Go back

Nikesh Arora, CEO Palo Alto Networks ($PANW)

59m 9s

Nikesh Arora, CEO Palo Alto Networks ($PANW)

The speaker, a leader at Palo Alto Networks, argues that AI is fundamentally transforming cybersecurity by making attacks faster and more accessible. They highlight that AI models can now discover and exploit vulnerabilities in minutes, whereas traditional patch cycles take an average of 55 days—a gap they aim to close with a new capability delivering patches in four hours. This urgency is driven by tools like "Mythos," which have heightened executive awareness of security risks, pushing companies to modernize infrastructure and adopt AI-based defenses. The speaker stresses that while models are powerful, the industry over-indexes on them; success requires robust contextual training, guardrails, and governance to ensure safe deployment in real-world scenarios. They advocate for open-source and open-weight models to spur innovation, but also acknowledge the need for liability frameworks to clarify responsibility when AI acts autonomously. From a business perspective, they describe a strategy focused on long-term growth, using M&A to fill gaps and anticipate market needs, even when short-term investor reactions are negative. Finally, they emphasize that cybersecurity is uniquely innovative because adversaries constantly evolve, forcing companies to stay nimble and invest in new technologies to protect against emerging threats. Overall, the speaker is optimistic about AI's potential but insists that cybersecurity must be prioritized to enable safe adoption across industries.

Transcription

11923 Words, 64724 Characters

English
The cash are war. The cash are war. The cash are war. This is the beginning. This is not a moment. You've seen most recently all the EL labs are flexing, showing how cool their models are, and how they can basically become an attacker and attack infrastructure rapidly because of all the vulnerabilities they can find. It's a lot easier to attack. As an EL lab, it's much harder to defend. If you found a vulnerability, a zero-day vulnerability, the average time to fix those 55 days. The average time missiles will find it and try and attack you is in minutes. For the black cat, we launched a capability, which allows us to deliver patches in four hours and deploy them to everyone for our customers. It's huge. From 55 days to four hours. None of the software in the last 20 years came in an opinion. So the entire software industry will get re-ripped in the next 10 years. What do you think the biggest question is that people are not asking? The Keshe Aurora Welcome Disorcery. Thank you for having me. Thank you for having us here at Palo Alto Networks. You guys have done a really good job in making this place look beautiful, so please feel free to come back anytime. So I think a good place to start. You guys are having a bit of a moment right now. Cybersecurity is very hot. AI is making it really top of mind. So I have to ask you, what is your hottest take right now? The hottest take right now is this is the beginning. I think you've seen most recently all the AI labs are flexing, showing how cool their models are and how they can basically become an attacker and attack infrastructure rapidly because of all the vulnerabilities they can find. Well guess what? That's going to become part of the course. Who's going to protect them? And it's a lot easier to attack. As an AI lab, it's much harder to defend. So I think all the cybersecurity companies are on a tear for that reason because the market understands that to get all the infrastructure in the world up to snuff in terms of its capabilities to be able to protect against this deluge of AI attacks that are going to be upon us, you need all the cybersecurity companies. So how are you keeping track of everything that's going on? Do you really heard? Watching your podcast. Listening to, look, it was fascinating in the last two years you've seen, we've been through so many iterations of AI. I started chat GPD, OpenAI has going to go run away with it and then I'm talking to people from nowhere, people have written Google off and they were not going to be able to compete. And like two years hence we're sitting here watching all the announcements and all the cloud companies which are going gangbusters because people want to use more compute, want to use more AI. And now we've gone from an elements to agents, agents are going to help us to a whole bunch of stuff, you've got agents to open-weighted models, open source, closed source. So there's so many variables because the market continues to evolve on a daily basis. In cybersecurity, it's going to make sense of these trends and see which ones of these trends is likely to catch up on, catch on. So we've got to go build the security infrastructure and harnesses around it. So it's kind of a bit of an dancing on your toes and constantly being nimble trying to figure out where this thing is going to land. It's interesting. I think some things are beginning to emerge. I think a lot still needs to be figured out. But I think one thing is clear, the appetite for AI is huge. And I don't think that trend is going to reverse itself. So if you believe the demand is infinite then a lot of things have to fall into place for this to be successful and what then clearly is cybersecurity. With more anomalies popping up in rogue agents which who knew that would happen, how are you handling that? How do you stay on track of that kind of thing? I think that totally as part of the flex is part of demonstrating the capabilities of the technology. For all practical purposes, the biggest use case you've seen is coding. Everybody is using AI to code. I think that's kind of mainstream because the capabilities of AI models have fair to say that surpassed humans in certain cases from a coding perspective. You still need humans to watch what's done. So to ensure that it's the right solve, test it, run out of care processes. But clearly you can see that the use case has been established, the productivity case has been established, and there's a huge amount of consumption in that space. Outside of that, I think people are still feeling the way how agents are going to work, how do you give agents what are called true agency, how do you let them decide. I think there's still a bunch of experiments going on over there, and it'll take time before people get really comfortable unleashing agents in their price. There's a little bit of controversy with what happened with the OpenAI thing. Just a little? Just a little bit. And then also how the response was after that, the same thing happened with Anthropic, and then now those leaders are asking for slowdown. So what part do you believe is controversial in that? Just out of curiosity? Well, I guess the main question is now they're asking for a slowdown to potentially cover their tracks later on. Are they asking for slowdown? Yeah. But they're asking for permission. They're to be able to go release these. I don't know, you tell me. I know. Look, I think it's clear from all the recent developments that these models are getting very powerful, and the edge case intelligence is really strong. Like, you know, it can solve some unique things. You saw some math problem being solved two days ago. You've seen that it can find cyber vulnerabilities, it can daisy-chain vulnerabilities, attack infrastructure. So it's clear these models are going to be extremely powerful. They already are. I think it's important that before we have to understand liability, we have to understand who's responsible at the end of the day. It's very easy to describe responsibility and liability human beings. If you do something wrong, it's your fault. I do something wrong. It's my fault. If I use a model and the model does something wrong, whose fault is it? The model's fault is the might fault for using the model. So I think all these things are going to come very torny issues. I think a lot of the AI labs want to get ahead of it. Make sure there is some governance framework around it to ensure that they can keep developing the technology and the pace which they'd like to. I think they, in a way, they're probably doing the right thing. It doesn't seem like it, but I think they are doing the right thing and trying to get some governance around it. So they don't get hauled back as you saw. They didn't get hauled back. When they tried to launch methods or Fable 5, they got hauled back because the model was not appropriately garaled. So I think we're going to go through a bunch of these growing pains. Mythos was a big moment. It still is. It still is. So how are you handling the mythos? You know, for eight years, I spent my career involved trying to convince the youth, they need to pay attention to cybersecurity. Tried everything. Called them, tried to talk to them, and they usually send you off to their technology and go talk to those guys. You know what mythos did? Have we seen you or wants to talk about mythos? Which is great. So the first time Mythos has every CEO sitting at the edge of their seats saying, am I vulnerable? Is something going to happen because of what mythos is? Do we have mythos? We're so important. Why don't we have mythos? Why can't we get mythos so we can test our own infrastructure? I think mythos has created a bit of a moment for cybersecurity. And what's fascinating to watch is that moment has, I think for now, said, advantage in confidence. Advantage is the big players in cybersecurity where the customers are going back to them and saying, listen, you are my cybersecurity partner of choice. What should I do? What am I supposed to do? How do I get my hands on mythos? What have you done? How have you done your testing? I think it is a moment because it has got everybody's attention. I also think it's a moment because it is going to change the way cybersecurity is done in the future. Like what? People would buy cybersecurity products and it was okay. You know, if you found a vulnerability or zero-day vulnerability, the average time to fix those 55 days in the industry. The average time mythos will find it and try and attack you is in minutes. So now you got to go get ahead of it, test all your software, test all your open-source, understand the vulnerabilities and patch them before and 55 days is too long. So this morning actually as part of Black Hat, we launched a capability which allows us to deliver patches in four hours and deploy them to everyone for our customers, which is huge from 55 days to four hours. So we do have the benefits of AI from a defensive perspective, which we are beginning to see. So I think what is happening is now has become a pattern to the market that the time from discovery of vulnerability to attack is going to compress tremendously, which means you have a lot less time to go fix it or find a bad actor in infrastructure. And time gets compressed, it requires our customers to modernize their infrastructure, requires our customers to start using AI in the deployment in terms of the defensive capabilities that they must have. That's good news for this cybersecurity industry. Great news. It's like I think so. There's not many, I mean there's a lot of fear mongering that goes around with AI, so it's nice to have positive, optimistic stuff. Like every technology eventually needs the right, let's say, 10 pulls for it to succeed. You need to make sure that things are done in a certain way so that customers feel comfortable deploying the technology. It's like, I don't know, take away more ever. Sometimes. You're comfortable in it? Yeah. You feel safe? Sometimes unless it goes down those hills, have you done that? In San Francisco? No, I haven't. You haven't taken one in San Francisco? I have taken away, of course. I just haven't gone downhill on the rolling hills of San Francisco. Highly recommend you both. Got it. Got it. Well, the reason to ask you the question is a lot had to get done right for you and I to feel comfortable walking into a way more and having it drive us. We effectively gave agency to AI to act and not be certain by it or not feel unsafe around it. That process needs to happen in every useful use case. that is going to be deployed using AI. And that's that's churning. It's not going to happen overnight. But I think