* [![perspectives](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/02/prespective-icon.png)](https://origin-www.paloaltonetworks.com.au/perspectives)
* Your 2026 AI Cybersecurity Strategy: Breaking Down the Hard Choices for Tech Leaders

# Your 2026 AI Cybersecurity Strategy: Breaking Down the Hard Choices for Tech Leaders

![Your 2026 AI Cybersecurity Strategy: Breaking Down the Hard Choices for Tech Leaders](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/12/AI-Cybersecurity-Strategy-featured.jpg)  
**By [Ben Hasskamp](https://origin-www.paloaltonetworks.com.au/perspectives/author/ben-hasskamp/ "Posts by Ben Hasskamp")** | **6 min read** |  
![share icon](https://paloaltonetworks.com/content/dam/pan/en_US/cxo-perspectives/images/cxo-share.svg)

* LinkedIn button ![linkedin-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-linkedin.svg)
* Twitter share button ![twitter-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-twitter-x-black.svg)
* \[Email share button ![email-icon](https://www.paloaltonetworks.com/content/dam/pan/en_US/microsite/cortex/images/share-email.svg)\](mailto:?subject=Your 2026 AI Cybersecurity Strategy: Breaking Down the Hard Choices for Tech Leaders\&body=Check out this article https%3A%2F%2Forigin-www.paloaltonetworks.com.au%2Fperspectives%2Fai-cybersecurity-strategy-hard-choices-for-tech-leaders%2F "Share in Email")
* ![copy-icon](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/themes/csp2025/dist/images/icons/icon-share.svg)
  [](https://origin-www.paloaltonetworks.com.au/perspectives/ai-cybersecurity-strategy-hard-choices-for-tech-leaders/?pdf=download&lg=en&_wpnonce=83197ae001 "Click here to download") MEET THE AUTHOR  
  ![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2025/07/ben-hasskamp-headshot.jpg)  
  Ben Hasskamp is the Managing Editor of Perspectives at Palo Alto Networks. He has led brand and narrative strategy in senior content and communications roles for organizations ranging from innovative startups to Fortune 500 companies. Ben graduated cum laude from the University of Southern California's School of Cinematic Arts with a major in critical studies and double minors in screenwriting and creative writing....

[Learn more](https://origin-www.paloaltonetworks.com.au/perspectives/author/ben-hasskamp/)

## IN THIS ARTICLE

A CIO's or CFO's ledger has a fundamental, if unspoken, equation: Resources must, at a minimum, match the scale of the risk. For 2026, however, this equation doesn't work. Today's AI supercharges and scales threats, which are multiplying at a rate no technology has ever seen. Meanwhile, many cybersecurity budgets remain stubbornly linear, forcing a series of hard choices about where to invest, what to automate and which risks to accept.

We've seen the effects of AI as a massive force multiplier for both attackers and defenders. It both accelerates the pace of attacks and promises new forms of automated defense. For leaders, the real test is how strategically they invest in AI to get the greatest return on security.

This ambiguity --- where risk and new technology collide --- is familiar territory for [Mark Settle](https://www.forbes.com/sites/marksettle/). A seven-time CIO (most recently at Okta), an author and an advisor, he guides technology leaders through multiple cycles of disruption, from moving to the cloud to the pressures of downsizing.

I sat down with Mr. Settle to discuss these critical tradeoffs. He reflected on the practical choices security and tech leaders must make as they plan for this new landscape. His insights offer a clear-eyed view for any leader tasked with managing exponential risk with finite resources.

#### How worried should we be about the pace of innovation on the offensive side of cybersecurity?

It cuts both ways. AI clearly creates new threat opportunities, but it's also the latest automation tool, after years of automating in cybersecurity. Many CISOs will tell you that criminals don't need AI yet, because people still make the same mistakes, like clicking on bad links, reusing weak passwords and leaving the door open. In that sense, attackers are still winning the old-fashioned way.

#### Security threats are multiplying, but budgets aren't keeping pace. How should tech leaders think about that tension as they approach planning for next year?

That's the reality they face. You can't defend on every front at once, and you can't expect headcount or budgets to suddenly expand. What you can do is recognize that the landscape itself is shifting --- through vendor consolidation, category convergence and AI capabilities getting embedded into larger platforms.

If you step back and look a bit beyond one budgeting cycle, those secular changes create opportunities to simplify and focus.

#### What are the biggest opportunities you see?

If I were going into a budget exercise for next year, I'd be looking at three things.

The first one is consolidation. Everybody complains about the size and complexity of their security tech stack. M\&As \[mergers and acquisitions\] are highly competitive in this space, with major platforms absorbing point solutions. If you look closely, you may find tools you bought two or three years ago that were "must-haves" then but now overlap with what your primary platform vendor does well. Dropping some of those tools saves real money.

Second, some categories are merging. Take vulnerability management, which used to require two separate tools --- threat intelligence and vulnerability scanning. Now, you have continuous exposure management platforms that marry those together and add business context. You don't want to be the last person paying for a tool that's on its way out.

And the third is AI. Every vendor is pushing AI capabilities right now. My advice would be to experiment aggressively, but with an objective. The one that appeals most to me is automation. Use AI to automate away routine work, reduce latency in responding to threats and eliminate some of the headcount pressure.

The reality is that you're not going to get more people. Rather, you might be told to make cuts, so it's better to put these tools to work now.

#### How do you pull that off without falling into the trap of always pursuing every new tool and capability?

That's the bigger issue. Do you leverage the AI capabilities your existing vendors are rolling out, or do you also invest in new AI-native products? You can't really afford to do both, which is where the tradeoff comes in.

My bias is to start with incumbent platforms that their vendors are embedding AI into. You can evaluate their capabilities with your concrete goals. For example, you might ask: Can they automate repetitive tasks? Can they shrink response times? Can they free up people? These areas, I believe, will have the fastest returns.

#### Once you've made those tradeoffs, how do you protect the savings to ensure they're reinvested in security instead of disappearing into the broader budget?

If you find ways to cut vendor costs or labor dollars, don't wait for finance to spend the savings on marketing. Talk to the CFO up front and cut a deal. You might say: "If I save three dollars, I get to reinvest two dollars into reskilling and cloud security." That way, you have a gain-share model that lets you reinvest in security instead of losing out on those dollars.

#### You've talked about automation as the most compelling near-term use case for AI. What happens as AI agents start acting more independently? How does that change your risk calculus?

I don't believe it's here yet, but it's coming --- and it's something I've been researching closely. In a multiagent world, AI systems will commission actions on behalf of one another, often with little or no human involvement. That raises fundamental questions about authentication. Today, we think about authenticating a person. But what happens when it's an agent initiating a transaction on behalf of another agent? How do you establish trust at machine speed? That's going to reshape identity and access management in the next few years, and CIOs and CISOs will need to start preparing for it now.

#### As leaders plan for 2026, what's the biggest change in mindset you would encourage them to make?

Before leaders become enticed by their existing vendors' new AI capabilities, they need to learn as much as they can about how cybercriminals are using AI to weaponize the threat vectors that matter most to their companies. They need to focus their AI investments on new defensive capabilities that can blunt those AI-turbocharged threats. Simply put, they need to use AI to fight AI.

If you're curious about what else is on the horizon for 2026, check out [Palo Alto Networks Predictions](https://www.paloaltonetworks.com/perspectives/2026-cyber-predictions).

* [AI](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=ai)
* [Cyber as a Boardroom Topic](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=cyber-as-a-boardroom-topic)
* [Staying Ahead of Evolving Threats](https://origin-www.paloaltonetworks.com.au/perspectives/all-articles/?cat=staying-ahead-of-evolving-threats)

## Related Content

![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Securing-the-Wrong-Layer-featured.jpg) BLOG

### Staying Ahead of Evolving Threats

**Cybersecurity in 2026: What we predicted, what surprised us, and what's next**

At Palo Alto Networks, we are privileged to sit at the intersection of cybe...

[Haider Pasha](https://origin-www.paloaltonetworks.com.au/perspectives/author/haider-pasha/ "Posts by Haider Pasha")
[](https://origin-www.paloaltonetworks.com.au/perspectives/cybersecurity-in-2026-what-we-predicted-what-surprised-us-and-whats-next/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Why-Cybersecurity-KPIs-Are-Changing-featured.jpg) BLOG

### AI

**Why Cybersecurity KPIs Are Changing (And What This Means for Security Leaders)**

True cyber resilience is impossible to achieve without strategic and tactic...

[Helmut Reisinger](https://origin-www.paloaltonetworks.com.au/perspectives/author/helmut-reisinger/ "Posts by Helmut Reisinger")
[](https://origin-www.paloaltonetworks.com.au/perspectives/why-cybersecurity-kpis-are-changing-and-what-this-means-for-security-leaders/)  
![](https://origin-www.paloaltonetworks.com.au/perspectives/wp-content/uploads/2026/03/Weaponized-Intelligence-featured.jpg) BLOG

### AI

**Weaponized Intelligence**

We are building the foundation that makes defense possible....

[Nikesh Arora](https://origin-www.paloaltonetworks.com.au/perspectives/author/nikesh-arora/ "Posts by Nikesh Arora")
[](https://origin-www.paloaltonetworks.com.au/perspectives/weaponized-intelligence/)  
STAY CONNECTED

## Connect with our team today

Job Level  
Sign me up to receive news, product updates, sales outreach, event information and special offers about Palo Alto Networks and its partners.  
By submitting this form, I understand my personal data will be processed in accordance with Palo Alto Networks [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) and [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown).  
This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.
Reach out  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown)

* [Customers](https://www.paloaltonetworks.com/customers?ts=markdown)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown)

* [Communities](https://www.paloaltonetworks.com/communities?ts=markdown)

* [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown)

* [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown)

* [Documents](https://www.paloaltonetworks.com/legal?ts=markdown)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* AU  
  Select your language
