BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

As AI Agents rapidly flood into intranets, the main battleground for "cybersecurity" has changed

MSX 研究院
特邀专栏作者
@MSX_CN
This article is about 4902 words, reading the full article takes about 8 minutes
From PANW and CRWD to SAIL and VRNS, the dividing line for "cybersecurity" has shifted completely.
AI Summary
Expand
  • Core View: After AI Agents enter enterprises, the security contradiction shifts from "model intelligence" to "uncontrolled permissions." The cybersecurity control plane is shifting from networks and endpoints to identity, data, and runtime. Whoever can first translate Agent security needs into ARR growth will win this round of revaluation.
  • Key Elements:
    1. Agents possess legitimate credentials but can execute unauthorized operations due to logic drift or malicious prompts. The traditional security architecture of "managing people and devices" becomes ineffective, and enterprises must add a new judgment dimension: "whether behavior aligns with the original authorization purpose."
    2. PANW has the most thorough platformization. Prisma AIRS covers models, data, Agents, and Runtime. Quarterly revenue was $3.41 billion, up 34% year-over-year. Platform companies have the shortest path to commercialization.
    3. CRWD extends from Falcon endpoint telemetry to Runtime, with revenue up 26% year-over-year and ARR up 25%; S is using Purple AI to explore how Security Agents can take over junior analysts' workflows.
    4. SAIL disclosed that AI-driven ARR exceeds $70 million, with AI products contributing more than 30% of net new ARR, validating that Identity governance has moved from a product story into the stage of real contracts.
    5. VRNS total revenue grew about 18% year-over-year, with SaaS ARR up 52% (about 25% excluding migration). Whether AI Data Security can take over growth is a key point to watch.
    6. ZS revenue and ARR both grew about 25%, and it is expanding from Employee→App to the new Zero Trust demand of Agent→App; FTNT is betting on the network isolation and security procurement cycle brought by Private AI.
    7. Valuation divergence is obvious: CRWD and NET maintain high premiums, PANW and FTNT are quality defensive plays, while SAIL, VRNS, ZS, and OKTA have yet to prove their elasticity. Whoever first proves that Agents are driving net new ARR will see valuation recovery.

Over the past two years, Silicon Valley and the tech world have been desperately trying to make large models "smarter."

But when models step out of the chat box, put on a badge, and become Agents — from Palantir's AIP demos to the internal deployment networks of major companies — enterprise CTOs suddenly realize that intelligence is no longer the primary concern; out-of-control permissions are the source of disaster.

Give an Agent an account, and it can instantly read SharePoint, run SQL, modify code, and even click the payment approval button in an ERP. It is not an employee, yet it holds system credentials; it is not traditional software, yet it can proactively invoke tools, access data, and execute tasks.

For the past twenty years, the subtext of enterprise cybersecurity has essentially been "control people and devices, guard your own yard." But today, a legitimate Agent holding a legitimate Token, within a legitimate business flow, can — due to logic drift or a single poisoned Prompt — carry out unauthorized operations that no one ever anticipated.

At this point, who gets to decide?

This is also the biggest difference between this round of cybersecurity revaluation and the past: AI lowers the barrier to attack on one hand, while on the other creating entirely new security objects — models, Agents, MCP, machine identities, enterprise data, and Runtime.

In other words, the control plane of cybersecurity is irreversibly shifting from perimeter networks and endpoints toward identity, data, and Runtime.

1. Why Has "Cybersecurity" Suddenly Become an AI Mainline Again

Over the past decade or so, enterprise cybersecurity has roughly formed a stable division of labor.

Firewalls handle network entry points, EDR watches endpoints, IAM manages identities and logins, data security handles sensitive information, and SOC handles alerts that have already occurred.

The underlying logic of this system is simple: it has always revolved around people and devices — the operator is either an employee or an intruder. As long as you can identify who this person is, whether the device is trustworthy, and whether the network connection is secure, most problems already have relatively mature solutions.

Agents have smashed this logic to pieces.

Even with a legitimate identity and normal login, an Agent can still — due to excessive permissions, erroneous tool invocations, or the influence of malicious Prompts and external content — behave in ways no one originally anticipated.

Therefore, enterprise security must answer an additional question it has never encountered before: does what it is doing now still align with the purpose for which it was originally authorized?

If we look at the actual chain of how Agents enter enterprises, the current batch of cybersecurity companies can actually be divided into three camps: one builds platforms, one controls identity and data, and another guards networks and access entry points.

