AI stopped being a theme and became the category frame
The clearest shift of the fortnight was not that cybersecurity vendors talked about AI. It was how completely AI displaced older positioning. On 15 Sep, SentinelOne changed its hero line from “The Autonomous Security Platform Built for Advantage” to “The World Runs on AI. We Secure It.” The same day, Palo Alto Networks moved its hero from identity chaos to “Let AI coding do more. With you in control.” On 16 Sep, Fortinet replaced event-led messaging with Gartner Magic Quadrant leadership for Hybrid Mesh Firewall.
CrowdStrike pushed the same line from the top. On 21 Sep, George Kurtz used CNBC to emphasise “agent states” and warn that AI-related cyber threats are already present. On 14 Sep, CrowdStrike launched a new autonomous product and released foundry-skills 1.5.0 with support for AI coding assistants including Claude Code, Codex, Copilot CLI, Cursor and Antigravity CLI. On 15 Sep, CrowdStrike and Wipro launched a CISO Command Centre.
The identity and exposure vendors followed. On 20 Sep, Okta’s CEO discussed AI agents in identity management as Helen Riley joined the board. On 17 Sep, Tenable was reported to be integrating OpenAI GPT Cyber Models to inspect community-created AI components. On 16 Sep, Proofpoint expanded insider-risk tools and AI-powered investigations into Microsoft 365. This is no longer feature dressing. The market is converging on a single claim: secure the agents, the code they produce, the identities they use and the data they touch.
The platform race is being financed and widened
Palo Alto Networks made the most direct inorganic move. On 14 Sep, it acquired Console, an IT help desk start-up, for $500mn, alongside reported 63 percent NGS ARR growth and a $282mn GAAP net loss. The signal is consistent with the homepage shift a day later: service workflows, developer control and security policy are being pulled into one operating layer.
Proofpoint’s reported pursuit of Varonis is the other large strategic marker. On 13 Sep and again on 19 Sep, multiple sources said Proofpoint was in advanced talks to acquire the data security company, with the potential deal described as worth billions. Proofpoint also appointed Brian Levey as chief legal officer and Puja Jaspal as chief people officer on 13 Sep, then expanded Microsoft 365 insider-risk coverage on 16 Sep. Leadership, product and M&A all pointed at the same surface: data movement inside the enterprise.
Tenable strengthened financial flexibility. On 17 Sep and 18 Sep, it raised $800mn in 0.25 percent convertible notes, added capped calls, ended its 2021 credit facility, announced plans for a $170.5mn share repurchase and payoff of a term loan. It also added Continental to its public customer wall on 17 Sep. That is not a sleepy exposure management vendor. It is a company preparing its balance sheet while the market reprices cyber risk around AI and infrastructure.
The real fight showed up in pages, ads and trials
The week’s most telling competitive movement was below the press-release line. CrowdStrike added 21 Falcon Shield product pages on 14 Sep, then on 20 Sep added 9 blog pages and 77 product pages while removing 85 product pages and one documentation page. In the same interval, it changed the site to feature “CrowdStrike is the only vendor named a Customers’ Choice for ITDR” and removed Fal.Con Las Vegas news framing. That is a fast handover from event momentum to proof and packaging.
On 14 Sep, CrowdStrike also added Firewall Management, Endpoint Detection and Response, Threat Intelligence & Hunting, Identity Protection and IT Hygiene to the Falcon Free Trial tier. A trial expansion of that breadth matters because it moves evaluation from a single wedge to a platform sample. It also landed while the company was adding AI security content, partnership material and developer assets, which makes the offer look less like a promotion and more like a funnel redesign.
Paid acquisition was synchronised across the category. CrowdStrike had 40 new Google ad creatives first shown from 26 Aug and running by 17 Sep. Palo Alto Networks had 40 new creatives by 20 Sep, Tenable 34 new creatives first shown 18 Sep, Qualys 24 first shown 18 Sep, SentinelOne 31 first shown 9 Sep, Okta 39 first shown 8 Sep, Proofpoint 28 first shown 2 Sep, Rapid7 14 first shown 17 Sep and Fortinet 20 first shown 11 Sep. The simultaneity is the point. When almost every major vendor refreshes message, pages and ads within the same fortnight, the market is not merely reacting to demand. It is trying to define the buying vocabulary before budget owners do.
Customer proof was edited with the same urgency. Darktrace introduced 30 new customer pages and removed 30 blog pages on 18 Sep, while adding a marine services resilience case study and logos for a US public interest law firm and a UK infrastructure services company. Fortinet added Pinery Water & Wastewater and published an OT security case study on 16 Sep, then refreshed customer logos again on 17 Sep. Rapid7 added two case studies on 14 Sep. These are small moves individually. Read together, they show vendors swapping generic education for vertical proof.
Operational trust remained the constraint
The fortnight also showed why the AI control-plane story cannot run on marketing alone. Palo Alto Networks had six CVEs published on 10 Sep across Prisma Access Agent and PAN-OS, covering information disclosure, privilege escalation, cross-site scripting, command injection and buffer overflow issues. Fortinet had CVE-2026-84390 published on 11 Sep with a CVSS score of 9.8 for FortiMonitorOnSight versions 7.2.0 through 7.2.7. CrowdStrike had CVE-2026-40058 published on 15 Sep with a CVSS score of 8.8 affecting the Falcon sensor for Windows.
Service reliability had its own drag. On 16 Sep, Qualys reported four minor incidents, including a delay in data processing on US Platform 3, intermittent login issues on IN Platform 1 lasting about 978 minutes, and patch deployment failures across shared platforms. On 17 Sep, Tenable reported a major connector normalisation failure for the Vulcan Platform in the EU region. On 20 Sep, Rapid7 reported four service incidents, including dashboard and reporting degradation in Vulnerability Management and a customer portal degradation incident with no impact lasting about 424 minutes.
None of these events changes the direction of travel. They do set the ceiling for trust. The vendors are asking customers to let AI agents, identity systems, code assistants and exposure engines sit closer to operational decision-making. In that context, vulnerabilities and status incidents are not background noise. They are part of the buyer’s assessment of whether a vendor can be the system of control rather than another system to control.
| Company | Change | Date |
|---|---|---|
| CrowdStrike | Firewall Management, Endpoint Detection and Response, Threat Intelligence & Hunting, Identity Protection and IT Hygiene were added to the Falcon Free Trial tier. | 2026-09-14 |
Cybersecurity’s centre of gravity moved towards AI control this fortnight. SentinelOne, Palo Alto Networks, CrowdStrike, Okta, Tenable and Proofpoint all made dated moves around AI agents, AI coding, AI investigation or AI-secured identity and data. The sharper signal was operational: CrowdStrike widened its free trial on 14 Sep, major vendors refreshed ads almost simultaneously, Darktrace and others swapped broad content for customer proof, and Palo Alto and Proofpoint used M&A to extend the platform perimeter. Buyers are being taught a new category map. The constraint is trust, because CVEs and service incidents at CrowdStrike, Fortinet, Palo Alto Networks, Tenable, Qualys and Rapid7 show that the vendors racing to secure the expanded surface must also prove they can operate reliably on it.
Each week this page takes a position and grades it in public once the horizon passes. Misses stay up. The full record.
This is the public read. OpsControl customers see this market live: every signal, graded and evidenced, the day it happens.
Track your own market
OpsControl