Cybersecurity ETF searches spike on a predictable schedule: right after a major breach or ransomware headline. The instinct makes sense, because corporate spending on security really does keep climbing. The catch is that "buy a cybersecurity ETF" is not one decision. There are four main funds, they charge different fees, and they define the theme differently, from strict pure-play baskets to broader mixes that include defense contractors. Here is how they actually differ.
The Four Main Cybersecurity ETFs
All four give you a diversified slice of the cybersecurity industry in one ticker. Where they split is fee, number of holdings, and how strictly they stick to pure-play security companies versus broader names with cyber exposure.
| Ticker | Issuer | Fee | Holdings | Character |
|---|---|---|---|---|
| IHAK | iShares | 0.47% | ~50 | Cheapest, global basket |
| BUG | Global X | 0.50% | ~25 | Most concentrated, pure-play |
| CIBR | First Trust | 0.60% | ~36 | Largest by assets |
| HACK | ETFMG | 0.60% | ~60 | Oldest, broadest, includes defense |
CIBR is the heavyweight, with the most assets and the deepest liquidity, holding roughly three dozen cybersecurity names for 0.60%. HACK was one of the first funds in the space and casts the widest net at around 60 holdings, mixing pure-play vendors with defense contractors that have cyber businesses. BUG is the purist, the most concentrated of the four at about 25 holdings, all focused security companies. IHAK is the value option at 0.47%, holding a global basket of around 50 names for the lowest fee in the group. We put the two most-searched head to head in CIBR vs HACK.
The Catch Behind the Theme
A durable spending story does not automatically make a good fund, and cybersecurity ETFs carry three things worth naming before you buy.
They are volatile and headline-driven. These are concentrated technology-sector funds, and the stocks can spike or drop on breach news and sentiment regardless of the underlying earnings. Many holdings are high-growth companies that are not yet profitable, which amplifies the swings.
They cost more than broad tech. At 0.47% to 0.60%, a cybersecurity ETF charges several times what a broad technology fund like VGT does at 0.10%. The theme has to beat plain tech by enough to clear that fee difference over time, which is not guaranteed.
You may already own the biggest names. The large cybersecurity companies are already inside your S&P 500 or Nasdaq fund. Adding a cybersecurity ETF concentrates a bet you partly hold already, rather than adding something genuinely new.
Cybersecurity is one of the more defensible thematic stories: security budgets rarely get cut, breaches keep happening, and demand is structural. That does not make these funds a free win. They are volatile, they charge a real premium over broad tech, and their biggest holdings already sit in your core index funds. If you want a deliberate tilt toward the theme, IHAK is the cheapest way in and CIBR is the largest and most liquid. Size it as a small satellite, understand you are paying up for concentration, and do not mistake a strong narrative for a guaranteed return. For most investors, broad tech exposure through a total-market fund already captures most of the upside at a fraction of the cost.
Common Questions
What is a cybersecurity ETF?
A cybersecurity ETF is a fund that holds a basket of companies in the cybersecurity industry, from pure-play software vendors like firewall and identity providers to larger firms with big security divisions. Instead of picking a single stock, you own the theme in one ticker. The four main US-listed options are CIBR, HACK, BUG, and IHAK. They all track cybersecurity but differ in how many companies they hold, how pure-play they are, and what they charge, which ranges from 0.47% to 0.60%.
Which cybersecurity ETF has the lowest fee?
Among the four main cybersecurity ETFs, iShares' IHAK is the cheapest at 0.47%. Global X's BUG charges 0.50%, and both First Trust's CIBR and ETFMG's HACK charge 0.60%. Because all four target the same theme, the fee is a real point of difference, though the funds hold different numbers of companies and weight them differently, so they are not identical baskets. Cost is one factor alongside how broad or concentrated you want the exposure.
What is the difference between CIBR, HACK, BUG, and IHAK?
CIBR (First Trust, 0.60%) is the largest by assets and holds roughly three dozen names. HACK (ETFMG, 0.60%) was one of the first cybersecurity ETFs and is the broadest, mixing pure-play vendors with defense contractors that have cyber exposure, at around 60 holdings. BUG (Global X, 0.50%) is the most concentrated, focusing on pure-play cybersecurity companies. IHAK (iShares, 0.47%) is the cheapest and holds a global basket of around 50 names. The main tradeoffs are fee, breadth, and how strictly pure-play the fund is.
Are cybersecurity ETFs a good investment?
That depends on your goals and risk tolerance, and this is educational information, not personalized advice. Cybersecurity is a durable spending theme because corporate security budgets rarely shrink, but these are concentrated, high-volatility sector funds that can swing on breach headlines regardless of earnings, and many holdings are unprofitable growth companies. They also charge 0.47% to 0.60%, well above a broad tech fund, and you likely already own the largest cybersecurity names through a total-market or Nasdaq fund. Most educators treat a theme like this as a small satellite position, not a core holding.