Skip to content
Palo Alto: Security Debt Exposes Firms to AI-Powered Attacks

Palo Alto: Security Debt Exposes Firms to AI-Powered Attacks

Govinfosecurity • September 2, 2026

The $1 trillion in global cybersecurity debt is the weak link against artificial intelligence-enabled threats and could contribute to major breaches in the coming years, Palo Alto Networks CEO Nikesh Arora warned.

See Also: Identity Is the New Control Plane in the AI Era

The solution to fast-emerging threats is to modernize network infrastructure and make security operations more agentic, he told investors Tuesday.

"The only way to solve this problem the long term is if something escapes past your perimeter, you got to find it quickly and shut it down," Arora said. "That talks modernizing their cyber estate. That talks platformization. That talks having an AI-driven SOC. So that's why we've been able to have so many conversations around the modernization of infrastructure."

The strategic imperative is to transition toward unified, real-time defense, Arora said, by integrating software and hardware firewalls with Secure Access Service Edge and Software-Defined Wide Area Network 2015 (see: Palo Alto Networks Sees AI Boom Driving Firewall Demand ).

"For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of open-weight and open-source architectures," Arora said. Palo Alto has seen agentic traffic on its SASE platform increase ninefold over the past nine months.

The move gives organizations more control over their proprietary data and sovereignty over agents, where they use internal telemetry to fine-tune models for bespoke use cases, Arora said, but the "rapid fragmentation and proliferation" of specialized models also widens the attack surface.

"Each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platformized protection is expanding dramatically," Arora said.

Open-source models' capabilities are already on par with frontier models like Anthropic's Mythos, and Arora said he only sees these models get better over time.

"If that happens and this capability becomes commonplace, we have a short window by when to get all the cybersecurity technical debt, which hasn't been paid over many years, back up to the mark. And I suspect there will be some major breaches over the coming years because customers have not been able to get their transformation act in place," Arora said.

That is because modernization doesn't happen in a matter of months, he said. Organizations have many business priorities and ambitions, so they often wait for existing products to reach end of life or contracts to expire, modernizing more slowly than the speed of AI development.

"The customers always have a full deck. And today, with AI, there's a very large contingent of AI transformation that's out there. People want to transform customer support. They want to go do coding on an aggressive basis. They want to deploy LLM. So this is yet another priority that must be managed in the context of that overall priority," Arora said.

Eventually, that modernization should lead to agentic cybersecurity, he said. New products should learn from data Palo Alto has already ingested, reducing the need for customers to configure each product from scratch during integration.

The company's Cortex XDR software collects 19 terabytes of data every day across endpoints, networks, cloud environments, identity and access management and applications, Arora said. There will only be more data in the future to train enterprise products so they don't "start dumb" for the customer, he said.

"Five years from now, if we were far exceeding our expectations of ourselves, I would be able to walk in to a company and say, 'You want to replace X? Guess what? I have agents that can understand your deployment. My agents will replace that product. I can do that in under a week, and when I deploy my product, you'll need a lot less people. And our products will actually just look for validation from you and get the task done without having you to get into the nits and grits of how to configure things, what policies to write, because we've seen that across thousands of instances,'" Arora said.

Revenue, Earnings Beat Expectations, But Stock Slides

Palo Alto Networks' revenue of $3.41 billion in the quarter ended July 31 edged out Seeking Alpha's sales estimate of $3.35 billion. And the company's non-GAAP earnings of $1.02 per bested Seeking Alpha's non-GAAP estimate of $0.98 per .

The company's stock is down $6.89 - 1.9% - to $362.09 per in after-hours trading Tuesday. For the quarter ending Oct. 31, Palo Alto Network expects diluted non-GAAP net income of $0.96 to $0.98 per on revenue of between $3.3 billion and $3.31 billion. Analysts had been expecting non-GAAP earnings of $0.93 per on sales of $3.22 billion, according to Seeking Alpha.

Attack Surface Management

Executive Editor, Business, ISMG

Novinson is responsible for covering the vendor and technology landscape. Prior to joining ISMG, he spent four and a half years covering all the major cybersecurity vendors at CRN, with a focus on their programs and offerings for IT service providers. He was recognized for his breaking news coverage of the August 2019 coordinated ransomware attack against local governments in Texas as well as for his continued reporting around the SolarWinds hack in late 2020 and early 2021.

Cybersecurity reporter

Wang previously reported on cybersecurity for IANS. She received a master's in data journalism from Columbia University in August 2025. She attended Boston University.

Extracted Entities

Attack Types (1)

Campaigns (1)