top of page

Cisco Security Revenue Jumps 14% as Agentic AI Sharpens Cyberattacks

Cisco’s security revenue rose 14%, turning a Google News headline into a clear signal about the economics of agentic AI. Enterprises are buying more security as autonomous software makes both cyberattacks and defensive operations faster.

The increase matters because Cisco’s security business had struggled earlier in fiscal 2026. Revenue in the category fell 4% during the second quarter and remained flat during the third. A return to double-digit growth suggests that newer products, cloud subscriptions, and Splunk integrations are starting to offset those declines.

It also arrives as AI agents move beyond generating text. These systems can plan tasks, call external tools, and take actions with limited supervision. That autonomy gives defenders faster workflows, but it also lets attackers automate longer portions of an intrusion.

Cisco is betting that the answer lies inside infrastructure rather than in another isolated security console. Its strategy connects networking, identity, observability, and threat response under shared policy and telemetry. Palo Alto Networks, Microsoft, Google, and CrowdStrike are pursuing their own versions of the same security platform contest.

The resulting tension is larger than one quarter’s revenue. Cisco must prove that integrating security with network infrastructure produces better outcomes, not simply a broader product catalog. Customers must decide whether consolidation improves control or creates deeper dependence on one vendor.

Cisco’s Google News Moment Follows a Difficult Security Reset

The 14% gain is meaningful because Cisco’s security category entered the quarter with weak reported momentum.

Cisco reported that security revenue declined 4% during its second fiscal quarter of 2026. The company attributed that decline partly to older products and changes in how customers consumed Splunk.

Customers were shifting from large on-premises transactions toward cloud subscriptions. That transition can reduce recognized revenue in the short term, even when customer demand remains intact.

Security revenue was flat in the following quarter. Cisco said growth in newer and refreshed products offset declines in previous-generation offerings and parts of the Splunk portfolio.

The latest 14% increase therefore represents more than another favorable percentage. It marks a reversal from two consecutive quarters without category growth.

Cisco also entered this period with much stronger companywide demand. Its third-quarter revenue reached $15.8 billion, a 12% increase from the previous year. Product orders rose 35%, while networking orders increased more than 50%.

Reports following the fiscal fourth-quarter release put total revenue at approximately $17.3 billion, up nearly 18% year over year. Those results exceeded the guidance Cisco issued three months earlier.

Security did not create that entire increase. AI infrastructure and networking remained major growth engines. However, security’s rebound makes Cisco’s wider AI narrative more credible.

The comparison with fiscal 2025 requires care. Cisco completed its Splunk acquisition in March 2024, which distorted early year-over-year comparisons. Security revenue doubled during fiscal 2025’s first quarter because the prior period included little Splunk revenue.

By the fourth quarter of fiscal 2025, the comparisons were cleaner. Cisco reported 9% security growth, driven mainly by Splunk and secure access service edge offerings.

The current 14% figure builds on that comparable base. It is therefore more informative than the earlier acquisition-driven jump.

Splunk remains central to the story. Cisco acquired the company to combine machine data, observability, and security analytics with its networking footprint. The deal also gave Cisco a larger subscription software business.

Cisco now needs Splunk to support organic growth. Investors cannot treat acquisition revenue as a permanent substitute for stronger products, successful cross-selling, and customer retention.

The Google News framing captures the immediate event, but the underlying story is operational. Cisco’s security recovery depends on whether customers adopt its newer architecture across networking, identity, and security operations.

That process will take several quarters to assess. One strong result shows renewed demand, but it does not establish a durable growth rate.

Agentic AI Is Compressing the Attack Timeline

Agentic AI changes cybersecurity by allowing software to execute connected attack steps, not merely recommend them.

A conventional chatbot responds to individual prompts. An AI agent can retain a goal, choose tools, evaluate results, and continue working through a multi-step process.

That difference matters during an intrusion. Reconnaissance, vulnerability analysis, credential discovery, lateral movement, and data collection once required repeated human decisions. Agentic systems can connect parts of that sequence.

Anthropic documented an AI-orchestrated espionage campaign in November 2025. The company said attackers manipulated Claude Code to target roughly 30 organizations and compromised a small number.

According to Anthropic’s espionage investigation, the system performed much of the campaign with limited human intervention. The targeted sectors included technology, finance, manufacturing, and government.

Anthropic attributed the operation to a Chinese state-sponsored group with high confidence. That attribution remains the company’s assessment rather than an independently adjudicated finding.

Still, the case illustrates what security vendors mean when they describe machine-speed attacks. The agent did not invent every technique. Its value came from coordinating familiar techniques with greater continuity and scale.

Anthropic later analyzed 832 accounts banned for cyber-related policy violations between March 2025 and March 2026. It found that 560 accounts used AI in connection with malware development.

Only 54 accounts used AI to assist lateral movement, which requires operating deeper inside a compromised environment. However, the more capable actors built systems that connected several attack stages.

Google has observed a similar progression. Its Threat Intelligence Group described a move toward the industrial-scale use of generative models in adversarial workflows.

In May 2026, Google reported finding a threat actor using a zero-day exploit that it believed was developed with AI. A zero-day is a previously unknown vulnerability without an available vendor patch.

Google’s threat tracker also identified attacks against AI integration components. Those targets included wrapper libraries, connectors, configuration files, and autonomous skills.

This distinction is crucial. Attackers do not always need to defeat a frontier model’s internal safeguards. They can compromise the surrounding software that gives an agent access to files, credentials, APIs, and infrastructure.

An insecure agent can magnify an ordinary configuration error. A compromised connector can transform limited application access into a path toward sensitive systems.

Cisco says the interval between vulnerability discovery and exploitation is shrinking from weeks to minutes. That statement is a company characterization, not a universal measurement across all attacks.

However, independent research supports the broader direction. AI assists vulnerability discovery, exploit development, social engineering, and operational coordination. Each capability reduces some of the time or expertise previously required.

The threat is therefore not an all-knowing autonomous hacker. It is a growing collection of tools that help attackers perform established work faster and more consistently.

Defenders face an unfavorable asymmetry. An attacker can test many targets, while a security team must protect every material asset and identity.

That pressure helps explain why security spending can rise before most enterprises deploy agents widely. Organizations must secure experimentation, connectors, data access, and machine identities before production adoption accelerates.

Cisco Wants the Network to Become the Security Control Plane

Cisco’s primary wager is that agentic threats require security embedded across infrastructure, not another disconnected layer of alerts.

Cisco controls a large installed base of switches, routers, wireless systems, and collaboration products. Splunk adds logs, analytics, observability, and security operations data.

The company wants those assets to operate as one detection and enforcement system. Network telemetry identifies behavior, identity controls determine access, and security tools respond using shared context.

Cisco Cloud Control is the clearest expression of that strategy. Announced in June 2026, it brings networking, security, compute, observability, and collaboration into one management environment.

The platform is designed for human operators and trusted AI agents. Cisco says both can work from the same data layer and system of action.

Its controlled availability began in the United States in June. Global availability is planned, although Cisco has not publicly established a complete adoption timeline.

Cloud Control includes an Agent Builder for creating agents around organizational policies and workflows. Cisco says it can connect with more than 50 third-party platforms through native integrations or the Model Context Protocol.

Model Context Protocol, commonly called MCP, is a standard for connecting AI applications with tools and data sources. Those connections create utility, but they also introduce policy and supply-chain risks.

Cisco’s answer includes an MCP gateway within Secure Access. The gateway is intended to inspect tool traffic and apply access policies to agent actions.

The company is also extending Duo identity management to nonhuman workers. Customers can register agents, assign accountable human owners, and grant task-specific permissions.

That approach addresses a basic governance problem. Traditional identity systems assume a person signs in and performs a recognizable job. An agent can execute continuously, call many systems, and generate activity at software speed.

Cisco also expanded AI Defense, which tests models and applications against manipulation. The company says the service can apply runtime guardrails after deployment.

Splunk provides the analytical side of the architecture. Its security products collect events, correlate signals, and help analysts investigate incidents. Cisco is adding agents that can automate portions of detection and response.

At the infrastructure layer, Live Protect applies runtime protections to supported Cisco systems without requiring immediate reboots or upgrades. Cisco first made the capability available for parts of its Nexus switching portfolio.

The company plans to extend it into campus switches and secure routers. If Cisco delivers that expansion, customers could apply temporary protection closer to exposed infrastructure.

Hypershield follows a related principle. It distributes enforcement across network environments instead of sending every decision through a centralized appliance.

Cisco reported in fiscal 2025 that most new enterprise Hypershield customers bundled the product with its N9300 smart switch. That bundle illustrates Cisco’s network-security thesis in commercial form.

The advantage is visibility. Cisco infrastructure can observe traffic and enforce policy at points where applications, users, and agents interact.

The tradeoff is concentration. A customer that relies on one vendor for networking, identity, analytics, and response gains integration but accepts a larger operational dependency.

Cisco must also make integrations work across heterogeneous environments. Most large enterprises use several clouds, endpoint products, identity providers, and security platforms.

A unified console has limited value if its best enforcement features require a mostly Cisco estate. Open integrations must support meaningful actions, not merely import alerts.

The 14% security revenue gain indicates that customers are buying into parts of this model. It does not reveal how many have adopted the complete architecture.

The Security Platform Contest Is Getting More Crowded

Cisco’s rebound pressures rivals, but every major security vendor is combining AI, telemetry, and automated response.

Palo Alto Networks has spent years promoting platform consolidation across network, cloud, and security operations products. Its strategy encourages customers to reduce overlapping tools and manage more controls through shared services.

That approach competes directly with Cisco’s broader portfolio claim. Palo Alto begins from a security-centered position, while Cisco begins with network infrastructure and adds security around it.

Palo Alto Networks reported 15% quarterly revenue growth in its fiscal fourth quarter of 2025. It also forecast approximately 14% annual growth for fiscal 2026.

Those figures are not directly comparable with Cisco’s product-category growth. The companies use different fiscal periods and reporting structures. They do show that Cisco is pursuing a market with established, fast-growing competitors.

Microsoft represents another route. It combines identity, endpoint security, cloud controls, productivity software, and Security Copilot within a large enterprise software footprint.

Microsoft can place defensive agents inside workflows that customers already use. Its identity and endpoint reach gives it context extending beyond network traffic.

Google has strengthened its position through Mandiant, Google Threat Intelligence, and the Wiz acquisition. Its strategy connects cloud posture, incident response, threat research, and AI-assisted defense.

CrowdStrike approaches the contest from endpoint telemetry and threat intelligence. Its Charlotte AI products automate investigation and response while preserving the Falcon platform as the central operating layer.

Each competitor uses a similar high-level message. Security teams have too many tools, too many alerts, and too little time. AI can correlate evidence and automate repetitive decisions.

The differences emerge in data coverage and enforcement. A useful security agent needs trustworthy telemetry, access to defensive tools, and permission to act.

Cisco sees network infrastructure as its differentiator. Microsoft emphasizes identity and enterprise applications. CrowdStrike starts with endpoint behavior, while Palo Alto spans network, cloud, and operations.

No vendor sees the entire environment. Customers will still need integration across multiple products and administrative domains.

This fragmented reality creates both an opportunity and a problem for Cisco. Its broad portfolio can reduce handoffs, but breadth alone does not guarantee precise detection or safe automation.

AI agents can make weak integrations more dangerous. An automated response built on incomplete context might disable a legitimate account, block production traffic, or destroy evidence.

Human oversight therefore remains important. Cisco describes its systems as keeping people in control, but the practical meaning depends on approval settings, audit records, and rollback mechanisms.

Enterprises should examine how an agent explains its recommendation. They should also ask which actions require approval and how the system handles conflicting signals.

Another competitive issue concerns security research. Google, Microsoft, Anthropic, and specialized vendors operate large threat intelligence teams with visibility into different attacker populations.

Cisco brings Talos and Splunk telemetry to that contest. It says more than 10 exabytes of packet data pass through its assets, applications, and switches.

That figure describes potential visibility rather than automatically usable security intelligence. Data quality, customer permissions, regional rules, and detection engineering determine how much value the platform can extract.

Cisco’s security growth shows that its installed base remains commercially valuable. The harder test is whether customers view Cisco as their primary security platform rather than a networking supplier with adjacent products.

What the 14% Figure Does Not Prove

One quarter of growth cannot confirm that Cisco has solved Splunk integration, product overlap, or agentic security risk.

The first uncertainty concerns revenue composition. Cisco reports security as a product category, but that category contains several distinct businesses.

It includes network security, identity and access management, secure access service edge, and threat detection and response. A 14% aggregate increase does not show which products created most of the growth.

Cloud subscription timing can also move reported results. Splunk’s shift away from some on-premises transactions affected earlier quarters. A later improvement could reflect easier comparisons or different contract timing.

Bookings, recurring revenue, renewal rates, and remaining performance obligations would provide more context. Cisco has not disclosed every security-specific metric needed to separate adoption from accounting effects.

The second uncertainty is product maturity. Cisco announced many agentic security capabilities during 2026, but announcements do not equal broad production deployment.

A Cisco survey found that 85% of major enterprise customers were experimenting with AI agents. Only 5% had moved agentic technology into production.

