AI Threats Are Reshaping Where Companies Spend Their Cybersecurity Budgets

The AI hacking threat isn’t just causing companies to jack up their cybersecurity budgets, it’s changing where they spend them.

Buyers at big companies have significantly raised planned spending on systems that monitor how employees use AI, as well as on AI models that detect vulnerabilities before hackers can and AI-powered tools that speed patching those holes, security executives said.

Not all cybersecurity products are poised to benefit, though. Many executives said they’re simultaneously looking for savings by spending less on traditional vulnerability management software, information-logging tools and penetration testing services, or pen testing—the human hackers for hire who try to find cybersecurity weaknesses. That could put pressure on legacy software from the likes of Cisco, SentinelOne, and Rapid7—all of which have cut staff this year to redirect spending toward newer AI products.

Brett Wentworth, vice president and deputy chief security officer at Lumen Technologies, said the telecommunications company’s cybersecurity budget will increase roughly 30% in the year ahead. That includes spending on new AI models like Anthropic’s Claude Mythos to scan for vulnerabilities, other AI-powered scanning tools from both incumbents like Palo Alto Networks and startups like Zafran Security, and tools that monitor and secure AI applications used by employees.

He said senior executives understand the urgency of responding to AI’s security threat.

“I’ve been in security for a lot of years now and have gone through feast-or-famine dynamics,” Wentworth said. “There have been times where it’s like, we need to cut costs…but now we’re seeing a seismic shift in the other direction.”

Many business leaders realized the need for new thinking around security when Anthropic announced Mythos in April, warning that the advanced AI model could autonomously hack into even sophisticated corporate networks. Concerns have grown amid news of coordinated attacks by rogue OpenAI AI agents against its own systems and those of companies including AI platform Hugging Face.

Leading AI labs also are becoming competitors in the market for security solutions. In announcing GPT‑6 Astra this week, OpenAI touted the new model’s ability to help defenders find and patch cybersecurity weaknesses. And the company last month tapped a veteran cybersecurity executive to replace its chief revenue officer.

After Mythos’ release, Lumen reassigned several cybersecurity staffers to a new team focused on using frontier models to scan for vulnerabilities, Wentworth said. Lumen also has seen a sharp uptick in outside researchers, many using AI, submitting bugs through its bug bounty program, he added.

Mythos and other frontier models are “absolutely changing the landscape in terms of spending,” Wentworth said.

The concern is creating an opening for younger cybersecurity companies selling niche products to address cyberthreats that didn’t exist just a few years ago.

Jeremiah Kung, chief information security officer at AppLovin, said his mobile ad technology company has negotiated discounts on AI security tools sold by early-stage startups. That has helped mitigate the growth of his nearly $1 million annual cybersecurity software budget, which already has increased roughly 10% this year.

For instance, his team has opened contracts with Pluto Security, which uses AI agents to monitor employee use of AI internally, and Fig Security, whose AI detects possible vulnerabilities and suggests patches. Both emerged from stealth earlier this year. AppLovin has also been using software from startup Endor Labs to scan code its engineers write for potential vulnerabilities.

“These attack vectors are reinventing themselves, and we essentially have to be in a catlike state of readiness,” Kung said.

Kung said AppLovin uses software from CrowdStrike and SentinelOne to manage the security of end points—devices and apps used by employees. But he said he’s reevaluating how much to spend on those because newer AI-powered technology from the likes of Pluto does a better job of detecting how employees are feeding data into AI tools like chatbots. Similar AI-focused tools AppLovin has looked at from CrowdStrike and SentinelOne are “not great,” he said.

“One customer’s decision not to purchase a module, without even testing it, is not evidence of competitive displacement, particularly when that customer continues to rely on CrowdStrike’s platform,” a CrowdStrike spokesperson said in a statement. “CrowdStrike’s AI Detection and Response solution has grown more than 79-fold in the three quarters since launch, demonstrating exceptional customer demand and rapid adoption.”

A SentinelOne spokesperson said AI security “is the fastest growing area of our business with traction coming from both net new customers and platform expansion within our large install base.” The spokesperson noted that the company reported last month that its annual recurring revenue from AI security products in the second quarter tripled year-over-year.

Cybersecurity vendors say they’ve seen a boom since the Mythos announcement. Sanaz Yashar, CEO of Israeli startup Zafran, said it typically takes months to close deals with large companies. But in the five weeks after Mythos’ release, Zafran closed three new deals with big banks, she said.

“I’ve never seen such a thing—this is 100% changing customer spending habits,” said Yashar.

Disrupting Older Security Vendors

The explosion of new vulnerability scanning tools powered by large language models poses a competitive threat to more established products that have been around since before LLMs, sold by established cybersecurity firms such as Qualys, Tenable, and Rapid7, according to security executives.

“The legacy scanners really haven’t been disrupted since the mid to late ’90s when they were created—they just aggregated a lot of information, which was mostly garbage without context,” said Jon Raper, who previously served as chief information security officer of Chevron and Costco and now advises companies on cybersecurity. He predicted that legacy scanners “will be replaced” by LLM-powered scanners.

“Why would I pay $2 million to one of those companies when agentic pen testing is now an option?” he said.

Doug Kersten, CISO at Appfire, said his software firm has been using new “red team” agents from Wiz, which Google acquired earlier this year for $32 billion. Wiz relies on AI models from the likes of Google, Anthropic and OpenAI to find vulnerabilities.

Kersten said his total cybersecurity budget is set to rise as much as 20% in the year ahead thanks to those tools and other new AI security software, but added that he expects to rely less on “legacy code scanners” in the future.

Tenable co-CEO Steve Vintz disputed that AI-powered tools would disrupt the company’s vulnerability scanning software. Tenable is a member of Anthropic’s and OpenAI’s early-access cybersecurity programs and sells software powered by their models that suggests patches. Vintz said Tenable has seen shorter contract cycles and growing demand in the wake of Mythos’ release.

“There’s a lot of noise in the security market, and the only way to cut it is numbers,” Vintz said, referencing Tenable’s steady revenue growth in recent quarters and its rising stock price this year. “Frontier models are creating more risk, not less. That’s creating major tailwinds for us.”

Spokespeople for Qualys and Rapid7 didn’t respond to requests for comment. Qualys in August reported 11% second-quarter revenue growth; it forecast slower growth in the current quarter, but said it was seeing demand for new AI-powered products “to address the post-Mythos threat landscape head-on.”

Rapid7 CEO Wael Mohamed told investors in August, when reporting a slight decline in revenue, that the company had overhauled its leadership to focus on AI-focused products while cutting 12% of staff. Mohamed said declines in customer spending weren’t due to price sensitivity but rather to “the ability to evolve into the agentic and the AI world—that was the No. 1 priority for them.”

CISOs Pay Up Front but Eye Potential Savings

Across the board, CISOs say they’re increasing their “token budgets” for spending on LLMs from the likes of Anthropic and OpenAI to scan their environments. But executives are optimistic they can bring costs under control down the road.

For instance, Gil Vega, CISO of data-backup startup Veeam, has gotten access to Anthropic’s Mythos model through its Project Glasswing program, and said his firm has “seen a surge in spending” in that area. But he added that Veeam has offset the cost of Mythos and other models by paying less than it previously did to third-party pen testers.

Kung similarly has relied on AI models to scan AppLovin’s IT systems and flag potential vulnerabilities. While testers of Anthropic’s Mythos and comparable models have found it’s exceedingly expensive, AppLovin has experimented with less-pricey Anthropic models such as Claude Opus 4.7. Kung said his team has used the models to run a scan once a week, which typically costs a couple hundred dollars in Anthropic tokens.

Even large cybersecurity firms that have been heavy users of Mythos and other leading models are optimistic that costs might eventually ebb. Palo Alto Networks burned through over $1 million worth of Mythos tokens early in its testing process in May, senior vice president Sam Rubin said. But last month, Rubin indicated that its Mythos usage might eventually level out.

“What we saw in our own environment is that initially there’s a lot more work” to use AI models to find and patch gaps, Rubin said. He declined to comment directly on whether Palo Alto expects its Mythos costs to go down, but said “over time that effort steadily declines” and “becomes more maintenance mode.”

“Still, what we’re seeing right now in our environment is a deep cache of vulnerabilities that need to be fixed,” Rubin continued. “The balance is broken, and there’s an asymmetric advantage for the adversary, and everyone across the industry needs to catch up.”

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论