Palo Alto Networks research: Palo Alto Networks (Company Profile) · Palo Alto Networks (Deep Dive).
- Palo Alto Networks (Palo Alto) is a rare quality compounder in cybersecurity, combining multiple growth engines with strong product breadth and best-in-class execution. Management has consistently demonstrated the ability to identify, invest behind and scale up through major technology inflection points. We view AI as the next inflection. While current discourse is dominated by elevated market concerns about large language models (LLMs), we view this as transitory.
- Unparalleled execution: Palo Alto has a strong track record of sustained compounding, with revenues on track to reach ~$13.7bn in FY27E – the first full year following the CyberArk and Chronosphere acquisitions – up from $13m in FY09 (a ~1,000x increase). It is not just Palo Alto’s scale that has structurally improved, but also its revenue quality. Subscription and support revenues now account for ~80% of revenues (versus ~32% in FY12), reflecting a transition away from appliance-led firewalls towards a higher-quality, recurring revenue mix, decoupling away from hardware refresh cycles and moving towards a higher–growth cloud and security operations portfolio.
- Multiple growth engines: Near-term revenue momentum is broad-based, particularly in Secure Access Service Edge (SASE) (40% yoy growth in Q226), software firewalls (25% yoy), security operations (~25% yoy), and there has also been an acceleration in hardware demand (~10% yoy). Palo Alto’s portfolio is well aligned to major technology inflections within cybersecurity, including automation of security operations, identity security, cloud-delivered observability and runtime security for AI infrastructure (including agentic browsers), with quantum security representing a longer-term optionality. Next-generation security (NGS) ARR has increased from $651m in FY20 to ~$7.5bn in Q226 (pro-forma); we think there is a clear runway for growth, with NGS ARR reaching $18.8bn by FY30E (4% ahead of consensus at $18.2bn), implying a ~23% organic CAGR (Q226-FY30E) – management’s target is $20bn.
- Consensus is under-appreciating the strength of Palo Alto’s platform: With its “platformisation strategy”, Palo Alto is replacing multiple point solutions with integrated products. Progress so far has been encouraging, with 1,550 platformisations carried out by the end of Q226, up from 850 in Q224, and with management targeting 2,500-3,500 platformisations by FY30E. In this note, we deep-dive into Palo Alto’s platformisation strategy drivers. Our analysis shows that consensus underestimates the strength of Palo Alto’s platform; we envisage 6-14% upside to consensus if management’s targets are met, with platformisations contributing to ~55% incremental revenue growth by FY30E. We believe management’s 2,500-3,500 platformisations target is clearly not a ceiling and that AI should further accelerate vendor consolidation. Our estimates leave scope for further upgrades if the pace of platformisations accelerates.
- Valuation: We believe current multiples do not reflect the improving portfolio quality, the success of the platformisation strategy, and Palo Alto’s best-in-class “Rule-of-40” within the software peer group.
Investment thesis
- Palo Alto has evolved its business from an appliance-based firewall vendor into a multi-product platform spanning SASE, cloud security, security operations and software firewalls, decoupling its revenue base from hardware refresh cycles towards higher-quality recurring revenues.
- Vendor consolidation and AI-driven complexity favour integrated platforms, Palo Alto is well positioned to gain market share in a highly fragmented cybersecurity market with its platformisation strategy. The recent acquisitions of CyberArk (identity security) and Chronosphere (observability platform) are other catalysts driving the acceleration of platformisation.
- So far in 2026, the cybersecurity sector has underperformed the broader technology sector, driven by market concerns about AI-led disruption. We believe this de-rating is particularly overdone and view AI as an opportunity rather than a risk; platform vendors are likely to benefit disproportionately.
Business description
Palo Alto Networks is a global cybersecurity company providing integrated security platforms across network, cloud, security operations, identity security and observability platform.
Key risks to our investment thesis
- Palo Alto’s strategy increasingly relies on acquisitions to expand platform capabilities, which introduces execution risk related to integration, product rationalisation and go-to-market alignment.
- While we view AI as a net positive in the longer term, there is a risk that certain use cases are commoditised faster than expected, which would affect growth in specific segments.
- Premium multiples embed near-flawless execution. Any deceleration in next-generation security (NGS) ARR or platformisation could trigger earnings downgrades and/or a de-rating.
Company overview
Quality compounder: Palo Alto has shown strong revenue growth driven by both organic growth and M&A
Palo Alto has transitioned from a hardware-centric firewall vendor towards a subscription-driven platform (revenue mix by type)
Despite being the number one player, there are significant consolidation opportunities in the fragmented cybersecurity segment…
While Palo Alto has shown unparalleled execution under the current management
Nikesh Arora joined Palo Alto Networks as CEO in June 2018
…with multiple growth opportunities in a large addressable market
NGS ARR is a key metric that reflects Palo Alto’s progress in new growth engines, with management targeting $20bn by FY30E
Valuation and growth overview
While the cybersecurity sub-sector was largely resilient until November 2025, the sector has experienced a de-rating since then…
…with Palo Alto experiencing a 30% de-rating versus 2024/25 multiples despite improving revenue quality and greater scale
Palo Alto has one of the highest scores in the Rule-of-40 metric of all the major global software companies
While aggregate cybersecurity sector revenues is expected to grow at a 13% CAGR with platform players growing 1.7x faster….
Platform players are growing 1.7x faster versus non-platform players
Rule of 40 combines revenue growth with FCF margin. CrowdStrike, Palo Alto and Zscaler are defined as platform players; organic revenue growth is used for Palo Alto.
There is strong platformisation momentum, with the number of platformisations increasing from 850 in Q224 to 1,550 in Q225
Platformisation will be the biggest revenue driver for Palo Alto; our calculations show 6-14% upside to FY30E consensus revenues
Our calculations show 6% upside to consensus if Palo Alto gets to 3.0k platformisations by FY30E (midrange of target) and 14% upside at the upper end of the target (3.5k)
Why do we like Palo Alto?
Quality compounder with best-in-class execution
Palo Alto is a rare quality compounder in the enterprise software space, with revenue increasing from $13m in FY09 to $13.7bn by FY27E (the first full year post-closing of the CyberArk/Chronosphere acquisitions) – a 1,000x increase in less than two decades. Revenue quality has increased over time, with a rising share of recurring revenue in the mix: the share of subscription and support revenues increased from 32% in FY12 to 80% in FY25.
