- Cybersecurity is evolving from protecting enterprise infrastructure to controlling how that infrastructure behaves.
- Palo Alto Networks is pursuing the control plane through an acquisition spree worth more than $35 billion — but its widely criticized technical support raises questions about the operational cost of platformization.
- Cisco may be Palo Alto's most important strategic rival, building upward from networking while Palo Alto builds outward from security.
Cybersecurity used to have a fairly straightforward job: protect the perimeter. Not an easy job, certainly, but at least the mission was clearly defined.
Enterprises built networks, connected applications and users to them, and then erected firewalls around the resulting infrastructure. Security protected the network, but it did not control the enterprise.
That distinction is disappearing.
As applications have moved into multiple clouds, employees have become distributed, APIs have proliferated and AI agents have begun interacting autonomously with corporate systems, there is barely a perimeter left to defend. Security increasingly determines who — or what — can access an application, what data it can see and what actions it can perform.
Security is therefore evolving from protection into control.
And some of the world’s largest cybersecurity companies are beginning to say so explicitly.
Security evolution
Palo Alto Networks provided perhaps the clearest example when it completed its acquisition of Portkey in May. The company described its Prisma AIRS AI Gateway as a “mission-critical control plane for the enterprise” capable of monitoring, orchestrating and governing autonomous AI agents.
Words matter here. Authenticate. Authorize. Route. Monitor. Orchestrate. Govern.
This is the language of control-plane functionality.
Palo Alto isn’t alone. CrowdStrike says its Falcon platform will deliver “AI’s security control plane.” Zscaler’s Zero Trust Exchange already sits between users, workloads and applications, applying policy rather than simply protecting a conventional network perimeter.
Cisco is heading toward the same destination from the opposite direction. It already owns much of the underlying communications infrastructure and is now combining networking with identity, observability, Splunk and increasingly autonomous security. Cisco describes security as being built into the foundation of the agentic AI economy.
HPE is assembling another version following its acquisition of Juniper Networks, combining networking and security with Mist and Marvis AIOps, Aruba Central, compute and hybrid cloud.
Security and Operational Sovereignty
This matters because Operational Sovereignty ultimately depends upon an organization being able to determine what its infrastructure is permitted to do — and enforce those decisions.
John Machado, CTO of legal technology company Elite, described almost exactly this requirement when I interviewed him recently for Fierce Network. In the age of AI, he argues, the challenge is becoming less about “the pure intelligence” and more about understanding how to “orchestrate and quite frankly operate.”
His starting point is data. Enterprises need a platform, he said, that provides “context of that data, control of that data as much as possible,” and then allows them to build their workflows, outcomes and processes on top of it.
Machado works with law firms, where the sensitivity of client data makes the issue particularly acute. As AI agents gain greater access to that data, he argues that governance becomes more important, not less: “Governing that data, whether it was a human or whether it's an agent now, that responsibility still persists.”
That is essentially the control-plane requirement.
It requires visibility, identity, policy, authorization and enforcement across networks, clouds, applications, machines and autonomous AI agents. Security platforms are acquiring precisely those capabilities.
The security layer could therefore become the mechanism through which Operational Sovereignty is actually enforced.
But there’s a catch
If security becomes the control plane, the companies providing it assume much greater operational responsibility. And that raises an uncomfortable question for Palo Alto Networks.
Under CEO Nikesh Arora, Palo Alto has assembled much of its broad platform through an extraordinary acquisition spree — roughly two dozen significant deals since 2014 representing more than $35 billion in announced and estimated acquisition value. The largest by far is its approximately $25 billion acquisition of CyberArk, completed in February 2026.
Demisto helped create Cortex XSOAR. Twistlock and PureSec helped create Prisma Cloud. Other acquisitions have expanded the company into attack-surface management, browser security, data security, observability, identity and AI security.
The strategy is “platformization”: consolidate fragmented security functions into a common platform capable of applying security and policy across much of the enterprise.
Palo Alto has demonstrated considerable skill at integrating acquired technology. But integrating technology isn’t necessarily the same thing as integrating the expertise required to support it.
The platformization paradox
Palo Alto has acquired a widely known and remarkably persistent reputation for poor technical support.