2. From PANW, CRWD to SAIL, VRNS — Who Is Choking the Real Throat?

1. PANW, CRWD, S: Platform Giants with the Shortest Path to Commercialization

Palo Alto Networks (PANW) remains the most thoroughly platformized company.

It has long ceased relying solely on traditional firewalls, instead continuously consolidating Network Security, Cloud Security, SOC, Identity, and AI Security into a single platform. Prisma AIRS now covers models, data, AI Applications, and Agents, while adding capabilities like AI Runtime Firewall and Red Teaming.

So what PANW wants to solve is actually the entire chain — including what models AI uses, what data it accesses, what tools it invokes, and whether anomalous behavior occurs once it's actually running. The company's latest quarterly revenue reached $3.41 billion, up 34% year-over-year. Although this includes acquisition contributions, it still shows that when new security budgets emerge, large platforms typically have the shortest path to commercialization.

After all, customers are already there, contracts are already there, and new products can be cross-sold directly into the existing system.

CrowdStrike (CRWD) has a different entry point, focusing more on the execution layer.

An Agent's reasoning may happen in the cloud, but the actual actions — running scripts, writing temporary files, invoking system processes — ultimately occur on servers, containers, or employee endpoints. This happens to be the Falcon platform's comfort zone. By naturally extending endpoint telemetry to Runtime, CRWD is inherently positioned at the front line where actions occur.

Therefore, CRWD's most core asset has always been the Falcon platform and the telemetry accumulated from a large number of endpoints and cloud workloads. Latest quarterly revenue grew 26% year-over-year, ARR grew 25% year-over-year, and net new ARR performance was even stronger — showing that CRWD is expanding from Endpoint into Identity, Cloud, Runtime, and SOC.

SentinelOne (S) is heading in a similar direction, just at a notably smaller scale.

Its Purple AI is more aggressive in ambition — rather than being an auxiliary tool, it wants Security Agents to take over the workflows of junior analysts, moving further toward automated investigation, event correlation, and triggered response.

If this step truly works, what AI changes is not just the product features of cybersecurity companies, but the very way security software is used and billed.

2. OKTA, SAIL, VRNS: The New Security Locks with the Highest Incremental Purity

If platforms like PANW and CRWD win on scale, then the native increments brought by Agents first strike Identity and Data.

Okta (OKTA) and SailPoint (SAIL) are both expanding into Agent Identity, though the two companies have different traditional strengths.

Okta is closer to Authentication and Access Management, dealing with "who you are, whether you can log in, and which applications you can access"; SailPoint leans more toward Identity Governance, caring about why a permission exists, who approved it, how long it should be retained, and whether it should be reclaimed after the task ends.

Applied to humans, this governance is already complex. Applied to Agents, the problem is undoubtedly more thorny. Because an Agent's lifecycle may be very short or long-lived, it may invoke multiple tools, inherit user permissions, and even further generate new Agents.

This is also the more noteworthy part of SAIL's recent data. Its latest quarterly ARR grew 25% year-over-year, SaaS ARR grew 36%, and more importantly, the company disclosed that AI-driven ARR has exceeded $70 million, with AI products contributing over 30% of net new ARR — proving that Identity has moved from product story to real contracts.

By comparison, OKTA's latest quarterly revenue grew about 11%, with cash flow and margins continuing to improve, but overall growth is notably lower than top-tier cybersecurity platforms. So what truly needs to be proven in the next phase is when these new products can once again influence the overall growth curve.

VRNS stands on another very direct Agent logic — data. What it has long done is sensitive data discovery, permission analysis, data classification, and threat detection, and now it is adding AI Governance and AI Runtime into the same system.

After all, the more capable the Agent, the more enterprises need to first figure out one thing: what exactly can this Agent see? Latest quarterly VRNS total revenue grew about 18% year-over-year, SaaS ARR grew 52% year-over-year. Of course, this 52% includes a large impact from traditional customers migrating to SaaS; excluding conversion, SaaS ARR growth is about 25%.

So what's truly worth watching for VRNS right now is whether AI Data Security can take over growth once the SaaS transition effect gradually fades.

If Agents truly enter enterprise production environments, then data permissions are likely not an "optional security module" but rather something that must be resolved before deployment.

3. FTNT, ZS, NET: The Network Subject Has Changed, But the Pipes Remain

The changes brought by Agents do not mean traditional network security will lose value — it's just that in the future, those accessing enterprise applications and the internet will no longer be only employees and devices.

