Executive readout · one minute
Call research workspace
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Conference · 2026-09-10
Executive readout · one minute
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Research coverage
2 live sources
Switch sources without leaving this page or losing your listening position.
Open the source you need; every reader stays inside this workspace.
Listen and read together
The spoken word highlights as audio plays. Select any word to seek to that moment.
Okay.
Hey, good afternoon, folks. We're really excited to have Nikesh Arora on stage with us, hot off the plane from Geneva. Thank you for taking the time. To be with us today. Hey, Nikesh, there's a lot of noise in the market, as you can appreciate. When you read and look at some of the fear-mongering, it may not be the right word, but some of the more. I like fear-mongering.
I spent eight years trying to convince people cyber security is important. Dario did it in one week. Better than me, clearly. Mythos has been more useful for me as a marketing tool than anything I did for eight years. I hope to have new models which are more capable and scare the lot of people.
Let's talk about the flip side of the fear mongering. Let's talk about the flip side of the fear mongering.
You have CEOs that call you and say I'm scared about XYZ agentic threat by Palo Alto Nikesh please solve this for me how do you solve that problem yeah well first of all lovely to see you guys thank you for staying in the room I saw a lot of people leaving as I was walking in so I figured nobody was interested in cybersecurity or anything that needed to be said had already been said so far this conference or the bar open any of those above when CEOs call more recently since mythos I think we've talked about 2,000 companies between CEOs CIOs and chief security officers and obviously they want to know what is mythos how does it impact my life what do I need to do about it and I think mythos is the first incarnation of showing us the capabilities of AI and how it can find vulnerabilities in our organization's technology stack so what would take us weeks or months or things we wouldn't care to go look for yeah I can do it pretty quickly so you've suddenly seen this peak of vulnerability finds we found twelve hundred at Palo Alto when we first tested it when mythos came out it took us you know three four months of cleaning to understand which ones are real which ones are not and go fix them now we're back to steady state we find pretty much a few every month like we used to find before mythos was around but we had to go through a huge learning curve and a discovery phase and fixing it so a lot of companies haven't been through that and what's happened now is mythos has become available to defenders so we have a service we can go to customers with and say you want us to test you we'll test you um but what's interesting is i'd say 60 of what we found was through mythos 30 odd percent using open ai and 10 percent using other models we actually have to use a multi-model harness to find all the vulnerabilities that current AI will help you find as opposed to using any one single models that's what we're doing but very quickly that conversation of also that's great what does this mean for the future how do I make sure that I can respond to finding vulnerabilities quicker and what do I need to do to my tech stack to make sure that I can find attackers quickly in my infrastructure and fix it before the shit hits the fan that's usually when the platform conversation begins and the sim conversations begin and we start telling them stop upgrading your stack in a multi-vendor solution try and consolidate because you need the data to be able to stitch together and make it work talk a little bit about that data advantage what are some of the things that you can do now with AI with your own roadmap because you have visibility across the different pieces of the platform well look it's still true that every customer runs about 30 or 40 cyber security vendors in their stack cyber security in my mind can be simplified as you have to stop bad stuff at the perimeter right anything bad shows up the perimeter if you know it's bad you're gonna stop it's like stopping a bad guy wearing a mask and carrying a gun at the door that's easy to do if you know it's bad most of cyber security problems are when you don't know it's bad and gets it gets into your infrastructure you've got to find it quickly to stop it because actually not a guy in a mask a guy wearing a suit sitting in the conference he's about to pull out a gun sorry I'm using non-cyber security analogies because you guys probably heard about all the agentic harnesses that George is building but so the challenge is how can you find that bad actor as quickly as you can to find that bad actor as quickly as you can, you need a seamless sort of layer of data behind it which is consistent, which can talk to each other and you understand the nuances. So take any attack, right? If an attack starts at your laptop and you're running a SASE vendor in a laptop, then the attack migrates from your laptop, heads to your data center, hits your firewall in a data center. Now you're running a different vendor in a data center. It goes from there to your database, which is sitting in AWS. You run to a different firewall in AWS. So you've traversed four or five cybersecurity vendors and all of them will give you an alert saying go figure out something bad's happening. But because they don't have the context of the other vendor, they can't stick together and say, oh, shit, I found this thing. It went to these three different enforcement points. I control all enforcement points. I know what this bad thing is. Because somebody has to collect all the data, then go make sense of it. If you're running one vendor to the entire lifecycle of that particular threat vector, you can solve the problem within that vendor's data lake. Or you can solve that problem using agents that that vendor runs. otherwise let's assume that I saw something bad at the end point but I don't know what it's going to do or it did something bad or not right take an example you got an email you clicked on the phishing link you went to a bad website the moment you left the email vendor that email vendor has nothing they can do anymore you're out of the email vendor stack you don't they run the data you probably went through your corporate firewall that allowed you go to a bad internet access so now the firewall has the data but they don't have the email data that you click on an email so somebody has to collect all the data and a sim and go make sense of it, which is done by SOC analysts. You have to be able to solve these problems in flight using agents. The only choice is if you don't have a single vendor managing at least part of your stack, each agent has to talk to other agent, which means all of us to build agents that need to talk to each other. This is a complicated solve. So you actually have to eventually start reducing your footprint of cyber vendors over time. And that's where the, I think AI, the best way to say is AI is advantage incumbents with platform stacks.
