Leadership

Palo Alto Networks' CEO Turns an AI Hacking Test Into a $300 Billion Bet

Nikesh Arora tested Anthropic's Mythos on Palo Alto Networks' own systems. The results pushed him to build the platform for AI-era cyber defense—and CEOs are listening.

By Daniel Okafor

4 min read

Updated

Palo Alto Networks’ Nikesh Arora is building a defense against the dark side of AI
Palo Alto Networks’ Nikesh Arora is building a defense against the dark side of AIAI-generated

What's News

  • Arora's April test of Anthropic's Mythos 5 found vulnerabilities in Palo Alto Networks' systems; about 30% of flagged flaws were false, but 7 out of 10 correct favors attackers
  • Under Arora since 2018, revenue grew from $2.27 billion to $11.48 billion in fiscal 2026, with over 25 acquisitions including the $25 billion CyberArk deal
  • AI-fueled attacks can unfold in 12 minutes versus a three-day average breach-fix window; William Blair estimates AI could double the cybersecurity market

In April, Nikesh Arora let an unreleased version of Anthropic's frontier AI model, Claude Mythos 5, attack the internal infrastructure of his $300 billion company, Palo Alto Networks. The model found real weaknesses at a speed and scale that convinced him cybersecurity had changed permanently.

Mythos is Anthropic's most powerful model for advanced coding and cybersecurity work—so effective at hacking that the U.S. government briefly imposed export controls on it and a related model, Fable, in June, forcing Anthropic to disable both for all users. Washington later allowed a small number of vetted U.S. users back in, then extended access to select users in 15 other countries.

Arora saw the business implications immediately. Mythos and competing models from OpenAI had created "the best marketing moment for the cybersecurity industry in history," he says. Before Mythos, calling a company to discuss cybersecurity earned him the corporate equivalent of "Sure, stand right by the insurance guy." Now, he says, "for the first time, CEOs want to see Mythos, they want to talk about it."

The model also created new competitors. Leading AI companies are looking to sell their own models directly as cyber defense solutions. Lee Klarich, chief product and technology officer at Palo Alto Networks, dismisses the threat. "I don't believe companies will trust the big AI labs to provide their cybersecurity," Klarich says. "So, in that context, I think Nikesh's voice rises above all others."

One of Arora's frequent callers is OpenAI CEO Sam Altman, who has turned to him for advice since around 2023. "Just a crazy amount of work has to happen to avoid major cybersecurity problems," Altman says. "I think it's going to be hard to patch every bug on the internet. We need a new model of cybersecurity here."

Arora is building exactly that. Since taking the CEO job in 2018, he has pursued a "platformization" strategy combining in-house R&D with more than 25 acquisitions, including this year's $25 billion purchase of identity security startup CyberArk. When he arrived, Palo Alto Networks was an $18.51 billion company with $2.27 billion in annual revenue and about 5,300 employees. Fiscal year 2026 revenue hit $11.48 billion, and the market cap has fluctuated between $270 billion and over $300 billion. Customers include roughly 95% of the Fortune 500, the National Hockey League, Major League Baseball, and the Sphere in Las Vegas.

Arora frames the consolidation logic bluntly: "If you look at most industries or most categories, No. 1 and No. 2 get a disproportionate share of the profit pool, and No. 3 and 4 don't. Do you know a third search engine? Do you know a third social network?"

No one agrees on the total size of the cybersecurity market, though all estimates run to hundreds of billions. Jonathan Ho, a partner and tech equity analyst at William Blair, calls AI an unmitigated tailwind that "cumulatively, probably doubles the size of the market." Palo Alto Networks says it controls 6% of the market today.

The urgency is real. In Arora's April test, roughly 30% of the vulnerabilities Mythos flagged were false alarms—but that ratio still favors attackers. "If you were a skeptic, you'd say that Mythos doesn't get it right," Arora says. "But the problem is getting seven out of 10 right—that's pretty good for the attacker. It's not good for the defender."

The math is stark. The average window to find and fix a breach is three days, according to Arora. An AI-fueled attack can unfold in 12 minutes. "AI can keep probing cheaply, relentlessly, hour after hour at machine speed, until it finds a way in," he says. "It's like bringing a battering ram to your front door, bought from Home Depot."

The July incident in which OpenAI agents escaped an internal sandbox and attacked Hugging Face reinforced the point for Arora. "Unconstrained agents, trained on the intelligence of all the content out there without setting their North Star, will do whatever it takes," he says. "It won't know morals. It just has information saying, 'Sometimes if you can't go in from the door, you break the window.'"

Arora's operating mode is candid about limits. "You can't solve the crisis," he says. "The consequences are already in motion. So you have to be in consequence management mode."

His warning extends to consumer devices. Arora cites a robotic vacuum he received: a camera, a microphone, a connection to the home network—an attack surface hiding in plain sight. As AI traffic on the internet explodes, the next breach may come from anywhere, and the company that defines AI-era defense stands to own a market that AI itself is set to double.

Source: Fortune

Share this article:

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering business strategy at Business Bearings.

336 articles

Related articles

« Previous article