Palo Alto’s real differentiation versus the competition lies in its ability to anticipate technology inflection points and enter new security domains early and building leadership positions. Management has done this consistently, with several product categories including cloud security (Prisma Cloud, 2018), SASE (Prisma SASE, 2019), security operations (Cortex XDR, 2019, Cortex XSIAM, 2022)1 and enterprise browser (2023). More recently, the group has expanded into run-time AI protection (2025), identity security via the CyberArk acquisition (2026) and observability via the Chronosphere acquisition (2026), and the company is now making early strides into quantum security (2026). We believe this forward-looking execution is underappreciated in consensus estimates, which remain anchored around existing product lines.
Vendor consolidation is a multi-year structural theme
As organisations rationalise security tools to reduce IT complexity and improve efficiency, vendor consolidation is emerging as a durable structural theme in cybersecurity. Beyond cost benefits, AI is acting as an accelerator, enabling a stronger security posture through integrated platforms.
Platform vendors are already seeing the benefit of vendor consolidation, growing ~1.7x faster than non-platform peers – we expect them to grow at a 2025-28E organic revenue CAGR of 17% versus 10% growth for non-platform peers. With a full-stack security fabric spanning network, cloud, security operations, identity and observability, we believe Palo Alto is well positioned to consolidate market share in a highly fragmented market.
Enterprise software offers a clear precedent: leaders such as Salesforce, ServiceNow and Adobe command a 30-60% market share in their respective categories. By contrast, we estimate Palo Alto’s share of the cybersecurity market at just ~5.9%. While cybersecurity is structurally more complex and a 30-60% market share for the number one player is unlikely, a mid-single-digit share appears too low in our view. We view platformisation as a multi-year revenue growth story for Palo Alto, and the central pillar of our investment thesis.
Multiple growth engines with a long runway of growth
Palo Alto has evolved from an appliance-based firewall vendor into a multi-product platform spanning SASE, cloud security, security operations and software firewalls, structurally decoupling its revenue base from hardware refresh cycles. This aligns the business model with key secular shifts, including cloud migration, SaaS2 adoption, remote working, SIEM3 displacement and SOC4 consolidation.
NGS ARR5 is the cleanest proxy to measure platformisation progress. NGS ARR has scaled from $0.7bn in FY20 to $6.3bn in Q226. Management targets ~$20bn of NGS ARR by FY30E versus consensus at ~$18.2bn (estimate: ~$18.8bn), implying scope for upgrades as platform adoption continues.
Key growth pillars include: 1) SASE ($1.5bn ARR, up by 40% yoy in Q226); 2) security operations ($1.7bn ARR in FY25, with Cortex XSIAM greater than $500m ARR in Q226); and 3) software firewalls (25% yoy ARR growth in Q226). With ~600 Cortex XSIAM customers, ~7,000 Prisma SASE customers and ~12,500 software firewall customers across a ~70,000 installed base, penetration remains low – underpinning a significant cross-sell and upsell opportunity.
Why does Palo Alto look interesting right now?
AI rotation overshot; cyber fundamentals intact
Since July 2025, the software sector has underperformed the broader technology sector, driven by concerns about AI-led disruption. While cybersecurity was initially viewed as relatively resilient, since November 2025 the sector has also been caught in the broader “AI eats software” narrative. The sector now trades near trough levels (~4.9x 12-month forward EV/sales).
We believe this de-rating is particularly overdone for cybersecurity names and view AI as an opportunity rather than a risk. AI expands the attack surface (data, cloud, identities), increases threat sophistication and drives demand for automated, AI-driven defence. The data advantage, network effects and ecosystem moats of cybersecurity platforms are difficult to replicate, limiting disintermediation risk.
While the sector should benefit from AI tailwinds, platform vendors are likely to benefit disproportionately. Cybersecurity platforms have the highest Rule-of-40 (three-year revenue CAGR plus FCF margin) score within software sub-categories, reflecting strong revenue growth and operational gearing. Palo Alto ranks number three among large-cap software companies (>$50bn market cap), behind only Palantir Technologies and ServiceNow.
Palo Alto has multiple growth engines and strategic levers to drive revenue growth
Transformative M&A with CyberArk and Chronosphere
M&A has been central to Palo Alto’s expansion, with the group completing more than 25 transactions since 2013. The recent acquisitions of CyberArk ($19bn; completed February 2026) and Chronosphere ($3.0bn; completed January 2026) are the most significant in group’s history, extending its security fabric into identity security and observability, respectively.
The CyberArk deal represents a decisive departure from the group’s established M&A playbook, with Palo Alto acquiring a category leader with a scaled technology platform (~$1.2bn ARR in Q226; ~10k customers) within identity security. CyberArk fills a critical gap in Palo Alto’s security fabric, strengthening its zero-trust architecture with significant cross-selling opportunity across its ~70k installed base.
The acquisition of Chronosphere further expands Palo Alto’s total addressable market (TAM) beyond cybersecurity into the fast-growing observability market (~$200m ARR in Q226). Together, these acquisitions materially strengthen Palo Alto’s platform, reinforcing its position as a scaled-up, integrated cybersecurity vendor.
Platformisations are accelerating
Starting in 2024, Palo Alto formalised its platformisation strategy across its top 5k customers, replacing multiple point solutions with integrated products across its network, cloud and security operations – ie three platforms across 5k customers, implying 15k potential platformisations.
Palo Alto has executed well on its platformisation strategy, with strong momentum. The quarterly run-rate of new platformisations has doubled from ~50 in Q224 to ~100 in Q226, bringing the cumulative total to ~1,550 (from ~850 in Q224).
Unit economics are compelling as the cohort matures: “platformised” customers have 119% net retention rates (NRR) and low single-digit gross churn (Q226), with ARR per customer trending higher as deal sizes scale up.
Where are we different from consensus?
In this note, we carry out a deep-dive on platformisation, quantify the economic impact and show what is implied in consensus estimates. We have also carried out a detailed product analysis breaking down NGS ARR by product categories.
Our revenue bridge highlights platformisation as the primary driver of Palo Alto’s revenue acceleration, accounting for ~55% of incremental revenues between Q226 and FY30E. We think consensus understates both the pace and the economics of the strategy, we estimate 6-14% upside to FY30E consensus revenues.
Management is targeting 2,500-3,500 total platformisations by FY30E. Palo Alto is currently adding ~100 per quarter on a trailing 12-month basis, a pace that broadly tracks the trajectory to the upper end of the target range. The lower end of the target requires just 53 platformisations per quarter, and the mid-point requires 81.
Our analysis suggests that consensus FY30E revenue of ~$19.4bn implies only ~2,600 platformisations, closer to the lower end of management’s target range. This equates to ~59 platformisations per quarter.
