OpsControl.
Market Pulse · Cybersecurity

Cybersecurity sells the agentic control plane

AI agents became the organising principle across homepages, launches, acquisitions and channel plays.
Week of 28 September 2026 · built from 80 observed events over 14 days · 11 companies watched · 366 signals in 30 days · 30+ sources each

The homepage war moved to AI governance

Cybersecurity did not have a quiet fortnight. It had a synchronised rewrite. On 28 Sep, Proofpoint changed its hero from 'Proofpoint Protect 2026' to 'Protect People, Defend Data, and Govern AI', and shifted the supporting copy from an event invitation to understanding behaviour and intent across people and AI agents.

Darktrace made the same turn earlier. On 24 Sep, its hero became 'BEHAVIORAL SECURITY IN THE AGE OF AI', with new navigation around Platform, Adaptive AI and security topics. On 25 Sep, press coverage said Darktrace had made SECURE AI generally available for monitoring enterprise AI use and had launched Darktrace Signal Labs to research risks from enterprise AI agents.

Palo Alto Networks pushed hardest into the frame. On 27 Sep, its site introduced 'Unit 42 Continuous Frontier AI Defense' after removing a section about the Portkey acquisition, while its CEO said slowing AI development is unrealistic and that AI is making attacks faster and more scalable. Okta also completed its event-to-positioning arc: on 21 Sep the homepage moved from 'Okta secures AI' to Oktane live-stream promotion, then on 27 Sep to 'Welcome to the secure agentic future.'

Product surface expanded around cloud, identity and managed detection

The AI language was matched by product packaging across the attack surface. On 27 Sep, SentinelOne added a product page extending Wayfinder threat hunting to continuous coverage for AWS, Azure and Google Cloud. On 26 Sep, press coverage said SentinelOne had extended Wayfinder coverage across endpoints, identities and cloud workloads.

CrowdStrike continued to widen Falcon's adjacency map. On 20 Sep it added 77 product pages and 9 blog pages, including AI security and partnership content, while removing 85 product pages and one documentation page. On 27 Sep it added 15 more product pages focused on browser security and identity security, plus 13 blog entries, while removing 28 product pages. Its GitHub activity also tracked the same operational surface, with terraform-provider-crowdstrike v1.0.0 on 27 Sep adding management for network containment allowlist rules.

Others moved the middle of the market. Rapid7 added 41 product pages on 26 Sep, including AI vulnerability management and cloud-managed detection and response, while removing 44 product pages. Qualys added 11 product pages on 22 Sep around Cybersecurity Asset Management and Endpoint Detection and Response. Arctic Wolf, on 28 Sep, targeted MSP growth with a streamlined MDR offering designed to simplify integration and delivery for managed service providers.

The buy-versus-build cycle is accelerating

The fortnight's deal flow shows the same priority list as the messaging: AI protection, agent security, data protection and cloud exposure. On 27 Sep, Palo Alto Networks was reported to have acquired Console for $500 million to enhance its security agents. The same day, coverage said Palo Alto Networks had delivered Anthropic's Mythos and OpenAI's GPT-5.6 to customers through Unit 42 Continuous Frontier AI Defense.

SentinelOne's acquisition trail was also visible. On 21 Sep, an SEC filing reported the completion of its Observo AI acquisition for $185.3 million. On 27 Sep, Dealroom reporting listed PingSafe at $83.0 million, Observo AI at $185.3 million and Prompt Security at $159.3 million, with the latter two closed in September 2025.

Tenable kept adding AI security and cloud security assets at smaller ticket sizes. On 24 Sep, Dealroom reported that Tenable acquired Apex Security for $47.8 million and that its Eureka acquisition involved $29.2 million in cash consideration. Fortinet's acquisition record also surfaced on 28 Sep, with Next DLP at $105 million, Linksys at $42.3 million, and the announced acquisition of Virtue AI to enhance AI protection capabilities.

The tape showed the repositioning before the narrative settled

The useful signal this week was the sequencing. Palo Alto Networks removed 'Fight AI with AI' on 21 Sep and added 'Palo Alto Networks Recognized as a Market Shaper.' Six days later, on 27 Sep, it had replaced the Portkey acquisition message with Unit 42 Continuous Frontier AI Defense. That is not a campaign refresh in isolation. It is a fast move from acquisition news to operating doctrine.

Okta's site told a similar story in two steps. The homepage became an Oktane broadcast page on 21 Sep, then changed to the 'secure agentic future' on 27 Sep, after press coverage on 26 Sep of an AI agent runtime gateway and the Blueprint Alliance with AWS and CrowdStrike. Proofpoint's path was also staged: 15 AI security and corporate blog pages plus 12 product pages arrived on 25 Sep, followed by the 28 Sep homepage rewrite around people, data and AI governance.

