Part 1: Story
An often-repeated account describes attackers using a connected aquarium sensor as an entry point to a casino network. It illustrates how an overlooked device can expand a network’s attack surface.
The public retellings listed below trace to an account by then-Darktrace CEO Nicole Eagan; they are not independent corroboration of one another. They do not supply enough independently verifiable information to confirm the casino, incident date, defenses, or amount of data taken. Treat it as a vendor-origin illustrative anecdote, not a documented case study or a quantitative measure of cyber risk.
This story brings us to an important subject—
Welcome, I’m Dex. Welcome to my industry report. Before we dive in, let’s take a look at a brief history of the industry.
Part 2: Industry History
1970s: ARPANET and Creeper
Early networked experiments such as Creeper and Reaper are part of the history of self-propagating programs and countermeasures. Assigning a single unqualified “first worm” or “first antivirus” to either program obscures differences in definitions and surviving records.
1980s: Birth of Commercial Antivirus Software
Commercial antivirus products emerged in the 1980s, and their precise chronology depends on how a “first” product is defined. The transition from standalone personal computers to connected business networks expanded the range of threats and defenses.
Key Turning Point: Mid-1990s
During the 1990s, more connected personal computers and business networks created additional opportunities for malicious code, denial-of-service attacks, and intrusions. This is a directional overview rather than a complete chronology of named incidents.
2000s (2000–2009): Commercial and Organized Cybercrime
The 2000s marked a transitional period for cybersecurity threats, shifting from mere pranks to serious, organized, and commercially driven criminal activity. Driven by core threat data and landmark incidents, people began to realize the vulnerabilities inherent in the early digital age during this explosion of cybersecurity incidents:
-
Fast-spreading worms (2000–2004): Incidents such as ILOVEYOU and SQL Slammer showed how email and software vulnerabilities could cause rapid, widespread disruption. Exact global infection and loss estimates vary by source and method.
-
Rise of Commercial Cybercrime (Mid-to-Late 2000s): Hacker motivations shifted from technical boasting to economic gain.
- Botnets and data breaches: Compromised computers were increasingly used for spam and fraud, while payment-card incidents highlighted the costs of weak data protection. Incident totals and exposed-record counts require case-specific primary reports.
-
Distributed denial of service: High-profile incidents exposed the operational costs of making online services unavailable; dollar-loss estimates are not directly comparable between incidents.
-
Espionage and advanced intrusions: Public disclosures such as Operation Aurora increased attention to persistent, targeted threats; cyber espionage itself predated the incident.
2010 to Present: Cloud-Native & AI-Driven Era
Between 2010 and 2019, the global cybersecurity landscape evolved from simple virus defense to geopolitical cyber warfare, massive data breaches, and ransomware ecosystems (e.g., Stuxnet, Sony Pictures hack, WannaCry).
Since 2020, the industry has undergone profound transformation characterized by supply chain attacks, open-source vulnerabilities, critical infrastructure ransomware, and AI-driven threats. The industry spans nearly six decades of history.
Part 3: Industry Value Chain
INDUSTRY MAP
The cybersecurity value chain
Explore the foundations, products and services that connect security suppliers to customers.
Read the full text outline
- Cybersecurity
- Upstream · Foundations
- Cloud infrastructure
- AWS
- Microsoft Azure
- Alibaba Cloud
- Core components
- Cryptographic libraries
- Specialized chips
- Threat intelligence
- Indicators and telemetry
- Threat-data feeds
- Cloud infrastructure
- Midstream · Products
- Endpoint & workloads
- CrowdStrike
- Network security
- Palo Alto Networks
- Fortinet
- Identity & access
- Okta
- CyberArk
- Security analytics
- Splunk / Cisco
- Endpoint & workloads
- Downstream · Delivery
- Integration & resale
- System integrators
- Value-added resellers
- Managed security
- MSSPs
- Customer security teams
- Incident response
- Mandiant
- Consulting and response teams
- Integration & resale
- Upstream · Foundations
DEX editorial map based on the accompanying report. Examples are illustrative, not exhaustive or ranked. Companies can operate across several stages; connections show categories, not verified supplier contracts.
Sources: Cybersecurity industry breakdown and source notes. Reviewed 2026-09-29.