We believe consensus estimates understates both the pace and the economics of platformisation
We model 2,855 platformisations by FY30E, implying an average run-rate of ~73 per quarter —below the current pace to allow for normalisation as scale increases. This translates into FY30E revenue of ~$20.1bn, ~4% above consensus.
We estimate Palo Alto could reach ~$20.6bn of revenue at ~3,000 platformisations (~6% upside to consensus), and ~$22.1bn at 3,500 platformisations (~14% upside).
We do not think the top of management’s range is the ceiling. Even at 3,500 platformisations, penetration would reach only 23% of the top 5,000 customer base, leaving substantial white space within Palo Alto’s largest accounts and a much longer runway across the broader ~70k installed base.
While we are 4% above consensus on FY30E revenues, we believe our estimates are conservative as we do not model platformisations beyond the top 5,000 customers; even within the top 5,000 customers, we model only 19% penetration rate.
We would expect 6-14% upside to consensus if management hits mid-to-upper end of the target and further upside if the pace of platformisation accelerates
We would expect 6% upside to FY30E consensus revenues if Palo Alto reaches 3,000 of total platformisation (the mid-point of the range)…
Our calculations show 6% upside to consensus if Palo Alto gets to 3.0k platformisations by FY30E (midrange of target)
…with 14% upside to FY30E consensus revenues if Palo Alto reaches 3,500 total platformisations (the upper end of the range)
Our calculations show 14% upside to consensus if Palo Alto gets to 3.5k platformisations by FY30E (upper end of target)
Cybersecurity caught in software sell-off
Since July 2025, the software sector has underperformed the broader technology sector, driven by market concerns about AI-led disruption. The recent reset in multiples has led investors to question whether rapid advances in AI could disrupt established business models, particularly in software and cybersecurity. While AI is already changing how parts of cybersecurity are delivered (eg application security testing), we think that ignoring the implications for the cybersecurity sector would be naïve. We believe that it is important to assess the practical implications and market concerns in greater detail (see the AI concerns comparison below).
While software stocks are beaten down, performance is not linear
In the analysis below, we have broken down the software sector performance by different sub-sectors across more than 100 software stocks. Within the software sector, share price performance has not been linear across sub-sectors.
Over the last six months, developer tools (down by 46%), vertical software (down by 28%), and larger enterprise software companies (down by 23%) have been the most underperforming sub-categories within software.
While the cybersecurity sector was largely resilient until November 2025, the sector has experienced a de-rating since then
Within the software sector, the performance has not been linear (six months share price performance)
Data and cloud infrastructure software companies are more directly levered to AI workloads than traditional SaaS companies, as they benefit from rising data intensity and consumption-led growth. The market also perceives this sub-sector as being closer to the “AI monetisation” trade. This is reflected in share price performance, with relative outperformance for content delivery software providers (+11%), engineering software (-2%) and data and analytics platforms (-9%).
The greater dispersion is reflected in the multiples
The divergence in performance is also evident in valuations. We have grouped software companies’ EV/sales multiple by subsector as well as by market capitalisation
Data and analytics platforms, content delivery platforms, engineering software companies and platform-based cybersecurity players are trading at EV/sales multiples of 11-13x. By contrast, vertical software, horizontal software and non-platform cybersecurity companies, as well as developer tools software companies, are trading at EV/sales multiples of 3-4x.
EV/sales dispersion across the software sub-sector reflects the difference in growth and duration
Our analysis shows a clear investor preference for scale, which is often a reflection of higher quality and stronger moats in the software sector.
Software companies with less than $1.0bn market capitalisation are trading at an average EV/sales multiple of 1.5x, compared with 5.1x for companies in the $20bn-50bn market range, and an average EV/sales multiple of 11.9x for companies with a market capitalisation greater than $50bn.
EV/sales multiples across software (by market cap) reflect growth, scale and execution
We believe the de-rating is particularly harsh for cybersecurity companies
While cybersecurity was initially viewed by markets as being more resilient within the wider software sector, since November 2025 the sub-sector has also been caught in the broader “AI eats software” narrative and is down by 18% over the last six months.
We believe this de-rating is particularly harsh, as we view AI as more of an opportunity than a risk for cybersecurity names. In addition, the cybersecurity sub-sector has continued to witness earnings upgrades and remains one of the fastest-growing sub-sectors within software, with platform cybersecurity names expected to deliver a three-year organic revenue CAGR (2025-2028E) of 17% – amongst the highest within the software sub-categories (overall, software companies are expected to deliver 14% revenue CAGR over the next three years), and score highest on the Rule-of-40 metric within the software sub-categories.
Following the de-rating, the cybersecurity sector is now trading closer to trough multiples, at a 2026 EV/sales multiple of 4.9x, representing a 25% discount to its five-year average EV/sales multiple of 6.6x. Nearly all the cybersecurity companies we cover are trading at one standard deviation below their historical averages.
The cybersecurity sector is now trading closer to trough EV/sales multiples…
…with most of the companies trading at lower end of EV/sales multiple
Platform names in cybersecurity are the one of fastest growing sub-sector within software…
…with a 13% revenue CAGR for the cybersecurity sector (based on aggregate revenues for all the cybersecurity companies)
Aggregate cybersecurity revenues are expected to reach $62bn by 2028E, implying a 2025–28E CAGR of 13%
Organic revenue growth is used for cybersecurity platform names for a like-to-like comparison.
All but three companies within the cybersecurity sub-sector have experienced revenue upgrades over the last 12 months; with a median revenue upgrade of 3%
Platform-based cybersecurity names lead on Rule of 40, driven by strong growth and operating leverage, scoring 51 – the highest score in the software sub-sector
Three-year sales CAGR is based on headline revenue growth.
We view AI as an opportunity, not a risk, for cybersecurity players
We clearly view AI as an opportunity and not a risk for the cybersecurity names.
- As companies embed AI, more AI means an increase in “attack surface” (eg an increase in data, cloud applications and the number of identities). Further, the rise of agentic AI materially expands the TAM for cybersecurity vendors as AI agents need to be protected.
- As cybercriminals are leveraging AI tools to exploit software vulnerabilities, lowering barriers to entry, organisations must harness AI to strengthen their defence capabilities. According to CrowdStrike, in 2025, AI-based attacks increased by 89% yoy while average breakout time 6 fell to 29 minutes in 2025, down by 65% yoy versus 2024. As cybercriminals leverage AI tools increasing speed, sophistication and scale of cyber-attacks, this requires increased investment by organisations towards AI threat detection systems (“AI versus-AI” arms race).
