In short
Podcast Episode Summary: Palo Alto Networks’ Nikesh Arora: AI, Security and the New World Order
Podcast Overview
- Title: Training Data
- Description: Host discussions among AI builders and researchers about the implications of evolving AI technologies on business and society.
- Hosts: Sonya Huang and Pat Grady, Sequoia Capital.
Episode Details
- Featured Guest: Nikesh Arora, CEO of Palo Alto Networks
- Episode Focus: Discussion on AI, security, and the necessary guardrails for enterprises deploying AI technologies.
Key Themes and Concepts
AI and Security
- DeepSeek Hype: Arora addresses the misconceptions surrounding the capabilities of models like DeepSeek, emphasizing the need for robust guardrails before enterprises can deploy AI agents effectively.
- Real-Time Detection: The shift from prevention-focused to real-time detection and response systems is crucial, given the rapid escalation of AI-driven threats.
Risk Management
- Role of CISOs: Chief Information Security Officers (CISOs) are primarily risk managers who must balance innovation with security. Legacy companies must adapt quickly to compete with more agile, risk-tolerant startups.
- Human Augmentation: Current use cases of AI in enterprises involve augmenting human capabilities rather than replacing them, with employees using AI tools for enhanced productivity.
Guardrails for AI Use
- AI Firewalls: Palo Alto Networks has developed security solutions (e.g., Cortex XSIAM) to inspect and control interactions with AI, ensuring proprietary data remains secure and preventing misuse.
- Precision Use Cases: Arora stresses that AI can be beneficial when applied to specific, narrow tasks with clear boundaries, but risks increase when AI systems are given broader capabilities prematurely.
Threat Landscape
- Bad Actors and AI: There is a real and present danger from bad actors using AI to exploit vulnerabilities. Arora notes that AI can facilitate faster, more efficient cyberattacks, increasing the urgency for enterprises to bolster their defenses.
- Perceived vs. Real Threats: Distinguishing between hypothetical risks and tangible threats is vital. While the fears around AI’s potential misuse are partly academic, there are already instances where AI is aiding malicious activities.
Future of AI in Security
- Bifurcation of AI Models: The episode discusses the potential for a split between general-purpose AI models and specialized, task-specific models that require significant proprietary data to operate effectively.
- Challenges in Deployment: Organizations need to ensure they have the data and infrastructure in place to effectively deploy AI without compromising security or operational integrity.
Insights from Nikesh Arora
- Innovation Necessity: All organizations must embrace AI and experiment with its applications to avoid falling behind competitors that leverage AI more effectively.
- Leadership Principles: Arora highlights the importance of clear vision, resource allocation, and ongoing communication within organizations to foster innovation and adaptability.
Conclusion This episode emphasizes the critical intersection of AI and security, highlighting the balance between leveraging AI for operational efficiency and protecting against the increased risks it brings. As AI technologies evolve, organizations must implement strict controls and adapt their security measures to meet new challenges.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Like, I have a principle that I was joking even in our all hands and say, I've never met a person who comes to work to screw up. I wake up in the morning, let's go sunshine, it's time to go to work, let's me see how badly I can do today. Every walks in with the right attitude. It's something that happens at work that we create that causes the unintended outcomes. It's not the person who walks in. If you found the right person with the right domain knowledge, right in the right attitude, then the rest is upon us.
0:47Today on training data, we have a very special episode with Necache Aurora, the CEO of Palo Alto Networks. Since joining Palo Alto in 2018, Necache has built it into the largest and most valuable cybersecurity company in the world with 70 ,000 customers and more than 120 billion dollars of market value. Prior to Palo Alto, Necache spent a decade at Google as the Chief Business Officer as the company grew from 3 billion to about 65 billion dollars in revenue. The Cache is an extraordinary CEO with an inquisitive mind and a wonderful sense of what is happening in the world of AI thanks to being in the center of it with Palo Alto and all of their customers.
1:30Please join us for a wide range in conversation about AI, its impact on security and what excellent leadership looks like. We hope you enjoy. The Cache is thank you for joining us on training data. So we emailed you and asked you if you joined us on the show and your response was and I quote as long as we can talk about deep seek and the new world order Let's start there. Tell us more I bet you know we all have our interpretation of AI and as a bunch of us trying to figure out and rationalize this and some sort of mental framework so like everybody else I have had my own and I mean from my perspective what we've seen in the last 12 months has been phenomenal And if we have people trying to build effectively a brain, right, of some sort, a brain with immense capacity to remember everything, to process everything and do pattern recognition, which is kind of like, you know, my interpretation of an NLM.
2:25Now that brain, because being trained on data that's out there, is susceptible to reaching it on conclusions, depending on the data that's using to train itself. So this is not a secret. and we hear of that in various contexts of hallucination or not having the right answer because I've never seen it before and that's fine. You can call it the early brain, but at some point in time, these things are going to become very smart, possibly smart as you bad. You know, it takes several more years to hit Sonya stage. That's exactly right. So at that point in time, I think we all have to start getting a little worried.
2:57So the question is how much money does it take to build this brain? One and two, how can all of us use it effectively? I think we can all use it effectively today in certain use cases as we've seen out there, whether it's in a creative use cases or search use cases or data aggregation use cases or data regurgitation use cases. At some point in time, you're going to take this brain and give your arms and legs and let it do stuff. And that's where things start getting dangerous. And we've seen examples where people gave these brains the right to do stuff too soon, too early, where they started giving you free cars or refunding airline tickets, which is not a good idea because that is their version of helicinating and getting stuff away.
3:37But on the other hand, people are sitting in cars where these brains have arms and legs that are driving us around without a driver. So there are examples where there are precision use cases which are narrow and thus specific where we are letting these things get access to it. So I'm sorry for the long preamble, but the whole notion of the new world order was, you know, and I don't have an opinion on whether it costs $6 million or more. my opinion is that if somebody built a brain cheaply and made available cheaply, it just expands the opportunity for a lot of these startups, a lot of people to try and deploy that brain to do various tasks.
4:11And that to me is a major shift in what has been sort of the main state of this industry where we all talk to you, it's about a lot of money to build amazing models and it looks like there could be task -specific models which we built a lot cheaper. And you mentioned some of the hallucinations and the attempts to geobrake these models or prompt inject these models. There's a report that came out a few days ago about deep seek R1 that said 50 out of 50 prompt injections worked. So basically 100 % success rate on attacking the model. Is that a deep seek thing? Is that an open source thing? Do you have a perspective on what the implications of that might be?