the ingredients are in place for that to happen. And it's cyber security is one of those things that needs to gotten right for people to be comfortable that no bad actor is going to take over my way, and drive me faster down the rolling hills or go out for a bit, take me away. The main topic was really on cyber security. You were part of that. You signed it as well. So why did you make that decision? Look, at the end of the day, if you want the diffusion of technology in a way that everybody can use it in every way, shape, or form, you want to make sure that there's no constraint or innovation. And having open source, open weight, having close weight, all these things are important parts of the puzzle to make sure that people can deploy them different circumstances. I don't think it's necessarily bad to hold back the development in open source or open weight for that matter. Open source will allow people to make these things available globally at the right price point for various people to be able to use, open weight, but allow a significant amount of fine tuning to make sure that can you adapt a model to your specific use case in a way that is more effective and efficient for the task at hand. So all these are important parts of the puzzle to make sure we get an innovation right. So that's the reason we signed it. I think there's an over indexing on the model part of it. I think to make AI useful, the models are important. But I think it's also important to get all the context collected and all the training data right. I think Billings of Dolls will spend to train my favorite example of Waymo. I think Billings of Dolls will be spent over the next few years training a whole bunch of use cases in enterprise or consumer to get that part right. Why do you like Waymo so much? It's not like Waymo so much. I think it's the most obvious relatable example of AI getting agency where a human does not get involved. And AI is allowed to make decisions which could mean life or death for human beings. And that's it right there. And if I tell you, are you comfortable letting OpenAI make a life or death's decision for you? What is your answer? I mean, I don't want to be in that situation. See? But you did put yourself in Waymo. So there's my example. My example is if you spend enough amount of money, enough guardrails, enough training, you can get comfortable in a scenario where AI can be used instead of a human who has agency. So I think that's what I mean by saying, look, would you let AI prescribe medication to you? And take it without asking for a second opinion. No. Would you allow your doctor to do that? Yeah. You would. Now do you believe it's possible for AI to get trained as well as your doctor and perhaps better? Yes. Good. So you would? Potentially. Right. But you won't take the models in the current draw form and let it happen. You would still wait for a whole bunch of contextual training data that needs to be deployed, a whole bunch of edge cases to be understood, even more context about you to be understood, but then you would. And I think that's what needs to happen. We're over indexing on the model. I think it was a great. But being able to take that model, package that, for all that context, all that knowledge, all that training, and be able to do a resolution to use, what the next big sort of revolution needs to be? And that needs to happen in thousands of different use cases. You're clearly a big beneficiary of this, and it's amazing. It's you joined the company at $18 billion valuation? Mark Yes. And now it's at around $300 billion, which is crazy. Who's counting? Oh, Mark. You are being intentional. Yes. Only two days it matters. The day you get to talk, the day you sell stuff. Here the other day, it's a vanity number. What's nice? To get to that point, like, one of the main things that I took away when we were walking around the office and we were meeting different people is one, you're super aggressive. Two, we were talking with Hamza, and he said, you're just as good as an operator as you are an investor. Super aggressive. Explain that to me. You're aggressive. You go after things. You watch support? Yeah. When you see somebody bowing through the defense and trying to make a basketball, who, like, make a shot, are they called super aggressive? Or are they called people trying to get it done? I guess they tried to-- they just do it. Good. So I prefer that characterization as opposed to super aggressive. I'm going to get it done. Yes. That doesn't require me super aggressive. But your question was definitely. You're talking about Hamza. Yeah. And-- So talk through that. You have an amazing career as both an investor and an operator. How does that come together in this role here so well? If you look at what the markets are award, if you look at what how business gets rewarded, business gets rewarded effectively in metrics like market cap, perhaps. What is a market cap? The market cap is the sum total of the expectations of the world about the strategy, execution, and the potential for your business, right? And video trades are five-fillion because people believe it has trends of demand that's going to happen. Jensen is a great executor and they're doing a whole bunch of stuff right. So you can actually work your way back from market expectations with the market expects that makes for a successful business. Now, the market is pretty straightforward in this expectation on some level. It says, if you have a durable business that grows at a robust rate, which you can run profitability with a generate tons of cash flow, we like you. Now, that's great, which means you have to run a good business. Must have good cash flow and must grow well. But the market is sort of smart on that. It says, well, not just that, I want to see the durability of it. What does durability mean? Can you grow at a rapid pace for a long period of time? Like if you're CEO trying to deliver in that environment, which means every time you think that you've done it, the market expects you to grow again. Like you get from a dollar to a dollar 15. The market says, great, tell me tomorrow can you grow 15% or 100%. So the market is expecting you to grow at a certain rate. The numbers keep getting bigger. The question is, how do you keep making sure your business continues to grow in that regard? And that's kind of put the art and science of leading businesses to make sure I don't spend all my time worrying about what happens next quarter. I worry about what happens two years from now. Because I can see for the next two years how my business is going to progress, what we're going to be able to sell, what we need to go fix, what how to be ready to make things work. And that's great. But after two years, your visibility begins to tend. It's like, oh my god, what if the market shifts to what if competition gets stronger? What are different products come from the market? My job is to say, all this went well. What would our business need to look like two years? So now, the growth levers need to be brought to deliver on that business. That's kind of the paranoia I live with. And as that paranoia, you see, we bought 40 plus companies in the last eight years. Because sometimes we're looking for interesting products. Sometimes we're trying to fill gaps. Sometimes we're anticipating the market and say, how can we get ahead? So all of that goes into that little thing you shake it together and say, that's what the market expects from an investment perspective. But what does that mean for our strategy? And what does that mean from how we execute the business? And sometimes, we disagree with the market. Sometimes say, no, what? Market, don't worry about it. We went and bought a $28 billion dollar company called CyberArc. And the market didn't like it for a certain period of time. And they turn around and we showed them results in a short period of time. I'm like, oh, shit, we love it. Why is the M&A so kind of consequential for cybersecurity companies? Because this is a common theme. They're very inquisitive. It is the most innovative industry in the world. Because the bad guys are trying to figure out how to attack you in a different way every time. The moment we suss out how they did it, they moved on to finding the next time. So we're constantly trying to chase them, saying, oh, shit, they figured out another way to attack us. Let's go figure that out. By the time we get to there, they move on. So constantly chasing and anticipating the bad guys who are constantly looking for a new way into your infrastructure, which makes them extremely innovative. And they're all over the world. Nation States, people in their basements, people with-- in the end, they're in front of the hand or laptop. They're all trying to figure out, either for trophy reasons or for economic reasons, how do I break into something? So it requires us all to be very innovative. Every new technology that comes to the market requires a different kind of harnesses, different kind of tools, different kind of capabilities in our products. If you don't pay attention to every new technology, the customer start buying something else. So it's almost like we have to stay on our toes on a constant basis to anticipate technologies, anticipate bad actors, make some of the most innovative companies, the most innovative sector. In that environment, it's impossible that all the innovations are going to come from us, because there's always somebody else who's got a different angle. There's always somebody else who's tried something that's going to work better than what I thought about. So you just have to live in this industry with humility to understand that you may not always have all the answers. The question is, however, are you smart enough to anticipate who has the answers, make them part of your team, charm them, be part of our auto? And when we do that, can you then deploy that as quickly as you can to your customers? So I think in the last areas fair to say, we've just struck the right balance between what we build internally, what we can go rapidly and build internally and later in top of our platforms. And what is unique out of the market, where if we partner a slash acquire, somebody, how can we bring them into the full spot of auto and deploy the capability or customer as quickly as we can? The notestar always is, how do I deliver that capability to my customer as quickly as I can? And sometimes it's by, sometimes it's built because it's too complicated to buy and integrate. Sometimes we look at it and say, no, it's not worth it. Let somebody else serve that part of the market. We can find it and integrate them with them. So once you do make an acquisition, what is the playbook