Some of your products are relatively straightforward to consolidate up and displace vendors. Other things like network security and Cortex, SOC, those are heavy lifts. And so to your point, when customers go on this modernization journey, do you already have visibility into multi-quarter, multi-year network transformation, SOC transformation type cycles?
SOC transformations are typically one shot. you can do a six month engagement with a customer and they'll tell you we want to and they'll do a six-month engagement and replace somebody else network stack evolves over time like literally I was walking in here and I hadn't seen my email for the last four hours and I saw two emails about two different customers wanted to replace a certain network vendor in us in their stack because they already have two out of the three pieces we do with them and the third one is coming up for renewal for a third vendor and they said but we already have two out of three from Palo Alto let's just go to Palo Alto and harmonize the stack so that typically takes the process of evolution there's no but he's sitting there and saying let's take useful things and rip them out they wait for the evolution on certain stack the revolution is happening in the sim because of mythos the revolution is happening on the observability stack because of cost the revolution will happen on AI security stacks that are going to be built which are not fully built in the market if anybody sat here and told you they can solve AI security there's a bunch of marketing going on but I'm sure they've said it well let me ask you a derivative of that question which is we had Jensen on stage earlier talking about the commercial opportunity that may exist for the frontier models in security and what is that opportunity I would love to hear your thoughts told you the question that I'll ask I'll ask it from from your industry I'm very curious Jensen is wonderful he's an amazing guy he's benefiting the entire AI industry and everybody associated with it so let me ask you what role you think frontier models play in security look the the biggest value of AI over time it's his reasoning capability it can reason and try and look for different alternatives all software is deterministic the design is input and output traditionally when we buy software we ask it a question we expect the answer to come back in a certain format in a certain way and it follows a certain process so if it's not doing that either says I have no idea bad entry or says I have nothing in the back to give you I have no output to give you yeah I will actually reason through it ah I didn't find anything here let me go look over there let me go over look there let me go look there it'll exhaust every possibility a human being would have tried from the outset you literally have to tell it the outcome you want and AI has this capture the flag mentality it tries every technique until eventually gets to the answer or as close to the answer it can get that makes it non deterministic in the back and that's the value of AI so anywhere where tremendous amounts of human time is spent interpreting things and looking for alternatives and analyze things AI is useful right so same thing it did a wonderful job of one that's one property the two problems second property is AI is not trained for the edge case it is the way when you get into Waymo, it doesn't have every edge case figured out. Somebody has to anticipate that edge case, train Waymo for that edge case to make sure that it performs the edge case. AI has the same property today. So if you take those two capabilities and understand, the reason it got so good at vulnerability management or vulnerability detection is, what is the number one use case of AI? Coding. Which means we're teaching it what good code looks like. Well, guess what? It's got figured out what bad code looks like because we've taught it a lot, you know, hundreds of billions of dollars of ARR of coding. Now it's figured out what bad looks like. So it can tell you what bad code looks like, hence it determines the vulnerability because the code is not in the way it should be written, but it has vulnerabilities. It finds the 80% mainstream, but it doesn't understand the intent of the code. For example, if you look at Palo Alto code, you will find code in our company which is designed to attack people because we're testing people. But if it sees that outside the context of Palo Alto, it says, that's bad code. Let's fix it. dude, no, stay away. We got this. Don't fix it, right? It doesn't understand the false positive because it does not understand business context. So it needs some degree of context with it to make it useful. That's where harnesses, that's where domain knowledge comes into play. So the extent that it can assist us in getting through a lot of mundane tasks or reasoning tasks is very helpful, but you still need the edge case and the harnesses. Two, LLMs do not sit in enforcement points. You do not want it sitting in your laptop at the edge case. If you remember the CrowdStrike incident you really want open and managing the endpoints and pushing