Nikesh Arora on why AI is the best thing that ever happened to cybersecurity sales — and the Console acquisition

Sep 2, 2026 · Full transcript · This transcript is auto-generated and may contain errors.

Featuring Nikesh Arora & Andrei Serban

Speaker 1: He's here after fantastic earnings. How are you doing, Nikesh? Welcome back. Great. How are you guys? We're doing fantastically. I

Speaker 2: appreciate the little console plug. Right. Of course.

Speaker 1: We've been very responsive.

Speaker 4: It's hard not to be

Speaker 1: laptop sticker.

Speaker 2: Is it a good company?

Speaker 1: It's a fantastic company. You've heard of it. Right?

Speaker 2: That's a bit late to ask but yeah, should have asked it before. But yeah, I think it's great.

Speaker 1: It is a fantastic company. We love the team over there. I had them on the show multiple times and of course talk about them every single show. Yeah.

Speaker 4: Super excited for you guys to be partnering out.

Speaker 1: But we can get to console later. Let's talk about Palo Alto Networks. What's the newest development this quarter? What is the story that drove this quarter?

Speaker 2: You know, I've been trying for eight years to get the attention of customers to focus on cybersecurity. It's been hard work. Yeah. But I really want to give a shout out to my friend Sam and Dario who did

Speaker 7: a fantastic job

Speaker 2: getting the living bejesus out of everyone.

Speaker 4: They're pretty good. They're a BDR. They're like your best best

Speaker 2: letters protect us on cybersecurity. They talk about MITSH, they talk about Astra. It's amazing. Every CEO, CIO wants to talk about cybersecurity and how do you secure me. I I love it. It's amazing. That's what drove a lot of the interest in cybersecurity. Yep. And people have realized that MITOS was interesting because it can find a lot of vulnerabilities and there's a lot of interest. People wanna talk about it. They wanna talk about the capabilities of OpenAI. But very soon after the first five, ten minutes becomes about, okay, wait, this is just the beginning. What happens after? When the next bigger, faster model shows up, what do I do? And like, okay, I get it. You guys can help me test it. What happens? How do I fight it if I get attacked? And the answer is, well, you can only fight that with some sort of a consolidated platform that sits in the back that looks for this stuff at machine speed and is able to respond at machine speed time, which means you have to fight AI with AI, and that's where Palo Alto comes in because we've spent our life building systems that can respond in near real time or at machine speed to protect them. So that's kind of been the inflection point or pivot that's driven a lot of the interest in cybersecurity over the last six months. I think that trend continues to sort of accelerate both from a customer interest level as well as, you know, my friends are continuing to build better, faster models which can be weaponized.

Speaker 1: Yeah. What was the last three to six months like? Because you have these moments where the AI labs are causing a lot of discussion around security and overhanging all of that. I think people were mostly worried about when the open source frontier catches up and the attackers get those level of capabilities. And there's this narrow window that is sort of a window that continues to move continuously but there's a window where Palo Alto Networks and other folks in the security space have to really get the posture correct. What actually changed? What was the conversation like? And what like, how did that process go? How much of a boogeyman was open source? Because it was discussed early, there were a bunch of different takes.

Speaker 2: Look, I think what has happened is even in the last six months, you've seen the capabilities of these models continue to rise. I read something that two days ago Sam said that Astra, their new model, is so powerful that they're going to have to clip its wings and trim it down. So that gives you a precursor of things to come. I'm sure those capabilities will be caught up with, whether it's with other frontier LLMs or the open source community, the open source models or Chinese models for that matter. So I think the capability is coming going to come out as hard and fast. Now, honestly, just cybersecurity is simple. I never grew up in cybersecurity. I have a very simplistic mental model. If it's bad and you know it's bad, stop it in the perimeter.

Speaker 1: Yeah. All right?

Speaker 2: That's called perimeter security. That's where 80% of our business lives. Yeah. That's where when you find a vulnerability, you found it in the perimeter, stop it, protect yourself. And that's what patching and fixing your vulnerabilities is all about. But unfortunately, stuff still gets through. Yeah. That's why breaches happen. It happens because you have a vulnerability that you didn't understand because a credential got hijacked or something got misconfigured. Then the question is, you've to find it quickly and you've got to get rid of it before it creates impact in your organization. This find and fix it part is where all this superhuman effort needs to be put in in transforming cybersecurity posture, cybersecurity architectures, ripping out old stuff that can no longer work in machine speed, and I don't think that's going to take two months or three months. That's a three to five year journey. And that's three to five years if everybody sets their mind to it. And you know, I look at life through a cybersecurity lens, so I would like everybody to do that. Unfortunately, my CIO friends are busy. Their boss wants them to do coding quickly. They want them to transform the company with AI. They have existential threats because the world is using AI. Why are we not using AI? So the poor CIO has got a lot on their agenda, cybersecurity being one of those things. So they're trying to balance all these priorities at the same time. But I will say there is more awareness, heightened attention, and more importantly, whatever they had on their cybersecurity docket, the priorities have shifted in that docket to make sure that they can protect themselves against the impending sort of weaponization of AI models and bad actors getting better and better at this stuff. The trend is our friend. There is positive momentum. The trajectory has changed for the better. But don't expect you know, a sudden inflection point that people are suddenly going to come out and say, The first thing I want to buy is cybersecurity.

Speaker 1: Sure. Sure. When when a CIO wants to buy cybersecurity, is the is the economic calculus changing because AI uses tokens? Like is there do they need to shift their thinking from this line item grows along a different axis than what we previously understood the cost and benefits would evolve over time as we scale our network?

Speaker 2: That's a very insightful question, my friend. That's a good question because I don't think if we slapdash frontier AI models in the protection scenario, that is a good economic outcome.

Speaker 1: Yeah. You just cannot do a 5.6 pro Fable 5.1 for every transaction that happens across your network. You're going go That's right.

Speaker 2: Think it. Every day Yeah. We inspect 180 terabytes of data. Yeah. Every day. Yeah. You stick anything against it, which has got a sort of a token based economics against it, it doesn't matter what the price of tokens is. Yeah. That's going to come that's going to add up a lot of compute. Yeah. That is why what we do today is we write machine learning code where the marginal cost of inspection is zero. Sure. It's hard to beat zero.

Speaker 1: Yeah. Yeah. Right? Yeah.

Speaker 2: So the marginal cost of inspection is zero. We got to figure out how, you know, what's the right balance where I want to use AI in the most intelligent way possible, but I don't want to do it in a way that the marginal cost goes up. Mhmm. The way it's going to work is already we're training small language models Yeah.

Speaker 1: Which are

Speaker 2: going to work on a very small footprint, which will do a specific task. Okay. My job is to stop people going on bad websites. Well, we get 150,000 new websites every day in the world. How do we find them, classify them, stop them? Well, let's train a model to identify these bad websites. Let's have it work on the endpoint or your laptop. It's doing that, and that's all it does. Yeah. And you can do that by taking all the collective intelligence that we've built over the last 17, train a small language model, deploy it to the customer where the marginal cost is zero, and my cost of training is $510.15, $20,000. Yes. Right? You'll find many of these use cases will be deployed over time where we won't need a Frontier AI LLM. Where we will need Fable five like capability or mid source like capability is in what let me call it the defender model. Sure. The defender model has to be as smart as the attacker model.

Speaker 1: Yep.

Speaker 2: Now there, there's going to be a debate about token economics. But remember, you're only using defender model in situations where you find that there's a problem. Mhmm. And those are fewer and far between compared to having to inspect all peacetime traffic using tokens. So I think that's where the balance is going to end up from an economics perspective. I'm hoping that AI costs don't become a factor in cybersecurity.

Speaker 1: Yeah. Talk about Oh, sorry.

Speaker 4: Talk about social engineering. Mhmm. We we heard yesterday that employees are actually clicking through phishing links at a higher rate than than they were historically simply because a lot of the the grammar being used in in these social engineering attacks is just better? It's harder to immediately clock it. Do people and teams not have their guards up enough? What is the solution there? You would think that everyone is reading about the potential risks LLM based, you know, attacks all over the news media. You would think that when they're in their inbox, they're maybe thinking, oh, I won't click this link from, you know that. It's a $20

Speaker 2: gonna tell you a funny story that, you know, we do phishing attack simulation at Palo Alto all the time. Yeah. There's only one time I was tempted to click on it. Thank God I didn't. And I'll tell you why I wasn't. Right? So there's this email that came saying it's National Pet Day. Take a picture take a picture of your pet

Speaker 1: Yeah.

Speaker 2: And anyone who puts the cutest picture of their pet, they're gonna donate $5,000 to charity.

Speaker 7: Well, tell you. Got windows. I got a window. Okay. That

Speaker 2: like put a little tear in my eye. Thank God I'm not into pets because if I was into pets, I'd be clicking a picture and uploading it and clicking on it.

Speaker 1: That's funny.

Speaker 2: This is where social engineering kicks in. Right?

Speaker 1: Yeah. Very

Speaker 2: will find ways to try and entice the end user to click on this. Yeah. The only way to fix it in the medium term, long term, is start running AI classifiers against the emails to understand whether it's a real email or a phishing attack. Yeah. And it's much better if you can build that into your scanning systems than if you expect every individual to be smart enough to discern whether it's a phishing link or not. Now, it was hard to do in the past because you couldn't really read email and get context, but today I'm pretty sure it's a trivial task to train a small model which says, look, this email address looks weird. It doesn't look like it comes from our company. This domain has never been seen in our entire infrastructure. This is talking about something which this domain should never be talking about. All those are simple checks which you can do using a small language model from a scanning perspective. So that's going to be the antidote to these much better social engineering attacks that are going on over there.

Speaker 4: Yeah. Speaking of dogs, Ilia posted yesterday and said that Neo Clouds, Ilia only follows three accounts, SSI, OpenAI, and Docx and fan account. Apparently a big dog guy.

Speaker 2: Even after you guys got bought out by OpenAI, he doesn't follow TBPN?

Speaker 1: We gotta get him. We gotta get him on the show. I dressed up as him on Halloween.

Speaker 2: It's an

Speaker 1: honor running these days.

Speaker 4: No. But he was posting that that Neo Clouds need a lot better security. Oh, yeah. Is He feels like it's an important issue. Is that an area that you're focusing or that you will be more focused on? Are they too busy

Speaker 2: I actually posted back, send them to us, I'm happy to help. But I am not aware of what he was particularly referring to. Everybody needs a lot of more security. Yes, of course. But I don't I don't actually don't know what he was what he was

Speaker 8: I think

Speaker 1: you were specifically worried about the the like, in the context of the Hugging Face incident, like an agent swarm, an agent state, like, wanting to get more resources and just going into a Neo Cloud to get more inference of themselves.

Speaker 5: That would be think and that would be way of

Speaker 2: hijacking capacity.

Speaker 8: Exactly.

Speaker 2: The good is the good news is there doesn't seem to be much excess capacity out there, so it's hard to hijack capacity. But Yeah. Let's let's hope that

Speaker 1: Yeah. Yeah. Yeah. A lot of a lot of alarm bells are gonna go off if you're like, wait.

Speaker 2: Yeah. I think so far Gratitude. It's my understanding, most of the neo clouds are re sort of selling their capacity back to the frontier LLMs. And the frontier LMs will basically build very strong tunnel pipes to basically sort of make it almost like captive capacity. So I'm less fearful that that's going be a problem. But yes, at an infrastructure level, everybody needs to put in basic infrastructure security, and I think some of them are. I think some of them are not putting it. They're still in the stages of building their clouds yet. Don't think I think the ones who are built, to be fair to them, are deploying firewalls and technology to make sure that there is no unauthorized access. But maybe Ilya knows more because he's smarter.

Speaker 1: Yeah. What's the state of AI research at Palo Alto Networks? I you mentioned training small models. Is is is it so exciting that you have current employees that want to jump onto that project and reskill and learn the art of training these small models? Are you hiring new AI researchers? Is there a specific skill set within AI research that is hyper relevant to that team? What is your strategy for sort of remaining on the frontier of small models that are great at cybersecurity?

Speaker 2: Well, I think there are two or three sets of people we want. Right? One set of people we want who are AI savvy,

Speaker 7: who know

Speaker 2: how to use AI to get their jobs done better, who know how to use coding agents for AI. That should be a lot easier than hiring AI researchers. There, we have pivoted, I think 50% of our new hires in the last six months are early in career.

Speaker 1: Okay.

Speaker 2: These are people who are learning and they're typically having to run through hackathons to get to Palo Alto. Don't look at where you went to school. We care about where you can use coding agents, you can use AI. So that's good because we're pivoting our workforce and if we keep following that trend, it's reasonably likely that we will overwhelm the un AI savvy people with more AI savvy people. That's kind of like ground zero. You've to get that done. The second part is there are people who are really good at cybersecurity and know AI and they'd like to get involved. If you want to work in cybersecurity, there's no better place to work than Palo Alto Networks, right? We're the largest cybersecurity company in the world. You want have an impact. You want lots of proprietary training data. You've got it. We are lucky given our position that we can attract some of the people who work intersection of cyber and AI. The third part is raw, pure AI researchers who can do wonders with small language models and large language models. There, we have people who are AI literate. We have some PhDs in AI who work here who had the cybersecurity ban, but they can go back to their roots in AI. And there, we supplement that capability with third party training companies because they've been doing it around now for multiple customers. So we want to make sure if we can do it once, let's not get it wrong. Let's have somebody who's done it 500 times and bring, not maybe 500 is too many, but twenty, thirty times. Let's bring them as part of the team so we can make sure we're getting it. So that's how we're tackling it. Thankfully, don't have to compete with the frontier models for, you know, hardcore AI researchers to build our own, you know Yeah. Big models with multiple parameters.