Let’s briefly summarize the structure of the cybersecurity industry.
Upstream: Foundational Infrastructure & Threat Intelligence
The upstream sector serves as the cornerstone of the entire security industry, supplying midstream vendors with computing power, fundamental components, and critical threat intelligence:
- Cloud Infrastructure & Computing Power: AWS, Microsoft Azure, and Alibaba Cloud are examples of infrastructure on which security services may run.
- Foundational Core Components: Deep-tech companies mastering cryptographic algorithm libraries and high-precision processing chips (FPGAs, ASICs).
- Threat Intelligence Providers: Acting as the “radar” of the industry. They gather Indicators of Compromise (IOCs) globally and package data feeds to power midstream security engines.
Midstream: Core Products & Solutions
Midstream vendors directly face hacker attacks and provide defensive tools to clients. Based on modern enterprise IT architecture, midstream is categorized into four major segments:
- Endpoint & Workload Security: Antivirus, endpoint detection and response (EDR), and workload protection address different risks; CrowdStrike is one example of an EDR vendor.
- Network & Perimeter Security: Firewalls, secure access service edge (SASE), and segmentation coexist; Palo Alto Networks and Fortinet are examples of suppliers.
- Identity & Access Management (IAM): Identity is an important control alongside devices and networks, not the sole perimeter; Okta and CyberArk are examples of suppliers.
- Security Operations & Data Analytics: Systems such as Splunk (acquired by Cisco) aggregate and investigate security events. Monitoring and analytics products differ in scope and are not interchangeable.
Downstream: Channels & Security Services
Because security products are complex, a massive downstream service market has emerged:
- System Integrators & VARs: Service providers assisting enterprises with procurement, installation, and basic hardware configuration.
- Managed Security Service Providers (MSSP): Addressing the global shortage of security engineers by directly managing enterprise security operations 24/7 on a subscription basis.
- High-End Consulting & Incident Response: Teams like the Big Four or Mandiant providing penetration testing and emergency rescue during ransomware attacks.
Summary: Simply put, upstream provides materials and infrastructure; midstream builds weapons and trains troops; downstream handles tactical deployment and command.
Part 4: Industry Market Landscape
This is a historical 2024 worldwide modern-endpoint-security revenue snapshot, using IDC estimates reproduced by Microsoft on August 27, 2025. The underlying IDC report was not directly retrieved in this review. The chart and its DEX CSV export do not measure the whole cybersecurity market, customer counts, or product effectiveness; the CSV is a derivative of the same chart data, not independent evidence.
There is no single comparable “cybersecurity market” figure without specifying geography, year, whether services and cloud infrastructure are included, and the research method. The supplied 2022 Menlo Ventures map identifies product categories and companies; it does not substantiate this article’s earlier $250B–$300B size, $500B forecast, CAGR, or vendor-share estimates. Those numbers have been removed pending a traceable dataset.
The global market is divided into four major camps:
1. Cross-Domain Tech Giants
- Key Players: Microsoft (Defender / Sentinel), Google (Mandiant)
- Competitive Moat: Leveraging software ecosystems and distribution to integrate security products.
2. Pure-Play Security “Big Three”
- Key Players: Palo Alto Networks, CrowdStrike, Fortinet
- Product focus: Palo Alto Networks sells network and cloud security; CrowdStrike emphasizes endpoint and cloud protection; Fortinet sells network-security appliances and software. These are illustrative positions, not audited share rankings.
3. Traditional IT & Hardware Giants
- Key Players: Cisco, IBM, Trend Micro
- Product focus: Enterprise networking and IT software, with acquisitions used to expand security portfolios.
4. Niche Specialists
- Key Players: Zscaler (Zero Trust / SASE), Cloudflare (Edge Protection), Okta (Identity)
- Competitive Moat: Dominating specific technical niches to attract top-tier enterprise clients.
Two Trends Shifting Market Dynamics
- Vendor Consolidation: Some buyers prefer fewer integrations and vendors; the outcome depends on their existing architecture and procurement needs.
- Cloud and AI: Cloud-delivered tools and automated detection are growing areas of investment, while hardware controls still serve important use cases.
