Palo Alto Networks is acquiring CyberArk in a $25 billion cash-and-stock deal. If it closes as expected in the second half of fiscal 2026, it will mark Palo Alto’s formal move into the identity security market. That’s a clear signal: identity is now central to the future of enterprise security, not an add-on.
This isn’t just portfolio expansion. It’s a foundational shift. With the rise of cloud-native workloads, non-human identities, and AI-driven automation, traditional identity and access management (IAM) tools have started to show their age. Palo Alto is betting that identity security, particularly privileged access management, needs to be part of the base security stack, not something bolted on later.
What’s Changing for Security Teams
CyberArk has spent years building out tools that control who or what can access critical systems, and under what conditions. That includes human users, service accounts, workloads, and machine identities. Palo Alto plans to integrate those capabilities directly into its existing platforms - Strata and Cortex - so that identity becomes part of detection, response, and access enforcement across environments.
For security teams, this could mean fewer silos, fewer vendor handoffs, and one fewer gap for attackers to exploit. It’s a play toward real-time, identity-aware enforcement that spans cloud, endpoint, and network. If Palo Alto executes, it could turn what’s usually a patchwork of IAM tools into something operationally useful across the board.
Broader AI Strategy
Palo Alto is also positioning this move as part of its broader AI strategy. As enterprises adopt automation and AI agents that operate independently, triggering actions, spinning up infrastructure, and accessing sensitive systems - the question of “who has access to what” becomes harder to answer. And more dangerous to get wrong.
By embedding CyberArk’s identity controls, Palo Alto aims to give enterprises the tools to apply least privilege and just-in-time access to these agents, just like they would for a human user. That matters if you’re running AI at scale and want clear boundaries on what it can and can’t do.
The Bottom Line
For security team, here’s the takeaway: the identity layer is now considered essential infrastructure, not a nice-to-have. This acquisition shows that controlling access, especially for machines and automated systems, is becoming as important as firewalls or endpoint protection. While this deal still needs regulatory approval and a shareholder vote, but the direction is clear. Palo Alto wants to own the security stack from the ground up, and that now includes identity.