Silicon Valley Byte Size - The Allianz Technology Trust Podcast
Cybersecurity Investing: Why Today's Winners Can Quickly Become Obsolete
Watch the video
Listen to the podcast
Cybersecurity has become one of the most critical areas of technology, but it is also one of the most challenging sectors for investors to navigate. In this episode of Silicon Valley Bite Size, Cherry Reynard sits down with Mike Seidenberg, lead manager of Allianz Technology Trust, to explore why success in cybersecurity can be surprisingly short-lived.
Mike Seidenberg (MS): One of the risks of investing in a cybersecurity index is you may own companies that no longer have the best products. Having platforms is really difficult. Everybody wants to be one and very few companies are able to be one. Perishability, I think of it if you think about a grocery store, cybersecurity is in the hot food area.
Cherry Reynard (CR): Hello, I'm Cherry Reynard and welcome to Silicon Valley Bite Size, where we discuss, chew over and get into the weeds of some of the biggest trends in tech investing.
Today, we're looking at one of the most fascinating and difficult areas in technology, cybersecurity. It's a sector that matters more than ever as businesses, governments and individuals all try to protect themselves in a world of constantly evolving digital threats. But from an investment perspective, it's also a sector where success can be surprisingly fragile. To understand why, I'm joined by Mike Seidenberg, lead manager of the Allianz Technology Trust. Mike, great to have you here.
MS: Great to be here.
CR: So Mike, you've said that cybersecurity is one of the hardest sectors to invest in. I wonder if you can talk about why that is.
MS: The thing that makes cybersecurity such a challenging sector to invest in is if you take a step back and look at other sectors, and let's just use the database sector, for example. When you take a look at a company like Oracle, who has innovated around the database for the last 30 plus years.
In cybersecurity, because the adversaries change vectors of attack, there isn't the opportunity to innovate around a certain technology or a certain direction. Due to the fact that your adversaries want to change how they attack you, it's very simple, right? You have AV software, adversaries decide antiviral software. They decide they want to attack through a different vector. And then that software becomes almost obsolete.
So in cybersecurity, this notion of having the right architecture at a given time is so incredibly important. And those architectures change. So, our job is to figure out the companies that are basically providing those layers of security that for the relevant vectors today is the way to think about it.
CR: Okay, that's interesting. So the idea they can do all this lovely innovation, and it could be obsolete if they...
MS: 100%. And that happens. And we've seen that. And we've seen companies that were relevant 15 years ago, 10 years ago, are totally irrelevant today.
And not only that, they're complete share givers. So, they're not gaining share, they're giving share back to some of the new innovative companies.
CR: Okay, so this is the idea of perishability, really?
MS: Yeah. Perishability, I think of it, if you think about a grocery store, and if you think about the various sectors of a grocery store, obviously the things in the freezer are going to last the longest.
Cybersecurity is in the hot food area, right? Right. Hopefully, the grocery store doesn't reheat that food the next day, but cybersecurity has a real perishability issue.
CR: You talk about vectors there. Can you give us an example of how that happens in practice?
MS: Absolutely. Traditionally, a lot of cybersecurity breaches occurred vis-a-vis clicking on a link in an email. It was something that was very kind of endpoint-oriented. Today, what you're seeing is the adversaries use things like applications, right? They will take a look at an application that you and I use as part of our daily interaction with a company or our corporate role, and they will actually use that as a modality to attack.
So, what you see is you have a variety of different, whether it's endpoint, which is more email-oriented, trying to block it at the firewall versus trying to actually attack vis-a-vis an application, and that doesn't even include the likes of people clicking on text messages. I mean, you're just in this digital world that we live in. It's great from a productivity perspective and from a daily life perspective. It's not so great from a points of presence on the network perspective because we are very present in a variety of different environments that allow us to be attacked by cybercriminals.
CR: Yeah, so it's opening up new things all the time.
MS: 100%. For example throughout your daily kind of existence, you may wake up in the morning, work at home, decide to go to the coffee shop, work on your corporate work from the coffee shop, and then, you know what? In the evening, you may be out at an event and need to respond to something on your mobile phone. Think about that. Those are three different environments that require a multitude of solutions in order to protect you, the corporate citizen, in our corporate example.
That's a pretty tall task for businesses, and obviously, businesses want us to be productive, right? They want us to be able to work from everywhere. The other side of that coin is that we're very vulnerable.
CR: Okay, so it's not like some of the other bits of technology where scale is a real advantage. It's not like the biggest companies are necessarily the safest bets.
It's the one with kind of the right technology at the right time.
MS: I mean, scale obviously helps to some degree because that affords you the ability to invest in R&D. But I think that the real kind of key factor here is basically having a variety of solutions that can protect the customers. Usually, what you see is a company will start with a single product, and then they'll innovate around that. In the next thing you know, they have a platform of products.
Having platforms is really difficult. Everybody wants to be one, and very few companies are able to be one.
CR: Can you give an example of how that sort of happened in practice, you know, a company that's done that well?
MS: Yeah, for sure. If I just think of a company like CrowdStrike and just a really good management team there, the way that their initial product came to market, they really thought differently about handling threats.
So, you had traditional antivirus software, and CrowdStrike kind of turned that model on its head, whereby they use the cloud to take advantage to take those digital threats back and then disseminate the protection across all their customers. So, a real network effect there.
CR: Okay, so it's not like building wall after wall, it's thinking differently.
MS: Thinking differently. In the case of CrowdStrike, really leveraging modern technologies, cloud-based technologies, which are commonplace today, but when they started the business, it really wasn't the way security was being handled.
They made a number of companies obsolete. One of the risks of investing in a cybersecurity index is you may own companies that no longer have the best products and therefore have challenges in front of them.
CR: Yeah. Okay, so that's really an argument for active management in this space. It's an area where that's particularly important.
MS: And, you know, I'm obviously somewhat biased here, but cybersecurity really speaks to active management, in my opinion.
CR: Okay. And when you're assessing a cybersecurity company, what are you really trying to work out? What are the big things that you're looking for?
MS: I mean, as we assess many companies, what we really want to look for is how difficult the problem is that they solve. Because I've often operated under the mantra that if you solve a difficult problem and have a happy customer, you can probably sell them more things. So, that paradigm continues to exist in cybersecurity.
But I think that the slight nuance here is there is an element of making sure that a company can execute effectively enough to get a critical mass of customers so that their solution can potentially become a norm.
CR: And what about the influence of AI in this space? I mean, does that bring in new threats and does it mean that companies have to change the way they do things as well?
MS: I mean, in my opinion, artificial intelligence will require companies to invest as much, if not more, in cybersecurity. Interestingly enough, the cybersecurity companies should be able to leverage artificial intelligence to make their products better.
CR: Okay. And what kind of share of this is your portfolio now? I mean, how important a theme is it?
MS: I mean, just depending on kind of the trust and the overall positioning, it's typically kind of somewhere between 10 to 20%, 15%. And depending on the opportunities that we're seeing in cybersecurity relative to other sectors.
CR: Okay, great. We will leave it there. Thank you so much, Mike. Thank you. If you'd like to learn more about how Allianz Technology Trust approaches areas like cybersecurity and other fast-moving technology themes, you can find full portfolio details, insights, and performance information on the Allianz Technology Trust website.
And if you're enjoying Silicon Valley Bitesize, please like, subscribe, and follow the series. Thanks for joining us.