Summary
- NTT Data and Palo Alto Networks are targeting $1bn in joint business by 2029.
- More than 2,000 Palo Alto-certified specialists will support the combined engineering and managed-services model.
- AI security is spreading across identity, cloud architecture, governance, and security operations rather than remaining a standalone product category.
NTT Data and Palo Alto Networks have expanded their cybersecurity partnership into a multi-year global alliance targeting $1bn in joint business by 2029, as enterprise AI creates a larger services market around governance, identity, cloud security, and automated defence.
The agreement combines Palo Alto Networks’ security platforms and Unit 42 threat intelligence with NTT Data’s consulting, engineering, and managed-services operations. More than 2,000 Palo Alto-certified professionals are expected to support the alliance, alongside dedicated engineers and direct collaboration between the companies’ technical teams.
Initial offerings span autonomous security operations, AI governance, identity security, zero-trust architectures, cloud resilience, and firewall modernisation. That breadth reflects how quickly an AI implementation can extend beyond the model itself into corporate identity systems, data stores, APIs, applications, cloud infrastructure, monitoring tools, and incident response.
Security spending is consequently becoming part of the implementation cost of enterprise AI rather than an adjacent procurement. Organisations may start with model access or an internal assistant, but production deployments eventually reach systems where permissions, data movement, software dependencies, and automated actions have to be controlled.
AI security becomes a services business
NTT Data says the alliance will give it early access to new Palo Alto Networks platform capabilities, while joint engineering teams will adapt products and services for customers. It expands existing work between the companies around managed detection and response, private 5G, and security operations.
Abhijit Dubey, chief executive and chief AI officer at NTT Data, said: “AI is redefining every aspect of the enterprise, but it is also transforming the threat landscape at unprecedented speed.” NTT Data says it has more than 7,500 cybersecurity professionals, over 70 delivery centres, and more than 20 cyber defence centres.
The services component is important because AI security is difficult to contain inside a single product category. An organisation deploying autonomous agents may need to reconsider identity permissions, application secrets, data access, logging, human approval, and the actions software is permitted to take, while security teams face attackers using AI to speed up reconnaissance and tooling.
Adding another security product does not necessarily resolve that architectural problem. Many organisations already operate fragmented estates accumulated through cloud migration, acquisitions, remote working, and regulatory requirements, and AI can add another control layer unless deployment is integrated with existing identity and monitoring systems.
Governance and defence converge
NTT Data’s earlier research found a substantial gap between interest in private or sovereign AI and near-term implementation. More than 95% of respondents regarded private and sovereign AI as important, according to the company, while only 29% were prioritising sovereign AI concretely in the near term.
Those findings help explain the scope of the expanded alliance. Governance is becoming a design requirement for AI infrastructure rather than paperwork applied after deployment, particularly in regulated or operationally sensitive sectors such as financial services, healthcare, manufacturing, and the public sector.
European policy is heading in the same direction. The Commission’s recent AI cybersecurity action plan treats advanced models as both defensive tools and sources of new offensive capacity, connecting AI governance with infrastructure protection and resilience.
Large platform alliances are one commercial response to that convergence. Security vendors gain access to implementation capacity and long-standing customer relationships, while systems integrators gain platforms around which they can build consulting, migration, monitoring, and recurring managed-service revenue.
The trade-off is greater concentration. Standardising on fewer security platforms can reduce operational complexity, but it also increases dependency on those suppliers and the services companies wrapping them into enterprise architecture.
Claims about simplification therefore need to be measured against migration cost, interoperability, data portability, and whether customers can replace individual components without redesigning an entire security operation. Consolidation solves some forms of complexity by moving them inside the vendor relationship.
NTT Data and Palo Alto Networks are putting a $1bn target against the proposition that AI deployment and cyber modernisation will increasingly be purchased as one programme. If that spending arrives, AI security will look less like a specialist add-on than another large systems-integration market.












