CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy · Terms of Service · Privacy FAQ

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Palo Alto Networks' Nikesh Arora is building a defense against the dark side of AI

From Fortune

By Allie Garfinkle

September 30, 2026

Palo Alto Networks' Nikesh Arora is building a defense against the dark side of AI

Palo Alto Networks' Nikesh Arora is building a defense against the dark side of AI

In April, Nikesh Arora applied a simple but unsettling test to his $300 billion cybersecurity company, Palo Alto Networks: He turned loose on the company’s internal infrastructure an unreleased version of a terrifyingly powerful new AI model called Mythos, created by the artificial intelligence company Anthropic. Arora’s team prompted it to find vulnerabilities in the company’s systems.

Claude Mythos 5, Anthropic’s frontier AI model for advanced coding and cybersecurity work, was so effective at hacking into systems that the U.S. government has sought to limit its release. It even temporarily imposed export controls on Mythos and a related model called Fable in June, a move that forced Anthropic to disable the model for all users. The government subsequently allowed the company to restore access to Mythos for a small number of vetted U.S. users, and later allowed Anthropic to make it available to select users in 15 other countries.

At Palo Alto Networks, the results of the controlled test were troubling. Mythos surfaced weaknesses in Palo Alto’s systems at a speed and scale that Arora immediately knew would change cybersecurity permanently. He also realized that Mythos—and competing models from Anthropic rival OpenAI—had created “the best marketing moment for the cybersecurity industry in history.”

The model’s capabilities made tangible a nightmare scenario where attackers could, almost instantly, find the sorts of vulnerabilities that could be used to cripple the infrastructure that runs our lives, from banks and corporations to hospitals, airports, and governments. That realization—along with several recent incidents involving AI agents “going rogue” and rising concerns about an AI-driven doomsday scenario for humankind—has led several leading AI vendors, including Anthropic, to call for a coordinated slowdown among the companies building AI systems, to allow the safety measures to catch up.

In short: For cybersecurity, AI is likely to be an unprecedented driver of growth as well as an existential challenge. The exigencies of the moment are placing Arora, Palo Alto Networks’ straight-talking chief executive, at the center of a widening reckoning in tech—and are making him a sought-after counselor to the leaders of AI companies and other CEOs.

Prior to Mythos, Arora says, when he called a company to discuss cybersecurity, the answer might as well have been, “Sure, stand right by the insurance guy.” Now, he says, “for the first time, CEOs want to see Mythos, they want to talk about it.”

At the same time, Mythos and its ilk have created some powerful new competitors for Palo Alto Networks, as leading AI companies are looking to directly sell their own models as cyber defense solutions. Lee Klarich, chief product and technology officer at Palo Alto Networks, doesn’t see this as a major threat. “I don’t believe companies will trust the big AI labs to provide their cybersecurity,” Klarich says. “So, in that context, I think Nikesh’s voice rises above all others.”

Interestingly, one of the leaders who has turned often to Arora for advice in recent years is Sam Altman. The OpenAI CEO is the first to admit that the powerful capabilities of the models his company is building have changed the risk equation for companies everywhere.

“Just a crazy amount of work has to happen to avoid major cybersecurity problems,” Altman tells Fortune. “I think it’s going to be hard to patch every bug on the internet. We need a new model of cybersecurity here.”

That’s exactly what Arora is trying to build at Palo Alto Networks, which was cofounded by the Israeli cybersecurity entrepreneur Nir Zuk in 2005. A firewall provider originally, the company has always sold products that prevent and remediate cyberattacks. Under Arora’s leadership, the company has grown and focused intensely on security in the AI era.

“Just a crazy amount of work has to happen to avoid major cybersecurity problems. We need a new model of cybersecurity here.”

OpenAI CEO Sam Altman

These days, Palo Alto Networks is a sprawling platform spanning areas including network, cloud, identity, endpoint, and observability. The company’s customers include some 95% of the Fortune 500. Tyson Foods and Colgate-Palmolive use the service, as do the National Hockey League and Major League Baseball. Palo Alto Networks even secures the Sphere in Las Vegas, one of the most targeted digital spaces in the world.

No one wholly agrees on what the total addressable market for cybersecurity is, though all estimates of its worth are in the hundreds of billions. Jonathan Ho, partner and tech equity research analyst at William Blair, believes AI is an unmitigated tailwind and “cumulatively, probably doubles the size of the market.” Palo Alto says it currently controls 6% of that market, and Arora is confident it can grow its footprint.

Indeed, for whoever can solve the cybersecurity conundrum of the AI era, it’s a moment of generational opportunity. But Arora is also clear about the risks in this landscape, where assumptions of the past can evaporate and the baseline is crisis. “You can’t solve the crisis,” Arora notes. “The consequences are already in motion. So you have to be in consequence management mode.”

