what the broker considers fair value, prompting downgrades for Palo Alto Networks (PANW.US), Okta (OKTA.US), and SentinelOne (S.US) to "Market-Perform." Among the names under coverage, only Zscaler (ZS.US) is viewed as still offering meaningful upside potential.

At the start of the year, Bernstein held a strongly bullish view on the cybersecurity industry, anchored in the incremental security requirements generated by AI adoption. Even as AI labs began introducing their own security offerings, sparking concerns about disruption to traditional software vendors, the firm maintained a positive fundamental outlook. That conviction has been validated, with demand metrics continuing to strengthen. Mid-year surveys of chief information security officers and chief information officers showed improved demand signals, while recent debates about cybersecurity risks potentially limiting the pace of AI lab development have further shifted investor sentiment favorably toward incumbent security companies.

The central problem, however, is that share price appreciation may have outpaced the improvement in underlying fundamentals. Bernstein points out that several cybersecurity stocks under its coverage have gained roughly 100% or more since early 2026, accompanied by a notable increase in crowding within the sector's trading.

AI Continues to Drive Security Spending, But Valuations Have Clearly Run Ahead

Bernstein argues that the core tension in the cybersecurity industry has shifted. Earlier in the year, the market was focused on whether AI would create opportunities or threats for traditional security vendors. Now, with demand increasingly validated, the key question becomes how much future growth is already priced into current share prices. The report's valuation analysis shows that cybersecurity companies trade at higher EV/forward twelve-month sales multiples than application software firms, with some names even exceeding the multiples of consumption-based infrastructure software companies that are also benefiting from the AI investment boom. For instance, as of September 14, both Cloudflare (NET.US) and CrowdStrike (CRWD.US) were trading at approximately 36 times forward sales.

Bernstein's regression analysis reveals a high correlation between the "Rule of 40" and valuation multiples for most companies, with the majority now sitting at or above the fair value levels implied by the model. Notably, even using Bernstein's own revenue forecasts, which are generally more optimistic than consensus estimates, the broker struggles to identify sufficient upside in current valuations, except for Zscaler. This suggests the issue is not a deteriorating fundamental picture, but rather that the market's valuation premium for the sector has expanded significantly, raising the bar for future growth implied by share prices.

Flex Contracts Emerge as a New Growth Engine for Cybersecurity Firms

Beyond AI demand, Bernstein highlights the increasing role of "Flex" contracts, a flexible agreement model that is helping security vendors accelerate revenue growth. Under this model, customers pre-commit a certain spending amount and gain the flexibility to deploy various products and services from the vendor within that agreed scope. This approach allows enterprise clients to avoid precisely predicting their future security needs at the outset. As new threats emerge, customers can quickly add additional products without going through a full procurement and sales cycle. For vendors, this significantly lowers the friction involved in upselling and cross-selling to the existing installed base.

CrowdStrike is cited as a key beneficiary of this model. Bernstein estimates that in the latest quarter, expansions and add-on sales generated through Flex contracts contributed an additional $30 million to $40 million in new annual recurring revenue (ARR), exceeding what would have been achievable through normal selling motions alone. This indicates that growth is not only coming from expanding market demand but also from enhanced sales efficiency driven by the business model itself.

Strong AI Demand Does Not Remove Natural Growth Ceilings in Cybersecurity

Nevertheless, Bernstein believes that while Flex contracts can boost growth rates, they are unlikely to fully justify the elevated growth expectations embedded in some cybersecurity stock valuations. The fundamental reason lies in the distinction between cybersecurity software and consumption-based infrastructure software such as cloud computing and databases. For hyperscale cloud providers or database platforms, consumption can theoretically expand rapidly and continuously as customer compute, data volumes, and AI workloads increase, creating strong usage-driven revenue growth. Cybersecurity products, by contrast, face more pronounced natural growth ceilings.

