Interview

Nikesh Arora on why AI is the best thing that ever happened to cybersecurity sales — and the Console acquisition

Sep 2, 2026 with Nikesh Arora & Andrei Serban

Key Points

  • Palo Alto Networks acquires Console, an AI-native automation platform for IT, HR, and finance, pairing Console's agent-first architecture with Palo Alto's 180-terabyte daily data lake and security operations backends.
  • Palo Alto deploys small language models trained for $5,000-$20,000 at endpoints where marginal inspection cost is zero, avoiding the economic impossibility of running frontier LLM inference against 180 terabytes daily.
  • Palo Alto is hiring 50% early-career AI-literate generalists through hackathons rather than credentials, supplementing them with cybersecurity specialists and a small AI research team to avoid competing with frontier labs.
Nikesh Arora on why AI is the best thing that ever happened to cybersecurity sales — and the Console acquisition

Nikesh Arora on AI, cybersecurity demand, and the Console acquisition

Palo Alto Networks CEO Nikesh Arora credits Sam Altman and Dario Amodei with doing his sales job for him. Eight years of trying to put cybersecurity at the top of the enterprise agenda, and the AI labs accomplished it in months — by making every CEO and CIO acutely aware of what powerful models can be used against them.

The commercial logic is straightforward. As frontier models get more capable, so do the attackers using them. That forces a conversation about whether existing security architectures can respond at machine speed, and Arora's answer is that only a consolidated platform with AI-native detection can. He's careful not to oversell the timeline: this is a three-to-five year re-architecture cycle, not a sudden buying spree, and CIOs are balancing it against AI transformation mandates from their own CEOs.

I really want to give a shout out to my friend Sam and Dario who did a fantastic job getting the living bejesus out of everyone... Every CEO, CIO wants to talk about cybersecurity and how do you secure me. And the answer is, well, you can only fight that with some sort of a consolidated platform that sits in the back that looks for this stuff at machine speed and is able to respond at machine speed time, which means you have to fight AI with AI.

Token economics vs. zero marginal cost

One of the sharper points Arora makes is on AI cost structure inside security. Palo Alto inspects 180 terabytes of data every day. Running frontier LLM inference against that volume at token-based pricing is economically impossible regardless of where token prices land. The company's answer is small language models trained for specific, narrow tasks — classifying malicious websites, scanning email for phishing signals — deployed at the endpoint where marginal inspection cost is zero.

Arora says training one of these models costs between $5,000 and $20,000. The attack surface for that use case is well-defined, and the model doesn't need GPT-4-class reasoning to handle it. Frontier-model capability gets reserved for what he calls the "defender model" — the system that engages when a threat has already been detected. At that point, compute cost is acceptable because incidents are rare relative to total traffic volume.

Social engineering and the phishing problem

On AI-enhanced phishing, Arora argues the antidote isn't better employee training — it's AI classifiers embedded in email scanning infrastructure. He describes the checks as relatively simple for a small model: unfamiliar sender domain, domain-topic mismatch, structural anomalies in the message. He makes the point with a self-deprecating example: a simulated phishing email offering to donate $5,000 to charity on National Pet Day nearly got him to click, and he knew it was a test environment. Expecting individuals to catch well-crafted AI-generated social engineering at scale isn't a strategy.

Hiring and AI research

Arora describes three distinct talent layers Palo Alto is building. The broadest is AI-literate generalists — people who use coding agents fluently. Roughly 50% of new hires in the last six months have been early-career, selected through hackathons rather than credential screens. The second layer is cybersecurity specialists who also know AI. The third is a small group of AI researchers focused on small and large language models, supplemented by third-party training firms that have run dozens of similar engagements. The model avoids competing with frontier labs for the researchers needed to build hundred-billion-parameter models — a competition Palo Alto would lose.

The Console acquisition

Palo Alto is acquiring Console, an AI-native IT, HR, finance, and legal support automation company co-founded by Andrei Serban. No financial terms were disclosed.

Arora describes the strategic rationale as a pairing of capabilities that neither side had alone. Palo Alto brings a large data lake — again, the 180TB daily figure — plus backends in security and IT operations, including observability infrastructure it runs for one of the largest frontier LLMs. Console brings what Arora calls a genuinely agent-first product architecture, which he says is rare and reflects how software needs to be built going forward.

Serban says Console started in IT three years ago and expanded so that most customers now use it across HR, legal, security, and finance. The decision to join Palo Alto came down to distribution and resources: going after a broader product roadmap as a standalone startup was the slower path. Arora says he had to work to convince Serban and his co-founder Neil to sell — they wanted to build independently — but describes the outcome as one he couldn't be more pleased with.

Every deal, every interview. 5 minutes.

TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.