Cybersecurity Mid-’26 CISO survey: AI-driven demand continues! This is the June ‘26 sample of our bi-annual CISO survey, with 100 US respondents. Peter Weed+1 917 344 8390peter.weed@bernsteinsg.com Our Mid-2026 CISO survey showed expected cybersecurity spend outpacing ITgrowth more significantly than in our EOY ‘25 survey(which had only a slight tilt), with43% expecting cyber budgets to grow faster vs. 20% with IT faster (rest equal). This seemsconsistent with the mid-year CIO survey findings with cyber being the top spend growthcategory (here). The strongest tailwinds are in Financials, Tech, and Services industriesat ~6% YoY growth (although all industries expect >4% growth). More than half of CISOsraised their full-year spending expectations vs. earlier forecasts, implying stronger H2spending as H1 remained largely in line with prior expectations. Armin Hadavi, CFA+1 917 344 8463armin.hadavi@bernsteinsg.com Luwei Yang+1 917 344 8342luwei.yang@bernsteinsg.com The biggest budget winner seems to be software, but both staff and managed serviceswere not far behind (hardware was positive, but mostly just in network security). Withinsoftware, identity, cloud sec, and endpoint remain the top investment priorities. Versus EOY’25,SecOps, Identity, and Threat Intelligence saw the largest incremental spendtailwinds(followed closely by Network Security, AppSec, and Internet/DDoS). On the otherhand, despite its strong baseline, Endpoint Security saw the 2ndlargest decrease in +1 yearspend plans, andthe already least-growthy area of SSE saw the largest incrementalweakness.Other less growthy areas from EOY ’25 (SIEM, Email Security, and SecureBrowsers) also decreased further. Interestingly Network Security, DDoS, and Data Securitysaw the greatest divergence in spend plans, with both budget increases and cuts becomemore common vs. EOY ‘25. Within vendors, hyperscalers broadly saw reputational improvement, while othervendors remained more stable. This placed most hyperscalers at or above the largecybersecurity peer average. More broadly, we sawsmall upticks in the already most-loved Palo Alto and CrowdStrike, reinforcing their leading reputations. Splunk was theonly vendor whose reputation declined (coinciding with the weakness in SIEM spend). On overall cyber strategy, the shift toward software, vendor-hosted SaaS, andvendor consolidation was clear(across both SSE/SASE and broader cyber). However,moving away from physical firewalls and other appliance-based security was more of afuture expectation than a present reality for most respondents, with the greatest deltabetween current execution and future plans. The asterisk on hardware is physical networksecurity both for branches and data center had the lowest expectation for displacement. GenAI has a large strategy impact and demand urgency on cybersecurity spend. Butthis isn’t about AI coding agents building solutions in-house and displacing vendor budgets.Not to mention cyber budget seems safe from broader AI-driven budget pressures fromthings like Tokenmaxxing. Perhaps surprisingly, Identity did not come up as a strongbeneficiary of GenAI adoption (counter a narrative in the market). But we do note thatIdentity was reported as a leading space of investment, so this may reflect the priorityalready being high and GenAI not really turning it up even further. The biggest AI investmentarea is SecOps, although tempered by concerns around model hallucinations / accuracy.And post Mythos, perhaps it’s not surprising that AppSec is expected to see significantdisruption from AI coding agents. BERNSTEIN TICKER TABLE INVESTMENT IMPLICATIONS No impact to target prices or investment recommendations. We refer to our recently published note (here) regarding company-specific expectations into H2.But relative to thatperspective, we thought a few insights were incrementally notable from our CISO survey: •Zscaler vs. survey’s SSE weakness: We believe Secure Service Edge (“SSE”) remains a strategic priority for enterprisesmoving to cloud-first SaaS vendors where they want global cyber consistency across those offerings and the benefits ofzero-trust architectures. But spending growth expectations were the weakest of all cybersecurity categories we tested inthis survey. This may reflect that in existing adopters, their organizations have already completed most of their deployments,and for non-adopters that they have other near term priorities due to GenAI adoption that put SSE rollout on the back burner.For existing customers, it seems to imply CISOs view SSE as a maturing market where functionality across leading vendorsis converging, shifting purchasing decisions toward consolidation rather than incremental expansion. In a tighter spendingenvironment, organizations are often optimizing existing SSE investments rather than adding new capabilities, which reducesthe urgency of spend growth relative to other security categories. •CrowdStrike / SentinelOne vs. Endpoint downticking