The escalating threat of AI-powered hacking is not just forcing companies to significantly boost their overall cybersecurity budgets, but it is also fundamentally altering where those funds are being allocated. Security executives report that major enterprise buyers have markedly increased spending on systems that monitor employee use of AI tools, deploying AI models to identify vulnerabilities before attackers can strike, and leveraging AI to accelerate patching processes. However, not all cybersecurity products are benefiting from this influx of capital.
Several executives note that companies are simultaneously cutting expenditures on traditional vulnerability management software, log collection tools, and penetration testing services to offset new costs. Penetration testing, which involves hiring ethical hackers to proactively seek out system flaws, is facing particular scrutiny. This shift is putting pressure on the legacy software businesses of firms like Cisco Systems, SentinelOne, and Rapid7, all of which have conducted layoffs this year as they pivot resources toward next-generation AI security products.
Brett Wentworth, Vice President and Deputy Chief Security Officer at Lumen Technologies, said the telecom giant expects its cybersecurity budget to climb by roughly 30% over the next year. The new investments cover AI models like Anthropic's Claude Mythos for vulnerability scanning, AI-powered scanning tools from established vendors such as Palo Alto Networks and startups like Zafran Security, plus security systems designed to monitor and protect employee use of AI applications. He noted that company leadership has recognized the urgency of addressing AI-driven threats, adding that the industry has seen a decisive shift away from constant cost-cutting pressure.
When Anthropic launched the Mythos model in April, many enterprise leaders realized their security strategies required a fundamental overhaul. Officials warned at the time that this frontier AI model could autonomously infiltrate complex corporate networks. Subsequent reports of a rogue OpenAI agent launching coordinated attacks on OpenAI's own systems and platforms like Hugging Face have further intensified these concerns. Major AI labs are themselves becoming competitors in the security solutions arena, with OpenAI's latest GPT-6 Astra release heavily promoting its ability to help defenders identify and remediate cybersecurity flaws.
Wentworth explained that following the Mythos release, Lumen assembled a new team of cybersecurity personnel dedicated to using frontier models for vulnerability scanning. The company's bug bounty program has also seen a surge in submissions from external researchers, many of whom are leveraging AI in their hunting efforts. He stated that Mythos and other advanced models have truly reshaped the security budget landscape.
This wave of security anxiety is opening market opportunities for emerging cybersecurity startups that offer specialized products addressing threat types that didn't exist just a few years ago. Jeremiah Kong, Chief Information Security Officer at mobile advertising technology firm AppLovin, said his company has negotiated discounted pricing on AI security tools from multiple early-stage startups. This has helped control the growth of their nearly million-dollar annual security software budget, which has already risen about 10% this year.
For example, Kong's team has signed contracts with Pluto Security and Fig Security, both of which only recently emerged from stealth mode. Pluto uses AI agents to monitor how employees interact with AI tools internally, while Fig Security employs AI to identify potential vulnerabilities and suggest remediation steps. AppLovin also uses Endor Labs software to scan developer code for potential weaknesses. Kong emphasized that attack vectors are constantly evolving, requiring constant vigilance.
Kong noted that AppLovin uses products from CrowdStrike and SentinelOne for endpoint security, which protects employee devices and applications. However, he is reassessing this spending because newer AI technologies like Pluto can better identify when employees upload data to AI tools like chatbots. He characterized the comparable AI security offerings from CrowdStrike and SentinelOne as subpar.
In response, a CrowdStrike spokesperson stated that customers deciding not to purchase a particular module without testing it does not represent a replacement, especially when they continue using the CrowdStrike platform. The spokesperson highlighted that CrowdStrike's AI detection and response offering has grown over 79 times in scale in the three quarters since launch, demonstrating strong customer demand. A SentinelOne representative said AI security is the company's fastest-growing segment, with new revenue coming from both new customers and platform expansions among existing accounts, citing a doubling in year-over-year annual recurring revenue for AI security products in the second quarter.
Cybersecurity vendors report that industry demand surged following the Mythos launch. Sanaz Yashar, CEO of Israeli startup Zafran, said enterprise contract negotiations typically take months, but within five weeks of Mythos's release, Zafran secured new deals with three major banks. She described the rapid change in customer purchasing behavior as unprecedented.
Security executives say the proliferation of new LLM-based vulnerability scanning tools poses a competitive threat to legacy products from established vendors like Qualys, Tenable, and Rapid7, whose offerings predate the widespread adoption of large language models. Jon Reber, a former CISO at Chevron and Costco who now works as an enterprise security consultant, predicted that traditional scanners, which have faced no major disruption since the mid-to-late 1990s, will eventually be replaced by LLM-driven alternatives. He noted that these legacy tools merely aggregate large volumes of information without providing sufficient context, leaving much of the data of limited value.
Doug Kersten, CISO at software company Appfire, said his firm is using a new red team agent from Wiz, which Google acquired this year for $32 billion. Wiz leverages models from Google, Anthropic, and OpenAI to find vulnerabilities. Kersten expects overall cybersecurity spending to rise as much as 20% over the next year due to these tools and other AI security software, but plans to reduce reliance on traditional code scanning tools going forward.
Steve Wenz, Co-CEO of Tenable, disputes the notion that AI tools will disrupt his company's vulnerability scanning software. Tenable participates in early cybersecurity access programs with Anthropic and OpenAI, selling software based on both models' recommendations. Wenz said contract cycles have shortened and demand has continued rising since the Mythos release, citing steady revenue growth in recent quarters and a rising stock price as evidence that frontier models create more risks rather than fewer, which benefits his company significantly.
Qualys and Rapid7 spokespeople did not respond to interview requests. Qualys reported 11% revenue growth in the second quarter, with some expected slowdown in the current quarter, while noting strong customer demand for new AI-driven products designed for the threat environment created by Mythos. Rapid7 CEO Wael Mohamed reported a slight revenue decline during the company's August earnings call, following a management restructuring focused on AI products and a 12% workforce reduction. He attributed customer spending cuts not to price sensitivity but to enterprises prioritizing their transformation to an agentic AI world.
While CISOs are making upfront investments in token budgets for LLMs from Anthropic and OpenAI to scan systems, many executives see potential for long-term cost control. Gil Vega, CISO at data backup firm Veeam, accesses the Mythos model through Anthropic's Glasswing program. He said spending in this area has surged, but Veeam offsets the costs of Mythos and other models by reducing third-party penetration testing procurement.
Jeremiah Kong similarly relies on AI models to scan AppLovin's IT infrastructure and flag potential vulnerabilities. Given the high cost of testing with Mythos, AppLovin has opted to use more cost-effective Anthropic models like Claude Opus 4.7. Kong said the team conducts weekly scans, with Anthropic token usage typically costing a few hundred dollars per session.
Even major security vendors that heavily use Mythos and other frontier models believe costs could eventually decline. Sam Rubin, Senior Vice President at Palo Alto Networks, said the company consumed over $1 million worth of Mythos tokens during the May testing phase. However, last month he indicated that Mythos usage is expected to plateau going forward, with workloads gradually stabilizing into normal operations. Rubin declined to comment directly on whether Palo Alto expects Mythos costs to decrease, but acknowledged that while the attack-defense balance has shifted giving attackers an asymmetric advantage, there remains a significant volume of vulnerabilities to remediate across the industry.