The rise of AI agents and automated attacks is forcing enterprises to reconsider what belongs inside the cybersecurity perimeter, with legacy infrastructure, endpoints, domains and digital brand identities increasingly becoming part of the defense equation.
Artificial intelligence is changing cybersecurity in two directions at once. Security teams are using AI to automate detection, investigation and response, while attackers are using increasingly capable systems to identify vulnerabilities, impersonate organizations and scale attacks faster.
That shift is creating a broader modernization problem than traditional network security alone can address.
VPN.com CEO Michael Gargiulo is arguing that enterprises should treat domains, endpoints, browsers, Internet Protocol space and digital brand assets as part of their cybersecurity strategy. The company’s position comes as cybersecurity vendors warn that much of the infrastructure deployed before the AI era was not designed for machine-speed threats.
Palo Alto Networks CEO Nikesh Arora recently estimated that there is approximately $1 trillion of global cybersecurity debt that needs to be modernized to defend against automated threats. The figure is a company estimate rather than an independently audited measure of global infrastructure spending.
VPN.com’s Gargiulo argues that the figure could be considerably higher when organizations account for expanding endpoints, cloud infrastructure, AI agents, domain portfolios and future technology refresh cycles.
That larger estimate should be treated as a strategic argument rather than an established market statistic. But the underlying issue is increasingly difficult to dismiss: AI is expanding the number of assets organizations need to protect while simultaneously increasing the speed at which threats can operate.
The perimeter is getting larger
Traditional enterprise security architectures were largely organized around networks, servers, laptops and cloud accounts.
The AI-enabled enterprise adds new categories.
Employees increasingly access applications through browsers and APIs. Software agents can receive credentials and interact with business systems. Companies maintain larger portfolios of domains and digital properties. Vendors and partners gain access through interconnected portals and SaaS platforms.
Each connection can become an attack surface.
Autonomous AI agents add another layer because they are software entities that may act on behalf of people or applications. Unlike a passive data source, an agent can potentially make decisions, invoke tools and interact with external systems.
Palo Alto Networks has similarly warned that autonomous agents will dramatically expand the network surface requiring protection and that AI security governance and guardrails are becoming essential enterprise requirements.
This changes the cybersecurity question from “How do we protect the network?” to “Which identities, systems, agents, applications and digital assets can act on behalf of the organization?”
AI is also accelerating the threat
The risk is not theoretical.
IBM’s 2026 Cost of a Data Breach research found a 56% increase in AI-driven attacks, with AI-enabled malware and deepfake impersonation contributing significantly to the rise. At the same time, organizations making extensive use of AI and automation in security reported an average $1.93 million in savings compared with organizations using none.
That creates an increasingly asymmetric environment.
Attackers can automate reconnaissance, phishing content, impersonation and portions of vulnerability discovery. Defenders therefore need automated systems capable of processing security telemetry and responding at comparable speed.
The result is a new investment cycle in AI cybersecurity, security automation, identity protection and real-time threat response.
Domain security becomes part of the discussion
VPN.com’s most distinctive argument is that domain names should be considered part of an organization’s security perimeter.
Domains have historically been treated primarily as web addresses and brand assets. But they can also function as trust signals.
A lookalike domain can be used for phishing. A compromised domain can redirect users. A misleading support website can exploit customers who believe they are interacting with a legitimate company.
The risk becomes more complicated as organizations operate across countries and languages.
ICANN’s 2026 New gTLD round has accepted more than 1,600 primary applications, while the program supports applications across multiple scripts, including Arabic, Chinese, Devanagari and other writing systems.
The expansion is designed to make the domain-name system more diverse and globally accessible. But for enterprises, it also means domain portfolios and potential brand-confusion scenarios could become more complex.
That does not mean every new domain represents a cybersecurity threat. Rather, the growing namespace reinforces the need for organizations to understand which digital identities they own, which ones could be abused and where customers might encounter confusingly similar properties.