for getting them to your customers? How do you onboard them one on the product basis, but then also on the team? Well, we've done acquisitions of all shapes and sizes. Some of them have been easier because they're clear product acquisitions and categories. you don't play in, so that becomes a lot easier because then all we do is we say, "Listen, you're going to be part of our auto." We might slow you down, but we're going to throw more resources at you so we can make you get more scale and more speed. And that's going to work well with our browser company. We didn't have to, we had to integrate in part of our product, but we were able to let them lose. We bought a bunch of AI security capability. Again, something we didn't do, we had to put more resources in there, put it together and let them lose. Now, what letting them lose means is, we actually make them part of our go-to-market engine. Our teams out in the field have tons of relationships, they're used to talking to their customers about unique things that we do. In that context, we sort of plug these capabilities into our go-to-market pipeline. We make sure our customers have various capabilities that allows our customers to go out there and use these capabilities as fast as we can. We can give it to them. - What do you think the biggest mistakes are that people make during the acquisition? - The biggest mistake that people make during acquisitions is underestimate the intelligence of the people who build the business that you acquired. Because sometimes you take on the imperialistic attitude, "I bought you and you must work for me." Our attitude is, "You kicked the rast. "Come tell us what you did wrong. "Come run this for us because you did well "without our money, our resources, and our scale." So you must have figured something out. So we spend our time trying to understand what they figured out, find a way that we can make them part of our culture, make that absorb that capability, and we let them run it. And that sometimes really makes it hard for my teams because they suddenly have a new boss in a category where they thought, "We require something." But it's just like I said, you have to approach this as humility because there are people out there who are smarter, faster, better resources, more resourceful than you in certain categories. And if you can embrace them in the right way, it allows us to build a durable business. - This episode is brought to you by Brex, my favorite. You become what you spend on. And I refuse to spend my time on work that shouldn't exist, expense reports, receipt chasing, and manual closes. The company is building what's next from Versel, OpenAI, Anthropic, Grenola, and DeepGram, all made the same call. They all run on Brex. Brex is the intelligent finance platform that combines cards, expenses, and banking into a single stack with a gentick finance built-in. AI agents that handle expenses automatically enforce policy before spend happens and close your books in minutes. That's why sorcery runs on Brex. So I can spend time on building and not busy work. It's time to get Brex AF. Learn more at Brex.com/sourcery. That's B-R-E-X.com/S-O-U-R-C-E-R-Y. Bye. - Turing is training the next generation of AI with tasks that require real expertise and real world judgment. That's why companies like Nvidia, Anthropic, Salesforce, and Gemini partner with Turing. Turing builds realistic reinforcement learning environments and data systems based on real operational traces. The kind of infrastructure frontier labs need to train superintelligence. Visit Turing.com/S-O-U-R-C-E-R-Y. - How do you remain curious in this like exploration process of finding new potential acquisitions, new companies to bring in? - Paranoia. - Paranoia? - Fear of failure. I've been a fear-mongering business. I also live with fear of failure. It's this constant idea that imagine that something happens out there and there is no security solution. And today we're delusional people like you doing these podcasts, these cool CEOs of building all kinds of new tech and like you barely understand half of them. Oh, we're gonna do open-weight models versus close-weight models. Well, how do I figure out what an open-weight model is? Well, you sit down and say, well, now you got an open-weight model. What are the consequences from a security perspective that it changed the game? What do you do with agents? Oh, shit. We got agents now. We do security updates. How do I find one in the first place? Well, they're gonna be all over the place. So we start thinking about it and bring about to people to go and say, dude, these things called agents, where are they gonna be? Well, they're gonna be everywhere. They're gonna be in SaaS software. They're gonna be in infrastructure. They're gonna be in all-empranable. How do we collect them together? I don't know. I gotta figure this out. So we then start looking at the market and saying, "Is anybody working on this problem? How are we thinking about it?" And that's where we find out, oh, these guys are thinking about it the same way we are. They started thinking about it one year ago. That's cool. What do we do? Should we build it? Because they're thinking about the same way or should we acquire them? You talk to them and saying, "Do you wanna come like, no, we're gonna be so big? We don't need you." They can move on. So there's a whole sort of discovery process of, what is the technology? What are the implications of security? How do you solve security problems? How do you think about it? Where does it fit in our portfolio? Is it gonna be big? If so, should we build it? Can we build it or are we late? And should we also, at the same time, look at what's happening in the market, what we do, and decide to, well, probably better to build it because it's gonna be more complicated to buy that integrated or it's just better to buy something because it's a lot easier for us to go run with it because they're ahead. - Homsa mentioned when we were over there that you do see things many years before. Like you're very good at predicting things. Like the SaaS apocalypse. - Well, actually, I didn't predict the SaaS apocalypse. I thought you did. Well, I predict the end of the SaaS apocalypse as opposed to the beginning of it. The market got ahead of itself. I think when AI came out, I think people started trying to predict what's gonna happen to the AI. There's this notion that AI is gonna eat software. And the market indiscriminately decided that every software company was destined to zero. And he saw the entire SaaS market went down 50%. He said that and saying, "That's makes no sense." AI can be great at finding vulnerabilities. AI can be great at 80% use cases. We live in the 0.1% use case. We're looking for the needle in the haystack. AI is not good at looking at every needle in the haystack. We write machine learning code. We look for a whole bunch of which attack techniques. We find the 0.1% use case just the way somebody goes and tells the car we return. And that's a tree. And that's the edge case. AI doesn't understand every edge case. It does the mainstream case. So we declared the SaaS apocalypse for cybersecurity was over. We did not believe that we were gonna get impacted. And you can see, now that was six months ago, we seem to be having a moment. What do you think though about the broader macro market? Do you think that some of these companies will actually not recover? What do you mean? Some of these companies are down like 90% and still haven't. Look, that's a fair question. I think every company is different. Every company is different in terms of what the capability they bring to the market or the market believes that either that capability is gonna be par for the course. In AI. I think there's a lot of questions in terms of what the native capability of AI model is gonna be. And if that native capability is exposed to me, you as a consumer or as a professional, do I need to buy the package software that existed that's all they're problem before? And is it better or worse? I think some of those categories, the market has already declared those companies dead. In certain categories, the market is wondering, you built software 15 years ago. There's a new game in town called AI. The shape of software is gonna change. The market is making a judgment call whether you, your team, and your product will survive this transition to AI. I think all that is happening so each company is different. And in the fun of the level, I believe we spend a life-building software, it had no opinion. If you bought software and it did kind of determine the stick tasks, the future software will come with an opinion. Your AI doctor will actually have an opinion. But somebody has to train it, somebody has to give a context, and it has to learn. We can build intelligence into our products. If you build intelligence into our products, they will come with an opinion. None of the software in the last 20 years came with an opinion. So the entire software industry will get rewritten in the next 10 years. And the market is making a judgment call which ones of these categories will survive, which on these companies will survive. Possibly getting a bunch of them wrong, we'll see. Time will tell. - What do you think the biggest question is that people are not asking right now? That's a hard question to answer. Like I don't know what question. I don't know if it's a question per se. I think the market is in a way confused. And you can see that every day. That something's go up rapidly for a week and suddenly they go down rapidly for a week because the market changes mine. Some of the long-term trends are obvious. It's obvious that this technology is big enough that it is gonna have a long far-reaching impact in our lifetime, so the next 10s of years. I think this is the early days. It's also clear that this technology is extremely compute-consumptive than it is a technology in the past. We need to build a lot more capacity around the world and you can see that in the prices of, in the elements of what goes into building compute. You can see that energy prices, you can see that nuclear, you can see that in generators, you can see that in states saying, I don't want more data centers, I'm applying. I balls in data centers, you're seeing all of that. But it's clear that there's gonna be a huge demand going forward. I think it's also clear that every one of us believes that our personal AI should be able to do a lot more and it's going to need to get better, right? I'm sure you are an avid user of some version of cloud, Gemini or OpenAI. Are you? I use like all of them. - All of them, right? - Literally, Grog, OpenAI, Cloud. - What do you use them? Have