4:47Maybe it's not as simple as six million bucks get you the same thing you get out of open AI? Well, of course, which one do you want, right? And like at the end of the day, Every model is putting a bunch of guardrails around it. These models all, if they're in the raw, they have, they're in the raw. They've, have you to remember the early versions of Chad GPD and Gemini, I think what it was called, vertex, what they call that. It was called something else before Gemini. And those things had the opportunity for us to prompt and inject as well. So they were versions of these models which had to have guardrails built around them and those things, that's what it cost money to do, to build guardrails.
5:24The guardrails initially were skin deep. As you know, we've read these phenomenal stories in the early days where people were able to jailbreak them and get around them and get models to start and it'll increase your stuff. So I think we will see more and more guardrails, more and more simpler attempts being blocked. I think there are still sophisticated things that can be done to these models. Even the more expensive models have loopholes or have side doors which can be used to attack them to some degree. And we've seen that happen the past. So yes, perhaps deep seek is not as guardrail as it is and Perhaps it was built cheaply but in the end of the day what Chevrolet model it is when you deploy it for a precision use case and give it arms The legs it doesn't matter what guardrails them all it comes that you will have to superimpose better guardrails and controls around it This is where people like us come in where we say it doesn't matter what you got I'm still gonna put a pile to firewall and put a straight jack around this and make it only respond to task -specific stuff IE, if the model is designed to improve your manufacturing process, you can't talk to it about, you know, rewriting Shakespeare.
6:26Let's talk about that for a minute. What's in scope and what's out of scope for fellow other networks as it relates to securing AI? Well, from our perspective, what we're seeing to interesting use cases. One, we're seeing a lot of people who are employees, who are kids, who are users, using AI in some way, shape or formed augment their day job. And you can call it Augment for now and maybe it'll creep up and do more and more a few day job. But it's being used as a human augmentation for now, right? Because we're not giving you control. I'm not telling an AI agent to go write me a paper for my class or I'm not telling an AI agent to write me a blog and possibly one of these days they will.
7:05But for now, it's being used for human augmentation and the general fear and the enterprises, my employees are taking to a proprietary data and for the added sub -model and it'll be used for training and over time, it'll get without a copyright, it'll get stolen, it'll become part of the general of knowledge based on that proprietary data. So we have a use case where we can intercept data, which is being used by employees, or AI that's being used by employees, and provide a disability to enterprises and to provide control so they can stop employees from going and using AI models, or AI apps without any control.
7:38So it's got one use case, which is kind of interesting. We see a lot of companies who want their employees to use AI, but they want them to be able to earn a control function. Other more interesting use cases, I haven't found a company which is not experimenting with some sort of AI project, whether it's a simple as a customer service chatbot, it seems to be the most popular example, or some sort of workflow automation capability, which is another example, to the extreme where people are using it to perhaps slowly edge giving in control over certain control systems, which may not be mentioned critical, but they're experimenting there.
8:13In all these scenarios, the biggest fear is the model runs amok. The model gives the wrong answer or the model takes control or somebody hijacks them all. All those are scenarios which customers are very about, which is kind of like understandable. And that scenario, we have a product which is effectively, we formally call it the AI firewall, the firewall which inspects anything going in anything going out of the model, it'll make sure the model doesn't have back doors Nobody can access it. The data is not being sent out of the model somewhere else. You can run it on -prem You can run it in your you know protect your cloud instead.
8:49So those are kind of the you two use cases we're seeing The behavior of the model is the responsibility of the people generating the model Our job is to make sure that the model doesn't get hijacked doesn't get intercepted doesn't get taken over or or manipulated so that people who's control off their couldn't go AI brain. Can you say a little bit more about, you know, what are the real threats from AI versus the perceived or the hypothetical risks? Like I remember back when self -driving cars were still a little bit of a pipe dream and everyone was saying we're going to have these adversarial images, QR codes, and the rows that are going to make the cars become weapons and things are going to go crazy.
9:30and that ends up being very academic theoretical risk. It feels like there's some of that happening in LLM lands. What do you think are the made up academic risks and what are the very real risks you think are going to, where AI is actually going to really help the bad guys and we have to protect ourselves? Well, there is these two scenarios. The scenario where the bad guys is going to use the LLM so it acts faster. Please hold that happen already? It is already happening. If there's a critical security incident or vulnerability in a product, you can go to certain jailbreak models or open source models out there, which will give you a recommendation on how to exploit the CV.
10:09Because there's 3000 miles of hunger base, you can pick a model that hasn't been given guardrails or given any morals effectively in the context of a brain and saying, hey, here's the CVE. One of the five steps you've taken to protect it and the other five steps that bad guys could use to attack it. So it says, oh, by the way, watch out for these five things bad guys could do. So there are models out there that can actually give you a recipe to figure out how to exploit a CVE or you can actually tell it I tried to attack a customer with option A, I tried option B, now they work because it gives this return response and it says A How many try options C?
10:42So there's a whole bunch of ways that these models can be used very easily because they're very helpful right now Right, so they're trying to solve your problem and there's a risk that like actually not just risk it's actually true right now and what that does is it reduces your your mean time to attack an X -Full Trade data or mean time to breach. Which means the only way to solve that problem is to be as nimble as effective and as quick as the bad guys are, which sort of like, you know, it's a, as I always say, it's kind of a disbalanced problem. They have to be right once. We have to write 100 % of the time, which means they might need this sliver of data to attack you.
11:17We need the entire corpus of enterprise logs and enterprise data from every IT system to be able to understand where there may be an almost activity which is being driven by AI. So it's going to be in right now AI is at the margin more helpful for the bad guys than it is for the good guys. Well it depends. We can always sell our book and tell you if you're deployed or an XI product, we can be as equally effective and equally helpful and talk to bad guys. But yes, they're not fully deployed, not everybody has it. So yes, there's a possibility that it just has made the ability to attack much faster for the bad guys.
11:48Right. And that's kind of a real threat. It's not a perceived set. And I think if you if you play the movie forward and say, and let's abstract ourselves from this today, and this is version one or version two of AI in even five years from now, everything will be happening in real time basis, everything every bad actor or bad LLM agent would be able to attack an enterprise infrastructure which is not fully secure. And there'll be agents running on the infrastructure trying to make sure that every loophole, every door, every window is locked and constantly monitored. So you can imagine the Battle of the Agents on either side.
12:20I don't think it's infeasible, it's possible. But to get there, there's going to be a seedest of people required of the enterprise data that exists in the company, which by the way is not unlike the fact that to get effective AI for organizations, we're going to have to have a lot of good data to automate or manage or run businesses. So I think that's kind of where we're gonna end up in terms of the other Parts when you asked about the perceive versus real threat look Think about it this way You know, let's assume and we all I think you know, I'm already guys talk about this But I'm guessing you agree that at some point in time these models get smarter and smarter and they'll be more and more capable So let's assume that's gonna happen they get very capable this person is equivalent of a PhD researcher from pick your favorite university and can do drug discovery.
