decryptingtech

Technology. Business models. Market debates.

Browse this section

Alphabet (Cybersecurity)

Technology / Cybersecurity / Company deep dive

This report focuses on Alphabet’s cybersecurity business. For the wider business and AI strategy, read the Alphabet company profile ↗.

Google is becoming a major cybersecurity platform by joining assets built for different purposes: hyperscale infrastructure, signals from Search, Gmail, Android and Chrome, cloud-native controls, VirusTotal’s malware ecosystem, Mandiant’s frontline expertise, Wiz’s multicloud graph and Gemini. The question is no longer whether Google has enough security products. It is whether these assets can become one operating system for defense.

Google is both a cloud provider with embedded security and an increasingly independent security platform. Security Command Center, Cloud Armor and native identity controls primarily defend Google Cloud. Google Security Operations, Google Threat Intelligence, Mandiant, VirusTotal, Chrome Enterprise Premium and Wiz can reach across other clouds, on-premises systems and third-party products. That second group turns security from a cloud feature into a possible enterprise platform.

The model contains conflicts: Google can investigate an incident in another hyperscaler’s cloud while wanting more Google Cloud consumption, and can partner with endpoint vendors while competing with them elsewhere. Alphabet does not disclose cybersecurity revenue separately, so the business must be judged by architecture, deployment reach and control points rather than an invented revenue estimate.

How the strategy evolved

Google’s security business began as an internal necessity. The Operation Aurora intrusion disclosed in 2010 became the turning point: Google stopped treating the corporate network as trusted and rebuilt access around verified identity, device state and application-level policy. That program became BeyondCorp and helped turn zero trust into an operating model.

Google then externalized parts of that defense. VirusTotal added malware data and community; Chronicle applied Google’s data architecture to security telemetry; BeyondCorp Enterprise commercialized identity-aware access; Siemplify added orchestration and cases. Mandiant contributed what infrastructure could not quickly create: investigators who see attackers inside compromised enterprises, managed defense and trusted access to security leaders.

The current phase is convergence. Google Security Operations joins SIEM, SOAR and intelligence; Google Unified Security connects operations, cloud risk, browser signals and Mandiant; Wiz adds a multicloud graph from code to runtime. Gemini and specialized agents sit above that fabric, moving the system from reporting risk toward reasoning and controlled action.

PeriodMilestoneWhy it changed Google’s position
2010–2014Operation Aurora response and the first public BeyondCorp workEstablished identity- and context-based access instead of implicit trust in a corporate network.
2012VirusTotal acquisitionAdded a large malware and URL analysis corpus plus an unusually broad contributor community.
2018–2019Chronicle launched from Alphabet’s X and then joined Google CloudApplied Google-scale data architecture to enterprise security analytics and made security operations a cloud business.
2021BeyondCorp Enterprise became generally availableCommercialized Google’s zero-trust design through Chrome, its network and identity-aware access.
2022Siemplify and Mandiant joined Google Cloud; Chronicle Security Operations took shapeAdded SOAR, case management, incident response, managed services and frontline threat intelligence.
2024Security Command Center Enterprise, Google Threat Intelligence and Chrome Enterprise Premium launchedExpanded multicloud risk management, unified intelligence and made the browser a paid enterprise enforcement point.
2025Google Unified Security became generally availableCreated a common strategic layer across security operations, threat intelligence, cloud risk, browser signals and Mandiant.
2026Wiz acquisition completed; security and identity agents expandedMade Google a top-tier multicloud CNAPP contender and extended the design toward autonomous detection, investigation and agent governance.
2026 onwardBeyond Zero architecture disclosedSignals a move from continuous verification of users and devices toward finer, real-time control of human and machine actions; it is an architectural direction, not yet a single commercial product.
How the strategy evolved

The architecture: three security loops

Google’s portfolio forms three loops: prevention secures identities, cloud configuration, software, data, browsers and edges; detection enriches telemetry with adversary knowledge; response investigates, contains and learns. The platform is strongest when evidence moves among them: Wiz or Security Command Center finds a risky path, Google Threat Intelligence adds adversary context, Google Security Operations investigates and Mandiant validates or responds.