Zscaler's (ZS) Zero Trust previously mainly managed Employee → Application, and will gradually expand to Employee + Workload + Agent → Application. The more Agents there are, the more machine access will need to be authenticated, authorized, and isolated.

So as long as machine access traffic explodes exponentially, the Zero Trust gateway's billing points remain.

Latest quarterly ZS revenue and ARR both grew about 25%, though excluding the Red Canary acquisition impact, both growth rates are closer to 20%. From this angle, what ZS truly needs to verify going forward is whether the new Agent-to-App demand can re-accelerate net new ARR.

Fortinet's (FTNT) AI logic leans more toward infrastructure, benefiting from the private deployment dividend.

It is not a typical Agent Security company, but if more financial, healthcare, large enterprise, and government projects build their own GPU clusters, Private Clouds, and AI Factories, demand for network isolation, east-west traffic, firewalls, SASE, and security operations will naturally increase.

These happen to be Fortinet's long-accumulated capabilities. In other words, it is betting on the rigid demand for traditional infrastructure in the new compute cycle, and whether Private AI will kick off a new round of enterprise network and security procurement.

Cloudflare is even more special — it has the biggest appetite and the most expensive valuation (further reading: "GPT, Claude, and Grok All Went Down — Why Is Everyone Suspecting Cloudflare?").

NET simply cannot be neatly categorized as a cybersecurity company. CDN, WAF, DDoS, Zero Trust, Workers, and a global Edge Network place it simultaneously in internet infrastructure, cloud, and security. As Agents proliferate, the internet's traffic structure itself may change.

Previously it was more Human-to-Web; in the future there will be more and more Agent-to-API and Agent-to-Agent. Agents will visit websites themselves, invoke models, execute code, and even complete machine payments. Ultimately, what Cloudflare is really betting on is not just AI Security, but a bigger shift:

If more and more internet traffic is proactively generated by machines, can NET become an important entry point for this layer of the Agent Internet? This is also its biggest difference from other cybersecurity companies — greater imaginative space, but also more expectations already reflected in the valuation.

3. The Valuation Watershed: Who Will Be First to Count Agents into ARR

Putting industry logic back into fundamentals and valuation, the market has actually already voted with its feet quite honestly:

  • High-premium camp (CRWD, NET): maintaining 20%+ or even higher growth expectations. The market is trading on their imagination of using AI to continue expanding TAM, giving them consistently top-tier EV/Sales multiples;
  • Quality defense camp (PANW, FTNT): growth is not as explosive, but supported by platform depth, network infrastructure attributes, and extremely solid free cash flow;
  • Flexibility-to-be-proven camp (SAIL, VRNS, ZS, OKTA): valuation centers are relatively restrained, but that also means opportunity. As long as one of them can be the first to prove that Agent products are substantively driving net new ARR, it could easily see a round of valuation recovery;

At this point, the AI narrative in cybersecurity has already passed the "hackers are also using AI, so the whole industry benefits" scattergun phase.

Because this logic is too broad — almost every cybersecurity company can tell it, can release a Copilot, Agent, Runtime Security, or Agent Identity, and can explain why AI will expand its TAM.

What's truly creating divergence now is that enterprises themselves are beginning to use AI at scale, so the original security architecture must also be redesigned accordingly — it's just a matter of who can clearly count these new demands into their financial reports and further drive overall revenue to re-accelerate.

This is why PANW, CRWD, SAIL, VRNS, ZS, FTNT, and NET can be discussed together. What is foreseeable is that the differences between them will only grow larger.

Platform companies compete on distribution efficiency, identity and data companies compete on whether new control points can be rapidly commercialized, and network and infrastructure companies must prove that Agents and Private AI will ultimately bring new traffic and procurement cycles.

So as this market rally moves forward, what's most worth watching is who can be the first to prove that Agents are changing their growth curve.

This is also why SAIL's recently disclosed AI-driven ARR is more worth paying attention to than simply launching an Agent product. As long as AI products actually have buyers, net new ARR begins to appear, overall growth picks up again, and this revenue ultimately turns into profit and cash flow, the capital markets will naturally vote with their feet.

From this angle, cybersecurity is not a new story that suddenly emerged outside the AI mainline.

The more capable AI becomes, the deeper enterprises' fear of "losing control." And the winner of this round of cybersecurity rally depends on who can fastest convert this fear into real cash flow in each quarterly earnings report.

Followthe official X for US stock news

Jointhe official community to discuss hot topics

Safety
AI
Welcome to Join Odaily Official Community