13:07Now you've trained it, you've given all the data that exists in enterprise, all proprietary, it's all the drug data for Alzheimer's Parkinson's, you pick your favorite, you know, research project that you want to do and you asked the model or this brain to give you an antidote to a various medication. It could be amazing for society. Now the question is in the wrong hands, this train brain could also be asked to make a virus to create that situation. Right? Create a bio weapon. It's possible. This brain has no guardrails. You've trained all the data. It has all the knowledge that you need to have.
13:40Then the question is, can I make sure that this brain cannot be taken over by the wrong people that it falls in bad hands? So just for fun, if you were supreme ruler of the universe and you had a magic wand, and you could determine exactly what regulation was going to apply to this hypothetical. What sort of regulation would you craft? You know, Pat, this is an interesting debate, and I had a debate about this with a very, very smart person who's involved in some of the regulatory aspects of this. Look, at the end of this, there will be two versions, I think. One version is critical systems, where before giving AI control of critical systems, you'll have to go through a serious certification discovery process with some part of the US government, right?
14:31You cannot give the control systems to AI for shipping routes and running cargo containers which can crack when burned or controls the entire electrical grid of the United States. You can't give it to an AI model because you need to have controls in place and need to be able to have a, you know, a conversation around what the fallbacks are and what the controls are. So I think there'll be a set of classified activities which will need some degree of consultation, some degree of certification, validation, it's kind of like, you know, FDA does drug approval. So there is some version of, you know, AI approval, which can have critical irreversible impact if you give control to AI.
15:05And that'll have to be some sort of certification mechanism. And I think where it is not as fatal, where it's not as critical, perhaps, you'll have some degree of self -responsibility, you know. You make a bad car, people have a problem with it, you're responsible. not every car goes through inspection process. But there is a tremendous amount of accountability to the car companies that are doing have seat belts that don't comply with regulations that they're responsible for the bad outcomes this way. If you deploy AI in a bad way in your company and give it on the legs and the troll, then you're responsible.
15:39There'll be some degree of self, because it's impossible for any kind of authority to create an inspection system. All this amount of compute and data which can get it right every time. So there will have to be self -policing and self -accountability in there just to wait existing today in many industries. Because do you think AI labs get nationalized in this, you know, your version of Supreme Rule of the universe? Yeah, I labs get nationalized. I don't think so. I think the problem is, if we're, you know, given that we're living hypothetical, if there is, it is true that a new model can be produced at a lot lower cost, right?
16:16which is in the single -digit millions or tens of millions. And AI Lab could be anywhere. It would be impossible to find, discover, and control. So what's stopping somebody from... And part of these challenges, these regularly, the concepts are very dangerous on a global basis today, which we live in effectively a world with no borders, even though I know that we have a whole different conversation on borders. But, and, essentially, what's stopping somebody from deploying $50 million in a silver cluster in a country which has lacks regulation vis -à -vis the stuff and me building it there or somebody building it there.
16:53So I don't think that the idea that yes of course if it's a $500 billion a cluster that needs is needed to build the world's super brain and AGI, yeah you can find a way of you know maintaining some degree of oversight perhaps on it. But if the answer is this $20 million box and I can build a world class model, which is really smart, then I think all bets are all. Let's say I am not as early as CESO, maybe a CEO. Let's say I'm a corporate executive or some sort. And I see the potential for AI, so I'm excited about trying to use AI, but I'm very scared. I'm very scared because I think that when people use AI, they're just increasing the attack surface and making us more vulnerable.
17:34And I'm also scared because I think there are bad guys out there who are going to weaponize AI against us and sneak in in ways that they might not have been able to sneak in before. What would your advice be? You know, top three things that you advise this person to do. What can people do to get the benefits of AI without exposing themselves to unnecessary risk? I think that would be ill -informed fear in my mind. Okay. I think they're perfectly fine use cases, which I'm sure you can enumerate and Sonya can and a lot of people can. Where you can run a model in a constrained on -prem or a dedicated cloud cluster which cannot be intercepted, it cannot be manipulated.
18:16In the end, that model is all useful if you put your own data into it. And if all you do is have the model generate responses which you're not letting it give it any control, you can not experiment. You can look at what the model produces and compare that to other things. They can do a B testing. They say, wow, the model says this and my best researcher says this and he can run experiments and understand the power of AI without giving any control. So I think that's why the fear is a bit mislight because it's not doing anything. And you're just trying to give you the outcome and you can see if it's faster, better, and both are possible or one is possible, right?
18:48Something's happened faster or something's happened better. So I think running AB testing, being able to test it is easily possible in today's world without having any fear. I think it's even possible for letting employees experiment with it in a way that it is not manageable. I think where it starts to get more interesting, not dangerous perhaps, is when you start letting AI act on your behalf, right? in whichever capacity. And that's where I think any person, not just CEOs, anybody would have to go to a rigorous amount of testing to see how it reacts in various circumstances because depending on what you're giving control to, it could have a significant impact to whatever product service business that you're running.
19:26But that's where I think it becomes more interesting. But I think for now, running experiments, running models which cannot be high -jacked and manipulated models at one run a mock, it's all possible today. I think it would be irresponsible for companies to not experiment. I'll put. Because I don't think that this thing's going away. Yeah. You may not know exactly how to get to the future, but you know if you do nothing, you're gonna get left behind. But I learned about Chad GPD on a flight to India. I was going there to go speak at my alma mater. And I read about this thing, I was sitting at Dubai Airport, not doing anything with two hours.
20:03I kept playing with it, and I redought my entire speech. I went and said, you're about to witness the biggest technological revolution. Now, I just said before Jensen said, this is the iPhone moment, but more important, he's got a bigger amount and he's a supreme commander of AI. So we'll let him, we'll attribute that quote to him, but that's okay. And I felt it was a seminal moment and I came back and I said, you know what? First things first, I have no idea about this. I call a bunch of my teams like, what do you guys know? What do you mean, nothing? We're all like, you know, a bunch of the important, uninformed, but we were important.
20:33So we were, but we had an opinion. And so the first thing I did is I put them all into a, like a training room. I invited everyone from Thomas Curian's team to, you know, that garment now, his team or bunch of startups, they just bring them on us. And we did that for two days a month. We got people to bring them. We had a bunch of our people go come with ideas. We had 70 ideas. People weren't executed. Cut them down to seven. We started playing with it. We ran everything. Every possible problem that you could run with Vertix AI or with the first model of chat GPD or the first model of a cloud.