The paid channel was equally loud. Palo Alto Networks had 40 new Google ad creatives first shown from 21 Sep and 40 running in total on 27 Sep. CrowdStrike had 29 new creatives first shown from 17 Sep and 40 running in total on 24 Sep. Qualys had 26 new creatives first shown from 24 Sep and 40 running in total on 26 Sep. Tenable, Okta, Arctic Wolf, Fortinet, Rapid7, SentinelOne and Proofpoint also showed 40 running creatives in their respective observations. When the homepage, product pages, ads and developer repositories all move in the same fortnight, the category is not testing language. It is repackaging the buying agenda.

Operational reliability stayed in the frame

The defenders were also reminded that they are software vendors. Fortinet had CVE-2026-84388 published on 22 Sep, with a CVSS score of 9.6, affecting FortiPAM Chrome Extension versions 8.0 and 7.4. On 22 Sep, press coverage also reported hackers selling a Fortinet FortiGate-related vulnerability on underground forums. Fortinet continued to invest and expand in parallel, including a $30 million Calgary cybersecurity innovation hub reported on 22 Sep and a New York innovation hub reported on 28 Sep.

Rapid7 reported four service incidents on 20 Sep, including dashboard and reporting degradation in Vulnerability Management and a Customer Portal degradation. On 27 Sep, two CVEs mentioning Rapid7 were published: CVE-2026-89325, a high severity InsightVM arbitrary code execution issue, and CVE-2026-97228, a low severity GraphQL query injection issue in Bulk Export MCP versions 0.2.5 through 0.6.1.

Tenable reported three incidents on 23 Sep: a minor Asset Tagging issue in Tenable Vulnerability Management, a critical orchestration failure in the USGov01 environment of Tenable Cloud Security, and a major Azure ingestion issue. CrowdStrike had CVE-2026-40058 published on 15 Sep, with a CVSS score of 8.8, affecting Falcon sensor for Windows, and on 27 Sep press coverage reported that the U.S. Justice Department concluded its investigation into CrowdStrike's business dealings with no charges filed.

The takeaway

This fortnight's signal is simple: AI agent security has become the organising wrapper for cybersecurity. Proofpoint, Darktrace, Palo Alto Networks and Okta rewrote top-level messaging around AI governance, agentic futures and AI defence between 24 Sep and 28 Sep. SentinelOne, CrowdStrike, Rapid7 and Qualys expanded product surfaces around cloud, identity, browser security and vulnerability management. Acquisitions at Palo Alto Networks, SentinelOne, Tenable and Fortinet show vendors buying capability to match the story. The winners will not be the firms with the loudest AI slogan. They will be the ones that turn agentic security into a coherent control plane while maintaining the reliability standards their own customers expect.

Calls on the record

Each week this page takes a position and grades it in public once the horizon passes. Misses stay up. The full record.

open called 28 September 2026 · judged by 12 November 2026
SentinelOne will announce an expansion of its cloud security offerings in the next 45 days.
SentinelOne has been extending its Wayfinder threat hunting to cover major cloud platforms like AWS, Azure, and Google Cloud, indicating a strategic focus on broadening its cloud security solutions.
open called 28 September 2026 · judged by 27 November 2026
Palo Alto Networks will launch a new AI-focused security product or feature within the next 60 days.
Palo Alto Networks has been actively repositioning its messaging and product offerings around AI, as evidenced by the introduction of 'Unit 42 Continuous Frontier AI Defense' and its recent acquisitions aimed at enhancing AI security capabilities.
open called 21 September 2026 · judged by 5 November 2026
CrowdStrike will expand its Falcon Free Trial tier to include additional AI security features within the next 45 days.
CrowdStrike's recent trial expansion and addition of AI security content suggest a strategic move to broaden its trial offerings to attract more users and showcase its AI capabilities.
open called 21 September 2026 · judged by 20 November 2026
Proofpoint will announce the acquisition of Varonis within the next 60 days.
Multiple sources have reported that Proofpoint is in advanced talks to acquire Varonis, and the strategic alignment in leadership and product expansion supports this move.
open called 14 September 2026 · judged by 29 October 2026
Proofpoint will announce a strategic partnership or acquisition related to data security within 45 days.
Proofpoint's reported talks with Varonis and its recent focus on expanding AI-powered investigations and SOC capabilities suggest an active interest in consolidating its position in data security, likely leading to a strategic move to enhance its offerings.
open called 14 September 2026 · judged by 13 November 2026
CrowdStrike's price cut on Falcon Go and Falcon Pro will lead to a reported increase in SMB customer acquisition within 60 days.
The significant reduction in pricing for Falcon Go and Falcon Pro, combined with added features like IT Hygiene, positions CrowdStrike to attract smaller businesses that previously found the products too expensive, making it a strategic move to capture a broader market segment.

This is the public read. OpsControl customers see this market live: every signal, graded and evidenced, the day it happens.

Track your own market