Technology / Cybersecurity / Company deep dive
This report focuses on Alphabet’s cybersecurity business. For the wider business and AI strategy, read the Alphabet company profile ↗.
Google is becoming a major cybersecurity platform by joining assets built for different purposes: hyperscale infrastructure, signals from Search, Gmail, Android and Chrome, cloud-native controls, VirusTotal’s malware ecosystem, Mandiant’s frontline expertise, Wiz’s multicloud graph and Gemini. The question is no longer whether Google has enough security products. It is whether these assets can become one operating system for defense.
Google is both a cloud provider with embedded security and an increasingly independent security platform. Security Command Center, Cloud Armor and native identity controls primarily defend Google Cloud. Google Security Operations, Google Threat Intelligence, Mandiant, VirusTotal, Chrome Enterprise Premium and Wiz can reach across other clouds, on-premises systems and third-party products. That second group turns security from a cloud feature into a possible enterprise platform.
The model contains conflicts: Google can investigate an incident in another hyperscaler’s cloud while wanting more Google Cloud consumption, and can partner with endpoint vendors while competing with them elsewhere. Alphabet does not disclose cybersecurity revenue separately, so the business must be judged by architecture, deployment reach and control points rather than an invented revenue estimate.
How the strategy evolved
Google’s security business began as an internal necessity. The Operation Aurora intrusion disclosed in 2010 became the turning point: Google stopped treating the corporate network as trusted and rebuilt access around verified identity, device state and application-level policy. That program became BeyondCorp and helped turn zero trust into an operating model.
Google then externalized parts of that defense. VirusTotal added malware data and community; Chronicle applied Google’s data architecture to security telemetry; BeyondCorp Enterprise commercialized identity-aware access; Siemplify added orchestration and cases. Mandiant contributed what infrastructure could not quickly create: investigators who see attackers inside compromised enterprises, managed defense and trusted access to security leaders.
The current phase is convergence. Google Security Operations joins SIEM, SOAR and intelligence; Google Unified Security connects operations, cloud risk, browser signals and Mandiant; Wiz adds a multicloud graph from code to runtime. Gemini and specialized agents sit above that fabric, moving the system from reporting risk toward reasoning and controlled action.
| Period | Milestone | Why it changed Google’s position |
|---|---|---|
| 2010–2014 | Operation Aurora response and the first public BeyondCorp work | Established identity- and context-based access instead of implicit trust in a corporate network. |
| 2012 | VirusTotal acquisition | Added a large malware and URL analysis corpus plus an unusually broad contributor community. |
| 2018–2019 | Chronicle launched from Alphabet’s X and then joined Google Cloud | Applied Google-scale data architecture to enterprise security analytics and made security operations a cloud business. |
| 2021 | BeyondCorp Enterprise became generally available | Commercialized Google’s zero-trust design through Chrome, its network and identity-aware access. |
| 2022 | Siemplify and Mandiant joined Google Cloud; Chronicle Security Operations took shape | Added SOAR, case management, incident response, managed services and frontline threat intelligence. |
| 2024 | Security Command Center Enterprise, Google Threat Intelligence and Chrome Enterprise Premium launched | Expanded multicloud risk management, unified intelligence and made the browser a paid enterprise enforcement point. |
| 2025 | Google Unified Security became generally available | Created a common strategic layer across security operations, threat intelligence, cloud risk, browser signals and Mandiant. |
| 2026 | Wiz acquisition completed; security and identity agents expanded | Made Google a top-tier multicloud CNAPP contender and extended the design toward autonomous detection, investigation and agent governance. |
| 2026 onward | Beyond Zero architecture disclosed | Signals a move from continuous verification of users and devices toward finer, real-time control of human and machine actions; it is an architectural direction, not yet a single commercial product. |
The architecture: three security loops
Google’s portfolio forms three loops: prevention secures identities, cloud configuration, software, data, browsers and edges; detection enriches telemetry with adversary knowledge; response investigates, contains and learns. The platform is strongest when evidence moves among them: Wiz or Security Command Center finds a risky path, Google Threat Intelligence adds adversary context, Google Security Operations investigates and Mandiant validates or responds.
The loop is not closed: outside its estate, Google often depends on third-party endpoint, firewall and identity products for sensors and enforcement. Openness suits heterogeneous enterprises, but also shows which control points Google does not own.
| Domain | Google capability | Buyer and delivery | Reach | Position |
|---|---|---|---|---|
| Cloud posture and CNAPP | Wiz; Security Command Center Enterprise and Premium | Cloud security teams; software-as-a-service and cloud-native controls | Wiz is multicloud; Security Command Center Enterprise covers major clouds while Premium is deepest on Google Cloud | Leading after Wiz, with integration still in progress |
| Cloud workload protection | Wiz Defend, Security Command Center threat detection and native workload controls | Cloud and security operations teams; agentless context plus native runtime signals | Multicloud through Wiz; strongest native visibility on Google Cloud | Credible to leading |
| SIEM | Google Security Operations | Security operations centers; cloud-native analytics service | Cloud, on-premises and third-party telemetry | Credible challenger |
| SOAR | Google Security Operations, built partly on Siemplify | Security operations centers; playbooks, cases and integrations | Cross-environment | Credible |
| XDR | Google Security Operations plus partner telemetry, threat intelligence and automated workflows | Security operations leaders; integration layer | Broad, but relies on partners for key sensors | Emerging rather than full native XDR |
| Threat intelligence | Google Threat Intelligence, Mandiant and VirusTotal | Threat-intelligence and operations teams; subscription, API and embedded intelligence | Global and cross-platform | Leading |
| Incident response and MDR | Mandiant Incident Response, Managed Defense and Threat Defense | Chief information-security officers and operations teams; expert-led service | Cross-cloud, hybrid and third-party estates | Leading in high-end response; credible in managed defense |
| Identity and access | Google Cloud IAM, Cloud Identity, Workforce Identity Federation, Identity-Aware Proxy and Context-Aware Access | Cloud and workplace administrators; native services | Strong on Google Cloud and Workspace; federates with external identity systems | Leading in Google Cloud, limited as the enterprise-wide identity standard |
| Zero-trust access | Chrome Enterprise Premium and Identity-Aware Proxy, evolved from BeyondCorp Enterprise | Workplace, identity and security teams; browser and cloud-delivered access | Can protect web and private applications across clouds and on-premises | Credible, browser-centric |
| Privileged access | Google Cloud Privileged Access Manager and just-in-time elevation | Google Cloud administrators; native cloud service | Primarily Google Cloud | Credible native feature, limited enterprise PAM platform |
| Data security and DLP | Sensitive Data Protection, Workspace DLP, Chrome DLP, encryption and Wiz data-security posture | Data, privacy, cloud and workplace teams; API and embedded controls | Some cross-cloud discovery through Wiz and the DLP API; deepest on Google services | Credible but fragmented |
| Network, WAF and DDoS | Cloud NGFW, Cloud Armor, Cloud IDS, load-balancing protections and reCAPTCHA within Google Cloud Fraud Defense | Cloud networking and application teams; infrastructure-native services | Primarily Google Cloud front doors, with selected hybrid use | Leading for Google-hosted applications; limited as an independent network platform |
| Secure browser and web access | Chrome Enterprise Premium, Safe Browsing and context-aware controls | Workplace and security teams; managed browser | Cross-operating-system and application access | Leading browser control; limited full security service edge |
| Endpoint | ChromeOS, Android Enterprise, Play Protect, Endpoint Verification and Chrome telemetry | Device and workplace teams; operating-system and browser controls | Strong in Google’s endpoints, partial elsewhere | Limited as general enterprise EDR |
| Email and collaboration | Gmail and Workspace anti-phishing, malware protection, DLP, investigation and access controls | Workspace administrators; embedded software-as-a-service security | Google Workspace | Leading within the suite, not a broad standalone email platform |
| Application and supply chain | Software Delivery Shield, Artifact Analysis, Binary Authorization, Assured Open Source Software and Wiz code-to-cloud | Developers, platform engineering and application security; managed services and developer workflow | Wiz broadens multicloud reach; native tools center on Google Cloud | Credible and improving |
| AI model, app and agent security | Model Armor, Security Command Center AI Protection, Wiz AI security, Agent Identity and Agent Gateway | AI platform, identity and security teams; APIs, gateways and cloud controls | Model Armor and Wiz can protect multiple models and clouds; several agent integrations remain in preview | Emerging with structural potential |
| Consumer security | Safe Browsing, Play Protect, account protection, password manager, passkeys and anti-abuse systems | Consumers and ecosystem partners; embedded protections | Global Google user base | Leading reach, mostly not a standalone enterprise business |
Where Google has a structural advantage
Google’s strongest advantage is visibility before an enterprise knows it has a problem. It observes phishing, malicious domains, browser activity, Android applications, email campaigns and cloud abuse at internet scale. Mandiant sees later stages during incident response, while VirusTotal adds samples and community verdicts. Few vendors combine a wide internet telescope with a frontline response team.
