From PANW and CRWD to SAIL and VRNS, the watershed moment in cybersecurity has completely shifted.
Article by DaiDai, MSX MaiTong
Edited by: Frank, MSX Maotong
Over the past two years, Silicon Valley and the tech industry have pushed relentlessly to make large models “smarter.”
But when models step out of chatboxes, put on name badges, and become agents—from Palantir’s AIP on-site to internal networks across major companies—CTOs suddenly realize that intelligence is no longer the primary concern; uncontrolled permissions are the source of disaster.
Assign an agent an account that can instantly read SharePoint, run SQL, modify code, and even approve payments in an ERP system. It’s not an employee, yet it has system credentials; it’s not traditional software, yet it can proactively invoke tools, access data, and execute tasks.
For the past two decades, enterprise cybersecurity has essentially been about “controlling people and devices and securing your own backyard.” But today, a legitimate agent, armed with a legitimate token and operating within a legitimate business flow, can perform unexpected privilege escalations due to logical drift or a single malicious prompt.
At this point, who’s in charge?
This is also the biggest difference between this round of cybersecurity reassessment and previous ones: AI has lowered the barrier to attacks while simultaneously creating new security targets—models, agents, MCPs, machine identities, enterprise data, and runtimes.
In other words, the control plane of cybersecurity is irrevocably shifting from perimeter networks and endpoints toward identity, data, and runtime.
One: Why has “cybersecurity” suddenly become the main AI theme again?
Over the past decade, enterprise cybersecurity has largely established a stable division of responsibilities.
The firewall manages network entry points, EDR monitors endpoints, IAM controls identities and logins, data security handles sensitive information, and SOC responds to alerts that have already occurred.
The underlying logic of this system is simple: it always revolves around people and devices—whether the operator is an employee or an intruder, as long as you can identify who the person is, whether the device is trustworthy, and whether the network connection is secure, most issues already have well-established solutions.
The agent completely shattered this logic.
An agent, even with a legitimate identity and normal login status, may still exhibit unexpected behavior due to excessive permissions, incorrect tool usage, or influence from malicious prompts and external content.
Therefore, corporate security must now answer a question it has never encountered before: are its current actions still aligned with the original purpose for which it was authorized?
Looking at the actual enterprise adoption pathway of agents, today’s cybersecurity companies can essentially be divided into three groups: one focuses on building platforms, another controls identity and data, and the third secures networks and access points.
II. From PANW and CRWD to SAIL and VRNS, who is stuck at the true choke point?

PANW, CRWD, S: Platform giants with the shortest path to commercial monetization
Palo Alto Networks (PANW) remains the most thoroughly platformized company.
It no longer relies solely on traditional firewalls; instead, it continuously integrates Network Security, Cloud Security, SOC, Identity, and AI Security into a single platform. Prisma AIRS now covers models, data, AI applications, and agents, while also incorporating capabilities such as AI Runtime Firewall and Red Teaming.
Therefore, PANW aims to address the entire chain—what models AI uses, what data it accesses, what tools it invokes, and whether any anomalous behavior occurs once it’s running. The company’s revenue for the latest quarter reached $3.41 billion, a 34% year-over-year increase; although this includes growth from acquisitions, it still indicates that when new security budgets emerge, large platforms typically have the shortest path to commercialization.
After all, the customers are already there, the contracts are already in place, and new products can be cross-sold directly into the existing system.
CrowdStrike (CRWD) takes a different approach, focusing more on the execution layer.
The agent’s reasoning may occur in the cloud, but the actual actions—running scripts, writing temporary files, invoking system processes—ultimately take place on servers, containers, or employee endpoints, which is precisely Falcon Platform’s strength: seamlessly extending endpoint telemetry to the runtime, placing CRWD right at the frontline of where actions happen.
Therefore, CRWD’s most core assets have always been the Falcon platform and the telemetry accumulated from a large number of endpoints and cloud workloads. Revenue for the latest quarter grew 26% year-over-year, ARR grew 25% year-over-year, and net new ARR performance was even stronger, indicating that CRWD is expanding from endpoints into identity, cloud, runtime, and SOC.
SentinelOne (S) is also pursuing a similar direction, but on a significantly smaller scale.
Its Purple AI ambition is more aggressive: rather than serving as an auxiliary tool, it aims to have the Security Agent take over the workflow of junior analysts, moving further toward automated investigation, event correlation, and response triggering.
If this step is truly implemented, AI will not only change the product features of cybersecurity companies, but also the way security software is used and billed.
2. OKTA, SAIL, VRNS: New security locks with the highest incremental purity
If platforms like PANW and CRWD excel in scale, the native growth brought by Agents first impacts Identity and Data.
Okta (OKTA) and SailPoint (SAIL) are both expanding into Agent Identity, but their traditional strengths differ.
Okta is closer to Authentication and Access Management, addressing “who you are, whether you can log in, and which applications you can access”; SailPoint focuses more on Identity Governance, concerned with why a permission exists, who approved it, how long it should be retained, and whether it should be revoked after a task is completed.
Applying this governance to humans is already complex; applying it to agents will undoubtedly be even more challenging, as agents may have short or long lifespans, invoke multiple tools, inherit user permissions, and even generate new agents.
This is also one of the more noteworthy aspects of SAIL’s recent data: its latest quarterly ARR increased by 25% year-over-year, SaaS ARR grew by 36%, and more importantly, the company disclosed that its AI-driven ARR has surpassed $70 million, with AI products contributing over 30% of net new ARR—demonstrating that Identity has moved from a product story to real contracts.
In comparison, Okta’s revenue growth for the latest quarter was approximately 11%, with cash flow and profit margins continuing to improve, but its overall growth rate is clearly lower than that of leading cybersecurity platforms; thus, the key challenge for the next phase is demonstrating when these new products will once again impact the overall growth trajectory.
VRNS takes a more direct approach to Agent logic, focusing on data—long specializing in sensitive data discovery, permission analysis, data classification, and threat detection, and now incorporating AI Governance and AI Runtime into the same framework.
After all, the stronger the Agent, the more essential it becomes for enterprises to first clarify one thing: what exactly can this Agent see? In the latest quarter, VRNS’s total revenue grew approximately 18% year-over-year, and SaaS ARR increased by 52% year-over-year. However, this 52% includes a significant impact from traditional customers migrating to SaaS; if conversion effects are excluded, the SaaS ARR growth rate is approximately 25%.
So what’s truly worth watching with VRNS now is whether AI Data Security can pick up the growth momentum as the SaaS transformation effect gradually fades.
If the Agent truly enters an enterprise production environment, data permissions will likely not be an “optional security module,” but rather a issue that must be resolved before deployment.

3. FTNT, ZS, NET: The network entities have changed, but the pipelines remain.
The changes brought by the agent do not mean that traditional cybersecurity loses its value; rather, future access to enterprise applications and the internet will no longer be limited to employees and devices.
Zscaler’s (ZS) Zero Trust has primarily managed Employee → Application, and in the future, it will gradually expand to Employee + Workload + Agent → Application; the more agents there are, the more machine access will need to be authenticated, authorized, and isolated.
Therefore, when traffic accessed by machines experiences exponential growth, the billing point for the Zero Trust gateway is triggered.
ZS’s quarterly revenue and ARR both grew by approximately 25%, but excluding the impact of the Red Canary acquisition, both growth rates were closer to 20%. From this perspective, what ZS truly needs to validate going forward is whether its new Agent-to-App demand framework can reignite accelerated growth in new ARR.
Fortinet’s (FTNT) AI logic is more infrastructure-oriented and has benefited from private deployment.
It is not a typical Agent Security company, but as more financial, healthcare, enterprise, and government organizations build their own GPU clusters, private clouds, and AI factories, the demand for network isolation, east-west traffic control, firewalls, SASE, and security operations will naturally increase.
These are precisely the capabilities Fortinet has accumulated over the long term; in other words, it is betting on the essential demand for traditional infrastructure in the new computing cycle, as well as whether Private AI will trigger a new enterprise network and security procurement cycle.
Cloudflare is even more special—it has the largest appetite and the highest valuation (see further reading: Why Are Everyone Suspecting Cloudflare as GPT, Claude, and Grok Go Offline?).
NET cannot simply be classified as a cybersecurity company. With CDN, WAF, DDoS, Zero Trust, Workers, and a global Edge Network, it simultaneously occupies positions in internet infrastructure, cloud computing, and security. After the widespread adoption of Agents, the very structure of internet traffic may also change.
In the past, it was mostly Human-to-Web; in the future, there will be an increasing number of Agent-to-API and Agent-to-Agent interactions. Agents will autonomously visit websites, invoke models, execute code, and even complete machine payments. Ultimately, what Cloudflare is truly betting on is not just AI Security, but a larger transformation:
If an increasing amount of internet traffic is generated proactively by machines, could NET become a key entry point for this layer of the Agent Internet? This is its greatest differentiator compared to other cybersecurity companies—offering greater potential, but also incorporating higher expectations into its valuation.

III. Valuation Watershed: Who Includes Agents in ARR First
Return the industry logic to fundamentals and valuation—the market has already given a very honest vote of confidence with its feet:
- High premium cohort (CRWD, NET): Maintain growth expectations of 20% or higher; the market is pricing in their potential to further expand TAM through AI, resulting in EV/Sales multiples consistently in the highest tier;
- Quality defense names (PANW, FTNT): Growth is not as explosive, but supported by platform depth, network infrastructure characteristics, and extremely solid free cash flow;
- Elasticity-in-waiting cohort (SAIL, VRNS, ZS, OKTA): Valuation multiples are relatively restrained, but this also represents an opportunity—should any one company be the first to demonstrate that its Agent product is materially driving net new ARR growth, it could trigger a valuation rebound;
Having come this far, the cybersecurity AI narrative has moved beyond the “hackers are using AI, so everyone benefits” sprinkle-everywhere phase.
Because this logic is too broad—almost every cybersecurity company can talk about it, can release Copilot, Agent, Runtime Security, or Agent Identity, and can all explain why AI expands their TAM.
What is truly diverging now is that companies are beginning to adopt AI at scale, requiring their existing security architectures to be redesigned accordingly—those who can clearly account for these new demands in their financial statements will be best positioned to reignite overall revenue growth.
This is why PANW, CRWD, SAIL, VRNS, ZS, FTNT, and NET are being discussed together; it is foreseeable that the differences between them will only grow larger.

Platform companies compete on distribution efficiency, identity and data companies compete on whether new control points can be commercialized quickly, and network and infrastructure companies must prove that agents and private AI will ultimately generate new traffic and procurement cycles.
So as this market cycle progresses, the most important thing to watch is who can prove first that agents are changing their growth trajectory.
This is why SAIL’s recently disclosed AI-driven ARR is more noteworthy than simply launching an Agent product. As long as AI products are genuinely purchased, new ARR begins to emerge, overall growth resumes, and these revenues ultimately translate into profits and cash flow, the capital markets will naturally vote with their feet.
From this perspective, cybersecurity is not a new storyline that suddenly emerged outside the main AI narrative.
The more capable AI becomes, the deeper enterprises’ fear of losing control grows—and the winners of this cybersecurity cycle will be those who can most quickly turn that fear into tangible cash flow on every quarterly earnings report.
