Transcription
Imagine a cyber attack that's so powerful it shuts down Britain's biggest auto manufacturer for weeks. From a thousand vehicles a day to zero. The problems lasted now for nearly a month. The government steps in to guarantee loans as over 700 suppliers face financial stress and possible bankruptcy. That's actually just happened. And now Japan's Asahi is the next company to fall. Their operations have been shuttered as well. Is something sinister afoot? Is AGI flexing its digital muscles? Who knows?
But the next big thing is arguably investing in cyber security stocks. I like this piece here on how cyber crime could cost the world $10.5 trillion annually by 2025. In 2021, back around the time that this was written, it was expected to be around $6 trillion in damages. That would make it the world's third largest economy after the United States and China, the greatest transfer of economic wealth in history. That would be more profitable than the global trade for all illicit drugs combined.
Now, the reason cyber crime is taking off is because there's a lot of money to be made. I took this picture in the war room of a hacker hunting group in Moscow called Group IB. And I sat down with one of their co-founders and he told me all about the sorts of problems they helped solve. More than 90% of all cyber crime now is about making money.
Now, I took this picture in Pyongyang, North Korea. This is the infamous Rayugyang Hotel. Inside that hotel is where Group IB traced a criminal group called Lazarus, one of the most dangerous cyber criminal groups in the world. They actually have subdivisions responsible for meeting goals and targets. Now, initially, the North Koreans disguised themselves as Russians. The Russians didn't take very kindly to that. Now, this group is probably since moving more towards crypto scams because there's so much low-hanging fruit to be had. But this goes to show you that it's about state actors as well. And this becomes more than just financial crimes. It's actually something that the government can get involved in because there's a lot of potential downfall that can happen. When you have entities like North Korea making loads of money off cyber security, it becomes more than just a corporate problem. It's a government problem.
Now the company that I met with in Moscow has since disbanded. This is an excellent article that tells you all about the sorts of sinister things that cyber criminals get up to. It's titled "The World's Most Elite Cyber Crime Fighting Unit." And the company has since disbanded and broken up. I imagine they'd have a tough time trying to raise funding.
Now even Mr. Buffett thinks that cyber crime is a real issue. He says that's the number one problem with mankind and says that it probably surpasses even nuclear weapons when it comes to risks. What's interesting is this report from McKinsey which talks about, now this was back several years ago, but it talks about how around $150 billion is being doled out to cyber security platform vendors when the total opportunity is more around $1.5 to $2 trillion. The reason for that is that plenty of companies out there don't have allocated budgets to spend what they need to on cyber security. And here you can see they've broken down all the more granular areas and they're showing you what penetration has been achieved so far. So there's a lot of potential money to be made in cyber security solutions and it's not a nice-to-have, it's a must-have.
And what's interesting also in this report is it looks at log volume. So that's a key component of cyber security platforms. We recently did a webinar with our paying subscribers that looked at a company we're holding called Data Dog, which processes logs. It's one of a number of companies that do SIEM or application monitoring. Just 3 years ago, the average enterprise saw only 30% of what was going on. And now that's changing as they're becoming more aware of the importance of tracking logs. Here you can see how midsize companies are really underrepresented when it comes to those types of solutions.
When you look at a large vendor like Crowdstrike here, you can see that component. See at the top there, SIEM and some familiar names. You have Splunk. They were acquired by Cisco. We used to hold that stock. You have Palo Alto, some other names in there. And then you start to see these various categories. And there's a trend for CTOs that are looking for vendor consolidation, right? They want one name to go to. They don't want to have to create a patchwork collection of cyber security solutions. They prefer to have one vendor.