Part 5: Industry Challenges & Bottlenecks
Despite intense competition, the industry faces fundamental challenges:
1. Asymmetric Warfare
Defenders must protect every single endpoint and password, whereas attackers need only find one weak link using AI tools. Defenders remain in a reactive cycle while AI drastically lowers attack costs and sky-rockets defense expenses.
2. Compliance-Driven “Shelfware”
Many non-critical enterprises buy security tools primarily to pass audits rather than stop hackers, creating a market flooded with “shelfware” installed for inspection and then ignored.
3. Tool Fragmentation & Alert Fatigue
Large organizations can struggle with overlapping tools and alert volumes. A universal average number of tools or false-positive rate would need a defined sample and measurement method.
Value Chain Bottlenecks
- Upstream: Shared software components can create widespread exposure, as CISA’s Log4j advisories illustrate.
- Midstream: Ongoing research, complex integrations and operational resistance can slow adoption of zero-trust approaches.
- Downstream: Labor-intensive services face staffing and incident-response challenges; margins vary across businesses.
This competition appears to be a death spiral with no end in sight; as for how the cybersecurity industry will evolve—whether a super-giant akin to Google will emerge, or if the advent of AI will trigger a commercial tsunami—only time will tell.
That concludes my industry report. If you found it interesting, please like the video and subscribe to my channel. I’m Dex—see you next time.
Source notes and primary materials
- NIST SP 800-207: Zero Trust Architecture (2020) — August 2020 architectural guidance supplied with the working materials. This Special Publication defines a zero-trust approach; it is not a product certification, market-size dataset, or company-share ranking.
- Menlo Ventures: Cybersecurity Market Map (2022) — Menlo Ventures, 2022, 2 pages. A dated category/vendor map, not a revenue-share dataset, current ranking, or endorsement of the named vendors.
- CISA: Apache Log4j vulnerability advisory AA21-356A — archived primary advisory, revised December 23, 2021, supporting the historical software-library vulnerability example. Direct retrieval returned HTTP 403; its official-domain indexed text was inspected. The 2021 mitigation instructions should not be treated as current operational advice. This advisory is separate from the unresolved CISA guidance-page link in the reading list.
Reference review: 2026-10-03. The accompanying Network Security document is a research reading list, not primary verification for the anonymous casino account or the removed market figures. The incident specifics remain unverified in public primary records. Access checks and topic matches do not independently verify every statement in a source.
View or download the supplied original
NIST SP 800-207: Zero Trust Architecture (2020)
Open PDF in a new tab Download original PDFPublisher's copy
If the preview is unavailable in your browser, use “Open PDF in a new tab” above.
The Menlo Ventures Cybersecurity Market Map PDF is a separate 2-page, 2022 category/vendor map, available directly from Menlo Ventures. It is not the 59-page NIST publication previewed above and does not report revenue shares. It is not hosted here because permission to redistribute that copyrighted PDF has not been established.
Links contained in the Network Security research note
These are the supplied note’s research and video links, reviewed for destination and scope on 2026-10-03. They have not all been independently verified and should not be read as endorsements or claim-level primary evidence. An unresolved access or content check does not establish that a link is dead. Original references are retained so readers can distinguish them from any separately checked destination.
Incident and industry background:
- The Hacker News: aquarium thermometer incident — April 16, 2018 retelling of then-Darktrace CEO Nicole Eagan’s anonymous casino account; not independent incident verification.
- Entrepreneur: casino thermometer account — April 14, 2021 retelling citing a 2018 account of the same Darktrace story; not a second independent case or corroboration.
- Privacy International: aquarium thermometer account — April 15, 2018 summary of the same Darktrace conference account; does not independently identify the casino or confirm incident details.
- Cyber Magazine: history of cybersecurity — October 4, 2021 secondary overview. Its historical forecasts and broad “first” claims are not verified current market data or primary evidence of priority.
- History of Information: first computer virus — Creeper history entry drawing on an earlier Wikipedia account; a secondary reading lead, not primary evidence for contested “first virus” terminology.
- Wikipedia: Creeper and Reaper — encyclopedia synthesis for orientation and underlying references; not primary historical verification.
- KMC Controls: Creeper and Reaper — July 1, 2024 vendor background article, itself citing a vendor explainer. Its “BBM” spelling is not evidence for the organization’s name; do not use it as a primary historical authority.