Speaker 1: No. Totally. Well, we have Andrei from Console here with us on the show. Let's bring him in. And I want to hear about the partnership, how this came together and what the plan

Speaker 2: Look how we bring him

Speaker 1: in. Oh, partner is always right here.

Speaker 2: Oh, there

Speaker 5: he goes. I thought he was thought he

Speaker 1: was remote. Sorry about that. Okay. So

Speaker 7: Oh, god's sake.

Speaker 1: Introduce the the the the the the here. How did you guys start talking? What does the future look like for console at Palo Alto Networks?

Speaker 2: Well, look, we spend a lot of time talking to a lot of startups across the ecosystem, cybersecurity and non cybersecurity. And as we sort of continued our conversations, we ran Andrei and his team. We run a very strong capability, obviously, in security operations and agentifying that. We have a lot of data, as I said, 180 terabytes just upon alternate networks. We have an observability company which looks at it from the outside end to see how customers' infrastructure is running. And we run observability for one of the largest frontier LLMs in the world from that vantage point. And as we were talking, Andrei shared what he was working on. When you look at what he's doing, he's taken a very AI native agent first approach to building a product. That is what future of software needs to look like. He's actually hit the nail on the head in terms of how we need to build software for the future. That is something which is a rare skill thing that we don't do internally. Then he coupled that capability by looking at the operations of a company, both on the IT side and non IT side, in terms of saying, Well, how can I take that agentic capability build product that sits on top of the underlying systems that work in a company? When we saw that, we thought, Wait. If we could bring the large data lake, the back ends we have in security and IT operations, and we can bring his capability, could we build something that's amazing for our customers? And that's sort of what started the conversation. He was a hard nut to crack. He and his partner wanted to do it alone. But I had to use every bit of charm and persuasive skills to convince him and Neil to be part of our alter. I couldn't be more delighted that he's part of the family now.

Speaker 1: I'm so excited for this. We were looking at the console website and in such a short time, you got every single logo on that website. Fantastic execution. What excites you most about the console journey thus far, and what are you most excited for in the next chapter?

Speaker 12: Yes. I mean, first of all, the TBPN sponsorship got us a lot of those a

Speaker 1: lot of those customers. So excited for that.

Speaker 12: That's amazing. Well, a little plug there. I think look. We we started this journey about three years ago, and it's been kind of better than we could have expected. We started in IT, then we've kind of, like, expanded. Most of our customers actually use us for more than just IT. It's, you know, HR and legal, security, finance, and so on. And I think what we realized was if we were gonna go broader, you know, go beyond IT, we, I think partnering with a larger customer, larger company that has, you know, works with the largest companies in the world, felt like a natural path. And so I'm excited, I think, for the future where we, you know, can just we have more resources. We can go after the vision at a much, much broader kinda, like, product roadmap.

Speaker 2: Amazing. Well, I wanna hit the We're gonna we're gonna work on the data to get him more excited, but Well, how

Speaker 1: about this first?

Speaker 7: It's the

Speaker 3: first one. About this?

Speaker 7: How about this? Is

Speaker 8: that exciting

Speaker 4: or not? So happy for both Like, of you Andrei, I Yeah. If there was a CEO that work for in my book Yep. You know, especially especially in your category, be Nikesh. Yeah. You know, he's like a he's like a you're very, like, fatherly figure, you know. It's true. You're

Speaker 1: Start working on your golf game, buddy. Yeah. Get Start working on your golf game because we're gonna need a lot of birdies.

Speaker 2: Yeah. No. He's gonna work, bro. He's going to work.

Speaker 1: No. No.

Speaker 4: Works, you golf.

Speaker 1: Yeah. Yeah. That's the plan. Yeah. Well, thank you

Speaker 4: guys so much for coming Real for you both. Fantastic. Yeah. Excited to see the progress you make. We'll talk to

Speaker 1: you soon. Have a good one. Bye. Let me tell you about Codex. Codex is a powerful workspace for getting work done with AI agents.