Cybersecurity 13Fs: Palo Alto, CrowdStrike, Fortinet, Zscaler
Palo Alto Networks, CrowdStrike, Fortinet, Zscaler, SentinelOne, plus CyberArk and Tenable anchor US cybersecurity 13F positioning. Multi-year emerging platform consolidation, AI-driven threat detection, plus emerging emerging CrowdStrike July 2024 outage drive distinctive institutional patterns.
US cybersecurity equities form a distinctive software corner of institutional 13F positioning. Palo Alto Networks (PANW), CrowdStrike Holdings (CRWD), Fortinet (FTNT), Zscaler (ZS), SentinelOne (S), CyberArk Software (CYBR), plus Tenable Holdings (TENB) anchor the cohort. Multi-year emerging platform consolidation, AI-driven threat detection, plus emerging emerging CrowdStrike July 2024 outage dynamics drive distinctive institutional positioning. Reading cybersecurity 13F positioning requires understanding the platform-vs-point-solution framework plus the multi-year category dynamics.
The cybersecurity business model
Cybersecurity companies operate four primary economic engines:
- Platform consolidation. Multi-year emerging platform consolidation drives operator economics. Multi-year emerging customer preference for integrated security platforms (Palo Alto Networks Cortex XSIAM, CrowdStrike Falcon, Fortinet Security Fabric, Microsoft Security) plus emerging emerging point-solution displacement drives platform vendor share gain. Multi-year emerging emerging mega-deal customers spending $1M-$10M+ annually drive emerging emerging platform vendor revenue concentration.
- AI-driven threat detection. Multi-year emerging AI-driven threat detection drives multi-year emerging operator differentiation. Multi-year emerging CrowdStrike Charlotte AI plus emerging emerging Microsoft Security Copilot plus emerging emerging Palo Alto Cortex AI plus emerging emerging Fortinet AI plus emerging emerging SentinelOne Purple AI drive emerging emerging customer ROI. Multi-year emerging emerging emerging emerging emerging AI-driven incident response plus emerging emerging emerging emerging emerging emerging AI threat hunting drive operator value proposition.
- SASE plus zero-trust transition. Multi-year emerging SASE (Secure Access Service Edge) plus emerging emerging zero-trust transition drives multi-year emerging emerging architectural shift. Multi-year emerging Zscaler ZIA plus ZPA plus emerging emerging Palo Alto Prisma plus emerging emerging emerging Cisco Umbrella plus emerging emerging Cloudflare drive emerging emerging emerging SASE category emergence. Multi-year emerging emerging zero-trust network access (ZTNA) replaces emerging emerging VPN drives multi-year emerging emerging operator competitive dynamics.
- CrowdStrike July 2024 outage emerging. Multi-year emerging CrowdStrike July 19 2024 global outage (faulty Falcon sensor update affected 8.5M Windows devices including airlines, hospitals, banks, broadcasters) drives multi-year emerging emerging customer trust dynamics. Multi-year emerging operational response plus emerging emerging customer retention plus emerging emerging emerging emerging emerging share dynamics. Multi-year emerging emerging emerging emerging emerging emerging emerging emerging emerging emerging legal liability plus emerging emerging emerging emerging emerging emerging customer settlement (Delta Air Lines $500M lawsuit) drive emerging emerging emerging emerging emerging operational trajectory.
Major US cybersecurity names
Palo Alto Networks (PANW)
Largest US cybersecurity platform vendor plus emerging emerging Strata firewall plus emerging emerging Prisma SASE-zero-trust plus emerging emerging Cortex XDR-XSIAM. Multi-year emerging operational scaling plus emerging emerging Nikesh Arora CEO leadership.
CrowdStrike Holdings (CRWD)
Diversified Falcon endpoint detection plus emerging emerging Falcon SIEM (post-Humio acquisition) plus emerging emerging Falcon Cloud plus emerging emerging Falcon Identity. Multi-year emerging operational scaling plus emerging emerging George Kurtz founder-CEO leadership plus emerging emerging July 2024 outage recovery.
Fortinet (FTNT)
Diversified Fortinet network security plus emerging emerging emerging Lacework cloud security acquisition (2024) plus emerging emerging FortiGate firewall plus emerging emerging FortiOS. Multi-year emerging operational scaling.
Zscaler (ZS)
Pure-play cloud SASE-zero-trust plus emerging emerging ZIA Secure Web Gateway plus emerging emerging ZPA Zero Trust Network Access plus emerging emerging Zscaler Posture Control. Multi-year emerging operational scaling.
SentinelOne (S)
Diversified Singularity XDR plus emerging emerging Purple AI plus emerging emerging Singularity Cloud. Multi-year emerging operational scaling plus emerging emerging Tomer Weingarten founder-CEO leadership plus emerging emerging share gain post-CrowdStrike outage.
CyberArk Software (CYBR)
Diversified Privileged Access Management (PAM) plus emerging emerging Identity Security plus emerging emerging Venafi machine identity acquisition (closed 2024). Multi-year emerging operational scaling.
Tenable Holdings (TENB)
Diversified vulnerability management plus emerging emerging Tenable.io plus emerging emerging Tenable Cloud Security plus emerging emerging Tenable OT Security. Multi-year emerging operational scaling plus emerging emerging Permiso acquisition (2024).
How institutional managers position around cybersecurity
Three patterns appear across smart-money 13Fs:
Pattern 1: Platform-leadership concentration
PANW, FTNT-concentrated growth manager positions reflect platform consolidation thesis.
Pattern 2: SASE-zero-trust positioning
ZS-concentrated growth manager positions reflect SASE-zero-trust transition thesis.
Pattern 3: Identity-security positioning
CYBR-concentrated growth manager positions reflect identity security thesis.
How to read cybersecurity 13F positioning
Three rules apply:
Rule 1: Identify category exposure
Endpoint vs network vs SASE vs identity have distinct dynamics.
Rule 2: Watch ARR growth
Multi-year annual recurring revenue drives operator economics.
Rule 3: Cross-check competitive dynamics
Multi-year platform consolidation drives share dynamics.
What cybersecurity positioning signals
- Platform-leadership conviction. Concentrated PANW positions signal platform consolidation thesis.
- SASE conviction. Concentrated ZS positions signal SASE-zero-trust thesis.
- Identity conviction. Concentrated CYBR positions signal identity security thesis.
For real-time tracking of cybersecurity 13F activity, see the institutional signals feed.
Investment Education Editor at 13F Insight. Breaks down complex institutional data into actionable insights for individual investors.
More from Sarah →