- We do not think there is a material disintermediation risk for cybersecurity platforms. Network effects and ecosystem moats are hard to replicate, while the limitations of AI models – including model hallucinations and an inability to provide run-time security – suggests that these risks are overstated.
Below, we detail our thoughts on what the key market concerns are in terms of AI, and implications for cybersecurity in detail.
One of the most topical debates has centred on disintermediation risks from frontier models, particularly following developments from Anthropic. The company’s Claude Code is reshaping software development by lowering barriers to entry. However, well-written code is not necessarily free of vulnerabilities. Reflecting this, on 20 February 2026, Anthropic introduced Claude Code Security, a security solution that scans codebases for vulnerabilities. On 26 March 2026, press reports indicated further advances in Anthropic’s new model with advanced reasoning, coding and cybersecurity capabilities. Both events triggered knee-jerk share price reactions across the cybersecurity stocks.
On 7 April 2026, Anthropic showcased “Mythos Preview,” which demonstrated materially improved capabilities, achieving an 83.1% score in vulnerability reproduction versus 66.6% for its predecessor, Opus 4.6. While earlier models were effective at identifying vulnerabilities, Mythos Preview can also generate exploits 7 , lowering the barrier for cybercriminals. Over the longer term, advances in AI should benefit corporates (as more vulnerabilities in software are discovered and resolved), but in the near term, it may present an advantage to attackers if LLM providers are not careful about how these models are released. Consequently, Anthropic does not plan to make Mythos Preview broadly available. Instead, it has been released to a limited group of partners under Project Glasswing (including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto), enabling them to stress-test capabilities ahead of wider deployment.
We view this collaboration as a clear signal that frontier AI companies are looking to partner with, rather than displace, cybersecurity vendors. It also highlights an emerging division of labour: LLM providers focus on model development and safety, while cybersecurity vendors provide the enforcement and governance layer – including run-time security, threat intelligence, data protection, and the discovery and governance of AI agents. As articulated by CrowdStrike, “Anthropic builds the model, CrowdStrike secures where it executes” – this division is becoming increasingly clear.
While we acknowledge the progress made by LLM providers in relation to vulnerability scanning and application security testing, we note that this is a relatively small sub-segment ($2.4bn) within the overall cybersecurity’s TAM of $195bn. Application security testing is fundamentally different from run-time security, which includes end-point protection, network security, identity and access management, cloud workload protection, data security, threat detection and response, and real-time monitoring and remediation of live threats across enterprise environments. We expect traditional cybersecurity vendors to remain the digital guardians, including securing the AI infrastructure.
Finally, as organisations consolidate their point solutions into integrated, end-to-end cybersecurity platforms for real-time visibility, cross-domain telemetry and coordinated response across end-points, networks, identities and cloud environments embedding AI-driven platform tools, we believe that larger cybersecurity vendors with multiple and unified platforms have a structural advantage over single point solutions.
AI concerns and cybersecurity resilience
Concern #1: Risks to SaaS model
Market concerns for software companies
As AI agents automate workflows, traditional per-seat-based pricing may come under pressure, reducing the need for a number of user licences with the move towards consumption-based models.
Why cybersecurity should be more resilient
We anticipate limited risk for cybersecurity vendors from this transition, as pricing is already largely aligned to consumption drivers such as number of end-points, volume of telemetry data, cloud applications and identities.
Moreover, hybrid (flexible) pricing models have already emerged within cybersecurity as a more effective alternative to legacy licensing, driving faster ARR growth as customers draw down committed spend over time.
Concern #2: Displacement and automation risk
Market concerns for software companies
As AI agents increasingly execute complex workflows autonomously, SaaS applications may lose their role as the primary user-facing interface, with users interacting directly with AI agents instead.
If traditional software is relegated to systems of record and policy enforcement layers, this could lead to pricing pressure and a weakening of competitive moats across many software categories.
Why cybersecurity should be more resilient
We expect limited displacement risk for cybersecurity vendors, as these platforms are not user-facing interfaces but rather operate as always-on control planes working in the background.
On the contrary, the rise of agentic AI expands the addressable market for cybersecurity, as AI agents must be governed, authenticated and monitored in a similar manner to human identities, increasing demand for identity, endpoint and workload security.
Concern #3: Competition from AI-native entrants
Market concerns for software companies
AI-native start-ups could displace software in certain categories such as collaboration, content creation, workflow automation, customer engagement, analytics and developer tools.
Why cybersecurity should be more resilient
Network effects for cybersecurity vendors are difficult to displace, in our view. Even if organisations were to build in-house security tools, the core moat of leading cybersecurity platforms – the ability to aggregate and apply real-time threat intelligence across a large, global customer base – remains highly differentiated and difficult to displace.
Concern #4: Lower module adoption rates
Market concerns for software companies
Even if core software applications are not displaced, the market is concerned that larger software vendors could experience weaker upsell and cross-sell rates, as additional modules may be built in-house or sourced from third parties.
Why cybersecurity should be more resilient
Cybersecurity spending is not viewed by organisations merely as a cost centre but as essential tools that integrate with other applications and are deeply embedded in organisational workflows (eg identity, networking and data security), creating high switching costs. We think that the risks associated with poorly integrated third-party or internally developed tools typically outweigh any potential cost savings from building in-house.
Concern #5: Competition from LLMs
Market concerns for software companies
LLM providers are increasingly offering application-layer functionality (eg agents, workflows and analytics), which enables IT teams to build internal tools that could compete directly with SaaS vendors.
Why cybersecurity should be more resilient
We forecast limited disruption risk for cybersecurity vendors. While LLMs are being used to scan codebases for vulnerabilities, this remains distinct from runtime security across identity, network, cloud, data and security operations. According to Gartner, the application security testing market (~$1.2bn in 2024) represents less than 2% of the ~$195bn total cybersecurity addressable market, highlighting the relatively narrow scope.
Further, efficacy and precision matter more in cybersecurity than general software, and hallucinations from LLM models can carry significant financial and reputational costs for organisations, which therefore limits their use cases.
Frontier AI companies are looking to partner with, rather than displace, cybersecurity vendors with LLM providers focusing on model development, safety and red-teaming, while cybersecurity vendors provide the enforcement and governance layer.
Concern #6: Longer sales cycle
Market concerns for software companies
Even if there is no longer-term disruption to software demand from AI, there could be near-term headwinds as organisations reassess their IT budgets under a “buy versus build” framework, leading to longer sales cycles.
Why cybersecurity should be more resilient
Cybersecurity spending remains fundamentally non-discretionary, underpinned by regulatory mandates, board-level accountability, and its mission-critical role in safeguarding IT systems. As such, we anticipate limited read-across to cybersecurity given its non-discretionary nature.
Furthermore, rising geopolitical tensions and the increase in nation-state attacks represent an additional tailwind to demand.
Concern #7: AI monetisation
Market concerns for software companies
While AI functionality is being rapidly embedded into platforms, most enterprise software vendors have yet to demonstrate clear AI monetisation, in our view – meaning that there is a risk that AI capabilities could ultimately be bundled into existing subscriptions.
Why cybersecurity should be more resilient
While most software companies require a cross-sell motion to monetise AI, AI is more naturally embedded within the cross-sell momentum of cybersecurity vendors.
AI adoption is a driver of incremental demand for the cybersecurity sector. Greater AI usage increases the volume of data to protect, expands the attack surface, and drives growth in applications and cloud workloads that need to be secured.
In an AI-versus-AI arms race, organisations must defend against AI-driven attacks while also leveraging AI in their own defence capabilities, which should ultimately support cybersecurity spending.
AI is also creating new budget categories (eg generative AI security analysts, AI-driven security operations tools), which drives TAM expansion (including agentic AI), enhances pricing power within existing modules through new features, and enables additional AI-driven product modules.
Concern #8: Gross margin pressure
Market concerns for software companies
Delivering AI functionality is inherently more compute-intensive, requiring greater cloud spend, GPU usage and platform-level integration costs.
With software gross margins historically in the 70-80% range, investors are concerned that, if these AI features are not explicitly monetised, gross margins could be structurally diluted.
Why cybersecurity should be more resilient
Considering that cybersecurity vendors can charge for AI features in several ways, we do not expect meaningful gross margin pressure for cybersecurity vendors.
Concern #9: Lack of data moat
Market concerns for software companies
As LLMs commoditise applications, software vendors without proprietary, high-quality datasets risk losing differentiation, because applications become increasingly standardised across platforms.
Why cybersecurity should be more resilient
Cybersecurity vendors, on the other hand, generate first-party, real-time, highly sensitive non-public data, unlike the largely historical datasets on which LLMs are trained.
Cybersecurity companies then aggregate and ingest this data across platforms and customers, applying shared intelligence creating a structurally defensible data moat that is difficult for LLM providers to replicate.
Cybersecurity as a sector continue to deliver mid-teen revenue growth, with higher quality point solutions and platform names delivering faster growth (yoy revenue growth)
Based on calendarised quarters; non-December reporting companies are aligned to their closest calendar quarter.
Beyond absolute yoy growth, the change in trailing 12-month revenue reflects share of incremental cybersecurity budgets; Palo Alto, CrowdStrike, Fortinet, Zscaler, Rubrik and Okta are clearly leading the way
While ARR is the preferred forward-looking metric, inconsistent disclosure and billings volatility limit comparability; we therefore use TTM revenue as a more standardised and less noisy proxy for like-to-like performance in capturing incremental cyber budgets
Company overview: evolution from network security to platform vendor
Palo Alto is a global cybersecurity company operating across the full stack of security domains. Over time, the group has evolved from an appliance-based firewall vendor into a multi-platform cybersecurity provider, offering an integrated suite of solutions across networking, cloud, security, endpoint, identity and AI security operations. The recent acquisition of Chronosphere further expands Palo Alto’s market beyond cybersecurity into adjacent areas, including observability.
The company has expanded its TAM since 2018, increasing from $19bn in 2018, when Palo Alto was primarily a firewall vendor, to $140bn by 2025, driven by entry into adjacent sectors including SASE, cloud security and security operations. The CyberArk acquisition adds an incremental $29bn TAM within the identity security market, while Chronosphere adds $25bn of TAM from observability. This brings the combined market opportunity to $206bn for 2025, an 11x increase versus 2019 levels. Based on our estimates, the TAM for Palo Alto is expected to grow at a 12% CAGR to reach $292bn by 2028E.
Palo Alto’s TAM has evolved from firewalls into a complete suite of cybersecurity and observability domains with a TAM of $206bn in 2025 and we expect the TAM to reach $292bn by 2028E
Observability TAM is from Datadog’s 2026 investor day presentation; Palo Alto TAM including identity is from Palo Alto’s July 2025 presentation.
Palo Alto’s strength lies in its comprehensive portfolio depth and breadth
With a comprehensive portfolio spanning the full spectrum of cybersecurity, Palo Alto is one of the few vendors that operates at scale across every domain. With organisations shifting away from fragmented security solutions towards integrated security platforms, we believe Palo Alto is well positioned to benefit from the structural consolidation of cybersecurity spending which underpins the group’s “platformisation” strategy.
Palo Alto is the most horizontally diversified cybersecurity vendor
While cybersecurity companies rarely provide complete revenue by security domain, our domain mapping aims to show the areas of primary exposure, mapping each vendor with domains. Given that each company has its own taxonomy, for consistency we have used Gartner’s core categories (but we have broken down infrastructure protection into further subdomains including end-point and SIEM, among others). Domain mapping is based on our understanding of product scope and disclosed growth vectors. The mapping indicates relative focus, not revenue attribution.
Palo Alto’s products fall into four core functional areas.
- Network security: Palo Alto’s network security offering is provided via the group’s Strata platform which includes next-generation firewalls, delivered both as physical appliances deployed across corporate data centres and branch offices, and software/virtual firewalls within public cloud environments. Growth in network security is increasingly being driven by the shift towards software-based firewalls and the adoption of SASE solutions, primarily through Prisma SASE.
- Security operations and cloud security: In Q225, the company unified security operations and cloud security capabilities into a single platform, reflecting its broader platformisation strategy. The security operations portfolio includes SIEM tools delivered via the Cortex platform, enabling organisations to prevent, detect and respond to cyber threats. Key products include Cortex XDR, Cortex XSOAR, Cortex Xpanse and Cortex XSIAM. Prisma Cloud represents the company’s cloud security offering.
- Identity security: In February 2026, Palo Alto completed the acquisition of CyberArk for $19bn (announced in July 2025), expanding into identity security, specifically privileged access management (PAM). The longer-term goal is to extend privileged access identity solutions, which is currently limited to administrative accounts, across every identity within an organisation, including machine identities.
- Observability: In January 2026, Palo Alto completed the acquisition of Chronosphere for $3.0bn, extending its platform into the adjacent observability market.
Palo Alto has a unified security platform
Strata platform (Network security): Prisma SASE; Prisma Access; Prisma SD-WAN; Next-Generation Firewalls (NGFW), including hardware and software firewalls; Cloud-Delivered Security Services (CDSS); Prisma AIRS; Strata Cloud Manager; Panorama.
Cortex platform (Security Operations): Cortex XDR; Cortex XSOAR; Cortex Xpanse; Cortex XSIAM.
Prisma Cloud (Security Operations): Cloud-native application protection platform (CNAPP); Cloud Security Posture Management (CSPM); Cloud Infrastructure Entitlement Management (CIEM); Data Security Posture Management (DSPM); AI Security Posture Management (AI-SPM).
CyberArk (Identity platform): Privileged Access Management; Workforce Identity; Consumer identity; Machine identity; Identity Governance and Administration.
Chronosphere (observability platform): Metrics; Logs; Traces.
Palo Alto’s evolution from an appliance-led firewall vendor to a comprehensive cybersecurity platform
- Pre-2012 – Appliance-led, firewall vendor: Next-Generation Firewall (Strata, WildFire)
- 2012 – Software firewalls: VM-Series (Virtual NGFW)
- 2018 – Cloud security: Prisma Cloud; Evident.io (2018) , RedLock (2018), Twistlock (2019)
- 2018 – SASE: Prisma SASE, Prisma Access; CloudGenix (2020), Sinefa (2020)
- 2019 – Security operations: Cortex XDR, Cortex XSOAR; Cyber Secdo (2018), Demisto (2019)
- 2020 – Software firewalls: CN-Series (Kubernetes)
- 2020 – Security operations: Cortex Xpanse (Attack Surface Management); Expanse (2020)
- 2022 – Security operations: Cortex XSIAM; IBM QRadar assets (2024)
- 2023 – Enterprise browser: Prisma Browser; Talon (2023)
- 2025 – AI Runtime Security: Prisma AIRS; Protect AI (2025)
- 2025 – Exposure Management: XSIAM modules within Cortex
- 2025 – Email Security: XSIAM modules within Cortex
- 2025 – AI agent platform: AgentiX
- 2025 – Quantum security: PAN-OS 12.1 Orion / IBM partnership
- 2026 – Identity security: Privileged Access Management, machine identity CyberArk (2026)
- 2026 – Observability: Observability platform (logs, metrics, traces); Chronosphere (2026)
- 2026 – Agentic endpoint: Agentic endpoint security; Koi (2026)
Significant scale advantages
Product depth and breadth underpin the technology moat at Palo Alto. For instance, Cortex XSIAM (security operations) leverages data from the Cortex XDR (end-points), Strata (network/firewalls) and Prisma Cloud (cloud) platforms to automate threat detection and response across domains, with unified policy enforcement and visibility. This cross-platform integration positions the group as a one-stop shop for enterprise security – a clear competitive advantage over single-point solutions. The addition of identity security further strengthens this architecture by enabling zero-trust enforcement across users and identities. The acquisition of Chronosphere in January extended the telemetry layer beyond security into application and infrastructure, further enhancing the platform’s data advantage.
With 2027E revenues of $14.5bn, Palo Alto is the clear market leader in cybersecurity, providing a significant scale advantage. For context, the combined revenues of the number two and three players are ~$15.6bn highlighting the company’s relative scale and consolidation potential within the sector. Based on our analysis, we estimate that Palo Alto has a 25% revenue share of revenues among listed cybersecurity vendors (based on 2027E consensus revenues).
While Palo Alto has 1.7x and 2.0x more revenues compared to the number two and number three players respectively, it has only a 5.8% share of the cybersecurity market with significant consolidation opportunities
Palo Alto’s R&D spending is greater than the combined R&D spend of the number two and number three cybersecurity players
Key investment point one: platform consolidator
- Vendor consolidation is a key structural driver in cybersecurity, with platform vendors growing ~1.7x faster than non-platform peers. We view this as a multi-year trend, further accelerated by AI adoption.
- Palo Alto has been at the forefront of the consolidation of the sector, with platformisations increasing from 850 in Q224 to 1,550 in Q226. Platformisations are driving improved revenue quality and revenue duration; management is targeting 2,500-3,500 platformisations by FY30E (excluding CyberArk and Chronosphere).
- In this note, we model platformisation on a bottom-up basis to quantify its economic impact. Our analysis suggests that consensus does not fully reflect the strength of Palo Alto’s platform, implying only ~2,600 platformisations by FY30E (below the mid-point of management’s target). We estimate that Palo Alto could reach $20.6bn in revenues by FY30E (range: $19.0bn-22.1bn), implying ~6% upside at the mid-point and ~14% at the upper end. Even at the high end, penetration would be only -23% of Palo Alto’s top 5,000 customers, highlighting significant remaining white space and long-term upside from platformisation.
Vendor consolidation in cybersecurity
Over the past decade, cybersecurity has become one of the most complex and fragmented parts of corporates’ IT stack. Large organisations now run ~45 security tools on average (Gartner) rising to more than 80 tools, and using 25-30 vendors in more complex environments. The result is an inefficient operating model: multiple dashboards, a high volume of uncorrelated alerts, integration overhead across disparate products and materially slower incident response times during a cyber-attack.
According to Wiz, more than 25% of organisations use 50 or more different security tools, and 10% use more than 100
Platform consolidation provides better security outcomes at lower cost, in our view
Risk gap: Risks remain due to spend, capacity, and complexity constraints.
The fragmentation of security portfolios is not simply at aggregate level but also exists within individual security domains. For example, in cloud security, organisations use ~16 tools from 14 vendors on average. More than 70% of organisations use more than 10 cloud security tools, and 4% use more than 100 (Check Point, Cloud Security Report, 2025). In identity, nearly 40% of organisations use four or more identity platforms, with 10% using seven or more (SailPoint, State of Identity Security, 2025). In security operations, teams typically manage ~20 tools. Even within narrower domains such as data security and application security, the typical tool count runs to three to five per organisation.
This tool “sprawl” is one of the foundations for platformisation. Empirical evidence and recent surveys show a clear intent on the part of corporate security teams to reduce the number of security tools in order to lower the total cost of ownership, achieve better security posture through unified telemetry and improve operating efficiencies.
Typical security tool fragmentation by domain
Identity security: 3–6 tools per organisation. Consolidation examples (point tools being unified into platforms): IAM; MFA; IGA; PAM; SSO; CIEM; ITDR; Secrets management.
Endpoint security: 2–3 tools per organisation. Consolidation examples (point tools being unified into platforms): EDR; XDR; Vulnerability management; Device control; Patch management; EPM.
Cloud security: 5–8 tools per organisation. Consolidation examples (point tools being unified into platforms): CSPM; CWPP; CIEM; DSPM; CNAPP; KSPM; CDR.
