AI security threats reshape corporate cybersecurity budget investment

📅 2026-09-09

Abstract:

The threat of AI hackers is not only prompting companies to significantly increase their overall cybersecurity budgets, it is also changing the direction of investment of funds. Security executives say large enterprise purchasers have significantly increased their budgets for deploying systems to monitor employee use of AI tools, employing AI models to find vulnerabilities before hackers do so, and using AI tools to accelerate vulnerability remediation.

But not all cybersecurity products benefit. Multiple executives said companies are also cutting spending on traditional vulnerability management software, log collection tools and penetration testing services to save costs. Penetration testing involves hiring “white hat hackers” to actively look for system security flaws. This will put pressure on the traditional software businesses of Cisco, SentinelOne, Rapid7 and other vendors, which have all laid off employees this year and shifted resources to a new generation of AI security products.

Bret Wentworth, vice president and deputy chief security officer of Lumen Technologies, said that the telecommunications company will increase its cybersecurity budget by about 30% in the next year. New investments include new AI models for vulnerability scanning like Anthropic Claude Mythos, AI scanning tools from established vendors like Palo Alto Networks and startups like Zafran Security, and security systems to monitor and protect AI applications used by employees.

He said company executives have realized the urgency of dealing with AI security threats.

“I have been in the security industry for many years and have experienced boom and bust cycles in the industry,” Wentworth said. “In the past, we have always been under pressure to cut costs...but now the wind direction has changed dramatically.”

When Anthropic released the Mythos model in April, many business managers realized that security thinking needed to be revamped. Officials warned at the time that this cutting-edge AI model could even autonomously invade complex corporate intranets. Subsequently, it was revealed that out-of-control OpenAI agents launched coordinated attacks on OpenAI's own systems and corporate platforms such as Hugging Face, and related concerns continued to rise.

Head AI Lab itself is also becoming a competitor in the security solutions track. When OpenAI released GPT‑6 Astra this week, it focused on promoting the model's ability to help defenders discover and fix network security flaws. The company also recently hired new executives to strengthen network security capabilities and replace the original chief revenue officer.

Wentworth said that after the release of Mythos, Lumen deployed a number of network security personnel to form a new team dedicated to using cutting-edge large models to scan for vulnerabilities. At the same time, the company's bug bounty program receives a large number of vulnerabilities submitted by external researchers, many of whom use AI to mine them.

Wentworth said Mythos and other cutting-edge models "are really changing the landscape of where security budgets are spent."

This security anxiety has opened up market space for emerging cybersecurity startups, which focus on specialized products to deal with new cyber threats that did not exist just a few years ago.

Jeremiah Kong, chief information security officer of mobile advertising technology company AppLovin, said that the company has negotiated discounts on the purchase of AI security tools with a number of early-stage security startups. That's helped rein in increases in the nearly million-dollar annual security software budget, which has risen about 10 percent this year.

For example, its team has signed up to purchase Pluto Security and Fig Security products: Pluto relies on AI agents to monitor the behavior of internal employees using AI; Fig Security uses AI to identify potential vulnerabilities and provide repair plans. The two companies only ended their stealth operations this year. AppLovin also uses software from Endor Labs to scan code written by engineers for potential vulnerabilities.

“Attack vectors are iteratively reconstructed all the time, and we must always be on high alert,” Kong said.

Kong introduced that AppLovin uses CrowdStrike and SentinelOne products to manage endpoint security, that is, the security protection of devices and applications used by employees. But he is reassessing that budget as new AI technologies like Pluto can better identify employees uploading data to AI tools such as chatbots. He commented that the performance of similar AI security products from CrowdStrike and SentinelOne was “not ideal.”

A CrowdStrike spokesperson responded in a statement: "A customer's decision not to purchase a certain module without testing does not mean that it has been replaced by a competing product, especially if the customer continues to use the CrowdStrike platform. In the three quarters after the launch of CrowdStrike's AI detection and response solution, the scale has increased by more than 79 times, which is enough to prove the strong customer demand and rapid implementation."

A spokesperson for SentinelOne said that AI security is the fastest growing segment of the company's business, and new revenue comes from new customers and the expansion of existing large customer platforms. The spokesperson mentioned that the company disclosed last month that annual recurring revenue from AI security products tripled year-on-year in the second quarter.

Network security vendors say industry demand exploded after the release of Mythos. Sanaz Yashar, CEO of Israeli start-up Zafran, said that contract negotiations with large enterprises usually take months; but within five weeks after Mythos was released, Zafran won new orders from three large banks.

“I have never seen anything like this, and it completely changes the purchasing habits of customers.” Yashar said.

Traditional security vendors are under impact

Security executives said that a large number of new vulnerability scanning tools based on large language models have emerged, posing a competitive threat to the traditional products of established security vendors such as Qualys, Tenable, and Rapid7. Such products were born before the popularity of large models.

Jon Raper, a former CISO at Chevron and Costco who is now an enterprise security consultant, said: "Traditional scanners have never encountered a disruptive challenge since their advent in the mid-to-late 1990s. They just aggregate a large amount of information, lack context, and much of the information is of low value." He predicts that traditional scanners "will eventually be replaced by large model-driven scanning tools."

“Why would I spend $2 million on a traditional vendor product when I can now use an agent for penetration testing?”

Doug Kersten, chief information security officer at software company Appfire, which Google acquired this year for $32 billion, said the company is using a new "red team agent" from Wiz. Wiz relies on large models from Google, Anthropic, and OpenAI to find vulnerabilities.

Kesten said that driven by such tools and other AI security software, the company's total cybersecurity budget will increase by up to 20% in the next year, but it will reduce its reliance on "traditional code scanning tools" in the future.

Tenable co-CEO Steve Wentz disagrees that AI tools will subvert its own vulnerability scanning software. Tenable is a member of Anthropic and OpenAI's cybersecurity early access program and sells security software that recommends fixes based on both models. After Mythos was released, contract periods shortened and demand continued to rise, Wentz said.

"There is a lot of noise in the security market, and only data can tell the truth." He cited the company's stable revenue growth in recent quarters and the rising stock price this year. "The cutting-edge large model brings more risks, not less, which brings us huge benefits."

Spokespersons for Qualys and Rapid7 did not respond to requests for interviews. In August, Qualys disclosed an 11% revenue growth in the second quarter and predicted a slowdown in growth this quarter. However, it also stated that in the face of the new threat environment brought by Mythos, customers have strong demand for a new generation of AI-driven products.

Rapid7 CEO Wael Mohammed reported a slight decline in revenue when releasing earnings in August. The company has completed a management reorganization to focus on AI products and cut 12% of its workforce. Muhammad said that customers are cutting back spending not because of price sensitivity, but because "enterprises must complete the transformation to the world of intelligent machines and AI. This is the number one priority for customers."

Safety managers invest upfront while seeking long-term cost reduction

CISOs of various enterprises generally stated that they are increasing their "word budget" and purchasing large models from Anthropic, OpenAI and other manufacturers for system scanning; however, executives are optimistic that long-term costs can be controlled.

For example, Gil Vega, CISO of data backup vendor Veeam, connected to the Mythos model through Anthropic's Glasswing project. He said the company's spending in this direction has surged, but Veeam is hedging Mythos spending against other models by reducing third-party penetration testing purchases.

Jeremiah Kong also relies on AI models to scan AppLovin’s IT systems to flag potential vulnerabilities. Mythos testing was expensive, so AppLovin switched to Anthropic's more cost-effective models such as Claude Opus 4.7. Kong said the team performs weekly scans using Anthropic tokens, which typically cost a few hundred dollars.

Even large security vendors that heavily use Mythos and cutting-edge models believe costs will come down in the future. Sam Rubin, senior vice president of Palo Alto Networks, said the company consumed more than $1 million worth of Mythos tokens during the testing phase in May. But last month, Rubin said Mythos usage was expected to level off going forward.

“We have observed in our internal environment that the initial workload of using AI models to find and fix vulnerabilities is huge,” Rubin declined to comment directly on whether Palo Alto expects Mythos costs to drop, but said “over time, the workload has steadily declined and shifted to the normal operation and maintenance phase.”

“But currently in our environment, there are still a large number of vulnerabilities that need to be fixed,” Rubin continued. “The balance of offense and defense has been broken, attackers have gained asymmetric advantages, and the entire industry needs to catch up.”

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet