The riskiest security product in a company may be the one everyone trusts. It was bought years ago, passed its audits, survived several leadership changes, and never caused enough trouble to replace. And that familiarity becomes its own form of reassurance.
Palo Alto Networks CEO Nikesh Arora put a large price tag on that accumulated comfort this week (Trading View, 2026). He estimates that companies are carrying roughly $1 trillion of cybersecurity infrastructure that needs modernizing for an AI-era threat environment, much of it deployed seven to ten years ago.
The estimate deserves some skepticism. Palo Alto has plenty to gain from a large replacement cycle. Its latest quarter produced $3.41 billion in revenue, up 34% year on year, while Next-Generation Security annual recurring revenue reached $9.1 billion, up 63%. Arora wants NGS ARR to reach $20 billion by fiscal 2030 (Palo Alto Networks, 2026).
But the case for modernization does not depend on Palo Alto’s sales pitch. The stronger argument is speed.
29 minutes to break in. 55 days to patch.
CrowdStrike puts the average eCrime breakout time at 29 minutes (with an important note that CrowdStrike’s fastest breakout in 2025 took only 27 seconds!) (CrowdStrike, 2026). Meanwhile, Palo Alto estimates that a traditional software fix takes around 55 days to reach production (Palo Alto Networks, 2026). Those clocks barely belong to the same operating model.
In another incident, data started leaving the victim’s environment within 4 minutes. AI-enabled adversary activity rose 89% over the year, while 82% of detections were malware-free. Attackers often moved through legitimate accounts, SaaS products, and cloud services rather than dropping obvious malware onto an endpoint.
Patching is hardly catching up. During the first half of 2026, 88% of observed exploitation involving vulnerabilities with public proof-of-concept code happened within 48 hours of release. Some China-linked groups were moving within 24 hours. After the React2Shell vulnerability became public, CrowdStrike identified more than 80 victims in four days. A 55-day remediation cycle can begin long after exploitation has started.
That shifts more of the burden onto detection, containment and temporary controls. Critical infrastructure makes the gap harder to manage because a rushed patch can interrupt a hospital, production line or energy facility.
Palo Alto’s recently launched Frontier AI Critical Defense Program targets that window. The company says its frontier models identified more than 14,000 previously unknown vulnerabilities in open-source software, while participating organizations can use network-level virtual patches until permanent fixes are ready.
Age alone is not the problem. A seven-year-old firewall does not become dangerous because it turned seven. The problem appears when the surrounding process can no longer move at the speed of the attack.
The price of expertise is falling
AI cyber risk is often framed around fully autonomous hackers. The nearer-term change is less theatrical: specialist work is getting cheaper. Anthropic studied 832 accounts associated with malicious cyber activity between March 2025 and March 2026. AI appeared across all 14 tactics in the MITRE ATT&CK framework and 482 individual techniques, from reconnaissance through to impact. The share of actors Anthropic classified as medium risk or higher rose from 33% to 56% between the first and second halves of the study (Anthropic, 2026).
An attacker no longer needs to spend hours reading documentation to understand an unfamiliar error, modify a script, or troubleshoot an exploit. A model can shorten that process substantially. Experienced operators get more output from the same amount of time while less experienced ones can attempt work that previously sat beyond their skill level.
Google Threat Intelligence Group has already seen a further step (Google, 2026). In May 2026, researchers reported the first case they had identified of a threat actor using a zero-day exploit believed to have been developed with AI assistance. One case does not establish a trend, but it makes it harder to assume that advanced vulnerability research will remain confined to a small group of highly skilled operators.
Defenders get access to many of the same capabilities. Models can search large codebases for vulnerabilities, reconstruct attack paths, and help analysts work through huge volumes of telemetry. Palo Alto says it has briefed more than 1,000 security teams on its frontier AI work and is deploying advanced cyber models inside customer environments.
The contest right now is over who can convert machine speed into action first.
Companies keep adding doors
While parts of the security stack age, the environment around them keeps expanding. Verizon’s 2026 Data Breach Investigations Report found that vulnerability exploitation accounted for 31% of breaches, overtaking stolen credentials as the leading initial access route for the first time in the report’s 19-year history (Verizon, 2026).
Third parties were involved in 48% of breaches, up 60% from the previous year. Meanwhile, the share of employees frequently using unapproved AI tools climbed from 15% to 45% in a year.
Enterprise security rarely grows from a clean design. SaaS products are connected to old identity systems. Suppliers gain access. Developers pull thousands of software dependencies into production environments. Employees introduce AI tools faster than governance teams can review them.
10 years of technology decisions accumulate into one security architecture, and attackers work in the gaps between those systems.
CrowdStrike recorded a 171% rise in cloud-conscious eCrime activity in the first half of 2026 and a 15-fold increase in monthly device-code phishing attempts. In one case, an account takeover became data theft in under five minutes. A separate software supply-chain campaign compromised more than 300 dependencies in one day.
The old idea of a hardened corporate perimeter now fits fewer organizations than it once did. An employee can authorize a cloud session, a contractor can authenticate into SaaS, and an AI agent can make requests across several systems on somebody’s behalf.
Cyber debt now has a stopwatch
A $1 trillion replacement program makes for a strong headline and an attractive market opportunity. Few companies need to respond by ripping out everything bought before generative AI.
A more useful place to start is delay. How long does a newly disclosed vulnerability remain missing from the asset inventory? Once an account starts behaving strangely, how quickly do identity, endpoint and cloud signals appear in the same investigation? Can the team contain activity immediately, or does somebody need to switch consoles, escalate a ticket and wait for approval?
And when production cannot be patched immediately, what protects the gap? Those timings expose a different type of technical debt. Some sits in old products. Much of it sits between products, teams and workflows designed when a response measured in hours was acceptable.
Arora’s $1 trillion estimate will be debated, particularly given who is making it, but the 29-minute breakout time is less negotiable. In fact, for security leaders deciding where modernization should start, response latency may reveal more than the purchase date printed on the hardware.
.png?width=1816&height=566&name=brandmark-design%20(83).png)