updates at the end point They haven't built that product. So I think the long-term answer is that all cyber Companies will use some form of AI in their products because it will make it faster It will look at edge cases. It will look at classification a whole bunch of stuff and we're all working on it I'm sure different people can talk about they're all working on it. I don't think the economics of frontier models make it useful AI to work, for example, we sit on people's endpoints, so does CrowdStrike and so does Central One and so does Microsoft Defender. The average price in the industry is probably $30 to $40 an endpoint. And on a day, about 160 megabytes of data goes through your laptop every day. If you put a frontier LM to inspect 160 megabytes a day at the edge of your laptop, I suspect it's going to cost you more than $40 a year. Now, if the customer wants to pay $4,000 a year to predict an endpoint, hallelujah, go for it. I'd like to be in that business too. but if it's 40 bucks you want a cheap alternative so you have to build a replacement product that only not only is better than the product that is currently in the market but it has to be cheaper than 40 bucks I don't think that it's going to be a huge takeover by LLM so the cyber security industry I think it'll work in certain categories where they'll have to work with our enforcement points to make the enforcement points faster and smarter and that's par for the course we will all work with them together we probably We'll become consumers of frontier LLMs, and we'll do our part, and we'll train edge cases, and they'll power some of our models. At Palo Alto, we spend an author of a billion dollars in buying cloud. We don't run our own cloud. We don't run our own data centers. Could I be spending a few hundred million dollars buying tokens? Sure, I could. But I'll buy them for all my customers and make their products much better over time.
Do you have a view on the right way to orchestrate tokens between leading-edge and not leading-edge?
So there are two scenarios. One scenario is where I don't need leading-edge, right? If I need to run AI at your laptop, it needs to run on a 20-megabyte footprint. There's no Frontier LLM that runs on a 20-megabyte footprint. However, I can go get 5,000 models of Hugging Face, which can be shrunk to a 20-megabyte footprint, do a very specific task at the end so yes I can use what are called small language models to do tasks specific things in cybersecurity which are much more efficient and doing it than using machine learning that's where I would use it but I wouldn't be orchestrating amongst different models in the case of vulnerability management I am orchestrating across five models because they all find different vulnerabilities so I'm literally running the same thing five times two different models to see which one one of them finds I don't know if in the long term we should be orchestrating across multiple models I think it's an economic argument it's a extremely complicated technical argument and I don't think the frontier LLMs are sleeping at the wheel they understand what the industry wants to do and they're building interim modes which are called you know instant memory they'll move stuff to instant memory which is where you store it so you can't actually arbitrate models over time I eventually I think what is going to happen is I said this differently I think average intelligence will become free but it will still have to pay for compute what I mean by that is I can buy a model running a laptop trading for $5,000 and run it for free marginal cost on your compute so I think what will happen is older models will become cheaper and cheaper over time we'll use a lot more of them but the hardest thing to find right now is compute even if you get yourself open source model you want to run it for a billion dollars a year you have to go buy a billion dollars of compute so still cost you I think people are mistaking that front a LM come country LMS come with compute plus intelligence if you go find intelligence for free you select to go by the computer which eventually ends up costing you probably more or as much as you pay for for LLM perspective and some of these elements are way more efficient than what you find in open source it costs you a lot more money to train them they're not as efficient and the portability is not there. So I don't know if the economics are there in the market yet for frontier tasks to start arbitrating between models just yet. But people are trying.
Let's talk about network security.
These people want to talk about AI.
We can talk about AI and network security. The hypothesis that we're experimenting with is how an increase in network traffic impacts the firewall cycle, impacts throughput going through the firewall. And I think there's a bunch of different flavors. The data point you gave on the earnings call was agentic traffic on SASE was up nine times. Maybe if we just take a step back, this idea that more agentic traffic drives more network traffic, drives more firewall. Where would you push back on that, or when do you think we'll start to see it?
So I think it's important to understand, if we believe that $5 trillion will be spent in the next five years to build compute, in the end at the most basic level that means more traffic right before we get into what the traffic is used for more data flowing between pipes and trying to get to enterprises and consumers so you if we spend five trillion dollars the last 25 years and build traffic to this traffic is X you expect the next five years traffic becomes 6x right so your traffic is up 6x in the next five years that all that traffic has to be inspected sassy is a form of inspection software firewalls as a former expect inspection hardware firewalls the form inspection pretty much every enterprise bit is inspected today you can't run a bit in any enterprise without being inspect without inspecting it doesn't matter where you live it could be in Google Cloud it could be in AWS could be in you know data center is inspected the bits that are not getting fully inspected according bits right now right that's the biggest kind of blind spot if you say a hundred plus billion dollars of error has been genuine coding most coding instances are not secured so we have to go fix that first that hasn't been fixed but let's assume that eventually over the next two years that all the traffic that's going around the world is going to get inspected it doesn't matter if it's human traffic or the genetic traffic it's traffic so right now of course the explosion is going to come from agents because humans cannot humanly consume that much traffic so the traffic is coming from agents but let's that's a second order problem the personal problem is every bit still has be inspected because it's coming from somewhere so you should expect the network security has this constant tailwind as the traffic continues to grow up that some form of inspection will be applied the gap right now in the market is not all AI traffic is being inspected because enough AI security tools don't exist because you can't do anything beyond inspection you don't have the tools to do it the second layer post inspection is I'm inspecting the traffic I run value-added software like what do I do on top of it what do I inspect it for For example, I inspect traffic and do observability. Great, that's a value-added service. I pay for observability on top of inspection. I take the traffic and I run a SIM on top of that, which means I get paid for running security analysis on top, for which I get value-added services. In network firewalls, I inspect the traffic. I get paid for various cloud services, where I run sandboxing, URL filtering, et cetera, et cetera. So the AI value-added service haven't been built. that are being built as we speak. No vendor, including us, has the full stack. Because if you tell me you have a full stack, you know, Facebook announced Muse two days ago. Muse comes with a totally different security architecture than any other agent that's out there. They run the agentic action. They run Sentinel, which is an operating system, which has security. That's a new architecture. To expect that all of us have built security products in anticipation is foolish. It's going to take us three to six months to understand the hooks. In fact, most AI implementations don't have security hooks on them. You can't automatically secure cloud code because you don't have hooks that are available from Anthropic. You can't secure Codex yet because they haven't delivered the hooks to run in-line security from an API perspective. They are saying, we're going to build a secure debt. It's not going to work. Historically, no company is going to buy a technology product from company A and secure it using company A's product. Typically, you will use company B's product to secure company A's technology. So that industry hasn't been built. The whole entire AI security industry has still to be built. The entire value of the service player is being built. There are 3,000 startups who got funded last year with something to do with AI, of which 2,000 will not survive, but that's a different order. This is the wrong audience. That's the venture capital guys. But so that stack is being built. They're all rushing towards it. When that stack gets built, it'll add a whole new TAM on top of existing TAMs in cybersecurity, which will be the AI security TAM. But we did $100 million in Prisma Airs, which is real-time AI security. We've intercept traffic and inspected for prompt injection or Model sort of let's say model manipulation, right? But there's a whole new stack going to be built for agentic security over time and it's not going to be Customers are not going to be able to stitch it themselves They're not going to buy agent identity from Okta and something else from somebody else and something else and say I'm going to stitch it all together They're going to wait for a stack that does the entire lifecycle of the agent You gave a three-to-six-month data point in there on how long it takes to build the AI security. At speed.
At speed, okay.
If you get it right, because remember, 3,000 companies are using 3,000 different hypotheses where the world's going to evolve. To anticipate the world and build it, some will get it right, many will get it wrong.
So walk us through when you think we get to some sort of steady state.