Its second advantage is data architecture. Chronicle was designed to search very large security datasets; Gemini can make that fabric easier to query, summarize and automate. AI does not replace clean data, normalization or deterministic detections. It makes an already-connected set of entities and events more usable.
Google Cloud also exposes asset relationships, permissions, network flows and software provenance without a separate appliance; Workspace and Chrome enforce policy where users work; Wiz extends context across clouds. AI can connect those control points to Mandiant expertise and customer telemetry. The proven assets are strong. The less proven claim is that administration, packaging and response already feel like one platform.
Where the platform remains incomplete
Google does not own the dominant enterprise endpoint sensor. Chrome is important for web work but does not replace EDR across processes, memory and host behavior. Android and ChromeOS strengthen Google’s surfaces without solving heterogeneous Windows, macOS and Linux estates. Endpoint partnerships are therefore architectural: Google Security Operations needs another vendor’s sensor and often its enforcement.
Identity has the same boundary. Google Cloud IAM, phishing-resistant authentication and agent identity are strong, but Google is not the default workforce directory in most large enterprises. Privileged Access Manager reduces standing privilege inside Google Cloud; it does not govern all human, machine and secrets-based privilege.
Network security is strong at Google’s front door but lacks a large appliance base or the full stack of a mature security service edge. Data discovery, masking, Workspace and browser controls are capable but fragmented. Product names and boundaries have also changed repeatedly. Wiz closes a major technology gap while creating a large integration task.
AI as an operating layer, not a feature label
Google applies AI first as assistance—natural-language search, summaries, malware explanation, query generation and response recommendations—and second as specialized autonomy. The Triage and Investigation agent is generally available. Threat Hunting and Detection Engineering agents are in preview; agentic containment remains preview-stage; a Third-Party Context agent is announced for preview. Status matters because autonomous production changes require much stronger control and auditability than an assistant.
The third use is protecting AI. Model Armor screens prompts, responses and agent interactions; Security Command Center discovers AI assets in Google Cloud; Wiz maps models, services, data and code across clouds. Agent Identity gives an agent a distinct principal, while Agent Gateway governs agent-to-agent and agent-to-tool traffic. Some identity controls are generally available, but several gateway integrations remain in preview.
The same provider can supply model, compute, runtime, gateway, identity, data controls and monitoring. That can improve context and enforcement, but also lets one failure propagate. Model-agnostic interfaces, exportable telemetry and human approval for high-impact actions will determine whether customers see a differentiated control plane or excessive dependence.
Which markets Google is attacking
| Strategic mode | Markets | Mechanism | Boundary |
|---|---|---|---|
| Defend the cloud franchise | Cloud IAM, posture, workload defense, data protection, network security, software supply chain and AI workload security | Make Google Cloud safer by default and reduce the operational cost of moving sensitive workloads | Many controls lose reach outside Google Cloud |
| Expand by bundling and integration | Workspace security, browser DLP, zero-trust access, fraud defense and native application protection | Turn products customers already use into sensors and enforcement points | Value is highest inside Google’s productivity and infrastructure estate |
| Attack established vendors directly | CNAPP, SIEM, SOAR, threat intelligence, incident response and managed detection | Wiz, Google Security Operations and Mandiant compete across clouds and on-premises, supported by cloud procurement and AI | Requires proof of neutrality and displacement outside Google-centric accounts |
| Build an emerging control plane | AI application security, agent identity, agent gateways, autonomous detection and remediation | Join models, identities, tools and security telemetry at runtime | Several capabilities are still preview-stage and operating standards remain unsettled |
| Remain partner-dependent | Full EDR, enterprise-wide identity governance, broad PAM, branch and appliance security, complete SASE | Integrate third-party sensors and controls into Google Security Operations | Google participates in the workflow but does not own the primary control point |
Which incumbents are exposed
Exposure is not displacement. Distribution, specialist depth and ownership of sensors Google needs can remain strong defenses.