you ever got yourself thinking, I wish it could do more than what it just did. - Every day. - Right? - I get very frustrated with them. - Right. So you're telling me this thing's not as good as it needs to be? - No, it's definitely not. - Which means somebody's gonna have to train a lot more, get a lot more compute, get a train, get better, right? - Yeah. - So that means there's a demand for capacity in the next few years. We're gonna have a lot more capacity demands on AI because we're gonna train them all the better, Make this until something. gets smarter. A lot of us in enterprise are frustrated because it doesn't understand edge cases. Why can't it be smart to understand? It was so smart here. Why not? It's here. So we're all waiting for it to get more capability and more capacity. So I just think this is an unstoppable trend that's ahead of us. I think we're underestimating demand across all dimensions of this, whether it's computer intelligence or what these models are capable of, which means there's going to be tons and tons of development. I think every piece of software is going to get rid of every consumer application you use. A lot of the applications we use are phones that we were used to using them. It's a lot of UI involves a lot of manual work involved. If you guys are going to be so good at being an agent and using an MCP server, it's going to fix all that stuff, right? So there's lots of stuff that's going to happen that needs to get done. So this tremendous demand, the market is just going through this digestion phase of figuring out what generations are going to cause which think to be overvalued to undervalued. Compute is a huge topic. We were just interviewing fall, yesterday, June of fall, generative media AI company. They do both compute. They also have APIs and all the other kinds of layers, but they started as compute. And then they noticed with all these video models, the voice, the 3D, like audio, all this kind of stuff that's going on, those ones are really just starting. Yes. And there's tremendous demand and those ones are going to need more compute than anybody else. So we were talking through all the different layers of that and like all the Neo clouds that are coming out and how even with hyper scalers, I was talking to every who it was, but it was at the raise summit. I think it was Andrew Feldman from Surieberg. And he was talking about this. We were talking to CJ at MongoDB and he was saying hyper scalers are turning away their top customers because they don't have capacity. Yes. So how do you think about that as a CEO in this era with everything changing around your customers and your company and all this kind of stuff? Look, everything you said is true. There is a constrained and compute right now because there's too much demand. Everybody needs more compute. Your video model friends need more compute to be able to build better videos and edit them. Your chat GPD needs more compute to be smarter to be able to satisfy and not have you frustrated. Your enterprise models need more compute because we need to put more intelligence into our enterprise capabilities so we can write software with opinions. So that's the point. The way you think about it is in for a very long build phase in the industry. I think the next 10 years is highly possible that 10 to 20% of our operating spend moves more towards technology than it already has. There's a huge amount of spend that's going to happen in technology that happen in people who are going to need more AI ready people so I don't buy the jobs argument. I think we have so many things to do that not enough people to do it. Either it's retraining or hiring more people that go to understand the AI stuff. I think in that process of technological upheaval people are going to want more robust security infrastructure. So from that perspective you know the demand is there. You just have to make sure we get both products, new products that serve the demand. And also we have to make sure that our existing products don't fall short in customer's expectations or AI must be embedded into those products as well. How do you think about this with your workforce? Are you checking on people if they're AI native? We've interviewed some CEOs that are really strict about this. It's very hard to check on people who are AI native. You know, deploying little tests? I think there are two or three things you can do. One, what we're doing is when there's no expert, the people learn from each other. So twice a week I run this meeting, AI O. It's like you all make a call. It's not EA. It's AIO. We get the top 24 technical people on a call every two days for two hours in the morning. And they walk through what they're working on, are they thinking about it, why they're doing certain things. So it suddenly gives more strength to the other 22 people to understand, oh my god, this person is a smart engineer. Here's how he's thinking about it. They get a chance to ask questions, they get a learn from that person. And by so we do that every twice a week so that people start understanding what's important, how do we get it. At a more micro level that's happening in teams, you know, we will take a team and say, okay, go out and take a third of your workforce and make sure you're hiring into hackathons because they're learning themselves. I think those are the two AI native people. We infuse those AI native people under team and say, keep hiring until you get to make sure that these people are more people than that team than people who've been there before. So once you start overwhelming these teams with more AI native people, you start watching that you start seeing a change in behavior. Feature start getting out faster. Some of the people who've been there for a long term who haven't played with the AI start playing with more. So you literally have to create sort of a transformation. And if enough people start being part of the transformation, I think some people who don't get it will self-select out. So that's the approach we have. It's unlike the approach of some other people who say, oh, I don't need a third of my people because they're not going to get it. That's not the way to do it. When did you start hiring from hackathons? About I'd say nine months ago. Really? How did you come up with that idea? How am I going to know that if you know how to use open-claw, well, how am I going to know you understand what an agent is? If you're not playing with it already, you're not sitting going back home from work saying, can't wait to get my hands on the new development that came out yesterday or use Azure Foundry or use Anthropic. If you're not going home and figuring yourself out yourself, that's a problem. If you're not curious and not learning, where am I going to find these people? Damn. It's pretty creative. So before speaking with you, I spoke with Carl who's on your board. And I asked him, like I asked many people who's around this office if they have any questions for you, anything I should ask. For some reason, no one in the office would answer the question besides Lee. And I'll ask that afterwards. But with Carl, he mentioned he was on the hiring board. He was on the team when they hired you and that you were a bit of a controversial hire. Most likely, yes. I would be controversial hire for sure. I've never done cybersecurity in my life. This is a cybersecurity company. Never been a public company CEO. This is a public company CEO job. And I had never so much enterprise. I was a consumer guy. Other than that, they got everything right. So yes, it must have been controversial. I was in the room. What was your learning process and getting up to speed like? It bossed a student room all the way. Do you still have that? Possibly sometimes. Yeah. Because I didn't grow up in this stuff. That's why I'm blessed to have people like Lee around. When I started, I had Lee and near-zoop around me. And I'd sit in meetings to learn a few things. Keep looking at Lee, what he thought about what I said. Ask him after everybody left. And then I'd call them in my way home. I'd not call near the way in and say, "Hey, and what do you think?" I spent all this time trying to get it out of people in terms of what they thought. In over time, I started understanding the pattern recognition in terms of what works, what doesn't work. And cybersecurity was the right thing to do. We did our first acquisition because we wanted to do something in space. We had no capability. So you learn over time. I began to learn. I still rely a lot on him and other technical people in the company. His question was, "Why do you like LinkedIn so much?" You know, there is a conspiracy. There is a conspiracy in my. I think other people didn't ask you to ask me questions because they all pedate to him. Really? The conspiracy is what happens is, in my moment of paranoia, I'll go troll X and LinkedIn to see what's going on in the market. I'll see a post from some of our competitors. I'll see a post from somebody about something. And it's probably between the hours of 430 and 630. People will get a copy of that LinkedIn post and say, "What are you going to do about this? What do you think about this?" That's why he's like, "Oh, these shit. He's LinkedIn again." Has that ever led to making pretty big business decisions? Yes, our general counsel, I hired a LinkedIn. I had a dinner last night with somebody who I found a LinkedIn because I think it'd be great for our company. So, damn, it's a great place to find people. You get to go look at everything they say if they're intelligent or not. They're not interviewing when they're posting a LinkedIn. If I can read what people have written over the last 40 years of LinkedIn, I can tell you who they are without having to ask them. I bring them in the room for half an hour. They'll, you know, if you can't fool me for half an hour, then you shouldn't have worked anyway. This is like probably one of the hottest takes. I don't know anybody who likes LinkedIn. I think it's said the way to think about it. I started a Google in 2004. And when you work at Google, you build this sort of thing where you don't meet someone before you Google them. Obviously, I can find out a lot more information about this person, this product, this cable because I work at Google. Not that you can't because there's no special Google version for Google people. But, you know, you become this becomes, of course, not. It becomes part of your sort of the way you do things with Google people. And then again, the more like, well, if there's any information I can have, I should have it. So, by definition, I will go find out whatever I can. Now, LinkedIn and Excel are wonderful places to find out what's happening, both from a business perspective and from a technology perspective. So, my team doesn't like that because then I keep sending them the only things like, I might tease client. I don't have time to answer your questions. What does a typical day look like for you? Like, broadcast in the afternoon, breakfast in the morning, golf in the evening, just kidding. Enterprise jobs are interesting. They're, let's say, 1% inspiration, 99% perspiration. So, in some ways, you perform either you're fixing a product, you're adapting strategy. You're trying to hire people in places or you're trying to meet customers. But, look, I joke that every job in the company which requires some accountability is already taken. Like, I have a CFO. He's responsible for finance, I have a marketing person. It's like, I kind of don't have a job, right? My job is to orchestrate these people in the strategy. So my job is to set the note star, define the strategy. My job is to make sure I resource the note star. If I want to go, but when in this, I just need to understand how many people it takes, how many hours it takes, what other things do I need. And then give it to the right people. Then my job is to remove obstacles from their way. And of course correct them, they're falling short. That's the job, right? This course correcting, getting people lined up behind you, making sure that you have the right people, the right place. But when I came to Paul to, for the first few months, they all sat and looked at me, who is this guy? He was strange. He has different ideas. What would he about? Then I realized we didn't speak the same language. Didn't understand me. So I sat back on a week and I wrote down something called my belief document, which basically describes why I do certain things in a certain way, what I believe. And then I walked up on a Monday morning and say, "Alright guys, here's my belief document." This is why I act the way I did. Now we can debate this. Once we debate it, I'm having to change certain parts of it if you don't like it and if I agree. But once we decide this is the way we act, then we're going to act like this, for example, I get really tough on hiding senior people. I want to spend time, I want to understand who they are, I want to have references, I want to meet that person. And people obviously, "Why are you slaying me down?" I need to get going and I need to hire this person. I'm like, "Listen, you hire the wrong person. They have 500 people work for them. It means firing people in my organization that's headed in their own direction, not climbing the mountain, I want them to climb, not doing the way we all want to do it. So it's an important hire. I'd rather have nobody into it myself until I find the right person." Like, explain to like this, like, "Well, I get it. Otherwise, I was just stopping saying, "You're not hiring that person." I was like, "Oh my God, he's frustrating. He's not letting me hire people." I'm like, "No, I'm not letting you hire people for reason." So sometimes you realize as leaders, we don't communicate the why. You spend, you just tell people what. Go do this. If you explain the why, people actually do a much better job. They always do the same thing. People don't come to work to screw up. It's like, "Good morning. I'm going to go to work. I'm going to do the worst possible job I can." That's not how people do it. They all come to say, "I'm the best." And at the end of the day, it says, "Holy shit, I didn't do the best." Or somehow my boss wasn't happy because he seemed or she seemed like they weren't happy with what I did. Maybe you aren't communicating. Today's episode is sponsored by VCX by Fundrise, the public ticker for private tech, allowing investors of all sizes to invest in venture capital. Learn more at getvcx.com. Some of you may not have heard this yet, but our sponsor public just launched something called generated assets. And it brings AI into investing in a way I've honestly never seen before. Here's how it works. You type in an idea like AI-powered supply chain companies with positive free cash flow or defense tech companies growing revenue over 25% year over year. Public's AI then dispatches a swarm of agents that scan every single US stock, evaluates them, and instantly builds a custom index around your thesis. What really stands out is how clearly it explains why each stock is included. And before you invest, you can even back test your idea against the S&P 500. So you're making decisions with real context, not just guessing. And beyond generated assets, public lets you invest in stocks, bonds, options, crypto, all in one place. They'll even give you an uncapped 1% match when you transfer your investments over from another platform. If you want to build a portfolio that actually reflects your thesis, visit public.com/sorcery, paid for by public investing, full disclosures in the description. Founders scale faster on deal, set up payroll for any country in minutes, hire anyone anywhere, get visas handled fast, and get back to building. Visit deal.com/sorcery. That's D-E-E-L.com/sorcery. I have two questions. What were the changes that you made if you made any? And two, what are the key traits you look for in leaders? I did make changes over time because we morphed our business from, you said, to the 18 billion dollar business to a much bigger business that acquired us to get new product categories, sell new things. So you need people. I have this framework that basically says, "I mean, everybody has?" Have you? My mom, I grew up my mom built houses, so. Lots of them. You build a house. You have an architect, right? Well, it's their job to build this beautiful aesthetic. Here's what it needs to look like. It has what's going to be beautiful. Then they do a bunch of drawings and you get a builder. Here she starts building the house. And then when they're gone, there's a person who comes and maintains it, like, you know, makes sure it's stuff's working. You never let a maintenance person be the builder. Would you? That would be a bad idea. No. You would never let a builder architect your house. Because they may not have the design aesthetic. You probably don't want an architect building your house either, because they don't have the capability. Yet, at work, we expect our people to be all three. They say, "Have a new idea. Great. Why don't you architect the idea?" Then you build the idea and make sure when it's working, you run the idea. And all of us have a different mix of capability amongst us. We're part architects, part builders, part maintenance people, and everyone's different. So for almost every leadership job, I need part architect, part builder. And if I get someone who's too architecture oriented, I need to make sure they're coupled with the best builders in the world. So I think building teams is a combination of finding that fit amongst people. And that's my job as a leader, is to build a team around me that is part architect, part builder, and know who's capable of what. And then make sure they have people with them who can't do so. It's not like, you know, there's a consistent set of creates across people. It's always a combination of people in terms of what they can do. Yes, but there's the basic level of smarts they must have. Because if you're not smart, if you're not creative, there's a risk you will miss the inflection, you will miss the. And then you have to have a little bit of. What do you call it? Super-gas it? A little bit of. A little bit of. The just do it. Go get it attitude. How's that? Agency. There you go. We all have a little bit of agency in us. I have to give the agency. If I don't give agency to people, then they feel constrained. So yes, we all have to have a little bit of agency from people. My board gives me agency. I give my team agency. But I only give agency to my guardrails and training. Otherwise, your agent is going to do shit you don't want to do. So where did that develop for you? How do you get this. Some people call it a chip on their shoulder. Where did that come from? The chips are high demand. Yeah, it's okay. No time to have the hang on your shoulder. Sull them. They get for a whole price. No, it's not a matter of chip on your shoulder. I think it's learned behavior, right? Over time, you understand businesses, you invest in business, you operate business, you figure out what patterns make it successful, what patterns make it not so successful. So you've got a pattern recognition over time. You figure out the right things, you know? I'm sure all of us have the right things that haven't worked as well as they should have. And I'm sure you've tried things that are worked out spectacularly. I want to ask you this because you have such a unique perspective of all the points in your career. What was the day-to-day like at Google and at Softbank? Because you explained out really well what it's like here and how it's changed over time, too. Google's a great place. Still is. It was a great place when I was there. Because remember, Google had this interesting business, right? Where we all kind of spend time on search and Google had built the best or had built the best commercial model around search in terms of how to monetize it in terms of such advertising. So, for the most part, Google was a scale problem. How do you keep scaling the business such a way that the business keeps working, nothing goes down, nothing fails. There's constant innovation in the pipeline, which keeps attracting more and more consumers to consume these internet kind of services, whether it was search, whether it was YouTube over time, and then how do you build a monetization harness around it, whether it's search ads or video ads, etc. I believe that most companies take on the form of their leader. Larry Page had this firm believe that great products win and Google is product obsessed. If you think about it, there's so many products even today don't make money. Right? Gmail doesn't pay for itself. Even I get Gmail for free. There's Google Maps doesn't make as much money. But it was a product. You know, Google Chrome doesn't make money. There's so many products that Google built over the years, which are great products which didn't think about a monetization model because that was the philosophy. Go build a great product. If it's great, we'll pick it out of way to monetize it or else it's going to contribute to the brand. Like, it's a good news. It's a kind of word. And as I said, it's a bit of a scalability thing. Now, it's the same thing. We take on the form of leader. He's the oldest man I know with the risk appetite of fattening her. As he gets older, his risk appetite becomes bigger. He keeps things very simple. And