You tell me when AI hits steady state, and I'll tell you when it's security steady state. Remember we're trying to secure a technology that is in flux. Yeah, every three months something new happens We thought we had LLM's that was cool We had it figured out damn these agents showed up You know we had to go figure out agents and then open I couldn't constrain their own agents It'll let them off to hugging face right When that industry reaches some point of stability will give you a stable security architecture You know this funny analogy that they didn't invent TSA when they invented planes. Yes, it took a long time to torture us so we'll take a while to get to torture the air guys one of the stacks that's being built as we speak is the neo cloud infrastructure stock beautiful yes tell us a little bit about your opportunity securing some of the neo cloud infrastructure well neo clouds are data centers right they're just data centers data centers any firewall especially if you can have multiple tenants the ones you don't get business from a single tenant clouds so if somebody's building a hyperscaler it's a single purpose data center it does one thing it runs AI training and AI inference and it runs usually as an extension of the hyperscaler stack hyperscalers is inefficient for them to buy firewalls because we are a Swiss army knife for what is a very single purpose task but if you're gonna run multiple tenants and you do segmentation and do all those things they need a firewall so you know I'm guessing I'm guessing I don't know the answer I don't think more than 10 or 15 percent of business in the world of building data centers is multi-tenant I think 80 90 percent of single tenant like anthropic goes and buys the entire capacity for data centers that this is mine which case they don't need to secure the firewalls because and tropical with a big pipe and run it between their multiple data centers themselves another piece to this which is enterprises I guess you would call it sovereign AI where enterprises say we want to have our own data centers
where we run our own AI Corey for example talks about Caterpillar doing this type of implementation? CoreWave? Caterpillar? So my question for you is, is there an enterprise angle to this where enterprises build their own proprietary data centers to do single tenant?
Sure. I think the struggle right now is the people who understand AI really well and how to work with it are working at Frontier Labs. We have 9,000 engineers, and I suspect 5% to 8% are good enough to get a B-plus grade in AI, and probably 1% or 2% will get an A grade in AI. And that's great. I think 92% of the people will not get a, it's like the teacher will have to rework their homework right now. I think in that environment, when things are moving so fast, it's dangerous to DIY. I think it just you have to wait for this to stabilize, so Sure, I'm sure there are examples of people trying different things I think the industry is in too much of a state of flux and things haven't stabilized or you might find these bets are wrong bets I think you know two years from now as I said you should be able to get average intelligence for free I should be able to do simple tasks or average tasks for no money, right? I mean you can buy instinct or muse without spending any money, which means it's going to do my, you know, book me an airline ticket, find me a vintage card, or find me a clip of a video on the internet for $0. That's average intelligence. That's for free in the consumer use case. Why shouldn't that average intelligence be free in enterprise use case if I have the ability to buy compute, right? As long as I pay for the cost of compute, I should be able to buy that intelligence for free. There's no value for me to pay a premium for that. I will pay premium for premium intelligence with harnesses and data training and for tasks now that's a combination of an LLM and domain knowledge that is hopefully in the domain of an enterprise unless the enterprise commoditized that by mistakenly training training a in a public model which also happened like you know you can solve Napier Stokes by having mathematicians use free models you've been very consistent in talking about when there is a disruption in an existing security vector, like network, like endpoint, like identity, Palo Alto takes advantage of that disruption and can actually sell something better and different into that market.
Given that we're in a period of time where technology is in a period of flux, how do you stop someone out Palo Alto networking you?
That's what I, you never used to have sleepless nights. Now I think about this before I go to sleep.
When did that change?
It changed because every morning when I wake up, there's new shit that I didn't understand until yesterday, and I got to learn this, like, literally, I learned about Muse and the new architecture on the plane back from Geneva. I had to read, like, for half an hour, 20 different posts, and then I had to go talk to Gemini, and I talked to Chad GPD, saying, what's going on here? Why do they do this? And try to understand it. Now, if that's the level of knowledge you have to have, because remember, our jobs are our jobs are trying to figure out where's the AI going to go what does that mean for security what do we need to build from a security perspective what is that going to destroy structurally from a market perspective how do you position the company over there so if you're going to get all these signals every day which you're going to have to revisit your thesis every day or every week it's hard and at this point in time if leaders don't pay attention understand where the market is going you can get stuck in where you are because you haven't thought about where the market go. Or you could try and knee jerk too quickly and build your own data sensor in a known new cloud and start trying to control the outcome and say, oh my god, I went down the wrong path. So you have to be sort of nimble and be able to validate your thesis on a consistent basis. So what do I know? I do believe that most software will get rewritten in the next 10 years. I think enterprise software will get rewritten. Now, unless you have a series of modes, even then, our UI and our software at Palo Alto is being rewritten as we speak. We're becoming more AI native. You will be able to talk to my software and have AI models behind them assist you in navigating my software and the findings of my software that will become par for the course every software piece of software would have to do that now the question is then what mode do you have no people said system of record is a mode I think that's a short term mode after a point in time the system record becomes just an unstructured database it doesn't become a mode anymore because your UI has been modified over time. So the mode is I'm deployed 180 million sensors around the world. Somebody has to physically replace those 180 million endpoints of Palo Alto from data centers, from firewalls, from endpoints. That's a mode. It'll last for a while. Could I go acquire another 120 million endpoints in the meantime so I can build a bigger mode? Hopefully. That's my mode. My mode is I run 19 petabytes of data through Google Cloud every day. It requires a big firehose for you to come and take that out and find somewhere else you can put 19 petabytes of data where you don't have compute. That's my moat. So within those moats, I have to keep building my business to make sure that what gets commoditized needs to be reinvented by my team. I have to protect my moats. That's what I have to do every day. So I'm sure somebody will out-parallel-alto networks, but not going to give up without trying to give them a run for their money.