Arora, 58, comes across as equal parts stoic and mischief-maker. He retains an outsider’s streak—an immigrant to the U.S., previously a chief marketing officer, chief business officer, and investor before landing in cybersecurity—though few are as connected in Silicon Valley as he is now. And he’s known for telling employees, CEOs, and luminaries the unvarnished truth.

“There are few people who have his depth and breadth, and he tells you what you don’t want to hear,” says Dara Khosrowshahi, CEO of Uber, where Arora is a board member. “Sometimes, as a CEO, it’s a lonely job. There are lots of people manufacturing their paragraphs to you, and Nikesh isn’t a guy who’s manufactured in any way.”

Altman says he has been turning to Arora since around 2023. “I think it’s hard to get direct, actionable advice,” Altman notes. “Most people aren’t sure, aren’t confident, are busy, or aren’t going to spend enough time. Maybe they don’t want to offend you.”

“I call him the CEO whisperer,” says Divesh Makan, a partner at Iconiq Capital and co-owner of the London Spirit cricket team with Arora. “Some people don’t like him being as direct as he is. ‘Who the hell are you, telling me this won’t work!’ He will tell you kindly, but he’ll sit you down and say, ‘Look, I think you’re wrong, and here’s why.’ I think that’s the secret.”

When Arora took the Palo Alto Networks CEO job in 2018, cybersecurity was in a weird spot: The cloud had become the key battleground, with cyberattack volumes rising, but an overall winner in the sector wasn’t yet crowned. Cybersecurity has long been a space of fragmented businesses stacking atop each other, a process Klarich half-jokingly calls “the conga line.” You protect your laptops and phones through an endpoint security provider, your cloud infrastructure through a cloud security provider, and so on. Eventually, you have an awkward group dance.

“No cybersecurity company in 2018 had ever gone from being a leader in one major category to being a leader in multiple categories,” adds Klarich, who’s been with Palo Alto Networks for over 20 years. “Symantec never really got out of endpoint security. McAfee, same thing, even though they tried to acquire their way into other spaces. Cisco, I wouldn’t call them a leader in other categories. Go down the list, it didn’t really happen.”

Arora quickly realized that in a world where chief information security officers were looking for reliable partners, Palo Alto needed to take control and lead the dance. His answer was a “platformization” strategy that blended in-house R&D with acquisitions, and under his tenure Palo Alto Networks has done more than 25 deals, including this year’s $25 billion acquisition of identity security startup CyberArk. Some deals didn’t work, but the point is to build a cutting-edge one-stop-shop cybersecurity platform that could dominate the sector.

“If you look at most industries or most categories, No. 1 and No. 2 get a disproportionate share of the profit pool, and No. 3 and 4 don’t,” says Arora. “Do you know a third search engine? Do you know a third social network?”

“If you ain’t first, you’re last,” as the Talladega Nights mantra puts it. And the approach has worked, at least so far. The full-stack approach is Palo Alto’s differentiator, says Matt Hedberg, managing director of software research at RBC Capital Markets. CISOs don’t want to buy dozens or hundreds of different point solutions, he says, so they’re “making a platform bet on Palo that they have the wherewithal, whether it’s partnerships, integrations, strategic M&A, [or] organic product development, to help uncover what the next unknown threat is.”

When Arora took the helm, Palo Alto was an $18.51 billion company with $2.27 billion in annual revenue and about 5,300 employees. Throughout the writing of this story, the company’s market cap fluctuated between $270 billion and over $300 billion in a volatile market. The company’s revenue for fiscal year 2026 was $11.48 billion. Palo Alto Networks joined the Fortune 500 in 2025 and is the only pure-play cybersecurity company on the list. AI is set to make Palo Alto even bigger.

“There’s obviously no precedent for [cybersecurity] companies getting to the size of Palo Alto,” says William Blair’s Ho. “Prior-generation leaders like Symantec, McAfee, and Cisco didn’t maintain innovation. And eventually, they got so big they couldn’t keep the plates spinning in the air. Palo Alto’s done a better job of that.”

Arora has come a long way since his first night in the U.S., in 1990, when he found himself in the dim back booth of an Indian restaurant in Cambridge, Mass., two suitcases stashed under his seat and $200 to his name.

Born in Ghaziabad, India, the son of a lawyer in the Indian Air Force, Arora moved often as a child and attended at least five different schools before earning a degree from one of India’s prestigious public Indian Institutes of Technology programs at Banaras Hindu University.

At 22, he’d arrived in Boston to start his MBA at Northeastern—the only program that offered to cover his tuition. An alum had picked him up from the airport and dropped him at the restaurant, Oh Calcutta, owned by the son of one of his mother’s friends. After a night crashing at the family friend’s place, Arora opened the Boston Globe and saw an ad: “four Indians, fifth room free.” He took that fifth room and wouldn’t eat at another restaurant for over a year. He worked a series of odd jobs through grad school—Burger King, night-class instructor, research assistant for a finance professor, note-taker for disabled students that paid top dollar, and campus security guard.

Now a billionaire, he still remembers checking IDs with formative clarity. “Nothing matters,” Arora says. “I can live the most opulent life, and I can live the most basic life.”

Out of school, he got a job as an advisor to the CEO of T-Mobile, then eventually joined Google in 2004 as VP overseeing Europe, a month after the IPO. He rose through the Google ranks precipitously, becoming chief business officer in 2009.

“AI can keep probing cheaply, relentlessly, hour after hour at machine speed, until it finds a way in. “It’s like bringing a battering ram to your front door, bought from Home Depot.”

Palo Alto networks CEO Nikesh Arora

After Google, Arora had a brief and trying tenure as Masayoshi Son’s would-be successor at SoftBank, which ended in 2016. He was accused of conflicts of interest by unnamed SoftBank backers—allegations found to be without merit after an internal investigation—and then he left anyway, as Son chose to stay at the helm.

By the time he was in the mix for the CEO job at Palo Alto Networks, he was known as a prescient and connected executive, though not a cybersecurity expert. Eric Schmidt, the famed Google CEO, worked with Arora for 10 years, and says that Arora was “hard-charging” and had a knack for foresight. He offers an example from when Arora was based in London: “In March 2008, I got this message from Nikesh saying, ‘Something’s going on, and I’m sending someone to talk to you,’ ” Schmidt recalls. “So his two analytical deputies flew in and said, ‘Something’s happened. In the U.K., there’s been a shift yesterday that we cannot explain in our revenue monetization’ … That day, we knew about the Global Financial Crisis, and we knew it a month before anyone else. It’s my best story about Nikesh, because the value of that early sentinel was incalculable.”

At Google, Arora developed a reputation for tear-inducing toughness, and he doesn’t deny it. “If people show up in this room unprepared, they’ll leave the room knowing they were unprepared,” he says. “I say to the people who come into this room, ‘If you have a lot going on, give it to me, and I’ll deal with it—but don’t show up here looking dazed.’” An exacting attitude is necessary, Arora says, when the work has such high stakes. “Would you want to get on that rocket that was built by somebody who was hungover and decided to not tighten the screw?” he asks rhetorically. “Would you ever excuse the person who didn’t do all the checks on a plane before it took off with 200 lives at stake? You expect that from these people. You expect them not to screw up. So why is it tough that I expect my team to not screw up? In every business we work, there are life-threatening or life-ending things that can happen if people don’t pay attention.”

The approach ties back to Arora’s father and his military discipline. “My dad would tell me: ‘Wake up in the morning and do the best you can. And if you’re not up doing your best, go back to sleep,’ ” says Arora. “If you’ve got to show up, show up the best way possible.”

When ChatGPT came out, Arora was on a plane to India to give a convocation address to 30,000 people at his alma mater, Banaras Hindu University. While changing planes in Dubai, he opened ChatGPT, and he knew: AI had gone from research curio to world-altering technology.

“I rewrote my speech on the flight between Dubai and Varanasi to talk about ChatGPT,” he recalls. “I said: ‘AI is like the invention of the iPhone. This is version zero of this technology; the moment you got your first app on your phone. If you play that movie forward, in about 10 years the whole world will turn upside down, and this is the first day of that event.’ ”

He was, of course, right—and he points out that he used the phrase “iPhone moment” months before Nvidia’s Jensen Huang popularized the concept. But perhaps no one could have predicted the seriousness and speed with which AI brought about a reckoning for cybersecurity.

The widely reported dangers of Mythos were soon followed by another AI-cybersecurity end-of-days-sounding scenario: In July, some OpenAI agents escaped from an internal sandbox and attacked open-source startup Hugging Face. The agents coordinated themselves, and the incidents showed what happens when AI agents together chase one common goal. AI doesn’t understand morals, it understands tactics, Arora says.

“Unconstrained agents, trained on the intelligence of all the content out there without setting their North Star, will do whatever it takes,” says Arora. “If I said, ‘Your task is to capture the flag,’ remember it’s been trained on every good thing and bad thing on the internet … It won’t know morals. It just has information saying, ‘Sometimes if you can’t go in from the door, you break the window.’ ”

In his April test, Mythos didn’t perform flawlessly. Some 30% of the vulnerabilities the model flagged were not real, by Arora’s estimate. “If you were a skeptic, you’d say that Mythos doesn’t get it right,” Arora says. “But the problem is getting seven out of 10 right—that’s pretty good for the attacker. It’s not good for the defender.”

The average window to find and fix a breach in cybersecurity is three days, Arora says, but an AI-fueled cyberattack can unfurl in 12 minutes. AI can keep probing cheaply, relentlessly, hour after hour at machine speed, until it finds a way in. “It’s like bringing a battering ram to your front door, bought from Home Depot,” Arora says.

Together, the Mythos and OpenAI–Hugging Face incidents are bringing into focus a future where AI systems that work this way can both discover vulnerabilities and decide to use them—at speed and at scale. We haven’t yet seen our generational cyberattack, but we know the frightening possibilities, even before the AI boom: In Ukraine, the 2017 NotPetya attack, among other things, saw radiation-monitoring computers go dark in Chernobyl and notched $10 billion in losses. Arora’s approach to this high-stakes moment, this tightrope, is linked to his overall philosophy. In the conference room next to his office, there’s a whiteboard filled with Arora-isms, from rules like “Sell what’s on the truck” to reminders of the silly arrogance we can fall into if we’re not careful: “Our innovation is genius. Theirs is dumb luck.”

John Donovan, former CEO of AT&T and a current Palo Alto Networks board member, says Arora is completely focused on the challenge ahead. “If you were to open his brain and look in, it always would be like Santa’s elf shop three days before Christmas,” he says. “He wants to arrive at the most important thing first.”

Michael Grimes, chairman of investment banking at Morgan Stanley, has worked with Arora on multiple deals, and says Arora’s push for clarity is singular: “People use this phrase ‘see around corners’ … In his case, it’s like he can engineer a city without corners.”

The next AI security threat could come from anywhere, Arora says—even your vacuum cleaner.

“Someone sent me this robotic vacuum,” he muses. “And I thought: ‘That’s an attack surface that could be hard to catch.’ Imagine this thing has a camera, and the camera’s helping it walk around your house? Imagine it has a microphone, so it can listen to you? All that has to happen: ‘Hey, let’s take over the listening device and camera in your Roomba-like vacuum. Let’s get pictures of your entire house while we’re at it.’ That sounds like a cyberattack.”

As the surface area for possible cyberattacks spreads and the sheer amount of AI traffic on the internet explodes, Arora has become a key shaper of the conversation in AI and cybersecurity, publicly and behind the Silicon Valley scenes. Where that all leads has never mattered more, for Arora and Palo Alto Networks, but for all of us facing an uncertain, AI-powered future.

I ask Arora what he’d want to know about the future, and he declines to speculate. “That would make life so boring,” he says. “It defeats the purpose of the future. The whole point of the future is that it’s amazing, optimistic, and unknown. If we already knew the future, it wouldn’t be called the future.”

This article appears in the October/November 2026 issue of  Fortune with the headline “Nikesh Arora: The man shaping a defense against AI’s darks side.”

View original article on fortune.com

Most Recent

I Quit OpenAI Because Its Culture Is Broken

What I'm about to tell you has, I realize, become something of a cliché: I resigned this week from OpenAI.

Oct 3, 2026

China’s DeepSeek open-sources tools to help Huawei chips supplant Nvidia in AI

DUV tools, though not as advanced as EUV, can be adapted to manufacture 7-nm logic chips and advanced memory for AI processors, report says.

Oct 3, 2026

The Sleuths Who Expose When AI Goes Rogue

Swarm chasers hunt for clues of bad behavior. Their work is our starkest understanding yet of what happens when AI goes wrong.

Oct 2, 2026

Claude Frontier Academy: $100M to train 10,000 engineers

Claude Frontier Academy trains Frontier Deployed Engineers to the standard of Anthropic’s own — a $100 million commitment to train 10,000 by the end of 2027.

Oct 2, 2026

Similar Posts

Palo Alto CEO says $1 trillion of cybersecurity infrastructure isn’t ready for AI

Palo Alto CEO Nikesh Arora said AI is forcing companies to modernize roughly $1 trillion of aging cybersecurity infrastructure that isn’t equipped for attacks.

Sep 1, 2026

Palo Alto CEO says slowing down AI is ‘unrealistic’, extinction threat ‘extremely small’

Palo Alto CEO Nikesh Arora's views chime closely with Nvidia CEO Jensen Huang who has a diverging opinion to the bosses of Anthropic and OpenAI.

Sep 24, 2026

Palo Alto Networks beats quarterly estimates on AI demand, continues acquisition spree

Palo Alto Networks' stock has nearly doubled this year as AI boosts demand for security detection and response tools

Sep 2, 2026

AI models are becoming the ‘most potent cyber weapon’ ever created, Cohere CEO says

Cybersecurity concerns are feeding a broader AI safety debate, with industry leaders calling for measures to slow frontier AI development.

Sep 14, 2026