The loop is not closed: outside its estate, Google often depends on third-party endpoint, firewall and identity products for sensors and enforcement. Openness suits heterogeneous enterprises, but also shows which control points Google does not own.

DomainGoogle capabilityBuyer and deliveryReachPosition
Cloud posture and CNAPPWiz; Security Command Center Enterprise and PremiumCloud security teams; software-as-a-service and cloud-native controlsWiz is multicloud; Security Command Center Enterprise covers major clouds while Premium is deepest on Google CloudLeading after Wiz, with integration still in progress
Cloud workload protectionWiz Defend, Security Command Center threat detection and native workload controlsCloud and security operations teams; agentless context plus native runtime signalsMulticloud through Wiz; strongest native visibility on Google CloudCredible to leading
SIEMGoogle Security OperationsSecurity operations centers; cloud-native analytics serviceCloud, on-premises and third-party telemetryCredible challenger
SOARGoogle Security Operations, built partly on SiemplifySecurity operations centers; playbooks, cases and integrationsCross-environmentCredible
XDRGoogle Security Operations plus partner telemetry, threat intelligence and automated workflowsSecurity operations leaders; integration layerBroad, but relies on partners for key sensorsEmerging rather than full native XDR
Threat intelligenceGoogle Threat Intelligence, Mandiant and VirusTotalThreat-intelligence and operations teams; subscription, API and embedded intelligenceGlobal and cross-platformLeading
Incident response and MDRMandiant Incident Response, Managed Defense and Threat DefenseChief information-security officers and operations teams; expert-led serviceCross-cloud, hybrid and third-party estatesLeading in high-end response; credible in managed defense
Identity and accessGoogle Cloud IAM, Cloud Identity, Workforce Identity Federation, Identity-Aware Proxy and Context-Aware AccessCloud and workplace administrators; native servicesStrong on Google Cloud and Workspace; federates with external identity systemsLeading in Google Cloud, limited as the enterprise-wide identity standard
Zero-trust accessChrome Enterprise Premium and Identity-Aware Proxy, evolved from BeyondCorp EnterpriseWorkplace, identity and security teams; browser and cloud-delivered accessCan protect web and private applications across clouds and on-premisesCredible, browser-centric
Privileged accessGoogle Cloud Privileged Access Manager and just-in-time elevationGoogle Cloud administrators; native cloud servicePrimarily Google CloudCredible native feature, limited enterprise PAM platform
Data security and DLPSensitive Data Protection, Workspace DLP, Chrome DLP, encryption and Wiz data-security postureData, privacy, cloud and workplace teams; API and embedded controlsSome cross-cloud discovery through Wiz and the DLP API; deepest on Google servicesCredible but fragmented
Network, WAF and DDoSCloud NGFW, Cloud Armor, Cloud IDS, load-balancing protections and reCAPTCHA within Google Cloud Fraud DefenseCloud networking and application teams; infrastructure-native servicesPrimarily Google Cloud front doors, with selected hybrid useLeading for Google-hosted applications; limited as an independent network platform
Secure browser and web accessChrome Enterprise Premium, Safe Browsing and context-aware controlsWorkplace and security teams; managed browserCross-operating-system and application accessLeading browser control; limited full security service edge
EndpointChromeOS, Android Enterprise, Play Protect, Endpoint Verification and Chrome telemetryDevice and workplace teams; operating-system and browser controlsStrong in Google’s endpoints, partial elsewhereLimited as general enterprise EDR
Email and collaborationGmail and Workspace anti-phishing, malware protection, DLP, investigation and access controlsWorkspace administrators; embedded software-as-a-service securityGoogle WorkspaceLeading within the suite, not a broad standalone email platform
Application and supply chainSoftware Delivery Shield, Artifact Analysis, Binary Authorization, Assured Open Source Software and Wiz code-to-cloudDevelopers, platform engineering and application security; managed services and developer workflowWiz broadens multicloud reach; native tools center on Google CloudCredible and improving
AI model, app and agent securityModel Armor, Security Command Center AI Protection, Wiz AI security, Agent Identity and Agent GatewayAI platform, identity and security teams; APIs, gateways and cloud controlsModel Armor and Wiz can protect multiple models and clouds; several agent integrations remain in previewEmerging with structural potential
Consumer securitySafe Browsing, Play Protect, account protection, password manager, passkeys and anti-abuse systemsConsumers and ecosystem partners; embedded protectionsGlobal Google user baseLeading reach, mostly not a standalone enterprise business
The architecture: three security loops

Where Google has a structural advantage

Google’s strongest advantage is visibility before an enterprise knows it has a problem. It observes phishing, malicious domains, browser activity, Android applications, email campaigns and cloud abuse at internet scale. Mandiant sees later stages during incident response, while VirusTotal adds samples and community verdicts. Few vendors combine a wide internet telescope with a frontline response team.

Its second advantage is data architecture. Chronicle was designed to search very large security datasets; Gemini can make that fabric easier to query, summarize and automate. AI does not replace clean data, normalization or deterministic detections. It makes an already-connected set of entities and events more usable.

Google Cloud also exposes asset relationships, permissions, network flows and software provenance without a separate appliance; Workspace and Chrome enforce policy where users work; Wiz extends context across clouds. AI can connect those control points to Mandiant expertise and customer telemetry. The proven assets are strong. The less proven claim is that administration, packaging and response already feel like one platform.

Where the platform remains incomplete

Google does not own the dominant enterprise endpoint sensor. Chrome is important for web work but does not replace EDR across processes, memory and host behavior. Android and ChromeOS strengthen Google’s surfaces without solving heterogeneous Windows, macOS and Linux estates. Endpoint partnerships are therefore architectural: Google Security Operations needs another vendor’s sensor and often its enforcement.

Identity has the same boundary. Google Cloud IAM, phishing-resistant authentication and agent identity are strong, but Google is not the default workforce directory in most large enterprises. Privileged Access Manager reduces standing privilege inside Google Cloud; it does not govern all human, machine and secrets-based privilege.

Network security is strong at Google’s front door but lacks a large appliance base or the full stack of a mature security service edge. Data discovery, masking, Workspace and browser controls are capable but fragmented. Product names and boundaries have also changed repeatedly. Wiz closes a major technology gap while creating a large integration task.

AI as an operating layer, not a feature label

Google applies AI first as assistance—natural-language search, summaries, malware explanation, query generation and response recommendations—and second as specialized autonomy. The Triage and Investigation agent is generally available. Threat Hunting and Detection Engineering agents are in preview; agentic containment remains preview-stage; a Third-Party Context agent is announced for preview. Status matters because autonomous production changes require much stronger control and auditability than an assistant.

The third use is protecting AI. Model Armor screens prompts, responses and agent interactions; Security Command Center discovers AI assets in Google Cloud; Wiz maps models, services, data and code across clouds. Agent Identity gives an agent a distinct principal, while Agent Gateway governs agent-to-agent and agent-to-tool traffic. Some identity controls are generally available, but several gateway integrations remain in preview.

The same provider can supply model, compute, runtime, gateway, identity, data controls and monitoring. That can improve context and enforcement, but also lets one failure propagate. Model-agnostic interfaces, exportable telemetry and human approval for high-impact actions will determine whether customers see a differentiated control plane or excessive dependence.

Which markets Google is attacking

Strategic modeMarketsMechanismBoundary
Defend the cloud franchiseCloud IAM, posture, workload defense, data protection, network security, software supply chain and AI workload securityMake Google Cloud safer by default and reduce the operational cost of moving sensitive workloadsMany controls lose reach outside Google Cloud
Expand by bundling and integrationWorkspace security, browser DLP, zero-trust access, fraud defense and native application protectionTurn products customers already use into sensors and enforcement pointsValue is highest inside Google’s productivity and infrastructure estate
Attack established vendors directlyCNAPP, SIEM, SOAR, threat intelligence, incident response and managed detectionWiz, Google Security Operations and Mandiant compete across clouds and on-premises, supported by cloud procurement and AIRequires proof of neutrality and displacement outside Google-centric accounts
Build an emerging control planeAI application security, agent identity, agent gateways, autonomous detection and remediationJoin models, identities, tools and security telemetry at runtimeSeveral capabilities are still preview-stage and operating standards remain unsettled
Remain partner-dependentFull EDR, enterprise-wide identity governance, broad PAM, branch and appliance security, complete SASEIntegrate third-party sensors and controls into Google Security OperationsGoogle participates in the workflow but does not own the primary control point
Which markets Google is attacking

Which incumbents are exposed

Exposure is not displacement. Distribution, specialist depth and ownership of sensors Google needs can remain strong defenses.

CompanyGoogle overlapExposurePressure and defense
MicrosoftCloud security, SIEM, identity, email, browser and AI securityMediumGoogle attacks through Wiz, SecOps and Chrome; Microsoft is defended by Windows, Entra, Microsoft 365 and integrated security distribution.
Palo Alto NetworksCNAPP, security operations, AI security and cloud network controlsHighWiz and Google SecOps overlap with core growth platforms; broad network, endpoint and SASE control points plus a large installed base remain strong defenses.
CrowdStrikeCloud security, threat intelligence, managed defense and security operationsMediumGoogle can combine Wiz, Mandiant and SecOps, but CrowdStrike owns rich endpoint telemetry and is also an important Google integration partner.
SentinelOneCloud security, AI-assisted operations and XDRHighGoogle’s data, bundling and agentic workflows pressure a smaller platform; SentinelOne’s endpoint sensor and independent cross-platform position defend it.
Splunk/CiscoSIEM, SOAR, threat analytics and responseHighGoogle attacks data economics and analyst workflow directly; Splunk’s ecosystem, search familiarity and Cisco’s network reach are durable.
FortinetCloud firewall, SASE telemetry and SecOpsLowGoogle competes in cloud controls but lacks Fortinet’s appliances, branch distribution and integrated networking; partnership is likely to coexist with overlap.
Check Point SoftwareCloud security, firewall and threat preventionMediumWiz strengthens Google’s cloud offer, but Check Point retains network enforcement, customer relationships and an independent multicloud posture.
ZscalerZero-trust access, browser DLP and secure web accessMediumChrome can move policy into the browser and Google can bundle access, but it lacks Zscaler’s complete traffic-inspection and security-service-edge fabric.
NetskopeBrowser, data protection, zero-trust access and cloud application controlMediumGoogle pressures browser-centred use cases; Netskope is defended by independent data context and a broader security-service-edge architecture.
OktaWorkforce identity, federation and context-aware accessLowGoogle can own identity in Workspace and Google Cloud, but Okta remains neutral across applications and enterprise technology stacks.
CyberArkPrivileged access, machine identity and agent identityLowNative Google Cloud controls can absorb narrow use cases; CyberArk’s enterprise-wide privilege governance and secrets footprint remain deeper.
WizGoogle’s principal multicloud CNAPP and AI-security assetInternalisedWiz is now owned by Google, retains its brand and remains the vehicle through which Google attacks multicloud cloud security.
Orca SecurityAgentless CNAPP, cloud graph and multicloud risk prioritizationHighGoogle can combine a close product substitute with cloud distribution, SecOps and Mandiant; Orca’s independence and product focus are its main defenses.
TenableCloud exposure, vulnerability and external attack-surface managementMediumWiz and threat-informed prioritization expand into exposure management; Tenable retains scanner depth and a broad vulnerability-management estate.
QualysCloud posture, vulnerability and asset riskMediumGoogle can bundle cloud context and automated remediation; Qualys remains defended by its installed scanning platform and compliance workflows.
Rapid7Vulnerability management, cloud security, SIEM and managed servicesHighGoogle overlaps across several product lines and has greater data and distribution; Rapid7’s mid-market relationships and services provide resilience.
CloudflareWAF, DDoS, bot defense, zero-trust access and AI application protectionMediumGoogle owns cloud and browser control points, but Cloudflare’s neutral global edge and developer distribution are structurally distinct.
ProofpointWorkspace email protection, phishing intelligence and browser DLPLowGoogle can absorb more security inside Workspace; Proofpoint remains deeper across heterogeneous mail, human risk and information protection.
MimecastEmail security and Workspace protectionLowBundling pressures Google-centric accounts, while independent continuity, archive and cross-platform email security remain defensible.
DatadogCloud telemetry, security analytics and application securityLowSecurity data can consolidate into Google SecOps, but Datadog’s developer-led observability workflow is a different primary control point.
DynatraceRuntime context, cloud risk and operations analyticsLowGoogle overlaps in cloud context and automation; deep application-performance and topology visibility remain the defense.
ElasticSearch-based SIEM, threat hunting and log analyticsMediumGoogle competes directly on security analytics and AI assistance; Elastic remains open, deployable across environments and embedded with developers.
Which incumbents are exposed

