Is Cybersecurity Too Big for Its Own Good?

Black Hat USA 2026 drew more than 20,000 people and over 400 exhibitors to Las Vegas, turning Mandalay Bay into what one longtime attendee calls a temporary city. In a special report titled “Is the Cyber Industry Too Big?”, Techstrong Group CEO Alan Shimel, who has walked the show for two decades, argues that the real story isn’t the industry’s scale. Instead, he says, the real issue is the gap between that scale and the cost and confusion it creates for everyone trying to navigate it.

From Research Spectacle to Sales Spectacle

Shimel recalls a Black Hat that once centred on landmark security research, moments that genuinely rattled the industry. Today, he writes, that research still exists, but it no longer dominates the show. Instead, commerce does giant booths and video walls, while a parallel economy of hotel suites and private parties has taken centre stage, showing how spectacle has displaced the old research focus.

A Quarter-Million-Dollar Ticket to Be Seen

The report estimates that a serious Black Hat presence booth, staff, travel, and hospitality can easily cost $250,000, working out to roughly $250 per badge scan before any of those leads become real customers. Shimel argues this isn’t irrational spending by individual vendors. Rather, it is a rational response to an industry-wide attention war, where standing out from thousands of similar-sounding pitches requires ever-bigger spectacle and deepens the gap between visibility and value.

More Than 4,100 Vendors, One Crowded Market

Citing IT-Harvest data, the report counts over 4,100 cybersecurity vendors selling roughly 11,000 products, with one estimate valuing the market near $336 billion in 2025 and still growing, but more slowly. Notably, the report finds the market isn’t dominated by a handful of giants. Instead, the top 10 vendors control less than 30% of spending, so the central issue is fragmentation, not dominance.

Buyers Have Money, Just Not Enough Bandwidth

Drawing on a survey of 929 decision-makers, the report shows security budgets are still rising for most organisations, and buyers aren’t fleeing specialist vendors for all-in-one platforms. Even so, the real bottleneck is operational: the average company already juggles 83 security tools from 29 vendors, according to IBM Institute for Business Value research, and more than half of major security deals take at least six months to close. The contrast is clear: money is available, but adoption capacity is not.

When Every Vendor Sells “Agentic AI”

The report singles out this year’s wave of autonomous, AI-driven security products as a case study in the problem. Nearly every exhibitor claimed some version of an autonomous security operations centre, making it hard for buyers to tell genuine innovation from marketing. Shimel warns that stacking multiple independent AI agents onto an already fragmented toolset risks creating “agent sprawl”. In effect, it creates a new version of the same coordination problem the industry is trying to solve, and sharpens the gap between promise and reality.

The Verdict

Shimel’s conclusion is nuanced: cybersecurity isn’t too big for the problem it exists to solve, and it isn’t short on capital or ideas. What’s strained, he argues, is the machinery connecting good products to the customers who need them: attention, trust, and the operational capacity to adopt yet another tool. In other words, the industry’s scale still outpaces its ability to turn noise into adoption.

Author