← Back to Library

Most cyber companies simply can’t scale as fast as the new AI startups

Ross Haleliuk delivers a sobering reality check for the cybersecurity sector, arguing that the industry's fundamental nature makes it structurally incapable of matching the hyper-accelerated growth curves now defining the AI startup ecosystem. While the broader market chases "Supernova" valuations achieved in under two years, Haleliuk contends that security will remain a "Cloud Centaur"—durable and profitable, but bound by the slow, deliberate pace of enterprise trust. This distinction is critical for investors and founders alike, as it suggests the current capital flight from security to AI is not a temporary market correction but a rational response to divergent business models.

The Speed Mismatch

Haleliuk anchors his argument in data from Bessemer's "State of AI 2025" report, which highlights a dramatic compression in the time required to reach $100 million in annual recurring revenue (ARR). He notes that while top software companies previously took seven years to hit this milestone, new AI "Supernovas" are achieving it in just 1.5 years. "Supernovas are the AI startups growing as fast as any in software history," Haleliuk writes, quoting the report to illustrate the sheer velocity of the new wave. These companies often sprint from seed funding to massive scale in their first year of commercialization, a feat that would have been unthinkable in the traditional SaaS era.

Most cyber companies simply can’t scale as fast as the new AI startups

The author contrasts this with the "Shooting Stars" of the AI world, which grow faster than traditional software but still face some scaling bottlenecks. Yet, even these are outpacing the security sector. Haleliuk points out that the industry is facing a new benchmark where "Q2T3 (quadruple, quadruple, triple, triple, triple) better reflects the five-year trajectory we're seeing from today's AI Shooting Stars," a stark departure from the T2D3 growth patterns that defined the previous decade. This reframing is essential; it suggests that the old metrics for success are no longer just outdated, they are actively misleading for those trying to navigate the current capital landscape.

Security moves with the speed of trust, not the speed of shipping new features.

The Trust Bottleneck

The core of Haleliuk's analysis lies in the distinction between product development and go-to-market (GTM) strategies. He argues that while AI has undeniably accelerated the ability to ship code, it has not—and cannot—accelerate the procurement processes of large enterprises. "In cyber, product is the game of inches, but GTM is the game of miles," Haleliuk paraphrases, emphasizing that the most technologically superior products often lose to better distribution. This dynamic is particularly acute in security, where the stakes involve risk mitigation rather than efficiency gains.

He observes that the very presence of AI in a security product can actually slow down sales cycles. "Interestingly enough, as AI is accelerating the speed of shipping new features, it's actually slowing down the speed of trust," he notes, explaining that enterprises are now scrutinizing how AI models handle data, leading to longer proofs of concept (POCs) and more rigorous vetting. This creates a paradox where the technology meant to speed things up becomes a barrier to entry. Critics might argue that as AI becomes more ubiquitous, these trust barriers will eventually erode, but Haleliuk's point holds weight: the fear of hallucinations or data leakage in a security context is a higher-order risk that buyers will not rush to accept.

The Venture Capital Exodus

Perhaps the most provocative claim in the piece is the prediction that generalist venture capital firms will abandon the cybersecurity sector. Haleliuk suggests that the incentive structures of these funds are misaligned with the reality of security growth. "Generalist VCs operate under a different set of incentives," he writes, noting that they are not bound to a specific vertical and will naturally gravitate toward the "AI Supernovas" that promise faster returns. He illustrates this with a hypothetical comparison: a fintech startup hitting $5 million in ARR in ten months will look far more attractive to a generalist than a security firm on track for $1.7 million in a year and a half, even if the latter is performing exceptionally well within its own context.

This shift mirrors historical patterns in tech, such as the dot-com bubble of the early 2000s, where capital flooded into high-growth, low-trust models before the inevitable correction. Haleliuk warns that unless security budgets expand indefinitely or buyers become less risk-averse, the sector will struggle to compete for attention. "I think we'll see more generalist VCs leaving security," he predicts, arguing that the "tourists" will depart, leaving behind only specialists who understand the long-term value of the space. This natural selection process, while painful, may ultimately strengthen the industry by filtering out hype-driven ventures.

It's not that security startups are bad investments; they're just different, and these differences are structural.

Bottom Line

Haleliuk's most compelling insight is the structural inevitability of the divergence between AI and security growth rates; the industry's reliance on trust and risk reduction makes the "Supernova" trajectory a physical impossibility for most players. The argument's greatest vulnerability lies in its assumption that generalist capital will exit completely, potentially underestimating the sheer volume of money chasing AI that might still spill over into security as a defensive hedge. However, the piece serves as a vital corrective to the hype cycle, urging founders and investors to stop comparing their progress to AI benchmarks and instead embrace the slower, more durable path of the "Cloud Centaur."

Deep Dives

Explore these related deep dives:

  • Dot-com bubble

    The author explicitly mentions bubbles (mortgages, bitcoin, AI) and the pattern of capital flooding into hot sectors. The dot-com bubble provides historical precedent for understanding how technology investment cycles work and what happens when 'everyone is jumping on the same opportunity.'

Sources

Most cyber companies simply can’t scale as fast as the new AI startups

by Ross Haleliuk · Venture in Security · Read full article

It’s now pretty obvious that AI is transforming the way the world works. It feels like a massive movement, and because so much capital continues to get allocated to AI, and so many smart people are dedicating their efforts to making use of it, it’s clear that the transformation is already underway. We can debate whether or not there’s a bubble, but that’s kind of immaterial to the topic I wanted to discuss today (besides, when everyone is jumping on the same opportunity, it’s always going to lead to a bubble, whether we’re talking about mortgages, bitcoin, or AI).

The topic I want to touch on instead is how AI has been reshaping the expectations around company growth (spoiler alert: it changed them completely). In this piece, I’ll discuss how AI is changing the trajectory of startup growth, and then I’ll talk about our industry and why I think that, for better or for worse, the vast majority of the cybersecurity startups won’t grow as fast as the new AI companies. I’ve initially wanted to say that “the rate of growth of cyber startups will never match the rate of growth of the new AI companies,” but then someone will always find an example that makes the point seem wrong, even if it applies to 99.99% of the market, so I would rather maintain some credibility and frame that differently.

This issue is brought to you by… Intruder.

30M Domains Later, Here’s What We Found Hiding In Shadow IT

How much Shadow IT can you uncover with only public data? We ran the experiment and the answer was: too much. From backups holding live credentials to admin panels with no authentication, these exposures stay invisible to you but wide open to attackers. Read the research to see what we found and how Intruder helps you find it first.

The new $100M ARR growth curve for AI startups.

Several months ago, Bessemer published The State of AI 2025 report (if you haven’t seen it, I highly recommend giving it a read). In this report, they discuss the trends in the AI world and put forward some predictions about the coming years. It’s a good read overall, but what stood out to me is the idea that before AI, top companies would on average need ~7 years to reach $100M ARR. In the post-AI world, the amount of time has been shortened ...