The attackers are getting smarter, but so are the things they're attacking—and the difference is everything.
The Summary
- AI agents shifting from passive tools to autonomous actors is creating a massive new attack surface, spurring demand for products that monitor agent behavior, identities, and permissions
- Rosenblatt Securities sees this as a structural tailwind for incumbent cybersecurity platforms like CrowdStrike and Palo Alto Networks
- More capable frontier models paradoxically strengthen established security vendors rather than disrupt them
The Signal
The cybersecurity industry just found its next growth cycle, and it's not coming from another ransomware variant. It's coming from the fact that AI agents are now doing things, not just answering questions. When your software can book flights, move money, edit codebases, and execute trades without human intervention, the stakes of a compromised agent jump from "annoying" to "catastrophic."
Catharine Trebnick from Rosenblatt Securities is tracking the shift. Companies like CrowdStrike and Palo Alto Networks are rolling out products specifically designed to monitor autonomous agents—tracking their identities, permissions, and behavioral patterns in real time. This isn't theoretical risk mitigation. This is responding to enterprises suddenly realizing they've deployed dozens or hundreds of agents with varying levels of access to critical systems, and nobody's entirely sure what they're doing at 3 a.m. on a Tuesday.
"When your software can book flights, move money, edit codebases, and execute trades without human intervention, the stakes jump from annoying to catastrophic."
Here's what makes this different from previous security booms:
- The threat model is inverted: You're not just defending against external attackers anymore. You're defending against your own infrastructure making autonomous decisions that could be manipulated, hallucinated, or exploited.
- Identity becomes fractal: Every agent needs its own identity, permission set, and audit trail. Multiply that by every employee who spins up a custom agent, and you've got an identity management nightmare.
- Behavior monitoring is mandatory: Traditional endpoint security watches for known malware signatures. Agent security has to watch for *anomalous decision patterns*—an entirely different problem.
The counterintuitive part is Trebnick's thesis that more capable frontier models strengthen incumbents rather than disrupting them. You'd think better AI would commoditize security, but the opposite is happening. As models get more powerful, the complexity of securing them increases faster than the models themselves can solve it. Enterprises don't want to roll their own agent security stack. They want CrowdStrike to tell them which of their 347 agents just tried to wire $2 million to a vendor that didn't exist yesterday.
This also explains why cybersecurity stocks have been resilient even as AI hype cycles through boom and correction. The companies building agents need security more than they need another basis point of model performance. An agent that's 2% better at writing emails but can be tricked into leaking customer data is a liability, not an asset.
The Implication
If you're building agents, budget for security before you budget for compute. The enterprises buying your product will ask about agent monitoring and permission scoping before they ask about latency. If you're investing, watch how quickly the big cybersecurity platforms integrate agent-specific features. The companies that treat agent security as a bolt-on will lose to the ones that rebuild their architecture around it. And if you're working alongside agents, start asking your IT team what's watching them. The answer will tell you how seriously your company is taking Web4.