1. Security teams know their tooling is disconnected but can’t fix it quickly because of procurement cycles, legacy contracts, and organizational silos. What’s your honest assessment of how long most enterprises can afford to operate that way given where the threat landscape is heading?
The exposure window has closed. Unit 42 has observed attackers weaponizing within 15 minutes of a major vulnerability being disclosed, while organisations take an average of 55 days to develop, test and deploy a patch. Frontier AI is accelerating vulnerability discovery, exploit development and attack execution, widening the gap between the speed of an attack and the speed of a traditional response.
The challenge is compounded by security complexity. Organisations manage an average of 83 security solutions across 29 vendors, making it difficult for teams to correlate information and act quickly. To address this, organisations need to move towards a more preemptive approach: protecting vulnerable systems before exploits are weaponized, disrupting attacker infrastructure before attacks reach the network, and using AI to help security teams operate at machine speed.
2. When you assess an organization’s security posture, what’s the specific signal that tells you their tool fragmentation has crossed from a management problem into an active vulnerability?
The signal is time, specifically mean time to detect (MTTD) and mean time to respond (MTTR). When a security team cannot connect what one tool is seeing to what another tool knows quickly enough to act, fragmentation creates a gap between detection and response. That gap becomes an active vulnerability when attackers can move faster than the organisation can understand and respond to what is happening.
We are seeing attackers exploit that gap through techniques such as direct-to-IP communications and residential proxies. Unit 42 research shows that up to 23% of malware connections now use direct-to-IP traffic. We also found that two out of three customers experienced malicious activity that was preventable at the network layer. This is where real-time network intelligence can make a difference by identifying and blocking attacker infrastructure before a payload reaches the target.
3. Attackers using AI can now automate reconnaissance, exploit identification, and payload delivery at a speed that wasn’t possible two years ago. Which part of that chain is the most dangerous and which part being the industry least prepared for?
The most consequential development is the collapse of time between vulnerability discovery and exploitation. Frontier AI is rapidly accelerating vulnerability discovery, exploit development and attack execution. In an initial two-month validation run, our NOVA framework analysed 3,915 open-source projects and generated 14,090 validated vulnerability findings. More than 99% had no matching public record, and nearly 40% were rated High or Critical. NOVA identified the flaws, generated exploit code and validated them without human intervention.
The industry is particularly challenged by the resulting remediation gap. With 29% of CVEs now exploited within 24 hours of disclosure, traditional patching can leave organisations exposed. We need to move protection earlier in the lifecycle, using approaches such as Advanced Virtual Patching to shield vulnerable systems before official patches are available.
4. The security industry talks about AI as both the threat and the defense. In your view, is defensive AI currently keeping pace with offensive AI and what would have to change for the answer to be yes?
Defensive AI needs to operate at the speed and scale of the threat. That means using AI to identify emerging threats, strengthen prevention and reduce the manual work involved in security operations, while maintaining human oversight over critical decisions. Palo Alto Networks’ SOC processes up to 90 billion security events a day, using AI and machine learning to narrow those down to 26,000 detections and an average of 75 response cases. The objective is to use AI to handle the scale and speed of routine security activity while keeping people focused on the decisions that require human judgement.
5. Critical infrastructure operates on systems that were designed decades before modern cyber threats existed. What does “integrated, real-time defense” mean in an environment where the underlying infrastructure can’t easily be replaced or updated?
Critical infrastructure highlights the mismatch between AI-speed attacks and human-speed maintenance. Many OT environments have long equipment lifecycles, strict safety requirements and limited maintenance windows, making rapid patching or taking systems offline impractical. In some industrial environments, the deployment cycle can take months.
Real-time defense has to work within those constraints. It means protecting vulnerable systems while they remain operational, through network-level protections such as virtual patching, as well as visibility and segmentation to limit an attacker’s ability to move through the environment. That is the thinking behind our Critical Defense Program and the OT security capabilities introduced with PAN-OS 12.2 Ceres.
6. When you advise an enterprise on moving toward real-time defense capability, what’s the organizational resistance that’s harder to overcome than the technical one?
In my experience, one of the biggest barriers is operational complexity and the concern about losing control as more processes become automated. Security teams are already managing a large volume of manual tasks across increasingly complex environments.
The last thing a network security administrator should have to become is a software engineering shop that manages AI infrastructure.
That makes trust and control important. AI should be able to identify issues, recommend remediation and automate approved actions, with guardrails, explainability and appropriate human oversight.
7. The security vendor market is overcrowded with products that solve specific problems in isolation. From your position as an advisor, what does the next generation of security architecture need to look like and how far is the vendor community from building it?
