Why Cybersecurity Will Survive The 'SaaS-Pocalypse'
IRONSCALES founder & CEO Eyal Benishti is a pioneering security software engineer & executive leader with 15+ years of industry experience.
gettyFor years, the default enterprise technology decision has been relatively straightforward: Why build software yourself when you can buy it as a service? Today, generative AI is starting to complicate that calculation. The rise of AI-assisted development and “vibe coding” has made it much easier for devs and even non-technical individuals to turn their ideas into working software.
Businesses are taking notice. A recent EY survey found that 87% of senior leaders at organizations investing in AI have either already deployed or are at least piloting programs to develop AI-built software in-house. Meanwhile, 82% expect traditional per-seat SaaS pricing to become less relevant in their industries over the next five years.
That doesn’t mean the SaaS industry is getting ready to disappear. But it does suggest that the barriers separating “build” from “buy” are getting significantly lower. If an organization can create a purpose-built application quickly and inexpensively rather than buying yet another subscription, areas of the SaaS market will inevitably face headwinds.
Cybersecurity will face some disruption, too. But I believe it’s uniquely positioned to survive this shift for one simple reason: Building security software and providing security are two very different things.
Most software exists to help someone accomplish a relatively defined task. Manage a project, create an expense report, build a dashboard, schedule an appointment and so on. Once you know the desired outcome, the challenge is largely one of execution. And increasingly sophisticated AI coding tools can make that execution easier.
But cybersecurity operates differently. That’s largely because the problem itself never stops changing. Security is less like a productivity application and more like a utility running continuously throughout an organization. Employees don’t log into their email security platform every morning and ask it to protect them. They simply expect their inboxes to work without exposing the business to phishing, malware, account takeover and other threats.
Even more importantly, threat actors are always evolving. Imagine using AI to build an internal tool that automates a particular administrative workflow. Once the application reliably performs that workflow, the problem has been solved. Now imagine building your own phishing detection system. The moment it successfully detects today’s attacks, attackers begin developing tomorrow’s. That fundamentally changes the nature of the product.
Email offers a useful illustration of this phenomenon as it remains one of the most persistent battlegrounds between threat actors and defenders. Over the years, phishing defenses have improved significally. But so have the tactics employed by attackers. Organizations became better at identifying suspicious links, so attackers started using legitimate services or QR codes. Employees learned to recognize poorly written phishing messages, so threat actors started using generative AI to help them produce more convincing ones. Security systems learn to identify known patterns, so attackers continually experiment with new techniques designed to evade them.
Agentic AI threatens to accelerate that cycle further. Attackers now have tools capable of helping them research targets, personalize messages, modify techniques and operate autonomously at scale, a lot quicker than before.
As a result, those playing defense aren’t really building toward a finished product. They’re participating in a continuous contest against intelligent adversaries. They’re locked in a constant game of cat and mouse that’s only accelerating.
This isn’t to say that cybersecurity vendors will be entirely immune to this change. However, it will change where they create value. Code itself will become easier to produce. And some security functionality will undoubtedly become commoditized as a result. Basic point solutions, interfaces, reporting capabilities and workflows may become easier for organizations to recreate internally.
But the code has never been the entirety of a security product. Behind effective cybersecurity systems sit years of threat data, telemetry and adversary knowledge. There are researchers studying emerging attack techniques, engineers responding to vulnerabilities and detection forces learning and adapting daily from attacks occurring across large numbers of customers and environments.
Each new attack potentially makes the system smarter. Each newly observed technique can inform how the next attack is detected. That accumulated intelligence is difficult to replicate by asking an AI model to build an application.
The same distinction applies to industry expertise. Cybersecurity requires understanding not only how software works but how attackers think and operate. It requires thinking adversarially, anticipating new attack vectors and continually questioning existing assumptions.
AI may be able to accelerate some of that work. But accelerating the accumulation and maintenance of expertise is entirely different from replacing it.
None of this is to say that cybersecurity companies can just ignore what’s happening elsewhere in the SaaS ecosystem. If AI makes software easier to create, security vendors will have to become even clearer about what customers are paying for. Simply offering another interface, workflow or collection of features will become less defensible as those things become easier to reproduce.
The enduring value will increasingly reside in the ongoing work that drives outcomes: continuously understanding threats, adapting defenses and absorbing complexity so customers don’t have to.
At the end of the day, cybersecurity is valuable because keeping an organization secure is a job that’s never finished. As long as attackers keep innovating, defenders will have to do the same.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?