Palo Alto Networks CEO Nikesh Arora just put a staggering price tag on the cybersecurity industry's AI problem. Roughly $1 trillion worth of legacy security infrastructure, he says, simply wasn't built to handle AI-powered attacks, and enterprises everywhere are now scrambling to catch up. It's a warning shot for every CISO still running yesterday's defenses against tomorrow's threats.
Nikesh Arora doesn't mince words when it comes to the state of enterprise security. The Palo Alto Networks CEO says roughly $1 trillion worth of cybersecurity infrastructure sitting inside companies today simply isn't built to withstand the new wave of AI-powered attacks, according to CNBC. That's not a typo. Trillion, with a T. And it's the kind of number that tends to get boardrooms moving fast.
The comment lands at a moment when AI is reshaping both sides of the security battlefield. Attackers are using generative tools to write more convincing phishing emails, automate reconnaissance, and probe for weaknesses at a scale human hackers never could. Defenders, meanwhile, are still running plenty of infrastructure built for a pre-AI world, systems designed to catch known malware signatures, not adaptive, machine-generated threats that mutate on the fly.
Arora's framing suggests this isn't a niche problem confined to a few laggard industries. A trillion dollars in outdated infrastructure implies this is an issue baked into the fabric of enterprise IT everywhere, from banks to hospitals to retailers, most of whom have spent decades layering security tools on top of aging networks rather than rebuilding from scratch. Palo Alto Networks has positioned itself as the company ready to fix that, pitching its platform consolidation strategy as the antidote to fragmented, legacy-heavy security stacks.
It's also a convenient narrative for a company that just posted a strong quarter. Palo Alto Networks has been on a run lately, with its stock climbing on the back of solid earnings and growing demand for AI-driven threat detection. Framing the market opportunity in trillion-dollar terms isn't just analysis, it's also a sales pitch aimed squarely at enterprise customers still dragging their feet on modernization.
The timing matters too. Cybersecurity spending has historically lagged behind the pace of actual threats, with companies often reacting to breaches rather than getting ahead of them. If AI is genuinely accelerating the sophistication of attacks the way Arora suggests, that reactive posture becomes a lot more dangerous. Security teams that once had days or weeks to detect an intrusion may now have hours, as AI-assisted attackers move faster than manual defenses can respond.
Competitors aren't sitting still either. CrowdStrike has leaned hard into AI-native detection with its Falcon platform, while Microsoft has been bundling AI security copilots directly into its enterprise suite, betting that customers will want protection baked into the tools they already use rather than bolted on separately. That competitive pressure is part of why Arora is talking up the scale of the problem now. Whoever convinces enterprises their current stack is obsolete gets first crack at replacing it.
What happens next probably plays out over years, not months. Ripping and replacing trillion-dollar's worth of infrastructure isn't something any CIO does on a whim, budgets are tight, migrations are risky, and plenty of organizations will patch around the edges before committing to a full overhaul. But Arora's comments put a number on an anxiety that's been building across the industry for a while now: that the defenses built for yesterday's internet aren't ready for an AI-accelerated threat landscape. Expect more vendors to start quoting their own versions of that trillion-dollar figure in the coming quarters, each hoping to be the one enterprises call when they finally decide it's time to rebuild.
The headline number is designed to grab attention, and it does, but the underlying point is hard to dismiss: a lot of enterprise security was built for a threat model that AI has already outgrown. For readers in IT and security roles, Arora's comments are less a prediction and more a nudge toward a budget conversation that's probably overdue. The companies that move first on modernization may end up setting the terms for everyone else who eventually has to follow.