Most organizations are struggling with too many tools—on average, juggling 83 different tools inside their SOC. This creates massive engineering complexity in integrating and sustaining those tools, as well as organizational churn as staff are constantly required to train on new tooling and governance documentation. As a result, this drives up an organization’s MTTD and MTTR.
The next-generation SOC is built on tightly integrated and simplified toolchains, a strategy known as Platformization. As a byproduct, Platformization provides the key foundation to integrate AI into the SOC and enable human operators to work on the security loop rather than bottlenecking in the loop.
The key here is to give the next-generation SOC the ability to observe, orient, decide, and act faster than the adversary, giving organizations decision superiority in defending their networks. Fighting AI with AI will be key to doing so.
The Palo Alto Networks SOC is a great example that this capability is already here: with a mean time to detect of 7 minutes and a mean time to respond of 1 minute, our SOC leverages the Cortex platform to operate at speed and scale.
8. Security buyers are fatigued. Too many tools, too many dashboards, too many alerts that don’t connect to each other. What should a security company be asking itself before it ships a new product and how many of them are actually asking it?
The operational toll of tool proliferation is unsustainable. Research we conducted with IBM reveals that organizations manage an average of 83 security tools from 29 vendors, with 52% of executives identifying this complexity as their primary operational risk.
This reality underpins Palo Alto Networks’ core mandate on Platformization.
Platformization is not simply a business strategy; it is a technical prerequisite for real-time defense. The IBM study proved that organizations who have adopted a Platformization approach take 72 fewer days to detect an incident and 84 fewer days to contain one.
The next generation of security architecture must replace fragmented tools with a unified platform built on shared global intelligence and inline prevention. Palo Alto Networks aggregates threat telemetry across more than 70,000 global customers and analyzes 5.43 billion new security events daily. Consolidating data onto a single platform creates a network effect – where a threat identified anywhere instantly updates defenses everywhere – while giving Precision AI the unified context needed to automate routine operations and eliminate alert fatigue. The industry is moving in this direction, but there is still considerable fragmentation to address.
9. You must have seen security companies build products for the buyer who approves the purchase rather than the analyst who has to use it under pressure at two in the morning. How much does that disconnect between buyer and user contribute to the blind spots?
For years organizations have been responding to individual security challenges by adding another tool and largely this has been done without a comprehensive strategy for integration of the individual tooling. Ultimately this has resulted in inefficiencies and sustainability concerns.
However, buyers are becoming increasingly more aware that the future of SOC operations needs to be more tightly integrated with a focus on matching the speed of AI enabled attackers. With time from attack to data exfiltration taking minutes, it is vital that organisations focus on removing those blind spots and drive down the MTTD and MTTR.
Bio :
Tom Scully, CSC
Director – Industry Principal, Japan and Asia Pacific, Palo Alto Networks
Tom Scully, CSC, is a distinguished senior engineering leader with over a decade of experience supporting government and commercial organisations across the communications, cybersecurity, and advanced technology sectors. As Principal Architect for Government and Critical Infrastructure at Palo Alto Networks, Tom plays a pivotal role in helping clients across the Asia Pacific and Japan region secure their most critical systems.
At Palo Alto Networks, Tom brings deep expertise in protecting high-security environments in government and critical infrastructure. He supports customers in maximising the value of the Palo Alto Networks platform, particularly in air-gapped or heavily regulated security environments, by aligning solutions with strict security and compliance demands. Tom is also a trusted advisor on the secure adoption of AI – whether organisations are just at the beginning of their AI journey or starting from scratch – sharing practical guidance on implementation, risk reduction, and emerging threats, including agentic AI risks.
Before joining Palo Alto Networks, Tom served as an Officer in the Royal Australian Air Force, where he was honoured with the Conspicuous Service Cross by the Governor General of Australia in 2018.
Tom holds a Bachelor of Electrical Engineering from the University of New South Wales and is currently advancing his academic expertise as a PhD candidate. His research focuses on the development of a Resilient AI Security Supervisory System for Connected and Autonomous Vehicles. Known for his ability to bridge deep technical knowledge with strategic thinking, Tom has guided both public and private sector stakeholders through complex security transformations.
As a thought leader, he covers a wide range of topics, including cybersecurity in high-security and regulated environments, the secure adoption of AI, aviation cybersecurity, and the evolution of digital transformation in Government, from legacy infrastructure to Zero Trust strategies.

Techedge AI is a niche publication dedicated to keeping its audience at the forefront of the rapidly evolving AI technology landscape. With a sharp focus on emerging trends, groundbreaking innovations, and expert insights, we cover everything from C-suite interviews and industry news to in-depth articles, podcasts, press releases, and guest posts. Join us as we explore the AI technologies shaping tomorrow’s world.










