When Nikesh Arora turned Anthropic's unreleased Claude Mythos 5 loose on Palo Alto Networks' own internal infrastructure this past April, the results were alarming. The model — powerful enough that the U.S. government temporarily imposed export controls on it and forced Anthropic to disable it globally — surfaced system vulnerabilities at a speed and scale that Arora says will permanently reshape cybersecurity. The test crystallized what many in the industry have quietly feared: that frontier AI can now act as an infinitely patient, machine-speed attacker, probing systems relentlessly until it finds a way in. Arora describes it as bringing a battering ram to your front door, bought from Home Depot.
The threat is not theoretical. AI-driven attack tools are creating what Arora calls the best marketing moment in cybersecurity history — because for the first time, CEOs are personally frightened. Where once a cybersecurity pitch might be deflected to an insurance broker, Arora now walks into board rooms where executives want to see Mythos demonstrated firsthand. OpenAI CEO Sam Altman, who has been seeking Arora's counsel since around 2023, puts it bluntly: patching every bug on the internet is no longer a viable strategy, and an entirely new model of cybersecurity is required.
Arora has spent his seven years at Palo Alto Networks building exactly that. When he took the helm in 2018, the company had $2.27 billion in annual revenue and an $18.5 billion market cap. Today it fluctuates between $270 billion and $300 billion, posted $11.48 billion in fiscal 2026 revenue, and serves roughly 95% of the Fortune 500 — from Tyson Foods and Colgate-Palmolive to the NHL, MLB, and the Sphere in Las Vegas. It is the only pure-play cybersecurity company on the Fortune 500 list. His strategy, which he calls platformization, bets that CISOs want a single trusted partner rather than dozens of point solutions stitched together in what Palo Alto's chief product officer Lee Klarich calls the conga line. The approach has included more than 25 acquisitions, capped by this year's $25 billion purchase of identity security startup CyberArk.
Arora himself is an unlikely figure at the center of the AI-security reckoning. Born in Ghaziabad, India, he arrived in Boston in 1990 with $200, two suitcases, and a Northeastern MBA offer that covered tuition. He worked Burger King shifts and campus security guard posts through grad school, joined Google a month after its IPO, became chief business officer by 2009, and later had a turbulent stint as Masayoshi Son's would-be successor at SoftBank before landing in cybersecurity. Eric Schmidt credits him with detecting the Global Financial Crisis a full month before it became public, based on anomalous UK revenue data Arora flagged in March 2008. The value of that early warning, Schmidt says, was incalculable.
Now 58, Arora has become a sought-after informal advisor to tech's most powerful CEOs, a role built on a reputation for unfiltered honesty. Uber CEO Dara Khosrowshahi, an Arora board colleague, says most people manufacture their paragraphs for CEOs — Arora doesn't. Altman echoes the point, noting that direct, confident, actionable advice is genuinely rare at his level. Analyst estimates suggest AI could roughly double the total addressable cybersecurity market, which already runs into the hundreds of billions of dollars. Palo Alto claims a 6% share today. Arora's ambition is clear, even as he warns that the AI threat cannot be fully contained — only managed. The consequences, he says, are already in motion.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free