flowing water in wave

August 12, 2026

When Geopolitics Reshapes Cybersecurity

Mark McLaughlin, Former CEO and Chairman of Palo Alto Networks

One thing I’ve learned over the course of my career is that cybersecurity rarely changes in isolation. It’s tempting to think the industry evolves because new technologies emerge, and for the most part, technology has been the dominant force shaping that evolution. Mobility changed where people worked. Cloud changed how organizations built and consumed infrastructure. Artificial intelligence will almost certainly reshape cybersecurity again. But those technologies mattered because they changed how organizations operated. Cybersecurity has always evolved in response to broader changes in the world.

That’s why I’ve always thought of cybersecurity as part of the fabric of a digital society rather than a discipline that sits apart from it. As technology evolves, businesses change. As businesses change, economic models evolve. Those shifts reshape the environment organizations operate in, and security architecture evolves alongside them. Looking back over the last three decades, I’ve watched that happen several times.

For much of that time, we centralized security because that’s what the economics rewarded. Organizations could achieve levels of efficiency and scale that simply weren’t possible before. Cloud didn’t become the dominant model because it was technically inevitable. It became the dominant model because it solved the problems organizations were trying to solve. Looking back, it’s easy to assume that architecture was permanent. I don’t think it was. I think it reflected the assumptions of a particular moment.

A Different Optimization Problem

We’ve lived through transformational technology shifts before, and AI will almost certainly prove to be another one. What makes this moment different isn’t AI itself. It’s the environment AI is arriving in. Cloud emerged during a period when globalization and economic efficiency were the dominant forces shaping technology decisions. AI is arriving in a very different geopolitical landscape.

There are certain things countries aren’t willing to outsource anymore. I don’t view that as a political statement. I view it as an architectural one. Governments are starting to look at certain capabilities and say, “It’s in our national interest to have more control over this.” That’s not a rejection of cloud or globalization. It’s a recognition that they’re solving a different problem. And when you’re solving a different problem, you end up building a different architecture.

Comparison of Public Cloud Model and Sovereign Model highlighting differences in optimization, scaling, centralization, and control.

What Sovereignty Is Really Asking

If architecture is changing, the next question is obvious: what is it optimizing for? For much of the last three decades, the answer was efficiency and scale. Today, I think control is becoming another design principle.

René Bonvanie and I spent some time discussing sovereignty, and I think we often make the topic more complicated than it needs to be. Most conversations begin with regulation or where data physically resides. Those are important discussions, but I don’t think they’re the place to start.

The better question is much simpler:

What actual level of control do you have over your data, your infrastructure, and the systems you depend on?

To me, that’s what sovereignty is really trying to answer.

Every organization will answer that question differently. A global software company isn’t solving the same problem as an intelligence agency. They will not arrive at the same architecture because they are not optimizing for the same outcomes.

AI only reinforces that distinction. As AI capabilities improve, data becomes more strategic. Organizations will differentiate themselves by the quality of the data they possess, how well they govern it, and the confidence they have in how it’s used. As data becomes more valuable, questions of governance naturally become questions of control.

That’s why I believe governments and other highly-regulated institutions will seek greater control over the data and digital infrastructure they depend on. Not because the cloud has failed or globalization is over, but because the assumptions that shaped the last generation of architecture no longer hold universally.

Architecture Reflects the World It’s Built For

People sometimes ask whether this means we’re entering an entirely new era of cybersecurity. I don’t think that’s quite right. Cybersecurity is still doing what it has always done: adapting to the world around it.

For decades, security architecture reflected a world optimized for globalization, efficiency, and connectivity. Those priorities haven’t disappeared, but they’re now being balanced against resilience, strategic independence, and control. Organizations operating in different environments will make different architectural decisions because they’re solving different problems.

I don’t see that as a rejection of the architectures that came before. They were the right answer for the world they were built in.

The world has changed, and cybersecurity architecture is changing with it.

— Mark