he's very focused on winning. I remember he told me once, I made an investment with him in a company and he saw me a bit disturbed. He saw me grinding away talking to CEO multiple times a week. So what are you doing? So I'm trying to talk to the CEO because we invested six months ago. We thought this was going to happen. And I think we need to coach him because he's down 50 percent for what we thought it was going to be. He can coach him. We can get him back on course correction in six months. He should be back where we started and then he can go from there. He put in that much effort on the company that's doubling their quadruple. We might make more money on the one that quadruples than you fix the one that's broken. That was an insight from him to me. As operators, tendencies try to fix everything because we don't want things to break. As the investor said, double down on your winners. They're going to be even more interesting for you than the ones that are in the video. They're gonna not make money. Concentration and power law. Something like that. Yes. See if I knew all those words then. So I know we're well into the conversation, but is there anything that we have in cover that you wanna talk about? There's no but anything you want. We can talk about the eye, we can talk about spending, we can talk about what do we want. So we had a special guest in here earlier. Can you explain who your newest intern is? Oh, my son was going to do everything. He loves coming hangin' out here. And he was very intrigued by all the cameras being put and all the stuff being arranged because some famous podcast was gonna be here. So he came over and he sort of spied with you. And today he wanted to see the fruits of his labor. So he came by to see what a podcast looks like. I think he's become the newest intern in our comms department. I mean, he'd be great. I mean, you should have him run some strategies over there. I don't know. Does he have any content ideas for you? He's always full of ideas and how I should do things differently but it'll be better. So. I was curious. So as we think about the next 12 months, I know you think a little like you think two years out or so. Do you think one? Do you think that will compress? Has that compressed over time? You're gonna think two to five years out. I think that the base at which we are, things will happen much faster than the used to. You just have to believe that what will happen, what you thought was gonna take five is gonna take two. It's always gonna take five. It's a step to change your horizon in terms of what you wanna think. I think if you go back and think about when we went through a technological sea change last like this, was in the late 90s with the internet. There was crazy evaluations on certain companies because people thought that these things were gonna grow infinitely and we're seeing a bit of a phenomenon at this point in time. Similarly, with the markets perhaps getting ahead of itself or not, where it believes there's infinite capacity, infinite demand for you. Which I think there is, I think it'll be interesting to watch. Some players will move around because the market moves so fast in terms of capability. At the present, the market is pricing in perfect execution for every company. Every idea that you see, the market wants to reward it because it thinks that their returns are outsized and the gains are gonna be so huge that it doesn't matter even if you fumble your way to some amount of success that's gonna be a lot better than we are today. I think two years from now, that would become less apparent. I think the market would have figured out it's fair shares of failures and successes. And the market will get more discerning, which is what typically happens at that point in time in the cycle. It usually takes five years, but then we talked about compressing time lives. I think it doesn't take away from the immense appetite for AI. It doesn't take away from the amount of reimagination and redevelopment that's gonna be needed from a software perspective. But yeah, I think the market could go through some stumbles and bumbles, but it would cost next two to five years. One of my favorite questions that we ask every interview is a partner question. So one of my partners is Brex. They're the performance credit card. They're super intelligent finance. I was an investor in Brex when it just started. Before the acquisition? I was an investor at a billion dollar valuation when they were my daughter's door at that. My son and my wife's door at that. No way. I know him really care really well. Yes. Oh, amazing. So this is great. This is my favorite question. So because they're all about performance, I like to ask people, you've had an outstanding career. You've learned from Larry, you've learned from Mossa, you've learned from yourself, you've learned from Lee, you've learned from everybody in this office every day. But I'm curious if there's anybody throughout that arc that has really inspired you and kept you motivated. I struggle to find one role model in life because every role model has certain parts of their life that you don't want to emulate. But there are certain parts you do. And I think you don't have to spend time with an insescently, but you obviously get a chance to spend time. But like, take Elon. And what is not there to get inspired by him? He built electric cars, which when people didn't think electric cars existed, he put a rocket up in space. He's got things landing in Mars and Moon. And things he's done to his NASA was funded for years and didn't do as well as he's doing them. So when he puts it, you've got starlink. You've got satellites that were sticking them on cars, boats and planes to make sure that we have a connectivity. And so there's tons of stuff that he's done, which is so radical, which none of us have thought. And I think the principal, he's explained to us there, if you take a really hard problem, nobody's working on. If you get it right, you win. And you win big. And if you look around, you have a lot of entrepreneurs that are busy trying to solve small problems because this is the problem they can see. They can see that far to solve the problem. Elon cannot see when he comes up with a problem he's trying to solve. He can't see that far, but he thinks he tries to put his mind to it. They're trying to solve it. Like, you know, we're talking about space, companies, space, manufacturing, space, mining, space data centers. Shit, no, no, don't know how it already started, right? But they're out there thinking about, and a bunch of people thinking about it. I think that's inspirational. I think you look at Masa, he's got an crazy appetite for risk. And he's taken that business, which used to be a software bank, used to sell software, back his software and he started his company. And he's paid it 20 times since then. He's been a richest man in the world and he's become poor. He's a richest man for 80 some days. I think back being poor nothing has gone back and built himself. So these people are inspirational for different reasons. For their creativity, their innovation, their big thinking, for their relentlessness, for their persistence. People like Larry, you know, there's so many people who can inspire you in different aspects of life. So you said to find the person to inspire you for the particular thing you're looking at. I was somewhere last week, I went to a conference and Steph was in stage peaking. My son was there listening to him. My son was obsessed with basketball. And Steph talked about this next play mentality. It's like, you can't win if you can't get it as a lost play that you missed. You got to focus on next play. That's kind of, that's an interesting lesson, whether in business or you're in sport. So you can find different people to inspire you. As you get more and more successful, how do you continue to find people that challenge you and don't just become a businessman? Oh, I'm constantly feeling like I'm an underachiever every time I look around. There's like young people running large hedge funds who've done so well and investing until the time they go back and reinvent themselves. There are people who put stuff on Mars. Compared to their achievements, I'm just running a regular cybersecurity company trying to make sure that you know, you protect the world. So what comes next? Next comes tomorrow. And tomorrow is going to be wonderful day. It's going to be beautiful. We're going to wake up really excited about the day for work hard and we go home really excited to hang out with the family. And then the day after, what is the same thing? Pretty good answer. You don't have to. The problem is if you set too many expectations on yourself, you're bound to feel disappointed. But if you don't set that high in expectation, if you set an expectation on doing your best, then good things will happen. Were you always this calm? This is my calm in terms of. It's kind of the karmic calm. The karmic calm is that you have to try to do your best. You had to put it hard and soul into it. But do you see it gets kind of contradicting? I understand. Life is contradicting. But you're also like, it'll be okay. Life is a series of contradictions. It's the yin and the yang. If I sort of torque myself up every time and I start feeling freaked out if I fail, something doesn't work out. I'll be a mental mess and I won't be able to make anything happen. So I have to work in a principle to do your best and then things will take their course. And if it works against you, wake up in the morning, shake it off and do your best again. This is an explain mentality. You get hung up on what happened yesterday. You won't be good. You can't be somebody else. If you be somebody else, then you lose all the other things that are you about you. So, yes, you can be all the things I said from a go get chit-dun, be paranoid because you want to win. The same time, you have to have some degree of inner calm. Do you be able to deal with the moves, the pressures, everything of the job? Good notes. AI psychosis over here, I guess. There's no AI psychosis. Amazing. It's a great positive, optimistic way in place to end it. Nikesh, thank you so much for taking the time, letting us rearrange your office. Thank you for coming all the way here. We appreciate that. Thank you. My pleasure. Thank you. Hey, it's Molly. If you enjoyed our interviews, check out our newsletter, sorcery.bc, where we deliver a once a week top deals and tech headlines email and also go deeper on our podcast interviews. Subscribe to sorcery today. And don't forget to subscribe to the podcast on YouTube, Spotify, Apple or wherever you listen. Link in description to sign up.