The five most exposed are Orca Security, Splunk/Cisco, Palo Alto Networks, SentinelOne and Rapid7. Orca faces the clearest collision with Google-owned Wiz. Splunk faces a direct challenge to SIEM data and workflow. Palo Alto Networks overlaps in both cloud security and operations, although its breadth is defensive. SentinelOne is pressured as XDR expands into cloud and autonomy. Rapid7 now faces Google across several adjacent markets.

Competitors can also benefit: endpoint, network and identity vendors supply signals and response actions that Google lacks. Rich bidirectional integrations would support an open control plane; preferential packaging of Google’s products would indicate a more closed one.

Google versus Microsoft and Amazon Web Services

DimensionGoogleMicrosoftAmazon Web Services
Core strategyJoin threat intelligence, security analytics, Mandiant, Wiz, AI and browser controlsUnify identity, endpoint, email, applications, cloud and SIEM through installed distributionEmbed security deeply in infrastructure and orchestrate a broad partner ecosystem
IdentityStrong Google Cloud and Workspace controls; weaker as the enterprise directoryStructural advantage through enterprise directory and access distributionStrong cloud IAM; less central to workforce identity
EndpointStrong browser, Android and ChromeOS; limited general EDRStructural Windows and endpoint-security advantageLimited endpoint ownership
Security operationsCredible SIEM/SOAR with differentiated intelligence and data architectureBroad SIEM/XDR integration with native identity and endpoint signalsCloud detection and response improving, but less of an independent enterprise SIEM platform
Cloud-native securityStrong Google-native controls plus leading multicloud reach through WizBroad native and multicloud platformDeepest native relationship with its own infrastructure and a strong partner model
Threat intelligence and responseDistinctive combination of Google telemetry, VirusTotal and MandiantLarge telemetry base and mature research integrated into productsStrong cloud intelligence and incident-response service, less differentiated outside its cloud
AIGemini, DeepMind research, agent security and model-agnostic runtime controlsAI embedded across a broad installed security suiteAI integrated into cloud security and operations with extensive model choice
Multicloud credibilityImproved materially by Wiz and Mandiant, but ownership tension remainsBroad support, tempered by Microsoft platform incentivesPartner-friendly but most native controls remain AWS-centred
Primary weaknessEndpoint and workforce-identity distribution; integration complexityNeutrality and suite complexityLimited ownership of enterprise-wide identity, endpoint and independent SecOps
Google versus Microsoft and Amazon Web Services

Microsoft’s model begins with distribution: identity, operating system, productivity and cloud generate signals and give it enforcement points. Amazon Web Services begins with infrastructure: native controls protect the account, workload and service, while partners fill much of the broader enterprise stack. Google begins with intelligence and data: it wants to understand the attacker, search the telemetry and now map cloud risk through Wiz, then connect that knowledge to Chrome, Workspace and Google Cloud controls. Each can bundle; the difference is what each owns before the security purchase begins.

The Mandiant question

Mandiant is simultaneously a product differentiator, enterprise entry point, cross-cloud asset and human feedback loop for AI: incident knowledge becomes detections, validation and training context. The conflict is that its advisers may need to assess Google Cloud or recommend a rival. Confidentiality, separation of duties, portable evidence and credible non-Google support must preserve independence. If Mandiant becomes cloud lead generation, trust erodes; if frontline knowledge improves products without distorting advice, the asset is unusually strategic.