| Company | Google overlap | Exposure | Pressure and defense |
|---|---|---|---|
| Microsoft | Cloud security, SIEM, identity, email, browser and AI security | Medium | Google attacks through Wiz, SecOps and Chrome; Microsoft is defended by Windows, Entra, Microsoft 365 and integrated security distribution. |
| Palo Alto Networks | CNAPP, security operations, AI security and cloud network controls | High | Wiz and Google SecOps overlap with core growth platforms; broad network, endpoint and SASE control points plus a large installed base remain strong defenses. |
| CrowdStrike | Cloud security, threat intelligence, managed defense and security operations | Medium | Google can combine Wiz, Mandiant and SecOps, but CrowdStrike owns rich endpoint telemetry and is also an important Google integration partner. |
| SentinelOne | Cloud security, AI-assisted operations and XDR | High | Google’s data, bundling and agentic workflows pressure a smaller platform; SentinelOne’s endpoint sensor and independent cross-platform position defend it. |
| Splunk/Cisco | SIEM, SOAR, threat analytics and response | High | Google attacks data economics and analyst workflow directly; Splunk’s ecosystem, search familiarity and Cisco’s network reach are durable. |
| Fortinet | Cloud firewall, SASE telemetry and SecOps | Low | Google competes in cloud controls but lacks Fortinet’s appliances, branch distribution and integrated networking; partnership is likely to coexist with overlap. |
| Check Point Software | Cloud security, firewall and threat prevention | Medium | Wiz strengthens Google’s cloud offer, but Check Point retains network enforcement, customer relationships and an independent multicloud posture. |
| Zscaler | Zero-trust access, browser DLP and secure web access | Medium | Chrome can move policy into the browser and Google can bundle access, but it lacks Zscaler’s complete traffic-inspection and security-service-edge fabric. |
| Netskope | Browser, data protection, zero-trust access and cloud application control | Medium | Google pressures browser-centred use cases; Netskope is defended by independent data context and a broader security-service-edge architecture. |
| Okta | Workforce identity, federation and context-aware access | Low | Google can own identity in Workspace and Google Cloud, but Okta remains neutral across applications and enterprise technology stacks. |
| CyberArk | Privileged access, machine identity and agent identity | Low | Native Google Cloud controls can absorb narrow use cases; CyberArk’s enterprise-wide privilege governance and secrets footprint remain deeper. |
| Wiz | Google’s principal multicloud CNAPP and AI-security asset | Internalised | Wiz is now owned by Google, retains its brand and remains the vehicle through which Google attacks multicloud cloud security. |
| Orca Security | Agentless CNAPP, cloud graph and multicloud risk prioritization | High | Google can combine a close product substitute with cloud distribution, SecOps and Mandiant; Orca’s independence and product focus are its main defenses. |
| Tenable | Cloud exposure, vulnerability and external attack-surface management | Medium | Wiz and threat-informed prioritization expand into exposure management; Tenable retains scanner depth and a broad vulnerability-management estate. |
| Qualys | Cloud posture, vulnerability and asset risk | Medium | Google can bundle cloud context and automated remediation; Qualys remains defended by its installed scanning platform and compliance workflows. |
| Rapid7 | Vulnerability management, cloud security, SIEM and managed services | High | Google overlaps across several product lines and has greater data and distribution; Rapid7’s mid-market relationships and services provide resilience. |
| Cloudflare | WAF, DDoS, bot defense, zero-trust access and AI application protection | Medium | Google owns cloud and browser control points, but Cloudflare’s neutral global edge and developer distribution are structurally distinct. |
| Proofpoint | Workspace email protection, phishing intelligence and browser DLP | Low | Google can absorb more security inside Workspace; Proofpoint remains deeper across heterogeneous mail, human risk and information protection. |
| Mimecast | Email security and Workspace protection | Low | Bundling pressures Google-centric accounts, while independent continuity, archive and cross-platform email security remain defensible. |
| Datadog | Cloud telemetry, security analytics and application security | Low | Security data can consolidate into Google SecOps, but Datadog’s developer-led observability workflow is a different primary control point. |
| Dynatrace | Runtime context, cloud risk and operations analytics | Low | Google overlaps in cloud context and automation; deep application-performance and topology visibility remain the defense. |
| Elastic | Search-based SIEM, threat hunting and log analytics | Medium | Google competes directly on security analytics and AI assistance; Elastic remains open, deployable across environments and embedded with developers. |
The five most exposed are Orca Security, Splunk/Cisco, Palo Alto Networks, SentinelOne and Rapid7. Orca faces the clearest collision with Google-owned Wiz. Splunk faces a direct challenge to SIEM data and workflow. Palo Alto Networks overlaps in both cloud security and operations, although its breadth is defensive. SentinelOne is pressured as XDR expands into cloud and autonomy. Rapid7 now faces Google across several adjacent markets.