21:07We tried everything. You ran everything through. We had models running with AI. We had models running with semantic search. You were training with all kinds of data. We learned. We learned what is useful. We learned what is not useful. Now it's doing some things by itself, which we had to go jetty rig. But, you know, we are partially informed. It's better than being totally ignorant. What was the biggest surprise from those learnings? The biggest surprise. Well, you know, the early version of this thing was pattern recognition, was data summarization, was, I'll call it infinite memory, right? Once you train it, some data is never going to forget it.
21:43Now, there are use cases where I have 50 people solving the same problem, and depending on who answers your phone, they're going to solve it differently. In this case, I improved the general level of awareness and knowledge for my entire team, playing, get it or tell you the answer, and then work from there. So it did set a lift the average intelligence of the average capability of the teams and I think as it gets better and better It's going to shorten the time the answers and I mean at the end I want to expose a lot of this stuff to our customers Right, so they can go solve this problem So so my problem is if you don't start learning when every startup is learning Eventually the startups to your business, right?
22:19You've seen that nary technological revolution that we run into whether it's a cloud mobility the internet We saw it every time and every time there was these large, now we can call them legacy, but large businesses with dominant market share with every asset at their behest, which they could have deployed. And nobody should have seen the lighter day who was competing with them with the new technology. But for some reason, every time you turn around, there was a Travis, there was a, you know, Chad Hurley at YouTube and there was a Larry pays and there wasn't Mark Zuckerberg and there wasn't no more.
22:51So the challenges that if we don't go and brace this as early as we can and learn, while everybody else is learning, we run the risk that we're late and then we go in, you know, law of unintended consequences. Maybe on that note, one thing I'd love to understand is it seems like the biggest platform companies and security are kind of formed on these platform shifts, like, you know, the firewall identity as a permutter, you know, maybe the cloud and CSPM. Like, do you think AI is a new platform shift opportunity from a security point of view and do you think a new security platform company, which could be you guys' emerges, or is this very much, you know, similar kind of set of tools is going to serve the AI of First World?
23:34I think AI has the opportunity to turn security on its head. And the reason I say that is that the security is in needle and haystack problem, right? Because you don't worry about it until you have to worry about it. See, to suddenly wake up and get really, really smart very, very quickly because something's happened in the infrastructure. And it's just impossible to go from zero to a thousand like overnight because somebody calls the early shit. There's somebody in the infrastructure that they've exfiltrated, sun mounted or they are in the midst of exfiltrating data. And traditional Social security has been, I'd say, 95 % at the border around prevention and 5 % are detection and mediation.
24:22If I, if I, if I were a wallet, I'd expect everything that's coming in, you block a bunch of stuff. You buy some sort of, you know, remote access endpoint agent, you buy an endpoint XDR capability. And that will work because there's a lot of prevention and that happens in that process. But the problem in breaches is it's not what you prevent, it's what you let in. And this thing's like zero day attacks, which had never been seen before. So you haven't seen it very often, you can't prevent it. And the only way you figure out all that stuff is you ingest a lot of data. You look at it and look for anomalous behavior, right?
24:51You can't rely on security signatures. So if you're going to look at anomalous behavior, you need to be able to ingest all data. You've got to look at pattern recognition and say, does this happen like this every time? And say, well, I don't know, but looks like it's something's different happening. So I think this whole notion of doing pattern recognition, ingesting a lot of data, analyzing it on the fly, and looking for things is easily possible with a call to machine learning, call it AI, call it whatever you wanna call it. But I think that's the only way we can do this at real time speed. What about what it means to be a security team, a CISO, a security practitioner in this new world?
Read the full transcript
25:28And we get 20 pitches a week right now for like the AI powered SOC analyst or the AI SOC. What is your vision for? You already have one, so you stand them our way. It's like, you know, try to follow them. What's everyone how that evolves and what the end state is for kind of humans and security? Like insecurity at a very first principle level, we sell two things. We sell a sensor with sensors at the edge of your parameter, whatever the parameter is, whether it's your laptop, whether it's your application, is it your customer accessing your bank account, that's the parameter, right? The parameter is the edge of your technology, technological footprint, that's the parameter.
26:06So we also send, so if it's sit at the parameter inspect, it's like having like a digital security card at the parameter, we also parameters, and we protect the parameters, we inspect the parameters, we block the parameters, right? And then what happens is that somebody's in the bad app, somebody's in the back door, somebody's in the side door, by mistake, then people enter through there. So we sell sensors, we protect parameters, and then we analyze data in the back end to look for any vulnerabilities that you might have been created by the infrastructure that you have. That vulnerability could be exploitable in the future, so we look for potential exploits, and that's what that's going to do.
26:40Which means, and the reason I tell you stories, which means if I want to sell and I power anything, I need to be at points of data collection in enterprise, because AI requires data. So, again, this is the old adage, right? I am in the best place to collect all this data and analyze it. And of course, that doesn't mean anything because in history, people who are in the best place got knocked off their knees and somebody else came and built something better because they were lazy sitting on their honches. Now, the only thing is we don't want to be lazy. We don't want to sit on our honches. We're out there hustling as fast as we can, not as nimble as possibly in a startup, but we're nimble enough as a company.
27:18We've done 27 products, which are in the magic corner and to the right. So we're not shy, but I think every security company, every security star that's going to walk to every customer I can build this for you. The customer is great. How do we start? Says well, let me go give away bunch of sensors around the perimeter so I can collect the data. Holy shit I only got a bunch of you guys in the industry. You got sensors out there. Then what do you want to do? Then give me all your data I'm like wait a minute you want all my data. Who are you again? So I think that's kind of that's kind of the risk you run into is this is a large data problem and And large data problems are harder to solve as a startup, not to say it's not being done.
27:55There are people out there raising $500 ,000, but not every week into that insecurity. Very enough. Do you think security themes are comfortable giving arms and legs? I think so to speak, like, a gen tick. Oh, no, I think they're petrified. Do you think that flips at some point and when? Well, I think most of security terms aren't asked, right? I mean, we more wouldn't exist if they are taught the security guy. Tesla FSD possibly would not exist in security guys. You're crazy. You're giving the car control to your car where all kinds of bad things could happen, right? So from a security perspective, these all bad things happen.
28:31Look, I mean, security leaders are or the most part of risk managers, right? They're risk managers. They're trying to understand what the business need is and how do I deliver the business need with the least amount of risk possible. The safest room in the world is one with no windows and no doors. but it's not very useful. So you got to let doors and windows be created, which means you're managing risk. So security people are risk managers. They sit down with the business, understand what potential risk does it cause? They'll give you some ideas as to how to make sure that you protect against that risk.
29:01Then they'll set up a whole bunch of safeguards. It's a, you know, you know, Gate one, Gate two, Gate three. If it doesn't stop, get stopped here, get stopped here, and then it off to the races. I think security people will allow the arms and legs have to because that's kind of the crying need of the hour. I think the question will be, what kind of security tools do we have in place to create those protections that customers can comfortably go ahead and use these capabilities? But that's true with every technology. Our partner Jim Gets, and for any listener who's not familiar, Jim has been involved with Palo Alto since formation.
29:34And Jim, Jim has a creative mind. One of the things that Jim mentioned was after you came in about seven years ago, CEO of the Innovation Engine, and Palo Alto really started pick up. And I think we see that today also with how quickly you guys have bounced on AI. I guess the question, maybe two questions. Question one. If you had to reach yourself, if you had to rate Palo Alto on agility, nimbleness, ability to respond to market conditions, I know you're a tough grader, so you can't give yourself an A+. How would you grade yourself? And then question number two, you do have all the advantages of scale and data and distribution and being at those points where you need to collect the information to do whatever detection remediation you need to do, but it's hard to get a big organization and move fast enough to respond to the markets.
30:21So question one, how would you grade yourself question two, how do you drive agility at this scale? Like just practically speaking, what do you do to make that happen? You know, let's go first, first. I'd give us a seven or seven and a half on scale of 10 in terms of agility because we We have about 15 ,000 people. Pop, solubiles, 5 ,000, 6 ,000 people in our product side. So there's a lot of stuff, a lot of complexity, a lot of legacy stuff that has to be brought along, a lot of stuff that has to be ticked and died to make sure that these things work. And you know, any part of the challenge you know is that you have a stall base of 70 ,000 customers, right?
31:00Any tweak you make, which impacts 70 ,000 customers, brings their infrastructure down, you lose your license to operate. So it's not like we can innovate, throw shit at the wall, and see what sticks and go with that and ignore the other stuff. So we have a serious responsibility in making sure a stuff that we build that we put in line has to keep performing and not bring down any other infrastructure because they're the best securities in line. We have to be able to watch what's going on. Inline security has the property that if it doesn't behave, it can impact your infrastructure. So we have a very high responsibility from an availability perspective and not disrupting our customers that we have to apply a higher precision standard as it relates to inline securities.
31:38From that perspective, I think 7 .5 is not a bad place to be. I see probably we were at three or four, seven years ago, as an industry. I don't even say a power out to other, as an industry with three or four. And I see the industries move to the agility. If I look at some of the newer players, they're moving faster. They're not sitting back anymore because they see the playbook for the future is not where you let other people sort of come by in the new swim lane. It's nice to see you, you know. Congratulations, great job. Not as like, oh, you should have the get there. We're going to go chase them down.
32:05So I think the industry dynamics have changed. In terms of how do you drive agility, you as you know possibly from talking to Jim and from talking to us that we have no sort of qualms about going and finding people who are doing it amazingly well and embracing them and saying you got this figured out, let's go to it together, we're on fast. Right? Sometimes companies get trapped in this idea that I have so many resources I can take them down. they don't understand there's a team of 50 hundred motivated people funded by people like you are out there running at sort of in a light speed who build an amazing Product which are gonna then dip the get traction and they your competition on every day in the market and they get better and better and stronger So the question is when's the right time to say oh shit less embrace them They've got less resourceable so much kicker ass.
32:54Let's go make them part of our team We've done that 19 times as you've seen so we're not we're not shy about embracing innovation if it doesn't come forth Then having said that, I was looking at it the other day. I think more than half of our products are made in Palo Alto, right? Not acquired. So it's not like, you know, we only have one strategy we do both because in some cases, building on our platform is a lot easier from a go -to -market and deployment perspective than buying something and spending time integrating it. So we've gone to the point of scale that it's more important for us to innovate on our platform than just go out then really nearly try and look at the fastest innovator and try and stick them onto our tech platform.
33:27So I think from that perspective, of the type constant balance, what do you buy, what do you build, how do you embrace somebody else doing it better, and then you've got to be nimble and say, you know what, I am going to get some stuff wrong. The question is, when you get punched in the face, how quickly you recover, right? Don't let them count to 10. So, it's kind of like how you maintain agility, and then, I mean, the only other thing is, I call it relentless inspection. Relentless inspection of your go -to -market capabilities, of your deal, relentless inspection. What's the sort of thing you might do in one of those relentless inspectors?
33:59in conversations that somebody else might not do. Well, I give example. For the longest times, I kept seeing us doing really well in certain things in our teams that create all these incentive programs to drive more behavior to get people to sell. And I have my sales leaders telling me that everybody has an account plan. I said, these things look like very interesting things. I should take a look at one. So one fine day is possibly, you know, half ago we're having a tough quarter. I said, great. Here's what we're going to do. I'll start from customer number one and keep going. You show me your account plan.
34:34So does that mean? Send them five slides and fill those five slides and show up on a Zoom call. You should have been explained those account plans to me. And I'll pass forward. I've probably been through 750 of them so far in the company. I did about 15 yesterday. And it's like, theta now that are 500 people dialed in from across the company. Wow. Wow, you all get to watch. Get these sales person pals, we can dial in and watch an account review and process. Because for me, it's basically them learning how to do it. And we go through it and say, who's the person, who's the buyer? Does they understand the product?
35:08What did you pitch? How do you sell it? Did you sell it? Did you talk about this? Did you not talk about this? Why don't you talk about this? And by the way, the best thing for our teams is, if you feel that this doesn't look as robust as we'd like it to, me, be a Jenkins or a president, and many of the product leaders, people get involved. We're not just readily inspecting, we're actually assisting. I don't like you'll be surprised that people have been up their laptops are open, like people are pinging people, LinkedIn texting people saying, hey, do you know this person in this company? I don't think our plan is robust enough.
35:38We don't know the right people. Let's go. So, it has kind of like grassroots, I have a little white board in my office, where I write down things, which I want my team to remember. and the second thing is not it, it says sales is a math problem. So, which people find hard to understand. Like, look, if you have the best product in the market, and you are able to win and generate billions of dollars of DCV a year, then the question is, why are you losing? It's not a product because there are people buying the product that is working. It's not that nobody's willing to buy it. It's not that lots of people are willing to buy it.
36:19What happened in that process, what you were selling that you didn't win somebody else did? Let's go inspect it. And sometimes you'll find some product things that you need to fix many times to just find execution errors. Let's keep going on this thread of driving performance out of people because one of the other things that Jim said was that you have sort of an exceptional ability to recruit and retain really exceptional people and that you sort of drive followership in a way that's unique. like you're pretty hard on people and you demand a lot from them. Yeah, I went to, I want to speak yesterday for a person who I worked with at Google.
36:55Her name is Lexi Reese and she actually ran for a sentence. She has a startup now and she introduced me by saying, yeah, I didn't quite enjoy my time when I was to work for you, but I'm a better person. I learned a lot. So I'm like, well, I'll take it whichever you give it to me, but anyway, sorry. Well, and Jim said you balance that with a very nice human approach where people know that you care about them and you'll go to batch for them in the right situation. So I'm just curious what you've now been an executive in a variety of contexts and you've been successful every time. Google as a consumer business, Palo Alto as an enterprise business, you know, you kind of grew up around marketing and sales and you become more of a product person.
37:30And so you've got this diversified set of experiences from that enterprise person. You're a full -fledged enterprise person from now. Right. I guess what leadership principles or what leadership techniques are sort of context independent that work at each step in your journey and are there other things that are kind of palo also specific but I'm most curious like what are the sort of core principles of your approach to leading people? Not a lot of palo all of this specific right because at the end of the day my senior executives are not writing product documents right they're analyzing strategy analyzing go to market they are understanding it of course.
38:09Do I have experts to subscribe of course? We could survive without that you know. So near Zook or Fahnberg, Lee Kvairich, what you product officer, so the other product leaders that we have, very smart guy, they understand what our products system is in the street, they act as sounding boards sometimes all challenge them, I find spare pushbacks, the cultural accept. So there's no getting this done right without the right domain knowledge. So you have to have But I think outside of that pack that there's domain knowledge, you see after the right people, like as is possibly understood that I don't suffer food because I can fix a lot of things I can't fix that out.
38:48And if somebody doesn't get it, why should I show it? And check them out, show you around yourself as smart people. But you find them, keep them, because the next question becomes, you know, what is the attitude these people bring to the table? As long as they are willing to learn and humble and they understand they're part of a team, all systems go. Like I have a principle that I was joking even in all hands and said, I have never met a person who comes to work to screw up. I wake up in the morning, let's go sunshine, it's time to go to work, bless me, see how badly I can do today. Everybody walks in with the right attitude.
39:24It's something that happens at work that we create that causes the unintended outcomes. It's not the person who walks in. If you found the right person, whether the right domain knowledge, right intelligence, the right attitude, then the rest is upon us. And then the question is, how does management create the environment that people can thrive? And it's not just about, you know, happy, go lucky environment. Like I always say, there are three jobs that we have as leaders. One is we have to identify the North Star. People have to know which mantra we're going to climb. You get the best climber, isn't it?
39:56You find out you haven't told the which one. They're all on eight different monitors around you. They'll really share what happened. They're all in their place. So my job is to make sure I identify the amount and I fight or argue, I debate, you know, I could Joel, whatever needs to happen to make sure we have a plan of record where we're going. But ample degree of input, but the end, somebody's got to make a decision. The next thing is, is a chivalry. Can we write a plan to make it happen? The last thing you want is people come and say, I get it. You want it to build this. But he gave me, you know, one pickaxe and one shovel into people.
40:26Right? And he wanted me to go dig the platinum mine. It takes a lot more than that. So the next question is, is there a feasible plan to get it done and are you resourcing it right? All right, and very often companies, you look at our industry, right? A lot of people had the right ideas. When I came to a bottle of auto, it's only a joke sometimes. I didn't do anything different. We had a cloud security acquisition we'd done. We had an XDR acquisition we had done. We had the idea of building a SIM. We just hadn't resourced it. We hadn't written the plan for it. We kind of knew what we wanted to do, But you haven't sat down debated, argued, so what does the future look like and we hadn't we hadn't written the plan We hadn't resorted.
41:01We have one tenth the resource that we need it so you don't have a plan you have an idea ideas are not good enough. You get a plan in an austral You have to Resourcing that you can sort of execute it's a plan the third job is management is to keep communicating it and reading out Things I block the execution of plan whatever it is whether it's a a person who's not doing it, whether it's a resource that's not available, whether it's a contract that's not working, you know, it's blogging and tackling and sort of making way for your team so they can go and execute behind it. So if you follow those principles, they find the right people around you and you know, don't suffer fools and have a good time while doing it.
41:41Sometimes some people do get more scrutiny than the others, but it's good for their career and good for the character. It's amazing. Let me ask one more question on sort of management leadership and then maybe we can go back to some AI topics. So you mentioned the 19 companies that you guys have acquired in the last six, seven years. Maybe two questions on that. One, at the moment when you're pulling the trigger, what goes through your mind? Like, when it's time to make the go, no go decision, how you decide that an acquisition is actually an acquisition you want to make. And then maybe second question, one of the things our partner Jim mentioned was that pretty much all the founders who've joined forces with Palo Alto Networks of stuck around.
42:22A majority of them. So yes, so what you do post acquisition to actually keep them around, and maybe it's the same thing that you're just talking about with leadership generally. I learned more than that. Like, I think before we get to decide it's an acquisition we want to make, we spend enough time to understand, you know, is it even worth engaging with the company for a few hours or a few days, right? And we have some principles. I don't like buying number two or three. It's a lot of founders for a lot of companies, They say, you know what, you know what, the first one's a billion, the third one's two and a million, let's just say the third one, we got enough resources.
42:55Well, spit and shine, it's gonna make it brand new, everywhere the billion dollars. Well, there's a reason it trades a three and a million, not a billion, first of all, which means they possibly have some gaps which the customers have identified and you have. Two, you didn't actually take out the biggest part of the market, it's still gonna be four steps ahead of you. So, now all you've done is taken an imble startup, which is number three, it possibly made it slower. It's quite all your love and attention to it. He's like saying, okay, well, let me like bring me along about So now you're suddenly slowed down number three you enhance the the opportunity of a number one or two So you said then it's okay and a lot of times you joke about it saying I wish this this competitive We keep bought by somebody in competition because it's long down So so we make sure we're only the kid one and two at best and sometimes they're neck to neck sometimes They're chosen two different parts and we did that in the browser space You know very happy with that acquisition of talent.
43:43I think they string really well with that in DSPM with dig actually in our industry what happens in spat and Sonya is that if first people looked at me and say what the hell is this guy's buying these companies I don't know what his plans are now he actually have a slide we keep track of once we buy something in a category that category becomes hot so people think we know something they're done a good job of what about that but like I think the principle is you got to make sure you're buying the right sort of right player in the market then you got to make sure that you can convince the founders that they believe a better together story then they go at a loan story right There's no sell and dump because not gonna happen.
44:18We're not gonna take the asset because when you're buying you're basically buying a North Star an execution plan and a team that executes but usually they're a third or 40 % down the journey It takes more to 70 years to build a great product Usually these things are three years out three or four years out They haven't fully matured into a full product that's gonna win in the market so you need them around and use a team around and And still, once we figure out this is the right company, the right attitude, you know, we can actually make it work. And there are now given our scale, there are some technical considerations to be able to rewrite the stack, which takes longer.
44:52Is this a complimentary area that can just run on our stack easily? Is this something you've never done before in which case it doesn't matter with stacks on? So, a lot of those considerations from an integration and time to market perspective. But let's assume all those hurdles have been surmounted. And we're actually engaged to the company. I have a rule, I walk in and tell my team and I live it. I say treat them on day one as their part of your team. Because if they're gonna work with you, they're gonna remember every interaction. In very often, I find many companies, the most well -intentioned company, start treating it as a choirer and a choir.
45:32I live, I come from a country which was a choir, a rule and I don't like this idea. There's no like one rules the other is like you know part of the team and the dates that you'll get signed Well log about it on the same page Well, we turn it around the same stock price and same business forward. So For that six weeks that you're in that discussion phase. How does it rise? It important that You're the acquireer and you're the acquired so so let's assume we do that We like a company then I send off the finance and accounting guys and legal guys to do diligence and I tell the founder and the team saying you're job now in the next six weeks is to build a joint product plan and a joint org chart.
46:08And at the end of six weeks, if you don't like the product plan, or I don't like it, and if you don't like the org chart, I don't like it. There's no deal. This is a lot of behavior. The first two three times we didn't do that. And we discovered we spent the next six months arguing about what the product should be and who should be the boss. That doesn't work. This is a bad idea. So I'm like, hey, buddy, you want the money? You can have the money. It's my house. I'm going to paint it yellow. You don't like the color? Tell me now you can get somebody else to paint it pink. No problem. So That has an amazing cleansing property Because you're making a decision with all the facts in front of you saying if I get part of you be part of all So this is going to be the product strategy.
46:48It could be yours. It doesn't not be mine. What's more now? So what do we have a joint product strategy to not start and we have a joint plan of execution and then Very often, badges go back to Jim's comment. Most often, the founders we have bought companies from, become the senior vice presidents of our company running their business. Our people work for them, which I think is unique in the market. Very often, you'll find there was an acquired RERSWP who ran crypto or blockchain or pick your favorite using non -security terms to keep it, protect the innocent. But you say, oh, since I'm responsible for this, these people are gonna work for me.
47:26I'm like, wait a minute, you had all the resources you lost to them. We're not going to have them go work for you. Maybe you can learn a few things. So we did that a bunch of times. And in some cases, our teams worked for them really well. And some cases our teams left it just fine. So I think those are some of the things that allow us to make these amazing founders come work here and actually drive more value for us collectively. Nick, I want to ask you about some of the chess that's now happening on the AI stage because I think you've played the chess game so flawlessly in the security market.
47:53And you know, you have so clearly emerged the winner. The AI space by contrast feels just white hot competitive hunger games right now. I'm curious your view. I think a lot clearer than that. It's just not clear to the naked eye, but I think it's a lot clearer. Same more. Yeah, tell us more. If you think about the state and maturity of AI, you know, there are two extremes. We'll call them the very precise alpha -go type situations which, you know, them as a Google build together which are, I'd say, fine tune models which are designed for drug discovery or the bio -former field. And there you see that they did a really good job.
48:38They focused on the trained right data. They hopefully tweak the models in such a way that that can actually become a useful thing for society. So, you have that which is highly tuned AI models, very toss -specific or category specific. And then you have the generic ones. And the generic ones are, you know, the rage today between the Claude and the mistrawls and the Gemini's and the opening eyes of the world. And those are large. They're all encompassing all knowledgeable. But you saw this movie before, right? You saw this movie in search. And as a Google, you know, they had vertical search because the large Google search could not do as good a job of local search, so you have local search.
49:17The God couldn't do a little job product search, so you have product search in Amazon. So how can you be amazing at everything in this space when you couldn't do it in the last few technological evolution? So I think we're dying. We're going to have to figure out what the distinction between in a general purpose, large scale. I know everything. I can do everything model versus models that are fine tuned for task. And I don't believe that all the perfect information in the world exists in open domain that you can go out and build it without specialization, which means you are going to need specialized proprietary data to build these models.
49:50And I don't know how you share data but I mean, Glaxo's mid -line and Novartis and Pfizer and say I can build the best drug discovery model in the world because I have perfect information. Right? So that's a question that remains to be seen. So I think over time you'll see a bifurcation from an enterprise use case. And in our business in the enterprise side, you need precision. I can't afford to be wrong. You know, wrong turn by a Tesla is going to kill somebody. The wrong block by Apollo also is going to bring somebody's infrastructure down or a wrong permission is going to let a bad actor in.
50:19So I don't have that tolerance that consumer models can have because they have low consequence. So the high consequence, high consequence applications require a lot better model, a lot more training, a more precise domain data. I think that's going to become a sort of thing of its own. I think everything we're seeing today is general purpose models and eventually they'll of you like, and I don't know the answer was that general purpose models become task specific evolved models or there's a new category of task specific evolved models, which are built more in the sort of genre of the alpha go version.
50:50Now on the on the general models, I think the people who can deploy them against existing consumer properties are sitting pretty. Right? Because it creates more retention, more continued monetization of space. So other Google can deploy a whole bunch of AI against it's three plus billion users across multiple properties or one Zuckerberg can do it These are Facebook and see billion users across Instagram. You know, what's happened in Facebook? That's that's cool. I think Sam's done a great job in building a consumer direct business on the subscription side Which he continues to drive very well and that's becomes his set of set of his his mode now because no other model has built a subscription -based consumer model.
51:32So I think you're seeing the general purpose models being built by existing large consumer properties. You're seeing a new consumer property emerged vis -à -vis in an open AI. I think the enterprise use case is still early because we haven't seen the mission critical applications be developed because of the lack of great training data. So that's what I think. But let me ask you one of the things that's not on your LinkedIn profile is prior to, prior to soft thing, prior to Google, prior to T -Mobile. If I had my fax straight, you were an award -winning equity research analyst covering Telecom.