Network security: 3–4 tools per organisation. Consolidation examples (point tools being unified into platforms): NGFW; SWG; CASB; ZTNA; SD-WAN; NDR; IDS.
Email security: 2–3 tools per organisation. Consolidation examples (point tools being unified into platforms): SEG; Phishing protection; Sandboxing; DLP.
Data security: 3–5 tools per organisation. Consolidation examples (point tools being unified into platforms): DSPM; Data encryption; Tokenisation; Data access governance; Cyber recovery; Backup.
Application security: 3–5 tools per organisation. Consolidation examples (point tools being unified into platforms): SAST; DAST; SCA; ASPM; Container security; API security.
Security operations: 5–8 tools per organisation. Consolidation examples (point tools being unified into platforms): SIEM; SOAR; XDR; Threat intelligence; Vuln management; Log management; ASM.
AI is another accelerator of platformisation
We view AI as another accelerator of platformisation as it materially strengthens the economic and technical rationale for vendor consolidation. With the increase in malware-free attacks, traditional signature-based threat detection tools are less effective compared to behaviour-based threat detection that is better equipped to correlate telemetry across end-point, identity, email, web, network and cloud security.
Where consolidation is happening and who is driving it
In our view, security architectures are moving towards common control planes, with increasing demand for centralised policy enforcement and unified telemetry correlation. Two main approaches are emerging in the sector.
1) Network-first approach: The first approach combines security operations with networking and cloud as a focal point – this is the approach primarily driven by Palo Alto.
2) End-point-first approach: The second combines security operations with end-point security – this is the approach taken by CrowdStrike.
Approach to consolidation strategy
Palo Alto Networks: Network-first approach — starting from firewall/network control, expanding into cloud (Prisma) and security operations (Cortex) to build a multi-platform architecture
CrowdStrike: Endpoint-first approach — starting from endpoint protection, expanding into identity, cloud and data via a single-agent Falcon platform
Microsoft: Ecosystem-led bundling embedding security across Microsoft’s enterprise stack (M365, Azure) via integrated, bundled offerings
Zscaler: Zero trust-first approach — starting from secure access (SASE), expanding into data protection and security operations from the cloud edge
In parallel with consolidation of the entire security platform, there is a growing trend towards consolidation within sub-domains, particularly in identity, cloud and data security.
- In our view, the strongest near-term commercial opportunity remains in security operations, where there is clear demand to unify SIEM, SOAR, XDR 8 and threat intelligence into a single data layer.
- In identity security, overlapping point tools (SSO, MFA, PAM, IGA, CIEM, ITDR9) are increasingly being consolidated into integrated identity platforms.
- In cloud security, multiple tools across CSPM, CWPP, CIEM and CDR10 are gradually converging into CNAPP platforms.
According to McKinsey (Cyber Market Survey, March 2024, n=200), domains with the highest preference for vendor consolidation are security operations (54% of respondents surveyed by McKinsey favour a single vendor), email security (51% of respondents) and web security (50% of respondents) – all of these domains that require integrated workflows for correlation of data and telemetry.
In contrast, for domains such as cloud security, data protection and end-point security, there is a greater preference for a best-of-breed approach, with 43-45% of respondents surveyed by McKinsey preferring a best-of-breed approach. This reflects the increased technical depth and specialisation for these security domains.
The cybersecurity market is at an inflection point in terms of selecting “best-of-breed” versus “best-of-suite” tools: security operations offer the strongest near-term commercial opportunity, in our view
Platform players are growing nearly twice as fast as non-platform players
For a CISO11 managing ~80 tools on average, consolidation represents a compelling value proposition in our view, and explains why the larger platform vendors are gaining share. Our calculations show that on an organic basis, the larger platform vendors (Palo Alto, CrowdStrike, and Zscaler) are growing at roughly at 1.7x faster than non-platform (the smaller) players, with organic revenue CAGR of 17% for 2025-27E versus 10% for non-platform peers.
Platform players are growing 1.7x faster than non-platform players
Platform players are growing 1.7x faster versus non-platform players
The comparison uses organic growth excluding CyberArk and Chronosphere for Palo Alto.
Palo Alto is at the epicentre of consolidation with its platformisation strategy
Palo Alto has been at the forefront in pursuing a platformisation strategy. Pre-2024, Palo Alto had taken a more passive approach which lacked a deliberate commercial push, with customers naturally choosing the best-of-breed products in each domain. The key metric measured at the time was the percentage of customers buying across all three platforms (Strata, Prisma and Cortex), with nearly 57% of Fortune Global 2000 customers using all three platforms in Q224, up from 31% in Q220.
Platformisation definition: Platformisation represents a higher bar than the multi-product adoption KPI
“Platformisation/Platformised defined as: Active ELA contract or >$1M SASE ARR; >$1M ARR for Cloud Security; active XSIAM contract or >$100k QRadar SIEM ARR with Cortex XDR/XSOAR for Security Operations. Total Platformisations defined as a count of all platformisations across customers, with a customer platformised on all three platforms counting as three platformisations, a customer platformised on two platforms counting as two platformisations, and a customer platformised on one platform counting as one platformisation. Platformisations are counted within our 5,000 largest customers, based on ARR. Excludes any impact of Chronosphere” – Palo Alto Networks, Q226 presentation
Well-crafted strategic execution by sharing execution risks with customers
Starting in 2024, Palo Alto formalised its platformisation strategy, shifting management’s focus away from near-term billings towards customer lifetime value, and with a stricter definition of platformisation (see above).
The company’s approach is built around replacing multiple single-point tools with integrated products across network, cloud and security operations. Across its three core platforms, Palo Alto can potentially displace 10-22 incumbent vendors per customer. In network security, Palo Alto’s Strata platform can potentially replace 4-7 vendors. Prisma Cloud can consolidate 3-8 vendors across cloud security functions. Within security operations, the Cortex platform can displace 3-7 vendors by unifying detection, response and automation.
Consolidation of tools
Network Security: Capability to consolidate 4–7 vendors. Cloud-Delivered Security Services; HW Firewalls; SW Firewalls; SD-WAN; SSE.
Prisma Cloud: Capability to consolidate 3–8 vendors. SCA; IaC; Secrets Scanning; CDS; CI/CD; API; CSPM; CWP; CIEM; WAAS; Vuln. Mgmt; CDR.
Security Operations: Capability to consolidate 3–7 vendors. EDR; NTA; ITDR; TIP; ASM; SOAR; SIEM.