Competitors can also benefit: endpoint, network and identity vendors supply signals and response actions that Google lacks. Rich bidirectional integrations would support an open control plane; preferential packaging of Google’s products would indicate a more closed one.
Google versus Microsoft and Amazon Web Services
| Dimension | Microsoft | Amazon Web Services | |
|---|---|---|---|
| Core strategy | Join threat intelligence, security analytics, Mandiant, Wiz, AI and browser controls | Unify identity, endpoint, email, applications, cloud and SIEM through installed distribution | Embed security deeply in infrastructure and orchestrate a broad partner ecosystem |
| Identity | Strong Google Cloud and Workspace controls; weaker as the enterprise directory | Structural advantage through enterprise directory and access distribution | Strong cloud IAM; less central to workforce identity |
| Endpoint | Strong browser, Android and ChromeOS; limited general EDR | Structural Windows and endpoint-security advantage | Limited endpoint ownership |
| Security operations | Credible SIEM/SOAR with differentiated intelligence and data architecture | Broad SIEM/XDR integration with native identity and endpoint signals | Cloud detection and response improving, but less of an independent enterprise SIEM platform |
| Cloud-native security | Strong Google-native controls plus leading multicloud reach through Wiz | Broad native and multicloud platform | Deepest native relationship with its own infrastructure and a strong partner model |
| Threat intelligence and response | Distinctive combination of Google telemetry, VirusTotal and Mandiant | Large telemetry base and mature research integrated into products | Strong cloud intelligence and incident-response service, less differentiated outside its cloud |
| AI | Gemini, DeepMind research, agent security and model-agnostic runtime controls | AI embedded across a broad installed security suite | AI integrated into cloud security and operations with extensive model choice |
| Multicloud credibility | Improved materially by Wiz and Mandiant, but ownership tension remains | Broad support, tempered by Microsoft platform incentives | Partner-friendly but most native controls remain AWS-centred |
| Primary weakness | Endpoint and workforce-identity distribution; integration complexity | Neutrality and suite complexity | Limited ownership of enterprise-wide identity, endpoint and independent SecOps |
Microsoft’s model begins with distribution: identity, operating system, productivity and cloud generate signals and give it enforcement points. Amazon Web Services begins with infrastructure: native controls protect the account, workload and service, while partners fill much of the broader enterprise stack. Google begins with intelligence and data: it wants to understand the attacker, search the telemetry and now map cloud risk through Wiz, then connect that knowledge to Chrome, Workspace and Google Cloud controls. Each can bundle; the difference is what each owns before the security purchase begins.
The Mandiant question
Mandiant is simultaneously a product differentiator, enterprise entry point, cross-cloud asset and human feedback loop for AI: incident knowledge becomes detections, validation and training context. The conflict is that its advisers may need to assess Google Cloud or recommend a rival. Confidentiality, separation of duties, portable evidence and credible non-Google support must preserve independence. If Mandiant becomes cloud lead generation, trust erodes; if frontline knowledge improves products without distorting advice, the asset is unusually strategic.