This isn't based on a couple of disgruntled customers. Practitioner forums are awash with complaints about Palo Alto TAC, stretching back years and continuing into 2026. The themes are strikingly consistent: inexperienced first-line engineers, scripted troubleshooting, slow escalation, tickets bouncing between engineers and customers having to involve account teams before reaching someone capable of resolving complex problems.
In February, one purported major enterprise customer paying millions of dollars for support described Palo Alto TAC as a “training-wheels” environment in which customers pay while inexperienced engineers learn.
The complaints became sufficiently prevalent that moderators of the Palo Alto Networks Reddit community publicly defended allowing the TAC complaints to remain, saying they concerned a core service for which “a LOT of customers” were paying substantial sums and receiving sub-par support.
A March 2026 discussion asked for alternatives to Palo Alto TAC because customers were paying significant sums to have support “literally waste our time and make our outages last longer.”
And as recently as June, another discussion of Palo Alto TAC began simply: “ours has been terrible.”
These are customer and employee accounts, not an independently audited measurement of Palo Alto's support organization. But the sheer volume, persistence and consistency of the complaints make the company's poor support reputation impossible to dismiss as a handful of isolated anecdotes.
Palo Alto did not respond to my invitation to discuss its control-plane strategy. For the record, Palo Alto has never replied to any of my inquiries, ever — certainly a novel approach to media relations, perhaps inherited from its tech support system.
Nor is there evidence establishing that Palo Alto’s acquisition strategy caused its support problems.
But the relationship deserves examination.
Platformization is supposed to reduce complexity for the customer by consolidating numerous functions onto a common platform. Yet it can simultaneously increase complexity inside the vendor, which must maintain expertise across technologies created by different engineering organizations, architectures and operational histories.
And that makes the comparison with Cisco particularly interesting.
Cisco's integration machine
Cisco is arguably the closest competitor to Palo Alto's larger ambition to become the enterprise control plane.
Cisco can combine networking, security, identity and observability with Splunk in a way the pure-play security companies cannot. Palo Alto is effectively trying to build outward from security to control the infrastructure, largely through platformization and acquisition. Cisco is trying to build upward from the infrastructure toward control, integrating security, networking, identity, telemetry and Splunk.
And Cisco has been acquiring companies for more than three decades. More importantly, it industrialized the process.
Cisco says its acquisition integration process begins during due diligence rather than after the deal closes. It maintains dedicated integration resources and has developed repeatable processes for absorbing technologies and organizations into the larger company.
Meraki retained its distinctive cloud architecture while gaining Cisco's enormous distribution machine. ThousandEyes has been woven into Cisco networking and assurance. And Splunk is being combined with Cisco networking, security and observability.
The objective is not simply to accumulate products but to make acquired technologies reinforce one another. Splunk can interpret telemetry generated across the infrastructure; security can determine what is permissible; and networking can increasingly enforce the resulting decisions.
Cisco's record is certainly not flawless — the integration of Sourcefire into Firepower generated years of criticism. But Cisco possesses something Palo Alto may still be building: institutional memory about how to absorb companies without merely accumulating products.
That could become an unexpectedly important competitive advantage.
Ultimately, the winner won’t simply be the company with the best firewall, endpoint product or AI security platform.
It will be the company capable of observing the entire enterprise, understanding what is happening, establishing policy and identity, and enforcing decisions across networks, clouds, applications, machines and autonomous AI agents.
Security is no longer merely protecting the infrastructure.
Security is becoming the infrastructure through which the enterprise is controlled.
Caveat emptor.
Learn more about operational sovereignty
AI isn’t the business — it serves the business
Opinion: Who will control the control plane of the world?
Carrier 2.0 - Who Governs The Agents? - YouTube
Stephen M. Saunders MBE is a communications analyst and USPTO-registered inventor examining how digital infrastructure — 5G, cloud and AI — is reshaping industry, power and society, as well as underpinning the emerging, ubiquitous global digital economy. As anchor of FNTV and a longtime industry insider, he focuses less on growth narratives and more on execution, risk and how hyperscale technology is distorting markets, governance and society at scale.
Opinion pieces from industry experts, analysts or our editorial staff do not represent the opinions of Fierce Network.