Podcast Summary

Key Points:

  1. The speaker emphasizes that AI-driven cyberattacks are becoming easier and faster, with vulnerability discovery-to-attack times compressing to minutes, while traditional patch times average 55 days.
  2. Palo Alto Networks launched a capability to deliver and deploy patches in four hours, reducing response time dramatically from the industry standard.
  3. The speaker believes the entire software industry will be reshaped over the next decade due to AI, with cybersecurity becoming critical to protect infrastructure.
  4. AI models like "Mythos" (likely a reference to a specific AI tool) have increased executive awareness of vulnerabilities, driving demand for proactive security testing and modernization.
  5. The speaker discusses the need for governance and liability frameworks for AI, noting that models are powerful but responsibility for their actions remains unclear.
  6. They support open-source and open-weight models to foster innovation, but emphasize the importance of contextual training data and guardrails for safe deployment in real-world use cases.
  7. The speaker explains their approach to business growth, focusing on long-term strategy, M&A (e.g., acquiring 40+ companies, including CyberArc), and anticipating market shifts to maintain durable growth.
  8. Cybersecurity is described as the most innovative industry due to constant adversarial evolution, requiring continuous adaptation and investment in new technologies.

Summary:

The speaker, a leader at Palo Alto Networks, argues that AI is fundamentally transforming cybersecurity by making attacks faster and more accessible. They highlight that AI models can now discover and exploit vulnerabilities in minutes, whereas traditional patch cycles take an average of 55 days—a gap they aim to close with a new capability delivering patches in four hours. This urgency is driven by tools like "Mythos," which have heightened executive awareness of security risks, pushing companies to modernize infrastructure and adopt AI-based defenses.

The speaker stresses that while models are powerful, the industry over-indexes on them; success requires robust contextual training, guardrails, and governance to ensure safe deployment in real-world scenarios. They advocate for open-source and open-weight models to spur innovation, but also acknowledge the need for liability frameworks to clarify responsibility when AI acts autonomously. From a business perspective, they describe a strategy focused on long-term growth, using M&A to fill gaps and anticipate market needs, even when short-term investor reactions are negative.

Finally, they emphasize that cybersecurity is uniquely innovative because adversaries constantly evolve, forcing companies to stay nimble and invest in new technologies to protect against emerging threats. Overall, the speaker is optimistic about AI's potential but insists that cybersecurity must be prioritized to enable safe adoption across industries.

FAQs

The average time to fix a zero-day vulnerability is 55 days, but Palo Alto Networks launched a capability to deliver patches in four hours and deploy them to all customers.

AI makes it easier to attack infrastructure by finding vulnerabilities rapidly, but it also helps defenders by compressing patch times and enabling proactive testing, shifting the advantage to cybersecurity companies that adopt AI.

Mythos is a powerful AI model that can find and daisy-chain vulnerabilities, attacking infrastructure in minutes, which has made CEOs pay attention and driven demand for better security measures.

They signed to ensure no constraints on innovation, as open-source and open-weight models allow global deployment at various price points and enable fine-tuning for specific use cases, which are important for the AI ecosystem.

They focus on long-term strategy, anticipating market shifts and acquiring companies (40+ in eight years) to fill gaps and stay ahead, even when the market initially disagrees with moves like buying CyberArc.

Because attackers constantly find new ways to breach systems, forcing companies to innovate and acquire new technologies to protect against evolving threats, making M&A essential for staying competitive.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.