Areas where AI is driving increased enterprise investment, such as SSE/SASE, endpoint security, observability, and communications and email security, typically correlate with the number of employees or endpoint devices, which grow at relatively stable rates. In comparison, cloud security and other areas more closely tied to compute usage have stronger consumption-based growth attributes. Using CrowdStrike as an example, Bernstein estimates that after adjusting for easier year-over-year comparisons, its "true" incremental ARR growth is in the high-20% range. As Flex contracts begin to mature into the comparable base, overall growth may eventually settle in the high-20% range, rather than the over-40% growth that current valuations appear to imply. The firm concludes that robust demand and business model innovation are real, but they may not be sufficient to satisfy the very high growth expectations already embedded in current share prices.

Palo Alto, Okta and SentinelOne Downgraded on Valuation

Based on its updated valuation models, Bernstein has significantly raised its valuation multiples for cybersecurity companies and increased several price targets. However, this has been accompanied by downgrades for three companies. Specifically, the price target for Palo Alto Networks was raised from $253 to $351, but the rating was cut from "Outperform" to "Market-Perform." The target for Okta was increased from $143 to $174, with a similar downgrade to "Market-Perform." SentinelOne's target was lifted from $21 to $25, also resulting in a downgrade to "Market-Perform."

Bernstein notes that these three companies had previously been viewed as "too cheap." However, following a re-rating over the past quarter, their current share prices are now broadly in line with the broker's updated industry valuation framework, making the risk-reward profile less attractive than before. Meanwhile, ratings for CrowdStrike, Cloudflare, Fortinet (FTNT.US), and Zscaler remain unchanged. Bernstein expresses particular caution regarding CrowdStrike's valuation, noting that it trades notably above the level implied by the industry regression model, while Palo Alto is closer to its model-implied value. Both companies benefit from AI-driven cybersecurity demand, and the firm suggests their valuation gap could gradually narrow over the long term.

SentinelOne's Potential M&A Appeal Noted

Despite downgrading SentinelOne, Bernstein still views the company as an attractive potential strategic acquisition target within its coverage. The report identifies SentinelOne as a possible takeover candidate for AI labs, hyperscale cloud providers, or even larger cybersecurity vendors, including Anthropic, Google parent Alphabet (GOOGL.US), and Palo Alto Networks. However, this assessment reflects Bernstein's view of potential strategic fit rather than indicating that any acquisition discussions are underway.

For Okta, Bernstein sees its biggest potential upside variable coming from AI agent infrastructure. As AI agents begin to access enterprise applications, databases, and other digital resources on behalf of users, the importance of identity verification and permission management is likely to rise, potentially creating new demand for Okta. However, Bernstein also cautions that the timeline for AI agents to achieve large-scale maturity and commercial deployment remains uncertain, and how related products will be priced and the ultimate demand scale are still unclear.

Zscaler Maintained at Outperform as Sales Transformation Reaches Key Stage

Zscaler stands out among the cybersecurity companies covered by Bernstein in this report. The stock closed at $191.58 on September 16, while Bernstein raised its price target from $224 to $298 and maintained an "Outperform" rating. In contrast, Palo Alto, Cloudflare, CrowdStrike, Okta, and Fortinet were all trading above their updated price targets at the time.

Bernstein attributes Zscaler's previous growth slowdown not to a loss of product competitiveness, but rather to a deliberate shift in sales strategy. The company is transitioning from a transaction-based sales model focused on new customer acquisition toward a model that emphasizes long-term customer relationships, upselling, and cross-selling. This three-year sales transformation is now in its final phase. Zscaler maintained its net revenue retention (NRR) at 115% for FY2026, and management expects the existing sales pipeline to support sustaining this level in FY2027. Latest quarterly data suggests that the decline in contribution from new customers appears to have halted. Bernstein anticipates that if this metric can stabilize or improve, the company's revenue growth rate could also stabilize.

Additionally, while Zscaler faces competitive pressures from the likes of Cloudflare, Bernstein notes that significant market opportunity remains in the migration of large enterprises from traditional web security and VPN solutions to modern SSE/SASE architectures.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10