52:11And I believe that one of your claims to fame was calling the internet bubble and the bursting of the internet bubble. I still have that note. A cell note at Rotten of Look, again, for the number of times I've heard it's different this time, you know, we could all be very rich. So, but there are some things just different, right? If you look at where the AI inflation has happened in the equity markets, it's still in the plumbing. And the plumbing is real, right? It's not like people are driving the plumbing up without substance because you're selling four times of 10 times more chips than you sold two years ago.
52:56So they've real revenues that underpin that. Now, clearly, people are projecting that into a trajectory, which I don't understand. And every day you see any development, you tell me, is target the future or is deep -seek the future? And I don't mean with all its negative connotations. I mean, as a concept, are we going to have cheaper models being built for large -scale application with limited specialization? Or are we going to have a super model in the context of AI, which is going to be expensive, but be able to do everything amazingly? You tell me the answer and I'll tell you mine. Signish, we head into Lightning Round or do you have more viewers?
53:32Let's do it. Great. Lightning Round. Okay. You just bought a cricket team. Why? You know, there's a bunch of us who are together. It runs not just me. There's Tennifuss, including your part in the gym, get.
53:45Brawl failed cricketers. We all have sport aspirants. So it will part of that. That's the part of the passion which says, wow, I can be associated with the sport at the highest level without having the talent. It's kind of interesting. That's one reason for it. Now, you couldn't have a bunch of us buy it who are business savvy and say, where is there a business model here? And if you look at it, the only thing that's left in streaming that is linear is sport. No longer news, television, movies, nothing is linear. The only thing is linear is sport. You wanna watch it when it's happening. Pretty much when it's done, you know the score and you lose the interest to watch that event, right?
54:22the post post event viewership a lot lower in sport than live or viewership every other is the other way around Every the streaming content is the other way around The post launch viewership is higher than launch viewership By this movies or television or any podcast or any videos streaming to do hopefully this one, right? So it's the only linear sport out there is being bit up Clicked with the second most watch sport of the world There's the biggest franchise, hundreds. It's the next best thing. It's in the country, which is the home of cricket. And then every follow the same philosophy that I told you about my startups.
55:01You've got to buy something by the best. So we bought lords, which is the home of cricket. It's gonna be fun. What a cricket teach you about life or a leadership. It's a team sport. It doesn't matter how good you are. If the other 10 people suck, it doesn't matter. It teaches you that, right? You can have a bad day in Newcastle win because you participate with the rest of 10 people. So it teaches you about life. It teaches you about business. You're wearing a Pebble Beach Pullover. I hear you want to pro -am recently. What's your name? My name is G .A. I'm a 9, and it's a combination of the best roles that I could find, luck, and a few misplaced good shots.
55:45In video, 118 bucks a share, $2 .9 trillion market cap, 39 times earnings, and he's grown about 150 % year over year, while we're short. I don't understand it. If you were Jensen, would you be making the same moves? Jensen has played a very long game. I think he's built a phenomenal franchise. I think what he's done is like no less than what Elon has done for electric cars. I think that he took something that he built for gaming, thought about it, understood the large need for compute and Put all his energy and thought behind it's been the longest serving CEO in the world, right? So you can't take it away from him, but they just can't even trivialize it We have to talk about him with tons of respect.
56:28What he's done is amazing He has a vision and he's taking it beyond just the chips because he's slowly building an ecosystem saying my chips work With a lot of other things which together so I don't think from a long -term perspective to give can argue that AI is not going to be relevant. I don't think you can argue for a long term perspective that we will be constantly doing some form of development which requires more more compute. Like in the history of mankind compute and bandwidth and memory have never shrunk. Yeah. So it's not about a start now. I think he's sitting at phenomenal acid. Is it a three trillion dollar acid today?
57:03I don't know. There will be a three trillion dollar acid in ten years, possibly more. What CEO do you admire most? You know, I have a collection of CEOs. I admire traits that CEOs exhibit is very hard to have one item in life because one idol has the property that they could disappoint. But if you admire certain things certain people do, you learn a lot from that aspect of it. And if you have the same circumstance, you might do the same thing. You have different circumstances. You might do a different thing. I mean, I admire Elon's creativity and what he's done for the world, I wouldn't want to work for it.
57:36But I admire what he's done. It's amazing. Like, I always joke with my team. I'm saying, would you go on a rocket tomorrow, is built by the guys around you? I don't think so. But you know, he's got a bunch of people who've been the rocket and people go up in that thing. That's amazing. We've sit in the car, which is not no driver and head and so people have done it. So, you know, what's out there? Did a Microsoft and he took somebody, nobody believed he could turn this around to $3 trillion and all the company and he did. It's amazing, right? So like a Tim Cook, you know, Steve Jobs a hard act to follow and Tim's gonna phenomenal job in taking that amazing company and maintaining it down the middle and concentrating.
58:11What can Mark Zuckerberg recently, right? He's taking that thing around, turned around. Now, you know, the fact there are certain things that they've done which I respect is amazing. That doesn't mean anything about the rest of their lives and I don't need to worry about it. Which CEO is executing the best in AI right now? for all the conversation around Sam, I think what he's done is amazing, right? I mean, before Chad GPD came about, we weren't talking about AI, right? And before Chad GPD came out, you know, you think Google didn't know about AI? I knew what AI went after Google. Do you think Google didn't have a self -driving car then?
58:49They did. No, do you think South that in order I mean, he did. But look at what's happening right now. You can run into a CEO who wants to view the words AI. So Sam has created the next, such as the impetus for the next technological revolution. That's the way Steve Jobs did it with the iPhone. And the fact that was a straight face, he can go out there and get people to commit to spending half a trillion dollars in building infrastructure. And every, I think the Mag 7, everyone wants to see, he was spending way more money in building compute and data centers because nobody wants to be left behind.
59:22I just sound like a great job executing an AI. Now, history is hard and business is hard. And we don't know that means that you'll be the winner in the future. But damn, has it done a great job in getting us to where we are? Yes. I think that's it. Thanks, Nickash.
59:41page.
From the publisher
Palo Alto Networks’s CEO Nikesh Arora dispels DeepSeek hype by detailing all of the guardrails enterprises need to have in place to give AI agents “arms and legs.” No matter the model, deploying applications for precision-use cases means superimposing better controls. Arora emphasizes that the real challenge isn’t just blocking threats but matching the accelerated pace of AI-powered attacks, requiring a fundamental shift from prevention-focused to real-time detection and response systems. CISOs are risk managers, but legacy companies competing with more risk-tolerant startups need to move quickly and embrace change.
Hosted by: Sonya Huang and Pat Grady, Sequoia Capital
Mentioned in this episode:
Cortex XSIAM: Security operations and incident remediation platform from Palo Alto Networks