- Atari Magazine: Computer Viruses And The ST — archive of George Woodside’s May 1990 START article about ST viruses and VKILLER. Historical descriptions and software advice retain their 1990 context.
- Atari Mania: ST Virus Killer — legacy URL redirects to a catalogue entry attributing the program to 1991; does not establish the earliest antivirus product.
- Carifred: UVK — Ultra Virus Killer for Windows — modern product whose publisher dates its start to 2010. It is different from the historical Atari Ultimate Virus Killer and cannot substantiate an Atari-era antivirus claim.
- Wikipedia: ESET NOD32 — encyclopedia product-history lead; inclusion does not verify a specific chronology or company metric.
- Internet Archive: Malware Museum — original reference — Content not confirmed in the 2026-10-03 review. The collection could not be retrieved or inspected; this does not establish deletion.
- Wikipedia: G Data CyberDefense — encyclopedia company-history lead, not primary evidence for commercial-antivirus “firsts” or current company metrics.
- Wikipedia: security-hacking incidents — chronological reading list; specific incident claims require their underlying records.
- Purdue TAP: hackers of the 2000s — August 27, 2024 historical overview; institutional hosting does not make a retrospective a primary incident record.
- Cofense: history of phishing — June 6, 2023 vendor-authored historical background, not original incident evidence.
- Wikipedia: computer virus and worm timeline — orientation and reference-finding only; the inspected page also carried a cleanup warning about entry noteworthiness.
- CISA: Log4j guidance — original reference — Content not confirmed in the 2026-10-03 review. The exact guidance URL returned HTTP 403, and its content or current destination was not established. The separately cited AA21-356A advisory does not verify this specific page.
- Wikipedia: Sony Pictures hack — encyclopedia background; specific incident and attribution claims require underlying official evidence.
- Wikipedia: WannaCry attack — encyclopedia background, not a primary incident report or verified loss estimate.
Market and technical references:
- Mordor Intelligence: cybersecurity market — commercial report landing page with a 2026–2031 outlook at review. Its changing proprietary estimates do not restore the removed market figures; the paid report was not independently inspected.
- Menlo Ventures: market map PDF — 2-page 2022 category/vendor map, not revenue shares or a current company ranking.
- Cloudflare: next-generation firewalls — vendor-authored technical explanation of NGFW features; does not establish market share or product effectiveness.
- Cybersecurity Ventures / Cybercrime Magazine — publisher homepage and research-discovery lead, not a particular report or traceable dataset for a market number.
- U.S. Securities and Exchange Commission — official research portal for filings and other materials; a specific filing is needed to substantiate an issuer’s financial or cybersecurity metric.
- IBM: a decade of global cyberattacks — Mike Elgan’s retrospective covering 2013–2023; background reading rather than original evidence for all incident figures it recounts.
- CSO: Target breach timeline search — original reference — Content not confirmed in the 2026-10-03 review. This is a search URL, not a verified direct article; neither the search page nor an underlying timeline was inspected.
- NIST SP 800-207 PDF — August 2020, 59 pages, architectural guidance; no market size, company-share ranking, or product certification.
Video references from the note (third-party material, not licensed for reuse here):
- Video 1 — original reference — Content not confirmed in the 2026-10-03 review. Title, channel, and topic remain unconfirmed after retrieval attempts; the video is not established to be deleted.
- Video 2 — original reference — Content not confirmed in the 2026-10-03 review. Title, channel, and topic remain unconfirmed after retrieval attempts; the video is not established to be deleted.
- Video 3: IBM Technology — Zero Trust Explained in 4 mins — canonical same-ID page identifies IBM Technology, September 10, 2021, and a 3:42 runtime. Title, description, and chapter labels were inspected; the full audiovisual content and transcript were not independently reviewed. Educational reading lead only. Original short-link reference retained for provenance.
- Video 4 — original reference — Content not confirmed in the 2026-10-03 review. Title, channel, and topic remain unconfirmed after retrieval attempts; the video is not established to be deleted.
- Video 5 — original reference — Content not confirmed in the 2026-10-03 review. A title-only search result was insufficient to verify the source; a Google unusual-traffic CAPTCHA then blocked inspection. Channel and video content remain unconfirmed, and deletion has not been established.