Nikesh Arora.

Palo Alto CEO says CyberArk is in a “pole position” as AI agents take over

Speaking during Palo Alto Networks’ fourth-quarter earnings call, Nikesh Arora says the acquisition is about far more than cost savings, arguing that non-human identities and autonomous agents represent a new frontier for cybersecurity. 

Palo Alto Networks CEO Nikesh Arora believes the cybersecurity industry is approaching a point where humans will no longer be able to keep up with the speed of the threats they are being asked to defend against. His answer is not to add more analysts or more security products, but to build systems that can increasingly detect, decide and respond on their own.
Speaking during Palo Alto Networks’ fourth-quarter earnings call, Arora described AI as a long-term tailwind for cybersecurity, but also outlined a more fundamental transformation in how security will have to work. As companies move from experimenting with large language models to deploying autonomous agents and specialized open-source models, he argued, the security infrastructure surrounding them will have to become increasingly unified and automated.
“Cybersecurity has to become less manual and more agentic and more done by us than the customers themselves,” Arora said.
1 View gallery
ניקש ארורה מנכ"ל פאלו אלטו
ניקש ארורה מנכ"ל פאלו אלטו
Nikesh Arora.
(Photo: Molly Goldberg)
His comments came as Palo Alto reported fourth-quarter revenue of $3.41 billion and forecast fiscal 2027 revenue of $14.1 billion to $14.2 billion. The company also announced the acquisition of Console, an AI-native platform that Arora said will allow customers to build agentic workflows in natural language that can automatically identify and remediate problems.
But the acquisition was only one part of a broader argument Arora made about the direction of the industry.
Arora said Palo Alto has watched the AI market move through three major shifts in just seven months: from conventional large language models to autonomous agents and, most recently, to open-weight and open-source models.
Each shift changes the security problem.
Autonomous agents, unlike conventional chatbots, can operate for extended periods without direct supervision. They interact with internal databases, other software and other agents, creating what Arora described as a new layer of machine identities and autonomous permissions.
At the same time, the growing sophistication of AI models means that attackers can discover vulnerabilities far faster than humans traditionally could.
That has changed the conversation with Palo Alto’s customers, Arora said. The companies he speaks to are no longer primarily asking whether AI can find vulnerabilities. They want to know what to do once those vulnerabilities are discovered.
“Customers are quickly disenchanted from this notion of finding more vulnerabilities,” Arora said. “They want to know what do I do about them. The last thing they want is more security problems.”
That distinction is central to his argument. In an AI-driven attack environment, simply detecting a vulnerability is no longer enough. The defensive system needs to understand the context, determine what matters and respond quickly enough to prevent exploitation.
Arora said Palo Alto has built capabilities that can identify certain open-source and operational-technology vulnerabilities and deploy signatures to its firewalls in less than four hours. He contrasted that with what he described as an industry standard of roughly 55 days for patching such vulnerabilities.
The implication is stark: the traditional cycle of finding a vulnerability, assigning it to a security team and waiting for a human to investigate and patch it may become fundamentally inadequate.
Arora also offered a less reassuring prediction about the transition.
Palo Alto estimates that enterprises face roughly $1 trillion in cybersecurity technical debt that must be modernized. As AI becomes capable of discovering and exploiting old vulnerabilities in minutes, companies that have postponed that modernization will become increasingly exposed.
“If this capability becomes commonplace, we have a short window by when to get all the cybersecurity technical debt which hasn’t been paid over the many years back up to the mark,” Arora said.
“I suspect there will be some major breaches over the coming years because customers have not been able to get the transformation act in place.”
That expectation is part of why Arora sees the current moment as more than a temporary boost to cybersecurity spending. He described it as a change in the industry's trajectory.
He also said the threat is likely to become more difficult as open-source models improve. Enterprises are increasingly deploying specialized models trained on proprietary data, while the market becomes more fragmented rather than concentrating around a small number of frontier AI systems.
For security companies, that means more systems to protect, more data to monitor and more machine-to-machine interactions to control.
The CyberArk logic
The shift is also helping explain Palo Alto’s unusually aggressive acquisition strategy.
Arora rejected the idea that mergers and acquisitions are themselves a strategy for the company. Instead, he described acquisitions as a response to changes in technology that can happen faster than Palo Alto can build every capability internally.
“M&A is not a strategy,” he said. “M&A is a consequence of stuff that we do from a product development perspective.”
Palo Alto can see dozens of startups being funded around a new security problem, he said. If another company has developed a strategy that Palo Alto believes is better or faster than what it is building internally, an acquisition can allow the company to respond before the market moves again.
That logic was evident in his discussion of CyberArk, the Israeli identity-security company Palo Alto acquired for $25 billion.
Arora said Palo Alto did not buy CyberArk simply to generate cost savings. It saw identity security becoming more important as companies deploy AI agents that operate with their own credentials and permissions.
CyberArk's position could become particularly important because enterprises are moving toward systems in which thousands of autonomous agents act on their behalf. Unlike human employees, these machine identities can operate continuously and at machine speed.
Arora said CyberArk had a “pole position” in helping Palo Alto address non-human identities and AI agents, a field where he believes there is not yet an established leader.
The integration is also becoming a test of whether Palo Alto can turn its platform strategy into something larger than a collection of acquired businesses. Arora said CyberArk's margins have improved by more than 1,000 basis points in roughly nine months, while the company has also generated more than 200 net-new logos from the Palo Alto installed base.
The most revealing part of Arora’s comments came toward the end of the call, when an analyst asked him to imagine Palo Alto five years into the future and identify the most valuable security task customers might no longer perform themselves.
His answer went well beyond today's security products.
If the enormous investment in AI infrastructure pays off, Arora expects enterprises to rely on autonomous systems for a growing share of their work. Cybersecurity will have to follow the same path.
Palo Alto's ambition, he said, is to reduce human intervention in detection, prevention and remediation.
The company is increasingly building around a centralized data architecture, ingesting huge volumes of security and observability data. Its SIEM product already processes 19 petabytes a day, Arora said, while its observability business is handling data from a major frontier AI company.
The strategic idea is that AI becomes more useful when it can draw on information from thousands of previous deployments rather than treating every new customer as a blank slate.
“Every enterprise product starts dumb for the next customer, despite being deployed for 100,000 customers,” Arora said. “I think AI gives us the opportunity of learning from the multiple deployments we do and the multiple customers we have and show up more intelligent for the next customer every time.”