When it comes to technology deals, 2025 will likely be defined by some very big spending on the cybersecurity front. The biggest "deal" of the year remains Google Cloud’s ongoing $32 billion Wiz buyout from March. Following that is the Palo Alto Networks acquisition of CyberArk, a $25 billion mega deal that was announced at the end of July.
Both deals are the year’s biggest financial transactions, regardless of sector. Both are also security-centric, with the Wiz deal leaning toward cloud security, and CyberArk toward network security.
Founded in 1999, Israeli firm CyberArk specializes in identity and privileged access management (IAM/PAM), with its end-to-end Identity Security Platform covering multiple identity types across varied environments.
By adding CyberArk to its long history of acquisitions, security leader Palo Alto Networks is offering network security teams an end-to-end cybersecurity platform, rivaling the likes of Cisco, Zscaler, and Fortinet.
According to Allie Mellen, principal analyst at Forrester, the scope of the deal dominated conversations at security calendar staple Black Hat this August, along with talk of Palo Alto Networks' ambitions going forward.
“Given all the acquisitions Palo Alto Networks has made in the past several years across various domains and user groups, and workflows, it seems they have adjusted to a ‘platform-of-platforms’ approach,” Mellen told SDxCentral.
In Mellen’s view, this approach can reduce costs, consolidate vendors, and provide a better analyst experience for practitioners. But Forrester warned that the real value depends on decent integration, while also questioning whether procurement will value the added capabilities.
“While the identity security team may historically be the deciding force on a new identity provider, security operations still has to live with the decision,” Mellen said. “Hopefully, the detection and response capabilities are strong and the detection efficacy is high, but it’s not the priority in the buying decision.”
Palo Alto Networks was contacted for this article, but comment was not returned in time for publication.
Agents on the outside
The CyberArk identity proposition reflects IAM’s growing strength in network security in light of the rise of agentic AI models.
Cisco recently suggested to SDxCentral that the growing number of AI agent deployments will become equivalent to “80 billion” users, posing an identity challenge for networks in the future. Cisco recently donated its Agntcy project, which is designed to be a de facto listing of AI agents, to the Linux Foundation, with Cisco staying on as a formative member for its development.
While researchers such as AvidThink are unclear on how PAM solutions will handle the AI influx, that hasn’t stopped vendors such as CrowdStrike from releasing solutions combining IAM with PAM details to detect human users, machine accounts, and AI agents on the network.
Similarly, Cisco updated its Duo Security platform this year, effectively turning it from a multi-factor authentication (MFA) service into an IAM solution, and continuing to complement Cisco’s suite with Duo’s continuous verification approach to zero trust.
In an interview on Cisco’s zero trust capabilities – recently lauded by SE Labs – Raj Chopra, SVP and chief product officer for Cisco Security, told SDxCentral that “Identity is a primary perimeter, and protecting it is non-negotiable [as] smarter identity protections lead to safer and more productive users.”
Chopra affirmed that the Cisco suite is going all-in on universal zero-trust network access (ZTNA) in response to AI-assisted identity attacks. This approach means having a consistent policy across all identities, from managed or unmanaged users and devices, to AI agents that work on behalf of these users and devices.
“As agentic AI gains traction, identity becomes an essential component of policy enforcement. Traditional access models are simply not equipped for today's hybrid work environments and the evolving AI landscape," Chopra explained. “Universal ZTNA provides seamless, secure access to any app, from anywhere, with continuous identity intelligence built in."
Agents on the inside
Vendors are also releasing AI agents across network security. Despite the similarity in names, such tools shouldn’t be confused with traditional security agents representing endpoint software components.
Palo Alto Networks, for example, offers one AI agent across each of its Strata, Prisma, and Cortex security platforms. Interestingly, these are dubbed as copilots, which may confuse those familiar with AI copilots – smart app-based assistants – rather than agents which can act autonomously, as Palo Alto Networks’ wares are capable of.
Aside from terminology, the Palo Alto Networks agentic approach varies in other ways from its rivals.
Fortinet for example, offers one AI assistant, FortiAI, as opposed to several across its ASIC-based suite. When released last year, Fortinet claimed its “decade of AI innovation” gave it an advantage over rivals, reinforced by a claim to have “more patents than any other cybersecurity vendor.” In addition, a Fortinet spokesperson told SDxCentral for this feature that its purpose-built silicon will keep it and its AI wares abreast of the market’s single-platform convergence.
Cisco also offers one AI assistant across its suite as opposed to several. While its agent exists within different parameters across each product, the branding is of a unified experience for the end user.
The Cisco AI Assistant was recently integrated into the Cisco ThousandEyes observability service, touted as able to automate troubleshooting workflows and preventative networks, enabling so-called self-healing networks.
For Joe Vaccaro, VP and GM of Cisco ThousandEyes – who believes other vendors are following Cisco’s position into becoming a full-stack provider – AI agents upgrade the mitigation stage in anomaly detection and resolution on the network.
“Remediation comes through the use of agentic systems that allow you to take that [problem] signal, apply it with the right remediation steps, and then be able to orchestrate that remediation at the controller in a true kind of self-healing way,” Vaccaro explained.
This is in response to what Vaccaro hears from ThousandEyes customers on the ground on what they really want from AI in network security: a faster meantime to resolution of an issue.
“[Customers ask] can you help me not only become better at detection or diagnosis or remediation, but importantly, can you take me through that full life cycle faster? Can you do a detection to diagnose from mediation as one contiguous flow so that I don't have these interrupts?" Vaccaro said. “Where AI helps them is to be able to go through all of these actions. … We've seen many customers that, as they begin to adopt these systems, are reducing their ticket count by over 90%.”
In other words, patents and fancy – perhaps convoluted – branding are not what ultimately hold sway in the procurement process.
SecOps and SOCs
Another vendor integrating agentic AI is native zero-trust platform Zscaler, which inherited agents from its acquisition of managed detection and response (MDR) provider Red Canary this year.
Zscaler recently built on the existing integration between its Zero Trust Exchange platform and CrowdStrike’s endpoint detection and response (EDR) Falcon product to include the newly-added MDR provision.
James Tucker, head of CISOs in residence for EMEA at Zscaler, explained the merging of EDR and MDR is a key milestone for the firm’s security operations (SecOps) position – and possibly AI's potential in network security.
“Zscaler will integrate Red Canary’s agentic AI technology … to enable customers to run their own security operations centers (SOCs) more efficiently and allowing partners to offer powerful managed SOC services based on this foundation," Tucker noted. “The core benefit of a highly integrated platform is the single pane of glass view that consolidates point products data streams in one centralized data fabric.
Tucker added that, "this way AI can live up to its full potential based on the massive data sets to look at wider anomaly patterns of potential attacks and lead to an automated response. The data based analysis capabilities of an integrated platform have clear benefits over a best of breed approach.”
The SecOps shift has benefited vendors such as Fortinet in recent years. According to a spokesperson from the company, Fortinet defines “end-to-end security not as a collection of point products,” but a unified solution spanning networks, endpoints, clouds, applications, and users.
Both Fortinet and Zscaler’s SecOps confidence make a stark contrast to Palo Alto Networks, which has shown skepticism over a unified approach, arguing that network security will always remain a separate platform unto itself – a philosophy that may also explain its diverse array of agent solutions.
The future of network security
AvidThink noted in a report that Palo Alto Networks' end-to-end focus aims to replace the people-based basis of SecOps with automation, moving beyond the SOC setup and potentially become the strategic security partner for a CIO or CISO.
Palo Alto Network’s CyberArk deal plays into this focus by unlocking up to $29 billion in “identity” total addressable market (TAM) opportunities. But Forrester’s Mellen says the gamble ultimately depends on the end buyer.
“That decision may be relegated not to the identity security team, but to the economic buyer, as consolidation presents an opportunity to bundle and reduce costs," Mellen said.
But having an all-encompassing bundle doesn’t necessarily guarantee a best-of-breed product for enterprises. Mellen highlighted that poorly integrated tools are sometimes worse than separate tools entirely, with consolidation of vendors presenting its own risks and challenges. This risk can be greater when offerings belong to different disciplines in the security stack.
“While there are some areas of natural synergies – such as consolidation of detection and response technologies like extended detection and response (XDR) and security information and event management (SIEM) – other areas introduce more friction,” Mellen said.
Cisco’s Chopra admitted there can be tradeoffs with individual features when compared to best-of-breed point solutions, but the SVP believes in the consolidated approach.
“Enterprises are tired of stitching together dozens of point products themselves – it's difficult to purchase, deploy, and maintain. By leaning into platform-based approaches, customers are seeing faster detection, faster response, and more effective security," Chopra said. "The upside of simplicity, scale, and better outcomes is too compelling to ignore."
Zscaler’s Tucker holds a similar view, claiming complexity as the enemy of security. The exec noted a typical process can revolve around 50 to 100 tools, many with overlapping functionality.
“This is both expensive and inefficient," Tucker said. "The current problem is not so much about vendor sprawl, but rather about a lack of return of investment from a business point of view. In times when organisations are trying to cut costs, organisations are trying to get rid of overlapping solutions."
The final word comes from Mellen, with a simple message for Palo Alto Networks' next steps with CyberArk and its platform-of-platforms.
“Palo Alto Networks needs to invest in ensuring its acquisitions are fully integrated into the platform seamlessly," Mellen said. "They also need to prioritize high-quality analyst experience so that teams can use the platform as intended.”
Comments