
Palo Alto Networks (NASDAQ:PANW) Chairman and CEO Nikesh Arora said artificial intelligence is increasing corporate focus on cybersecurity vulnerabilities while also creating new demands for security tools, data integration and network inspection.
Speaking at a company news event, Arora said the release of AI models capable of identifying software vulnerabilities has prompted more conversations with corporate leaders. He said Palo Alto Networks has spoken with roughly 2,000 companies through discussions involving CEOs, CIOs and chief security officers about the implications of AI-driven threats.
AI Vulnerability Testing Drives Customer Discussions
“What would take us weeks or months or things we would not care to go look for, AI can do it pretty quickly,” Arora said.
He said Palo Alto Networks offers customers testing services using multiple AI models. According to Arora, about 60% of vulnerabilities identified in the company’s testing came through Mythos, about 30% through OpenAI models and the remainder through other models. He said the results support using a multi-model approach because different models can identify different vulnerabilities.
Those assessments often lead to broader discussions about consolidating security products, improving response times and deploying security information and event management, or SIEM, capabilities, Arora said.
Platform Integration and Data Context
Arora argued that enterprises using dozens of security vendors can face challenges correlating data across endpoints, email systems, firewalls, cloud environments and other enforcement points. He said companies need consistent data layers that can connect activity across their technology stacks and identify threats as they move between systems.
For example, he said an employee could click a phishing link in an email, visit a malicious website and then create activity visible to a corporate firewall. Individual security products may generate alerts, but separate vendors may lack the context needed to connect those events, he said.
Arora said AI agents could help address threats “in flight,” but such deployments become more complicated when agents from multiple security suppliers need to communicate with one another. He said this dynamic favors incumbent providers with integrated platform offerings and may lead customers to reduce the number of cybersecurity vendors they use over time.
He characterized security operations center transformations as generally shorter-term projects, potentially involving six-month customer engagements, while network-security consolidation tends to occur over time as existing vendor contracts come up for renewal.
Frontier Models May Assist Rather Than Replace Security Products
Arora said large language models can be valuable for tasks involving reasoning, analysis and vulnerability detection. However, he said they need domain context to avoid false positives and are not yet positioned to replace security enforcement products at endpoints or other parts of the network.
He cited the economics of applying frontier models to endpoint data as a constraint. With endpoint security products priced at roughly $30 to $40 per endpoint annually, he said using a frontier model to inspect the daily data processed by a laptop could exceed that cost.
- Smaller language models may be used for specific tasks on devices with limited computing footprints, Arora said.
- Multiple models may be useful in vulnerability management because their findings can differ.
- Frontier models may increasingly supply capabilities that make cybersecurity products faster and more effective, he said.
Arora said Palo Alto Networks could become a consumer of frontier-model tokens and cloud resources to improve its products, noting that the company spends more than $1 billion on cloud services.
Traffic Growth and AI Security Opportunity
Arora said rising AI-related computing investment should increase network traffic and, in turn, the need for traffic inspection through SASE, software firewalls and hardware firewalls. He said much of the current gap involves AI and coding traffic that is not yet fully secured.
He said the broader market for AI security is still being developed because AI architectures and products continue to change rapidly. Palo Alto Networks reported $100 million in Prisma AIRS revenue, which Arora described as real-time AI security that can inspect traffic for issues such as prompt injection and model manipulation.
Still, he said no vendor has a complete AI-security stack today. Security providers need access to technical hooks and application programming interfaces from AI-product developers before they can build inline protections for certain products, he said.
Arora said Palo Alto Networks is seeking to maintain its competitive position through product development, acquisitions and its installed base. He said the company has acquired 47 companies and now conducts 70 product deployments annually, compared with its prior focus on hardware firewalls.
He added that Palo Alto Networks operates across 27 product categories and is positioned in the upper-right quadrant of more than 20 Gartner Magic Quadrants. Arora said scale can provide an advantage by allowing the company to fund development projects and pursue efficiency gains, including through AI.
About Palo Alto Networks (NASDAQ:PANW)
Palo Alto Networks, Inc is a cybersecurity company that provides security products and services to businesses, governments and other organizations worldwide. The company helps customers protect networks, cloud environments, endpoints, applications and connected devices from cyber threats.
Its portfolio includes next-generation firewalls and network security technologies, as well as cloud-delivered security solutions such as Prisma Access and Prisma Cloud. Palo Alto Networks also offers Cortex products for endpoint protection, security operations, threat detection and response, and automation.