The central industry debates

DebateCase for GoogleCounterargumentEvidence that would resolve it
Can a hyperscaler be a trusted independent security platform?Scale, secure infrastructure and broad telemetry improve defense.The provider is judging environments it also wants to host.Independent Mandiant recommendations, portable data and sustained wins in other clouds.
Will cloud security be bundled into consumption?Native context and procurement make embedded controls efficient.Enterprises still need one view across clouds and specialist depth.Attach rates for native security versus independent multicloud platforms.
Can Google win in Microsoft-centric estates?SecOps, Mandiant and Wiz can sit above infrastructure choices.Microsoft already owns identity, endpoint and collaboration signals.Large SIEM and CNAPP replacements where Google is not the primary workplace or cloud.
Does Google have enough endpoint and identity distribution?Chrome is a major work surface and agents create a new identity layer.Browser visibility is not EDR and Google is rarely the enterprise directory.Expansion beyond browser policy and material adoption of cross-enterprise identity governance.
Can Google Security Operations disrupt SIEM?Fast search, long data retention, integrated intelligence and agents change analyst economics.Migrations are difficult and incumbents own workflows and content.Referenceable replacements, lower operational cost and durable third-party ingestion at scale.
Will AI favour hyperscalers?Compute, models, telemetry and research reinforce one another.Security accuracy depends on proprietary customer context and specialist sensors.Measured autonomous outcomes with low error rates, transparent reasoning and customer control.
Can Google integrate the assets?A common data fabric and Gemini can connect separate products.Acquired products, consoles and sales motions remain fragmented.Shared policy, cases, entities and packaging without duplicated administration.
Will multicloud support remain credible?Wiz and Mandiant are more valuable when neutral.Google’s economic incentive is to move workloads to Google Cloud.Feature parity, support quality and roadmap investment across competing clouds.
Will specialists retain an advantage?Platform context and automation can remove tool boundaries.Specialists focus more deeply and avoid cloud conflicts.Whether integrated platforms deliver better results than specialist products in difficult environments.
Is security a standalone destination or cloud pull-through?Cross-cloud products and Mandiant can win independently.No separate cyber revenue is disclosed and bundling can mask demand.Standalone customer references, transparent packaging and continued investment independent of Google Cloud migrations.
The central industry debates

What to watch

  • Whether Wiz, Security Command Center and Google Security Operations share one asset and risk graph without forcing customers through duplicate consoles.
  • Whether Google wins large multicloud CNAPP and SIEM deployments in enterprises that standardize on another hyperscaler.
  • Whether Mandiant intelligence becomes continuously actionable across detections, cloud prioritization, validation and managed defense.
  • Whether preview-stage hunting, detection-engineering and containment agents become generally available with auditability, measurable accuracy and human control.
  • Whether Agent Identity and Agent Gateway become cross-platform standards or remain features of Google’s AI runtime.
  • Whether Chrome Enterprise Premium expands toward a broader web-security control plane without sacrificing ecosystem partnerships.
  • Whether Google builds or buys deeper enterprise identity, endpoint, data-security or SASE capabilities.
  • Whether packaging makes security independently purchasable and portable, or increasingly inseparable from cloud consumption.
  • Whether partners gain richer workflows or find Google’s owned products receiving preferential treatment.
  • Whether customers describe security as a reason to choose Google Cloud rather than a benefit included after that decision.

Bottom line

Google is already a serious platform in threat intelligence, high-end incident response, security analytics and multicloud cloud security. Its strongest proposition is the loop among them: Wiz finds the exposed path, intelligence adds adversary context, Security Operations investigates and Mandiant validates or responds. Google Cloud, Workspace and Chrome provide native enforcement.

The broader claim remains unfinished. Google controls fewer enterprise endpoints and identities than Microsoft, has less network and SASE depth than specialists, and carries hyperscaler neutrality concerns. Wiz matters because it repairs a structural gap rather than adding another feature.

The market most likely to be reshaped is the junction of cloud security, security operations, threat intelligence and AI-agent governance. If Google preserves multicloud credibility and turns its assets into one usable control plane, it can influence security far beyond Google Cloud. If integration and neutrality fall short, the whole will remain less powerful than its parts.