The central industry debates
| Debate | Case for Google | Counterargument | Evidence that would resolve it |
|---|---|---|---|
| Can a hyperscaler be a trusted independent security platform? | Scale, secure infrastructure and broad telemetry improve defense. | The provider is judging environments it also wants to host. | Independent Mandiant recommendations, portable data and sustained wins in other clouds. |
| Will cloud security be bundled into consumption? | Native context and procurement make embedded controls efficient. | Enterprises still need one view across clouds and specialist depth. | Attach rates for native security versus independent multicloud platforms. |
| Can Google win in Microsoft-centric estates? | SecOps, Mandiant and Wiz can sit above infrastructure choices. | Microsoft already owns identity, endpoint and collaboration signals. | Large SIEM and CNAPP replacements where Google is not the primary workplace or cloud. |
| Does Google have enough endpoint and identity distribution? | Chrome is a major work surface and agents create a new identity layer. | Browser visibility is not EDR and Google is rarely the enterprise directory. | Expansion beyond browser policy and material adoption of cross-enterprise identity governance. |
| Can Google Security Operations disrupt SIEM? | Fast search, long data retention, integrated intelligence and agents change analyst economics. | Migrations are difficult and incumbents own workflows and content. | Referenceable replacements, lower operational cost and durable third-party ingestion at scale. |
| Will AI favour hyperscalers? | Compute, models, telemetry and research reinforce one another. | Security accuracy depends on proprietary customer context and specialist sensors. | Measured autonomous outcomes with low error rates, transparent reasoning and customer control. |
| Can Google integrate the assets? | A common data fabric and Gemini can connect separate products. | Acquired products, consoles and sales motions remain fragmented. | Shared policy, cases, entities and packaging without duplicated administration. |
| Will multicloud support remain credible? | Wiz and Mandiant are more valuable when neutral. | Google’s economic incentive is to move workloads to Google Cloud. | Feature parity, support quality and roadmap investment across competing clouds. |
| Will specialists retain an advantage? | Platform context and automation can remove tool boundaries. | Specialists focus more deeply and avoid cloud conflicts. | Whether integrated platforms deliver better results than specialist products in difficult environments. |
| Is security a standalone destination or cloud pull-through? | Cross-cloud products and Mandiant can win independently. | No separate cyber revenue is disclosed and bundling can mask demand. | Standalone customer references, transparent packaging and continued investment independent of Google Cloud migrations. |
What to watch
- Whether Wiz, Security Command Center and Google Security Operations share one asset and risk graph without forcing customers through duplicate consoles.
- Whether Google wins large multicloud CNAPP and SIEM deployments in enterprises that standardize on another hyperscaler.
- Whether Mandiant intelligence becomes continuously actionable across detections, cloud prioritization, validation and managed defense.
- Whether preview-stage hunting, detection-engineering and containment agents become generally available with auditability, measurable accuracy and human control.
- Whether Agent Identity and Agent Gateway become cross-platform standards or remain features of Google’s AI runtime.
- Whether Chrome Enterprise Premium expands toward a broader web-security control plane without sacrificing ecosystem partnerships.
- Whether Google builds or buys deeper enterprise identity, endpoint, data-security or SASE capabilities.
- Whether packaging makes security independently purchasable and portable, or increasingly inseparable from cloud consumption.
- Whether partners gain richer workflows or find Google’s owned products receiving preferential treatment.
- Whether customers describe security as a reason to choose Google Cloud rather than a benefit included after that decision.
Bottom line
Google is already a serious platform in threat intelligence, high-end incident response, security analytics and multicloud cloud security. Its strongest proposition is the loop among them: Wiz finds the exposed path, intelligence adds adversary context, Security Operations investigates and Mandiant validates or responds. Google Cloud, Workspace and Chrome provide native enforcement.
The broader claim remains unfinished. Google controls fewer enterprise endpoints and identities than Microsoft, has less network and SASE depth than specialists, and carries hyperscaler neutrality concerns. Wiz matters because it repairs a structural gap rather than adding another feature.
The market most likely to be reshaped is the junction of cloud security, security operations, threat intelligence and AI-agent governance. If Google preserves multicloud credibility and turns its assets into one usable control plane, it can influence security far beyond Google Cloud. If integration and neutrality fall short, the whole will remain less powerful than its parts.