HomeArticle

Zhipu has already obtained 1 billion yuan in orders, why are domestic cybersecurity stocks in China still falling?

硅基观察Pro2026-09-22 13:40
China's cybersecurity industry is trapped in IT budget constraints

There is a highly counterintuitive divergence in this year's AI market rally.

US cybersecurity stocks have skyrocketed. As of August 31, the US cybersecurity ETF CIBR has risen by 40.36% year to date, far outperforming the Nasdaq in the same period, with many outstanding stocks even doubling in price.

On the other side, China's cybersecurity stocks present an almost completely different picture.

Even though Zhipu has received cybersecurity-related orders exceeding 1 billion yuan, the entire sector is still performing terribly. As of September 18, the CSI Information Security Thematic Index has dropped by 12.49% year to date.

With one side up 40% and the other down 12%, the gap between the two sides has widened by more than 50 percentage points in less than a year.

This is very thought-provoking.

Given that both sides are facing the same wave of AI development, why have US cybersecurity stocks become top-performing AI stocks while their Chinese counterparts have plummeted so sharply?

The core reason is that cybersecurity in China and the United States has increasingly evolved into two completely different types of business:

Cybersecurity in the US has become infrastructure that grows alongside AI usage, profiting from the expansion of AI. In contrast, domestic cybersecurity in China is still largely positioned as a cost center, tightly constrained by the compliance budget of traditional government and enterprise IT systems.

This is the fundamental reason why the performance of Chinese and US cybersecurity stocks has diverged so significantly this year.

01

Two Completely Different Markets

Chinese and US cybersecurity stocks are evolving into two entirely distinct business lines.

Cybersecurity in the US is shifting from a traditional software expenditure to a kind of "tax" in the AI era, while the revenue of domestic cybersecurity in China is still locked in the compliance budget of traditional government and enterprise IT systems.

This difference is first reflected in the industry scale.

Gartner forecasts that global information security spending will reach 244 billion US dollars in 2026, a year-on-year increase of 11.6%.

The fastest-growing segment is precisely the new demand brought by AI. Gartner has separately tracked a market called Securing AI, which covers products such as AI application security, AI usage control, AI governance platforms and AI Gateway.

In 2026, this market is expected to reach 2.835 billion US dollars, representing a year-on-year increase of 83%; by 2027, it will further grow to 4.783 billion US dollars, marking another 68.7% increase.

This means that after the rise of AI, US enterprises have not diverted their security budget from the existing pool, but instead created a brand-new security budget.

From model licensing to data security, every additional AI application may bring a new layer of security demand. The more AI deployments there are, the higher the security expenditure will be.

More importantly, this revenue has started to appear in financial reports. Fortinet posted a revenue of 2.05 billion US dollars in its second quarter this year, up 26% year on year; its billings reached 2.37 billion US dollars, a 33% year-on-year increase; and its GAAP operating profit margin hit 34%.

The performance of Palo Alto Networks is even more notable. In the fourth quarter of fiscal year 2026, the company's AI security product Prisma AIRS had an ARR exceeding 100 million US dollars only four quarters after its launch, making it the fastest-growing new product in the company's history.

To sum up, US cybersecurity companies are facing a market with double-digit annual growth, where AI is creating incremental new demand. In contrast, domestic cybersecurity companies in China are facing a market that has been shrinking for three consecutive years.

Data from Shishijie Consulting shows that the scale of China's domestic digital security market reached 88.743 billion yuan in 2025, a year-on-year decrease of 1.5%.

More importantly, this marks the third consecutive year of decline. In 2022, the scale of China's digital security market still reached 98.12 billion yuan; it decreased by 0.76% in 2023, 7.4% in 2024, and another 1.5% in 2025.

Over the three years, the market size has shrunk by nearly 10 billion yuan.

Qi Anxin made this very clear in its semi-annual report this year. Affected by the macro environment and government fiscal conditions, customers have generally cut their budgets, and project delays still exist; meanwhile, price competition in the industry is fierce. With limited budgets, customers are increasingly inclined to maintain existing systems rather than launch new projects.

In the first half of this year, Qi Anxin recorded a revenue of 1.497 billion yuan, down 14.09% year on year, with a net loss attributable to shareholders of 411 million yuan.

In fact, some domestic cybersecurity companies have also benefited from the AI dividend, but the funds may not flow to the "security" business first.

The most typical example is Sangfor. In the first half of this year, the company's revenue reached 3.998 billion yuan, up 32.85% year on year, and its net profit attributable to shareholders was 231 million yuan, turning losses into profits.

However, the fastest-growing business is not the security business. Revenue from cloud computing and AI infrastructure reached 2.212 billion yuan, up 58.6% year on year; revenue from cybersecurity was 1.587 billion yuan, up 10.57% year on year.

The former has accounted for 55.34% of the company's total revenue, becoming the absolute core of growth for the first time.

02

US Cybersecurity Gains Platform Dividends, While Chinese Cybersecurity Still Relies on Project-based Revenue

Apart from the budget gap, the business models of the cybersecurity sectors in China and the US are also becoming increasingly different.

US cybersecurity companies sell subscriptions. Customers sign a contract and then renew their subscriptions continuously. As there are more and more AI applications, new security demands can be continuously superimposed on existing customers.

With the advent of AI, cybersecurity in the US is increasingly becoming a platform-based business.

On one hand, AI Gateway, AI application security, Agent identity and permission management are all new demands that did not exist in the past.

On the other hand, AI is making the entire IT environment more complex, and customers prefer to reduce the number of suppliers. As a result, leading vendors such as Palo Alto, CrowdStrike and Fortinet can appropriately capture more budget that originally belonged to other security companies.

The most representative company is Palo Alto. Over the past few years, Palo Alto has been emphasizing one concept: Platformization.

Simply put, in the past, a large enterprise might procure products from dozens of different security vendors at the same time, with separate vendors for network security, cloud security, SOC, and identity security. Palo Alto aims to gradually integrate these originally scattered budgets into one single platform.

Nowadays, this model has started to deliver results. In the second quarter of fiscal year 2026, the number of platform-based customers of Palo Alto reached about 1,550, up 35% year on year; the net revenue retention rate of these customers reached 119%. In the fourth quarter, this figure further exceeded 120%.

This means that after a customer joins the platform, they usually spend more money in the second year than in the first.

The market is growing, and leading players can also increase the revenue per customer at the same time. This is why the growth quality of US cybersecurity companies is particularly outstanding.

However, this trend has not yet emerged in China.

A large number of domestic cybersecurity companies still adopt a project-based operation model, and can only obtain funds from enterprise IT budgets, with a very low priority in the budget allocation.

For example, a local state-owned enterprise is willing to spend tens of millions of yuan to build a large model platform, because it expects the system to be truly integrated into its business. The system can process materials, analyze data, build a knowledge base, and even assign part of the manual work to Agents. Such projects have clear usage scenarios and can be established as independent projects.

Cybersecurity is different. Security rarely directly generates business revenue. This means that in a new technology construction cycle, the demand for security usually lags behind the demand for production systems.

China's domestic market is currently in exactly the previous stage. Many government and enterprise customers are still in the process of building their own large model platforms, and a large amount of budget first flows to models, computing power, data governance and application development. Although security has been taken into consideration, in most cases it is only a part of the entire project, and it is difficult to form a separate large budget.

In this process, traditional cybersecurity companies are mostly just one of the suppliers, and can only obtain a small share of the total revenue.

This is also why Zhipu can obtain orders worth 1 billion yuan, but cybersecurity vendors can hardly get revenue of the same scale.

Of course, domestic cybersecurity vendors are also using AI to upgrade their own products. For example, they use large models to upgrade SOC, threat detection and security operations.

But there is another problem here. The integration of AI does not mean that customers are willing to pay an extra sum of money.

A traditional security system used to sell for 1 million yuan. Now with the addition of large model analysis capabilities, customers are very likely to regard it as a normal product upgrade.

Vendors need to increase R&D investment, but the unit price per customer may not rise synchronously. Therefore, at the current stage, AI first increases the costs of many domestic cybersecurity companies, and has not yet turned into a sufficiently large amount of new incremental revenue.

What may truly transform this industry are dedicated security products designed specifically for protecting AI, including model access control, data leakage prevention, prompt attack protection, and Agent permission management.

However, the realization of this demand has a prerequisite: AI must first be truly integrated into the production environment.

But this market is still in its very early stage. The reason is simple: these problems will only become sufficiently prominent when large models are truly integrated into the core business of enterprises. If the AI of a company is only occasionally used by employees to write materials, AI security can hardly become an independent budget item.

This is where the US market moves faster than the domestic market.

A large number of US enterprises have already deployed Copilot, code Agents and various AI applications in their actual production environments. As AI gains access to more and more enterprise data and internal systems, security has become a prerequisite for the launch of large models.

As a result, AI security in the US has gradually formed an independent market, while the domestic market in China has not yet fully reached this stage.

03

Conclusion

The real divergence between Chinese and US cybersecurity sectors lies in the change of the economic attribute of security in enterprises.

Cybersecurity in the US has evolved from a compliance cost to infrastructure that grows alongside AI usage. The more enterprises use AI, the higher their security expenditure will be, and leading platform vendors can continuously increase their revenue per customer.

Cybersecurity in China is still largely positioned as a cost center. Customers purchase security products to meet compliance requirements and ensure the normal operation of systems, so the budget has a natural upper limit and can hardly grow synchronously with the increase of AI usage.

One side profits from the expansion of AI, while the other side still profits from IT construction. This is the fundamental reason why the valuations of the two sides are increasingly diverging.

This article is from the WeChat Official Account "Silicon-based Observation Pro", written by A Qi, and authorized for release by 36Kr.