What was it about the due diligence on, we could pick any one of your acquisitions. Chronosphere is actually my favorite. What was it about Cronosphere that made you think this asset has a moat that is not going to be disrupted by next-gen observability?
Look, if I want to be a bigger business in the next five or ten years, I have to get in the token flow. If you believe the world is going to spend $5 trillion and they're going to try and monetize that $5 trillion somehow in ARR using AI in some way, shape, or form, I'm a security business. security is a typically a two to five percent attach to IT businesses if I can find a way to just be that little parasite that sits on the back of the whale or wherever you said just suck out two percent of the money I'm in good place because you're gonna have a trillion dollars of ARR two percent a trillion I heard is a lot of money it's more than I make today so I just need to find something to get into token flow a proxy for token for me is data right if I'm the data flow at least I'll be in the data inspection business so what are the three largest businesses and data observability sock and endpoint inspection that's why I own observably business that's why I live in the sock world and that's why I have an endpoint mode so if I can just make sure my endpoint modes and my security data and my observability data allows me to be in the token flow I'm in a good place there's more there's internal IT data which also is interesting that's why console is interesting because console actually builds on top of internal IT databases. So if I can build Palo Alto in a place where I collect the data once and I analyze it for multiple use cases multiple times, I can optimize the cost for my customer so they have to spend less money, and I can then charge for the intelligence in each of those verticals over time.
Are there other markets that fit or other adjacencies that look like an observability or a console?
Should I just tell you the company I'm going to buy next and make it easier?
I'm not asking for a company. I'm asking you an abstract philosophical question about how you think about the IT world.
So, you know, When I was at Google in 2004, Larry Pagin came and told a story. Steve Jobs told him that the only thing Larry could do differently was he should focus like Apple does because that's how you build a great product and you have a lot of people use it. Larry posited an alternative hypothesis saying, if I have competent people and access to a lot of capital, I can have a lot of competent people try a lot of different things and many of them will work. And you can see both strategies work. We've tried the second strategy. We try and do multiple things. We try and see how many we can do well. We have access to capital, and we try and find the best people to do them. Sometimes the best people work for companies that are not ours, and we buy those companies, and they can work for us. When I started eight years ago, we were a hardware firewall company. We were able to use our internal resources to build. The last product innovation PowerAlter did before I got there in 2018 was in 2015. Today, we do 70 product deployments every year. We've changed our pace of innovation, and then we acquired 47 companies so far that allows us to live where we live. So, we're constantly paranoid. We'll keep looking at the market to see how do we get access to great people and great markets and wait for markets to inflect. We have to be ready. Five years ago, we're running the SIM business. We have a $700 million ARR SIM business, which is now taking down most SIMs in the market. We had no SASE business seven years ago. Today, we're second in SASE with 40% of growing faster than the largest player and taking share from them. So, if you set your mind to it, over time, security markets commoditize. Customers start looking at each other and saying, your product looks very much like their product. Why should I buy yours? Well, guess what? Mine works seamlessly with my hardware stack and software stack and sassy. So over time, as software commoditizes, platforms become more important. So that's what we're trying to play. It's worked out so far. Hopefully it keeps working.
I think it leads to a little bit of a question on industry structure. Tell us, so with this view of the world where platformization, I think there's enough evidence at this point that suggests the largest cybersecurity companies are compounding at scale. The M&A is proving to be successful from a cross-off, from a technology, from a MOTS standpoint. Do you think that the industry continues to concentrate in terms of profits over the next few years, or is there a part of the security stack that fragments?
Well, history should suggest so. In 2012, the market cap of cybersecurity was $40 billion. The Symantec had the largest share. that point in time at 30% today the industry is 670 billion dollars market cap but we're close to 300 of it so it does seem like it does consolidate over time you just have to make sure you don't sleep at the wheel so you have to be constantly paranoid to make sure products are beating the top of the market so we have 20 plus Gartner magic coordinates were at the top to the right which is good which tells which is it's an arbitrary metric but at least gives me comfort that in 20 categories our products are as good as anybody else in the market which is always a good sign the idea is you don't want to become somebody who's not in leading quadrant and out of 27 categories you play in 20 run the right so as long as I keep aspiring to have the best product in the market I'm going to have heft as long as I have a good sales force which keeps driving more value for customers hence getting our customers to spend more is great and then you have to run the business efficiently like I can run a $10 million or $15 million Skunk Works project and not impact my P&L, smaller companies can't. We're doing tons of work on using AI to be more efficient. And if we do that, we're probably going to run our business at a 500 to 600 base-to-point differential than smaller companies in the market. If you're going to run a profitable business at scale, it becomes a competitive advantage.
You gave us a couple of examples on how your day-to-day has changed with sleeping less and doing more research on AI.
Just more emails to my team. I only have 12 people to work for me. Everybody else, it's like literally people get emails.
Any other wisdom you would leave us with as to how your day-to-day has changed and what we should be paying attention to? You spend more time on X as well. The thought Leadership Avenue has changed.
Yes, that has changed because I went to do this podcast, and I told this guy, you know, he's building his own brand in the back of interviewing all of us and getting us to speak for an hour, and he does 20 a month or whatever he does, and he's becoming more popular. I'm like, dude, this is unfair. He's like, well, you're stupid. I'm not. I said, why am I stupid? He says, you could build your own brand by tweeting once a day. And then, of course, I started tweeting once a day. And then Al, your head of comms, said, that's too much. Don't do so much. You put your foot in your mouth. I said, that is, doesn't matter. I can do that once a week, and I can still put my foot in my mouth. So I'm trying to balance putting my foot in my mouth once or twice a week.
How do you pick what to tweet about?
I don't really pick. I didn't really want to say that you have to protect your IP because it looked like I have something to say about that Napier-Stokes thing, which I don't. So I sort of made it more generic. That kind of inspired me to talk about how people should secure their AI. I saw people getting all excited about NeoCloud, so I kind of said, NeoCloud is going to trade at the same price two years from now than they're raising money at today. It was like, I had all the nebbiest lovers come after me quickly. Like, that's a NeoScaler. That's not NeoCloud. Then they got to calm down. So I just had to watch out where I put my foot in.
Well, you're one of the few CEOs that has an investing background, so.
Yeah, sometimes that works.
Multiple perspectives.
I used to maintain my CFA, but then they started questioning shit like, never mind, I'm not paying you $2,000 a year.
I don't think you need your CFA to have an opinion on NeoCloud.
Well, honestly, they sent me a letter once saying, oh, we just saw in a public profile.
It's a subscription model.
Yeah, I stopped paying for it because I didn't use it, and then said, oh, somebody on your CV says you have a CFA. You owe us $2,000. So I sent them $2,000, and now I can say I'm a CFA. And then they say, oh, you have to do this training to do professional services conduct or something. I'm like, shit, I don't want to do it. So I stopped paying. I was like, I still do not write CFA in my CV anywhere. So now I'm gone. I could say former CFA, I think. I wonder how that would go legally, but I could say former CFA.
I don't know if that would give you more or less credibility with the Nebius people.
No, they're very passionate. I think, look, Nebius is a neoscaler. Look, eventually long-term data centers have an 18% IRR. In the meantime, funding CapEx with equity is a bad economic decision, but you guys can tell me that. I don't think so. But for now, it's working.
I think that's all the time we have. Please join me in thanking Nebius for talking to Nebius. Have a wonderful rest of your week.
Thank you very much.