Cybersecurity isn’t short on money; it’s short on attention and clarity.
A new special report from Techstrong Group, written by CEO Alan Shimel after Black Hat USA 2026, asks a pointed question: has cybersecurity grown too big for its own good? Based on data from the show floor and several market trackers, the answer is more nuanced than a simple yes-or-no.
A city built for a week
Black Hat USA 2026 drew more than 20,000 attendees and over 400 exhibitors to Las Vegas, spilling far beyond the official Business Hall into hotel suites, ballrooms, and private parties across the Strip. Shimel, who has attended the conference for two decades, notes that the show once centered on hacker research and dramatic vulnerability disclosures that shook the industry. Now, commerce dominates the spectacle.
The cost of being seen
Getting noticed isn’t cheap. Shimel estimates a serious Black Hat presence booth, staff, travel, and hospitality can run around $250,000. Spread across 1,000 badge scans, that’s roughly $250 per lead before any follow-up work even begins. The real issue, he argues, isn’t that companies overspend; it’s that hundreds feel they must spend heavily to avoid disappearing into the noise. That pressure sets up the market-wide numbers that follow.
A crowded, fragmented market
According to IT-Harvest, more than 4,100 cybersecurity vendors now offer roughly 11,000 products, meaning Black Hat’s exhibitors represent just a sliver of the total market. Yet the market itself isn’t dominated by a few giants: Futurum Group’s analysis shows the ten largest vendors control only about 29.5% of spending, with Microsoft the single biggest player holding less than 10%. The industry, in other words, is highly fragmented rather than consolidated.
Still, the broader cybersecurity market is enormous and growing, estimated at $335.8 billion in 2025 with a trajectory toward $404.5 billion by 2027. Growth rates, however, are steadily cooling from nearly 18% in 2023 to a projected 9% in 2027, a sign of a maturing sector.
Money isn’t the constraint; attention is
Funding remains healthy, with startups raising $13.97 billion in 2025 and another $7.41 billion in the first half of 2026. But Shimel argues much of this capital now buys visibility rather than pure innovation sales teams, PR, sponsorships, and flashy booths creating a cycle where startups must raise ever more just to be heard.
On the buyer side, Futurum’s survey of 929 decision-makers found budgets still rising, with 67% expecting increases. But buyers are drowning in options: the average organization juggles 83 security solutions from 29 vendors, and over half of major deals take six months or longer to close.
Consolidation and the rise of “Agent Sprawl”
Mergers are one release valve. Momentum Cyber tracked roughly 400 acquisitions in 2025 alone. But Shimel warns that the AI agent boom risks repeating the same fragmentation problem in a new form, with vendors bolting “autonomous” features onto separate, uncoordinated products rather than solving complexity at its root.
The verdict
Shimel’s conclusion: cybersecurity isn’t too big for the problems it needs to solve, nor is it running out of money. What it may be running short on is attention, operational capacity, and buyers’ tolerance for complexity—a distinction that matters as the industry continues to expand.
