Estimated reading time: 5 minutes · Last updated:
Nikesh Arora, chief executive of Palo Alto Networks, has put the company at the center of an AI-driven shift in cybersecurity after running Anthropic’s Mythos against Palo Alto’s own systems and finding vulnerabilities at speed and scale. The company, which reported $11.48 billion in revenue for fiscal 2026 and counts about 95% of the Fortune 500 as customers, is pursuing a platform strategy and aggressive M&A to meet what Arora calls a new baseline of continuous attack risk. This profile draws on reporting and interviews, as first reported by Fortune, and explains how Mythos reframed both the threat and the market.
Just a crazy amount of work has to happen to avoid major cybersecurity problems. We need a new model of cybersecurity here.
Sam Altman
Key takeaways
- Mythos test: Arora ran Anthropic’s Mythos against Palo Alto Networks’ infrastructure and found vulnerabilities at a speed and scale that changed the company’s threat calculus.
- Company scale: Palo Alto Networks reported $11.48 billion in revenue for fiscal 2026 and says it serves about 95% of the Fortune 500.
- Market position: Jonathan Ho of William Blair estimates AI will be an unmitigated tailwind; Palo Alto currently reports controlling 6% of the cybersecurity market.
- Strategic moves: Under Arora, Palo Alto has completed more than 25 deals, including this year’s roughly $25 billion acquisition of CyberArk, to build a full-stack security platform.
Table of contents
How Mythos changed the threat model
Anthropic’s Mythos—described in reporting and interviews—can probe systems at machine speed and surface potential vulnerabilities far faster than human teams. In Arora’s controlled test at Palo Alto Networks, the model flagged issues with a combination of scale and speed that forced a rethink of defenders’ timelines.
Arora estimated about 30% of the flagged vulnerabilities were false positives, but he argued that 'seven out of 10' real findings is enough for an attacker to exploit. He contrasts the industry average window to find and fix a breach—three days—with an AI-powered attack that can unfold in roughly 12 minutes, illustrating why defenders must change their playbook.
Palo Alto’s platformization and M&A push
Arora responded by accelerating a platform strategy that blends organic R&D with acquisitions: Palo Alto has done more than 25 deals under his tenure to assemble network, cloud, identity, endpoint, and observability controls into a single offering. The company joined the Fortune 500 in 2025 and argues that customers now prefer a one-stop approach rather than dozens of point products.
That acquisitive thrust included this year’s roughly $25 billion purchase of CyberArk, an identity security vendor, part of a wider bet to control a larger share of a market Palo Alto says it currently holds at about 6%. Executives at the company and outside analysts frame this as a bid to convert the sudden demand created by AI-driven risk into durable product revenue.
Arora’s role as adviser and strategist
Arora has become a go-to voice for CEOs and AI leaders; Sam Altman told Fortune that AI’s capabilities mean 'a crazy amount of work has to happen to avoid major cybersecurity problems.' Arora’s reputation for blunt counsel and his board-level relationships—he sits on Uber’s board, among others—have placed him in frequent private consultation with industry leaders.
His leadership style prizes scrutiny and rapid decision-making. Colleagues quoted in reporting point to an insistence on consequence management: Arora says you can’t fully eliminate the crisis, so organisations must get adept at managing outcomes while hardening systems continuously.
What defenders must change now
The practical implication is that defenders cannot rely on slow patch cycles or legacy insurance-first postures. Arora and Palo Alto advocate building integrated detection and response that assumes probing will continue relentlessly, and they emphasise identity and cloud controls as central to that posture.
At the same time, the industry faces a coordination problem: governments have already moved to limit access to models like Mythos, and vendors debate whether AI labs can or should supply defensive tools directly. Palo Alto’s view, articulated by product leaders in reporting, is that many customers will prefer a vendor they trust to run their security rather than accept direct defense from a large AI lab.
The case for and against Palo Alto’s approach
The case for
- AI-driven tools create urgent demand for security and could materially expand the cybersecurity market, a tailwind Jonathan Ho of William Blair describes as 'probably doubles the size of the market' cumulatively.
- Palo Alto’s full-stack platform, bolstered by more than 25 deals and the CyberArk acquisition, aligns with CISO preferences to consolidate point solutions.
The case against
- Frontier models can be powerful defenders and attackers; some AI labs are pursuing defensive products, creating new competition for Palo Alto.
- Regulatory steps—such as the export controls that limited Mythos access—can restrict defensive use or complicate deployment of the very models defenders want to use.
What to be careful about
- Government export controls and licensing on frontier models could limit defenders’ access to the same capabilities attackers might use.
- High false-positive rates—Arora estimated roughly 30% in the Mythos test—can overwhelm teams and erode trust in AI-assisted findings.
- Large acquisitions like the roughly $25 billion CyberArk deal carry integration risk that could slow product delivery at a moment of heightened demand.
- Coordinated AI-agent attacks, demonstrated in the OpenAI–Hugging Face incidents, show how multiple models acting together can multiply impact quickly.
The bottom line
Anthropic’s Mythos and similar frontier models have turned a previously incremental threat into a problem that operates at machine speed. Nikesh Arora’s answer—accelerate platform integration, buy selectively, and run continual consequence management—is Palo Alto Networks’ bid to turn that urgency into durable advantage. The company’s scale ($11.48 billion in FY2026 revenue, roughly 95% of the Fortune 500 as customers) gives it reach, but false positives, regulatory constraints, and new vendor competition mean the next year will test whether platform bets convert into sustained leadership.
What to watch
- Watch for further government action on export controls or licensing for frontier AI models; no date has been set.
- Watch for public progress updates on integrating CyberArk into Palo Alto’s platform; no date has been set.
- Watch for any public incident reports where AI models are named as the primary vector in a breach; no date has been set.
Frequently asked questions
What is Mythos and why does it matter?
Mythos is a frontier AI model from Anthropic that, in Palo Alto Networks’ internal testing, surfaced vulnerabilities at machine speed; U.S. regulators briefly imposed export controls on Mythos before allowing limited access to vetted users.
How large is Palo Alto Networks today?
Palo Alto Networks reported $11.48 billion in revenue for fiscal 2026, has a market cap that fluctuated between about $270 billion and over $300 billion during reporting, and counts roughly 95% of the Fortune 500 among its customers.
How fast can AI-driven attacks unfold compared with traditional breaches?
Arora contrasts a traditional average window to find and fix a breach of three days with AI-fueled attacks that he says can unfold in about 12 minutes, underlining why defenders must change timelines and tooling.
Related reading