That gap supports Cisco’s opportunity, but it also limits current evidence. Customers may buy security tools while delaying the deployments those tools are designed to protect.

The third uncertainty concerns automation quality. Agentic defense sounds attractive because attackers operate faster. Yet speed can amplify errors on either side.

A defensive agent needs constrained permissions, reliable inputs, and clear escalation rules. It must resist prompt injection, manipulated telemetry, and malicious instructions hidden in external data.

It must also recognize uncertainty. A system that acts confidently on a false correlation can create an outage faster than a human analyst would.

Cisco says its architecture keeps humans in control. Buyers should test that claim through specific workflows rather than presentation diagrams.

They should examine identity mapping, temporary permissions, action logs, simulation, and recovery procedures. Those controls determine whether an autonomous workflow remains governable during an incident.

The fourth uncertainty involves Cisco’s own attack surface. Infrastructure vendors become valuable targets because their products sit at trusted control points.

Google recently documented active exploitation of a zero-day vulnerability affecting Cisco Catalyst SD-WAN Manager. The incident illustrates why runtime protection and rapid patching matter.

It also shows the tension inside Cisco’s strategy. Embedding security into infrastructure can improve enforcement, but vulnerabilities in that infrastructure can have wide consequences.

The fifth uncertainty is platform lock-in. Consolidation reduces the number of consoles and contracts, yet it can complicate migration and independent validation.

Organizations should preserve access to raw telemetry and interoperable formats. They should also test whether third-party systems receive enough context to perform independent detection.

Cisco’s 14% growth supports the argument that security demand is returning. It does not prove that one vendor should control every defensive layer.

A more defensible conclusion is narrower. Customers increasingly see value in combining network, identity, observability, and response data as AI changes attack speed.

Cisco has an unusually large set of assets for delivering that combination. Execution will determine whether those assets become an advantage or an unwieldy portfolio.

Three Signals Will Test Cisco’s Agentic AI Security Strategy

The next several months should reveal whether Cisco’s security rebound reflects durable adoption or a favorable quarter.

The first signal is security growth across consecutive quarters. Another double-digit increase would strengthen the case that newer products and Splunk cloud subscriptions have created sustained momentum.

A return to flat or negative growth would weaken that interpretation. It would suggest that contract timing, comparisons, or isolated transactions contributed heavily to the latest result.

Investors should look beyond the headline percentage. Growth in security orders, recurring revenue, and long-term obligations would provide stronger evidence of durable demand.

The second signal is production adoption for Cisco’s agentic products. Cloud Control, agent identity features, AI Defense, Hypershield, and Splunk agents need measurable customer use.

Cisco has previously disclosed combined customer additions for newer security products. Similar reporting would help readers distinguish availability from operational adoption.

The most useful evidence would include repeat usage, expanding deployments, and cross-product adoption. A customer testing one feature is less meaningful than one enforcing policy across agents and infrastructure.

The third signal is independent technical validation. Security researchers and customers need to test whether Cisco’s agents resist manipulation and take safe, explainable actions.

Google’s AI defense guidance emphasizes hardening software while preparing for faster exploitation. Anthropic likewise recommends using AI for defense while strengthening safeguards against misuse.

Cisco’s thesis fits that direction. Its systems aim to reduce the interval between detection and protection by combining telemetry with automated action.

However, independent evaluations should measure false positives, response accuracy, privilege controls, and recovery. They should also test heterogeneous environments that include non-Cisco systems.

These signals matter to more than security teams. Developers must understand which tools an agent can access and how credentials are scoped. Product leaders must account for security before automating business workflows.

Enterprise buyers should treat every agent as a machine identity with potential access to valuable systems. That means assigning ownership, limiting permissions, logging actions, and rehearsing failure scenarios.

Knowledge workers also have a role. An agent connected to documents, email, calendars, or internal search can expose sensitive context if its permissions are too broad.

The latest Google News cycle gives Cisco a favorable financial headline. The deeper question is whether its architecture can turn networking visibility into safer agent operations without creating excessive dependence.

Watch the next security growth rate, disclosed production adoption, and independent testing results. Together, those signals will show whether the 14% gain marks a lasting shift.

Security leaders should not wait for autonomous attacks to become routine. They can inventory current agents, map every tool connection, and require accountable human owners now.

The practical question is simple: can your organization identify every agent, explain what it can access, and stop its actions quickly? If not, Cisco’s revenue gain is not merely market news. It is evidence that other enterprises are already spending to close the same control gap.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page