Decrypted | Insights from Virtru to Unlock New Ideas

Nikesh Arora Is Right: It’s Time to Rethink Your Cyber Security Architecture

Written by Matt Howard | Sep 2, 2026, 9:33:54 PM

Nikesh Arora spoke the truth yesterday on Palo Alto Networks' fiscal Q4 earnings call. Then he did it again on live television.

"There's approximately $1 trillion of global cybersecurity debt that must be modernized. Nothing that was deployed seven or 10 years ago is ready to handle AI. You have to rethink your entire cyber architecture."

He's not just directionally correct. He’s 100% spot on.

The Old Assumption is Now Wrong

A trillion dollars of security infrastructure is now obsolete. Everything from firewalls, gateways, proxies, to appliances. Nearly every dollar of that trillion was spent on a single premise: if you control the boundary, you control the data inside it. Build the perimeter, segment the network, inspect the traffic, harden the endpoint, and the data takes care of itself.

That premise held up reasonably well when data mostly stayed put. But it has been slowly eroding for fifteen years — SaaS, cloud, mobile, remote work, mission partner ecosystems – they all chipped away at the old assumption.

Then AI came along and ended the argument.

Perimeter-centric architecture rests on one assumption: that data sits still. It doesn't anymore. Data moves constantly now, into and out of the hands of humans and machines alike, at a volume and speed no boundary was ever built to handle.

Fifteen years ago, enterprise software was mostly monoliths. One big application, one deployment, one boundary, and you secured it by guarding the front door. Inside, every component trusted every other component, because they were all the same thing.

Then the world realized that application architecture should become more granular. So the world began to break monolithic apps into containers and microservices.

Now look at the data. For the most part, data is still treated as a monolith. We secure it by guarding whatever it happens to be sitting inside: this repository, that tenant, this network segment. Access is coarse and implicit.

AI is doing to data exactly what containers did to applications: breaking the monolith into granular units. For applications, the unit of work was the service call. For data, the unit of work is the object.

That is what attribute-based access control (ABAC) does. It authorizes each request against the attributes carried on the object and the entitlements of the identity asking — human or machine. And Trusted Data Format (TDF) is the open standard that lets the object carry its own policy, so that decision can be made anywhere the data travels.

Recommended Reading: While AI Accelerates, the Data Owner is Left in the Dust

What Enforcement at the Object Looks Like

Strip away the gory technical details, and there are only two things on the table when someone asks for data.

There is the data, which carries attributes (classification, ownership, releasability, sensitivity, purpose, retention. And there is the requester, which is an authenticated identity carrying entitlements) role, clearance, nationality, contract, device posture, and increasingly, what kind of thing it is: a person, a service, an agent acting on a person's behalf.

Access is the decision made at the intersection of those two sets, evaluated fresh on every single request. That's attribute-based access control, and it is the only model that scales to the number of decisions the AI world demands.

For data access decisions to be made granularly at scale, three things must be true:

The policy has to travel with the object. In Trusted Data Format (TDF) terms, the payload is encrypted and the policy is cryptographically bound to it, so the rules go where the object goes. While a locked room protects what's inside the room – TDF is closer to a sealed envelope that checks the requestor’s credentials before it opens, every time.

The encryption keys have to live apart from the data, and the release decision has to belong to the data's owner. Not to whichever platform is currently holding the file. That single property is what turns "we have a data-sharing agreement" into "we have true data control."

And every decision has to be recorded. Not just the grants — the denials, the identity that asked, the attributes evaluated, the time. When the data has left your environment, the audit trail is the only thing standing between you and a prayer.

Get those three things right and you have a next generation data security architecture that is optimal for the AI world.

Control is What Makes Sharing Possible

The cyber industry has spent two decades selling solutions to customers designed to lock data down and prevent it from being lost or stolen – which is absolutely valuable.

But locking data down and preventing loss and theft is not the whole job.

Object-level enforcement is the rare mechanism that breaks the tradeoff, because the thing that locks the data down is the same thing that lets you let go of it. If policy travels with the object and the keys stay yours, then you can hand a file to a partner on Tuesday and revoke it on Friday. You can expire access on a schedule. You can share sensitive data within a workflow you don't control, without sacrificing ownership or sovereignty.

When it comes to AI – the reason to make security architecture more granular and enforce policy at the object level – isn't to keep agents away from your data. It's to make it safe to let them in — and to be able to prove, afterward, exactly what data they were permitted to touch.

Why It Has to Be an Open Standard

Let me be direct about the risk in Arora's prescription, and in ours.

If the data control plane is proprietary, we haven't built a new architecture. We've built a new perimeter — and moved the lock-in from your network to your data. That's a worse trade, not a better one.

The microservices shift only worked because the primitives were open. The data shift needs the same thing. That's why TDF is an open specification, not a product feature. It evolved from technology developed at the National Security Agency by our co-founder Will Ackerly, and it's stewarded in the open through OpenTDF, where Virtru is the lead contributor.

Virtru also supports ACP-240, the Five Eyes-ratified Zero Trust standard for secure coalition operations. Allied partners share intelligence without trusting each other's infrastructure. That's the hardest version of this problem, and it was solved there first.

Open means interoperable, inspectable, and independent of us. It also answers the question every enterprise should put to every vendor in this cycle: what happens if we don't want to work with you in five years?

Data Can Protect Itself. It's Time to Retire Any Other Assumption

I agree with Nikesh. A trillion dollars of security architecture has to be rethought, and AI is the forcing function.

I'd add one thing. The largest line item in that debt isn't hardware in a rack. It was an architectural assumption that walls had to be built to protect data wherever it was kept – because data couldn’t possibly protect itself.

That assumption can be retired now. Attributes on the object, entitlements on the identity, a decision made fresh on every request, wherever the data happens to be. Not a bigger perimeter — a smaller one, wrapped around each object, that travels with it.

That's the data control plane. That’s TDF. That’s the granular security architecture Virtru is enabling for the age of AI.


Read the TDF specification and the OpenTDF project at opentdf.io

Arora's comments are from Palo Alto Networks' fiscal Q4 2026 earnings call and a September 1, 2026 appearance on CNBC's Mad Money and Q4 FY2026 Palo Alto Networks, Inc. Earnings Call.