Now when we look at investing in cyber security, we always want to invest in leaders. Large providers are going to have lots of breadth in their offerings that's going to cater to that industry trend. And of course, using AI to protect against AI attacks is the way forward. AI-first companies like Crowdstrike have been doing this for a while now. I was looking at some old pieces that we wrote about cyber security startups well before any of them went public. And I think it was nearly 10 years ago that we focused on how Crowdstrike was using AI for cyber security solutions. One of the reasons for that is in the olden days, they used to have to push out patterns of attacks, right? So that's where you would download the latest signatures. Well, now AI is doing that at the edge, right? That's how you need to do it. So it can recognize attacks as they're occurring broadly across various types of industries and companies. So we're going to want to explore not just stocks but ETFs. And we always want to start by establishing a universe of pure-play stocks.
Now for more mature themes like cyber security, somebody's already done this. In this case, a number of firms have. And we'll start with MSCI, a company that I spent a decade working at, the leading global provider of indices, and they have a remarkable platform that they can use to produce over 100,000 indices when I was there. Here you can see where they've created the MSCI ACWI. All that means is All Country World Index. So it's developed and emerging. Means essentially the investable market. So every company out there across every geography that's investable. And they've put together this list. Here's the top 10 constituents.
Now it starts to get rather interesting. You see names like BAE Systems, Vodafone Group, Motorola. So what we'll want to do here is understand how they created this. So when we go look at the index methodology document, they talk about this relevance score and weighting. So they're doing some capping here, but this relevance score is rather interesting. So you see here in a different methodology document, they talk about a set of relevant words and phrases used for assessing a company's thematic exposure. Now, I think MSCI probably these days is either using AI or thinking about using AI. They were when I was working there, aware of it at least. And I think it's probably going to be more sophisticated than just screen scraping company documents and looking for mentions of words. You see, they also of course look at business segment information. That's what we do here at Nanalyze. We really dig into those financials and try to find this stuff out, but it becomes very tricky. And I don't know that keywords are that great of a way to go about doing it.
But one of the things we can do here is to look at ETFs that are created out there. None of these three biggest ETFs that I've highlighted here are using MSCI's index. So we can look at the indices that they're using and sort of compare there. I put up fees here. So first of all, when it comes to size, you see that CIBR is the largest by far. What that will allow them to do is lower fees and still bring in a decent amount of money. So when you look at the expense ratios across these, there's nothing too horrible, right? Anywhere from 51 to 61 basis points.
Now, what I've done here is pulled out the top 10 names for the three ETFs and the MSCI index. And I've highlighted in green anything that appears across all of these indices. And in yellow, I've highlighted anything that appears in two or three of these indices. Right? So, we can then consolidate this list of names and have a mini universe. Now, first of all, you see Cisco and Broadcom. We're going to talk about those, but the more pure-play names here on the right, Zscaler, Crowdstrike, Palo Alto, CyberArk, Fortinet, and Cloudflare are mainly what we're going to be focused on.
And when you look at Cisco, around 14.3% of their exposure comes from cyber security. It generated about $8.1 billion last fiscal year against a $56.7 billion total revenue base. So about 14.3%. And this particular segment, interestingly enough, saw a 59% year-over-year increase. They say driven by AI integrations and acquisitions like Splunk. See, so SuperGrok pulled this up and it's able to see that relationship between log monitoring and cyber security.
Now, when we look at Broadcom, you see we have this actually in our catalog as a "like." They do a lot more than just cyber security. So I think that would sort of be an incidental bit of exposure you would get investing in this company and not primarily the reason why you would choose it. I think it's somewhere around 5% of revenues Grok estimated, but not something that's pure-play.
Now when we're looking at this list of software names out there, we also want to consider new names that have had an IPO recently. Why? Because oftentimes these index providers will lag the addition of an IPO by months so that they give it some time to trade. Right? So, we've looked at new cyber security IPOs that have happened recently, noting NetScope and SailPoint. So, we're adding those to our list. And look, that gives us eight cyber security stocks.
I wanted to comment about a couple of these names. Firstly, Cloudflare. We've covered that. This is a firm that sells essentially to everybody. We don't necessarily like firms where you can put in a credit card and subscribe to their product because then it's very easy to cancel that product, right? And of course, I've highlighted CyberArk here because they're possibly going to be acquired by Palo Alto. That hasn't been approved, but they're expecting that to happen in the second half of fiscal 2026. We'll touch on that a bit later. But when you look at the number of customers, again asking Grok here, this is roughly accurate. When you look at Cloudflare and Fortinet, 250,000 and 890,000 customers, you know, these aren't all large enterprises. They're also presumably lots of "pay with a credit card" solutions. And of course, along the top there you see Palo Alto Networks and Crowdstrike. Two of the largest names selling primarily to enterprises.
When we look at revenue growth, no surprises to see growth is strong across the board for all these companies. This is looking at trailing 12 months compared to last year. And when we look at Crowdstrike's revenues, this was taken from a slide in our recent webinar. We noted 21% growth expected for their coming year. And that deceleration that you see here is sort of to be expected with larger firms. And you see Palo Alto decelerating sort of at the same pace. And we're going to be doing an article update on Crowdstrike in January of this year. So stay tuned for that. But when you look at Palo Alto, I always pay attention to top-line revenue growth. So they had 15% last year and now for the coming fiscal 2026, they're expecting 14%. So a continued deceleration. That doesn't take into account the potential acquisition of CyberArk. So, you can expect now that they're going to start looking for growth outside of just organic growth. Here you can see where they're expecting that acquisition to close in the second half of fiscal 2026. We're now in Q1 of fiscal 2026.
So, when you consider both Crowdstrike and Palo Alto Networks being two of the largest players out there and we like to invest in leaders, so it was sort of down to this decision. Now we've invested in Crowdstrike and that was when their simple valuation ratio dropped to below our target of 15. So I think this was back in 2022. SVR or simple valuation ratio is simply market cap divided by annualized revenues. I've calculated that here for Crowdstrike and Palo Alto Networks and you can see that Crowdstrike is very richly priced at the moment at 26.5. So, we don't invest above three times our catalog average, which is currently 7.7, consistently slowly creeping up as we see the frothiness in the tech markets. And our target SVR right now for Crowdstrike, where we would consider adding shares, would be an SVR of 20 or lower. And that's right, roughly at our threshold. How do we calculate these targets? Well, we simply take the average SVR of the last four quarters. And then you can presume then that that target based on an average will be above and below the mean. Right? So that sort of provides you at least with an objective way to buy stocks without buying too much into the hype.
So I think the thesis for cyber security is really simple. Budgets just haven't been meaningful enough, especially in the small to medium-sized business space. And I think perhaps that points to the concerns around Cloudflare, you know, being able to purchase that with a credit card perhaps being less of a concern because once large enterprises are sorted, you'll want to go after that small to medium business segment. So something to think about there. This whole attitude towards cyber security being a nice-to-have is going to change as we see more high-profile catastrophes like what happened with Jaguar and Asahi.
So what do you want to pay attention to here? Net retention rates are a key metric to show that existing customers are spending more on a breadth of solutions offered by these large vendors. Right? So in both cases, they're talking about how they have all these modules and saying, well, X% of our customers have four or six modules or more. Right? So they're trying to describe the adoption of their breadth of solutions by their customer base. That consolidation trend is likely to persist. No CTO wants to have to call up numerous firms and have them start pointing fingers at each other. So, we think investing in either Crowdstrike or Palo Alto as leaders makes sense. You want to take valuation into account as we've shown you in the previous slide.
And when it comes to ETFs, we're really leaning towards the Global X ETF, the ticker BUG, because that seems to have more pure-play exposure to the type of names that we want exposure to. Not the Cisco and the Broadcoms of the world, but the Palo Altos and the Crowdstrikes of the world. So, you'll notice how a number of these ETF providers have sort of thrown defense stocks into their list, and that's really a completely different topic. Defense and aerospace is its own category, in which case you want to invest more in defense and less in aerospace if that's what you're after. We did a recent piece on that. You can watch that here.
Thanks so much for taking the time to watch this video today.