Brand impersonation moves closer to cybersecurity
AI-generated content makes that problem harder.
Attackers can create convincing websites, emails, voice interactions and other communications at much greater scale. Fake support pages or employee impersonation campaigns can exploit customer trust without directly compromising the organization’s primary infrastructure.
For security teams, this makes external attack-surface management increasingly relevant.
The inventory extends beyond assets controlled by the IT department to include public-facing domains, exposed services, third-party applications and digital identities that could be used to impersonate the organization.
The challenge is determining which assets actually create material risk.
That distinction matters because simply registering large numbers of defensive domains is not equivalent to having an effective cybersecurity program. Enterprises still need identity controls, authentication, endpoint protection, vulnerability management, monitoring and incident response.
The cybersecurity stack is becoming more automated
The broader market is moving toward platforms that combine telemetry, AI models, security analytics and automated response.
Microsoft, Google, Amazon and Palo Alto Networks are among the major technology companies investing in AI-assisted security operations, while specialist vendors are developing systems for identity security, endpoint defense, cloud protection and attack-surface management.
The competitive question is increasingly how much of the security lifecycle can be automated without sacrificing oversight.
AI can analyze large volumes of alerts and identify patterns humans may miss. It can also accelerate investigation and response. But organizations still need governance around automated actions, particularly when those systems can modify infrastructure, disable accounts or block legitimate traffic.
This is especially important as agentic AI moves into security operations.
A future security architecture may contain AI agents monitoring other AI agents, validating access decisions and automatically containing suspicious behavior. That could improve response times, but it also creates new machine identities and permissions that must themselves be secured.
From cybersecurity debt to AI-era resilience
VPN.com’s broader argument is therefore less about domains alone and more about the changing definition of enterprise cyber resilience.
The $1 trillion cybersecurity-debt figure from Palo Alto Networks is a useful indicator of the modernization pressure facing enterprises, but Gargiulo’s suggestion that the total could reach $3 trillion remains a company executive’s projection rather than an established industry estimate.
The more measurable trend is that AI is increasing both offensive and defensive automation. IBM’s data shows attacks using AI are rising, while security automation can materially reduce breach-related costs.
For CISOs, that means cybersecurity planning increasingly has to encompass AI agents, cloud workloads, endpoints, APIs, browsers, domains and external brand identities alongside traditional network defenses.
The perimeter is no longer a single boundary.
It is an interconnected collection of digital identities and systems—and AI is making every part of that environment faster, more autonomous and potentially more difficult to defend.
Market Landscape
The AI cybersecurity market is moving toward automated, identity-aware and real-time defense architectures. Palo Alto Networks describes the current modernization opportunity in terms of roughly $1 trillion in global cybersecurity debt, while IBM’s 2026 research shows AI-driven attacks rising 56%.
At the same time, the enterprise attack surface is expanding beyond conventional infrastructure. AI agents, APIs, SaaS applications, cloud workloads, endpoints and digital brand assets all create additional identities and access paths.
The next generation of cybersecurity platforms will therefore need to combine AI security, endpoint protection, identity management, cloud security, attack-surface management and automated response rather than treating them as isolated controls.
The expansion of the domain namespace adds another dimension. ICANN’s 2026 round received more than 1,600 primary applications for new gTLDs, increasing the potential complexity of digital identity and brand protection.
Top Insights
- AI is increasing both the speed of cyberattacks and the number of digital assets enterprises must monitor and protect.
- Palo Alto Networks estimates roughly $1 trillion of cybersecurity debt requires modernization, but the figure is an industry estimate rather than an audited market total.
- IBM found AI-driven attacks increased 56% in its 2026 breach research, reinforcing the need for automated defensive capabilities.
- AI agents introduce new machine identities, permissions and application connections that must be incorporated into enterprise security architectures.
- Domain portfolios and digital brand identities are becoming increasingly relevant to external attack-surface and impersonation risk.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI










