This post was originally written in Turkish and translated into English with AI.
The software sector—and SaaS1 in particular—is living through its deepest de-rating2 in 25 years. IGV US3 (the iShares Expanded Tech-Software ETF) has fallen roughly 37% from its September 2025 peak, wiping out more than $2 trillion in market value along the way.

What makes this correction different from the ones before it—the rate shocks, the demand cycles—is that this one is fundamentally about terminal value uncertainty. The market is repricing how durable the software business really is in a world where agentic AI tools can increasingly replicate, abstract away, or outright compete with the application layer. The chain of events is easy to trace: Anthropic’s Claude Cowork launch (January 12), Microsoft’s disappointing Azure growth against sky-high capex expectations (January 28), the OpenClaw developments, and a wave of LLM applications aimed squarely at vertical workflows—legal, security, SMB operations.
In this post, we’ll first dive into the software sector and take a look at how the market has been behaving. We’ll dig into what’s actually being priced in, and what the potential catalysts are in both directions. Then we’ll move on to cybersecurity, walk through the broader industry dynamics, and go deep on two companies in particular (CRWD and PANW). Writing pieces like this informs you while sharpening my own thinking process. Enjoy the read.
What Has Been / Is Being Priced In
With the launch of Claude Cowork and a flurry of agentic AI applications behind it, the SaaS business model has landed under the microscope. These companies have enjoyed 70-90% gross margins for years thanks to the moats4 they built in their respective domains—and whether those margins and revenue figures can survive is now a very big question mark. What they’re going through is not a cyclical demand slowdown but what we call terminal value compression5: a serious markdown in the long-term projections that their valuations rest on.
Another factor is the cross-sector rotation already underway. When AI fears first flared up last year, investors began rotating into energy, banks, mining, and industrials—companies that would be far less exposed to all of this. That rotation has stung software companies, which are already asset-light6 by nature.
Perhaps the most interesting development came from the private credit7 side. A handful of firms with outsized balance-sheet exposure to the sector—the largest and best known being Blue Owl—began seeing redemptions8 pick up and started marking their loans down. That, in turn, pushed software-sector CDS spreads higher, piling more weight onto companies that were already being priced ugly. ORCL and MSFT CDS spreads:

Bull Case: An Allocation Opportunity
The bull thesis rests on two main pillars.
(1) Competitive advantages rooted in domain expertise and data quality—which will matter more, not less, as AI matures—are still not being priced properly. Many of these companies, as we’ll see in cybersecurity later on, have spent years accumulating serious know-how and proprietary datasets simply by doing business. Some of that is too specific, too application-focused, to be replicated on the AI side.
One of the most striking data points of recent weeks came out of Datadog’s investor day: management showed that small language models trained on their own datasets outperformed frontier LLMs at a fraction of the cost. This is not a one-off—it’s a structural advantage sitting there for every company that has spent years piling up domain-specific data and workflow intelligence.
HubSpot’s recently introduced Agentic Customer Platform makes the same point. AI falls short in enterprise use cases for lack of context. Customer history, decision rationale, team collaboration patterns, industry-specific operational logic—none of it can be reproduced by a general-purpose model. Companies that have been accumulating this context for decades don’t get displaced that easily.
(2) Investors are seriously underestimating what it costs to migrate enterprise workloads off incumbent platforms. Enterprise software migrations are measured in quarters and years, not weeks. Ripping out SAP S/4HANA9 takes a minimum of roughly 18-36 months. Salesforce’s platform ecosystem—Flows, Apex, AppExchange—creates deep integration and dependency. And these switching costs get amplified even further in government-adjacent sectors, where compliance and regulatory requirements bolt extra layers of friction onto any platform change.
Decades of poor data governance, siloed10 systems, and legacy integrations mean that even a technically superior solution runs into enormous implementation barriers. ServiceNow, for one, keeps hammering the point in meetings: building your own custom AI solution and maintaining that infrastructure is difficult and expensive—every new domain you enter effectively means standing up a small company inside the company.
In short, everyone who thinks AI lets them compete with these companies is missing one thing: these companies use AI too. And in a far more sophisticated way. Their years of accumulated knowledge keep them several steps ahead at the application layer as well—they know exactly which dataset to implement, and how.
Bear Case: Permanent Structural Damage
The bear thesis comes in three main headings:
(1) Creative destruction has already started to get real for some companies. SOAR11 platforms in particular—platforms that house both the workflow and the data—could be reduced to mere data custodians if the workflow gets handed over to AI agents. What that scenario means for margins and growth is anyone’s guess, because forecasting it is close to impossible.

(2) Collapsing coding costs could upend the old organizational structure from top to bottom. Rather than paying expensive fees to external SaaS vendors—especially for the simpler problems—companies may increasingly embrace the Forward Deployed Engineer model that Palantir is already running. Engineers physically show up at the client’s office and build the platform right there, directly on top of the customer’s own data and workflows. The customer isn’t buying “Palantir software”; they’re buying a system embedded in their own operations that nothing else can replace.

With LLMs, it’s entirely possible we see new competitors adopt this model. Producing software that plugs into a client’s own systems is not a strength of many SaaS companies, and a market shift toward that segment could eat into their share.
(3) Nobody can tell you where the exponential progress on the LLM side ends. Application areas that were unimaginable a year ago are now feasible with the new agentic models. A year from now, we can’t know which new model will put which company out of business—so the multiple compression isn’t an opportunity; it’s exactly what should be happening. From here, it all comes down to where these companies’ multiples ultimately settle.
Cybersecurity
Another sector caught up in the risks above is cybersecurity. The sector sold off on the initial announcement of Claude Code Security and Mythos, but with the newsflow of late it has settled onto a plateau. Mythos is the most powerful model Anthropic has built to date—a new tier above the existing Opus offering. It has shown striking capabilities in cybersecurity, coding, and academic reasoning in particular. And precisely for that reason, rather than opening the model to everyone, Anthropic granted access under Project Glasswing to more than 50 select companies—Microsoft, Nvidia, and Cisco among them—along with $100 million in usage credits.

Fair warning: the rest of this piece is biased, because I believe this is an opportunity for the cybersecurity side. Let’s look at why—and within that framework, examine two companies (CRWD and PANW).
Cybersecurity is the one sector least affected by the current software selloff—in fact, paradoxically, it feeds on it. To see why, ask the following question: Is agentic AI a threat to software companies? Yes. So what does that mean for cybersecurity companies?
For them, it means the exact opposite: TAM (Total Addressable Market) expansion. More attacks grow the market. And the growing market isn’t just on the B2B (Business to Business) side; it applies to B2G (Business to Government) as well. Rising cyberattacks are pushing cybersecurity spending up in government defense budgets, and that lets these companies grow safely by winning large government contracts.
Anthropic’s Claude, meanwhile, adds a whole new dimension to the sector. These companies—already sitting on solid backlog and ARR (Annual Recurring Revenue) growth figures—can use Mythos to dig their existing moats even deeper.
At this point, the idea that companies will abandon end-to-end cybersecurity software or build their own in-house solutions strikes me as nonsense. When I put the question to Claude directly—“Do you think companies could build this kind of cybersecurity software themselves?”—here’s what came back:
Short answer: theoretically yes, practically close to impossible.
Think of it this way—a company decides to write its own security infrastructure from scratch. What does it need?
1. Endpoint agent software — CRWD’s Falcon agent runs at the Windows kernel level. It has been optimized separately for every operating system version and every hardware configuration. Writing this means 5-7 years and hundreds of engineers. On top of that, add this: Microsoft, Apple, and Linux ship kernel updates constantly, and you have to chase every single one of them.
2. Threat Graph — This is where CRWD’s real moat lies. Trillion-scale telemetry data from 30,000+ customers is processed in real time, and every new attack pattern is learned for the benefit of all customers. The challenge isn’t writing this yourself—it’s generating, on your own, the data that thousands of customers produced over many years. That cannot be bought, and it cannot be copied.
3. Threat intelligence — PANW’s and CRWD’s SOC analysts and researchers continuously track the dark web, APT groups, and nation-state actors. They feed this intelligence into the platform. You could do this yourself, but the cost is astronomical.
4. Regulation and certification — FedRAMP, SOC 2, ISO 27001, HIPAA compliance. Each one is a separate bureaucratic process. You need all of them to sell to a large enterprise customer.
Look at it from the cost side:
A rough calculation—100 engineers, 5 years, at San Francisco cost levels—puts software development alone at $500M-1B. Add the threat intelligence team, the data infrastructure, and the regulatory process, and you easily get to $2-3B. CRWD’s annual R&D spend alone is ~$1.2B.
And the truly critical point:
By the time you finish after five years, CRWD will have moved five years further ahead. Competing from scratch against a product with network effects is like aiming not at a destination but at a moving target.
So why don’t companies build their own?
Because in the rational “build vs buy” calculus, buy wins. A CFO asks: “Are we a security company, or should we focus on our core business?” Companies like Google and Amazon built their own security teams—but even they use CRWD and PANW, because they need external threat intelligence.

PANW and CRWD
In the final part of this piece I’ll cover the PANW and CRWD business models and valuations. Palo Alto Networks and CrowdStrike are the two dominant cybersecurity platform companies in the public markets, and both are running aggressive consolidation strategies that will shape the competitive landscape for the next decade. Palo Alto wants to grow primarily by acquiring outside companies, while CrowdStrike layers the modules it builds in-house onto its customers one on top of another. A quick look at the financials:

PANW: The company guides to 22.5% growth next year, with EPS expected to rise 133%. Its latest results came in better than expected but got buried under the ongoing SaaS selloff. In the most recently reported figures, total revenue beat both guidance and consensus, rising 15% year over year to $2.59 billion. Next-Gen Security ARR grew 28% organically to $6.3 billion, hitting the top end of guidance. Product revenue rose 22% year over year to $514 million on strong demand for hardware and software firewalls, while adjusted diluted EPS beat both guidance and consensus at $1.03. The company delivered operating margin above 30% for the third consecutive quarter, keeping its profitability momentum intact. SASE ARR grew roughly 40% year over year to more than $1.5 billion.

The company recorded a record number of net new platformizations in Q2, reaching approximately 1,550 platformizations in total. Platformized customers rank among the industry’s best with a 119% net retention rate—an extremely strong signal for customer loyalty and expansion. Meanwhile, the CyberArk and Chronosphere acquisitions were successfully completed; both are being integrated with an eye on AI adoption and the inflection points in the security market. The company also announced the acquisition of Koi Security for approximately $400 million to strengthen agentic endpoint protection and AI security capabilities.

FY2026 full-year revenue guidance was raised to $11.28-11.31 billion, reflecting 22-23% year-over-year growth, with organic growth projected at roughly 14%. Operating margin guidance was lowered by about 100 basis points to the 28.5-29% range on M&A integration costs. The company reaffirmed its 40% adjusted free cash flow target for FY2028, while guiding to 37% for FY2026 and FY2027.
CRWD: CrowdStrike’s Falcon platform was built from day one on a cloud-native single-agent architecture. Falcon streams telemetry from a single lightweight agent installed on endpoints and feeds that data into the CrowdStrike Security Cloud, where AI processes trillions of data points in real time through the proprietary Threat Graph. Endpoint, cloud, identity, SIEM, exposure management—every module runs on the same architectural foundation. And because the modules share one data model, there is no integration cost to speak of.

The advantage this architecture delivers boils down to this: deployment gets faster—a Fortune 100 healthcare company brought more than 46,000 sensors online in short order—the marginal cost of each new module approaches zero, and the data network effect keeps compounding. In other words, every new customer and every new module further enriches the Threat Graph for everyone. The subscription model, paired with government-level renewing contracts, also hands the company a steady stream of recurring revenue.

CrowdStrike delivered record net new ARR of $330.7 million in Q4, up 47% year over year, taking ending ARR to $5.25 billion. Total revenue grew 23% year over year to $1.31 billion, with subscription revenue rising at the same rate to $1.24 billion. On the back of record top-line strength and gross margin improvement, non-GAAP operating income rose to $325.8 million, closing above guidance with a 25% operating margin. The company generated record free cash flow of $376.4 million (29% of revenue) in the same quarter, ending the period with $5.23 billion of cash on hand. Non-GAAP gross margins hit record levels at 79% overall—including an 81% subscription gross margin—helped by ongoing cloud optimization.

The emerging modules—cloud, next-gen SIEM, and identity security—reached over $1.9 billion in combined ARR, growing more than 45% year over year. Next-gen SIEM ARR surpassed $585 million, growing more than 75% year over year. Falcon Flex ARR, with 1,600 customers, is growing at over 120% year over year and now accounts for roughly 30% of total ARR. The AI security front looks extremely strong as well: AIDR revenue grew more than fivefold quarter over quarter, while Charlotte ARR tripled year over year.
CrowdStrike raised its FY27 ARR outlook to a range of $6.466-6.516 billion, reflecting 23-24% year-over-year growth. Net new ARR growth for FY27 is projected at 20-25% year over year—above the prior “at least 20%” guidance. FY27 operating margin guidance stands at roughly 24.5% at the midpoint, helped by accounting tailwinds related to sales commission amortization—about 40 basis points above consensus. The company also reaffirmed its long-term FY2029 targets of 28-32% non-GAAP operating margin and 34-38% free cash flow margin.
To keep this piece from running even longer, I’ve compiled a more detailed analysis of the two companies—the product of my conversations with Claude—into a PDF. Those who want to dig deeper can find the companies’ offerings and strategies here: https://drive.google.com/file/d/1o8fDIZteFbsGk68ko9xht9lRNy\_htwpP/view?usp=sharing
Closing Thoughts
This selloff should be read not as a blind buying opportunity but as a culling. I don’t think the market is wrong—for some software companies, the terminal value debate strikes me as entirely reasonable. But throwing everything into the same basket is just as much of a mistake. Companies with deep databases and vertical integration, high switching costs, and an approach that treats AI as a tool rather than a rival will come out of this period stronger. On the cybersecurity side, the story is much clearer: as the attack surface grows, the TAM grows, budgets aren’t being cut, and developments like Mythos—far from eroding existing moats—are deepening them. In this environment, PANW and CRWD are not merely surviving; they are feeding on the very thing the market fears.
Disclaimer
This article has been prepared for informational purposes only and does not constitute investment advice, a buy or sell recommendation, or an offer relating to any security. The views and analyses contained herein reflect the author’s personal assessments and do not represent the official views of any institution or organization with which the author is affiliated. The author may hold positions in the securities mentioned in this article. Past performance is no guarantee of future results. All investments involve risk, and investors should conduct their own research and consult a licensed investment advisor where necessary. The information in this article is based on publicly available sources, and no guarantee is given as to its accuracy or completeness.
SaaS (Software as a Service) is a delivery model in which software applications are provided over the internet on a cloud basis, rather than being installed locally on computers. Typically operating on a subscription basis (monthly/annual), this model has the provider manage all infrastructure, security, maintenance, and updates. -Gemini
A decline in company valuation multiples
America’s largest software ETF
The structural strength that preserves a company’s long-term, sustainable competitive advantage and profitability against its rivals
In discounted cash flow (DCF) analyses, the situation where the terminal value’s share of total valuation shrinks proportionally, as a result of lowered perpetuity-period growth assumptions or reduced valuation multiples. It typically occurs in the transition from a high-growth phase to a stable phase -Gemini
A capital model that does not carry costly, long-lived assets such as production facilities, real estate, or machinery on the asset side of the balance sheet
Direct debt financing provided to companies by institutions outside of banks or public bond markets (private funds, asset managers). More flexible, faster, and more “tailor-made” than bank loans, these credits typically meet the financing needs of mid-sized or higher-risk companies -Gemini
Investors requesting to withdraw their investment
SAP S/4HANA is an integrated platform designed to manage traditional business applications faster and more efficiently. Thanks to its data analytics and real-time processing capabilities, businesses can make faster and smarter decisions while further optimizing their processes. -Gemini
The situation in which departments or individuals within an organization work in isolation (separated by “invisible walls”), avoiding sharing information with others. -Gemini
Security Orchestration, Automation, and Response
The widest theoretical market volume and total revenue opportunity a product or service could reach