The group runs several programmes to drive platformisation, including legacy trade-ins, no-cost introductory offers and product add-ons and incentives. Palo Alto engages customers 6-12 months ahead of contract expiry and signs forward-dated deals, with payments typically starting only after the incumbent contract rolls off, removing double-spending risk and easing conversion as a platform customer.
Palo Alto’s earliest platformisation deals were driven by a “land-and-expand” strategy, starting with next-generation firewall and SASE tools, with subsequent expansion into adjacent domains including security operations (Cortex XSIAM) and cloud security (Prisma Cloud). Palo Alto’s go-to-market strategy has evolved beyond purely commercial-led bundling and price discounting towards a more strategic relationship with its customers. There is increased sales emphasis on product integration and technology architecture, with cross-domain telemetry and AI-driven threat detection forming the core of the value proposition, rather than price-led competition.
Platformisation momentum is building
Momentum is clearly building. The company’s quarterly run-rate of new platformisations has doubled from ~50 in Q224 to ~100 by Q226, bringing the cumulative number of platformisations to ~1,550 in Q226, up from 850 in Q224. Given that the total platformisation opportunity is 15,000 among its top 5,000 customers (three platforms * 5,000 customers) we estimate Palo Alto’s current platformisation penetration rate at about 10%.
Palo Alto’s total number of platformisations have increased from 850 in Q224 to 1,550 in Q226
A long runway of opportunity ahead
Management is currently targeting total platformisations to reach 2,500-3,500 by FY30E. What stands out to us, however, is the scale of what remains untapped. Against a ~15,000 theoretical opportunity, the FY30E target implies just ~17-23% penetration of the top 5,000 customer base. In other words, even if management delivers on its medium-term ambition, platformisation would still be in its early stages given the installed base of more than 70,000 customers.
Our calculations suggest that Palo Alto requires a sustained quarterly run-rate of ~53 to reach the lower end of the 2,500-3,500 platformisations range by FY30E, and a quarterly run-rate of ~108 to edge towards 3,500 platformisations (~81 needed to get to the mid-point range).
If the current quarterly run-rate of 100 is sustained, the group could easily reach 3,500 total platformisations by FY30E. We are modelling 2,855 total platformisations by FY30E which implies an average quarterly run-rate of 73.
Given that the current definition of platformisation includes SASE, Prisma Cloud and Cortex and excludes CyberArk and Chronosphere, we model revenue synergies from identity and observability within the revenue synergies.
Management is aiming for Palo Alto’s total number of platformisations to reach 2,500-3,500 by FY30E
By FY30 we expect Palo Alto’s total platformisations to reach 2,855 with platformisation revenues to reach ~43% of revenues
The implied penetration rate among the top 5,000 customers with a 15,000 total platformisations opportunity
Palo Alto has strong momentum with its platformisation strategy
~1,550 total platformizations; ~100 new platformizations in Q226, up from ~60 in Q126. 2,500–3,500 platformizations to reach $15B Organic NGS ARR Target; $20bn including CyberArk and Chronosphere in FY’30.
The quality and duration of Palo Alto’s revenue is improving measurably
As platformisation transforms the business model from transactional, point-product sales into a more strategic and relationship-driven engagement, this creates a strong flywheel with network effects and higher-quality and longer-duration of revenues. The economic effect of this flywheel is best reflected in NRR and ARR per customer.
According to Palo Alto, its platform customers have an NRR of 119% (Q226) with low single-digit gross churn – which makes it best-in-class among enterprise software companies at any scale. For context, this places Palo Alto’s platform customer NRR only behind Rubrik (120%) among the cybersecurity peer group.
Platformisation creates a strong tech moat with a flywheel network effect
Customers who use all three platforms spend $4.3m pa versus $418k using two platforms and $86k using one platform
Platform spending is based on FY23 data for illustration purposes; the latest FY26 data is not disclosed.
Palo Alto has best-in-class NRR* within cybersecurity
Source: Visible Alpha 2025 NRR for cybersecurity companies where available. NRR for Palo Alto is for platform customers.
The customer base is also concentrating into higher-value relationships. In Q226, the number of customers with NGS ARR greater than $5.0m grew by 48% yoy to 173, up from 60 in Q125. The number of customers with more than $10m NGS ARR grew by 50% yoy to 60. The implied ARR uplift is substantial: customers on a single platform spend approximately $86,000 pa, those on two platforms spend $418,000 pa, and those on all three platforms spend approximately $4.1m pa – implying a 7x-47x uplift as a customer moves from one platform to full platformisation (these figures are based on FY23 data as the more recent vintage is not disclosed).
The number of Palo Alto customers with greater than $5m NGS ARR have nearly doubled to 160
The number of Palo Alto customers with greater than $10m NGS ARR have increased from 30 in Q225 to 60 in Q226
Palo Alto is increasingly focusing on ARR as opposed to billings
Given the extended rollout and bundling inherent in platformisation deals, billings and revenue recognition are compressed in the early years. This creates volatility in billings while inflating remaining performance obligations (RPO) as forward-dated commitments accumulate ahead of payment commencement. As a result, billings were retired as a guidance metric starting from Q424, with increased emphasis on NGS ARR and RPO as the primary financial KPIs.
Palo Alto is increasingly focusing on long-duration KPIs including RPO and ARR growth instead of billings, which tend to be more volatile
Quantifying the upside from platformisation
Our platformisation framework shows that Palo Alto could reach $20.6bn of revenues by FY30E – at the mid-point of management’s target, with a range of $19.0bn-22.1bn. This compares to consensus estimates of $19.4bn, implying 6% upside at the mid-point and 14% upside at the upper end of the target range.
Reverse-engineering consensus estimates shows the market is implying just ~2,600 total platformisations by FY30E, closer to the lower end of management’s 2,500-3,500 target. We do not think the top of management’s range is the ceiling. Even at 3,500 platformisations, penetration would reach only 23% of the top 5,000 customer base, leaving substantial white space within Palo Alto’s largest accounts and a much longer runway across the broader ~70k installed base.
We present the analysis below in two stages. First, we show the upside from platformisation at current economics – holding average ARR and non-platform revenues constant – to isolate the pure volume effect. Second, we extend the analysis to FY30E incorporating growth in average ARR per platformised customer, non-platform revenue growth, and contributions from CyberArk, Chronosphere and cross-sell synergies.
Upside from platformisation on current economics
In the first stage of the analysis, we compute Palo Alto’s revenue upside through the lens of platformisation at current economics – if customers make the transition as of today.
Palo Alto currently has ~1,550 platformisations at an average ARR of $2.25m 12 per platformised customer, implying $3.5bn of platformisation revenues and $5.7bn of revenues from non-platform customers on a trailing 12-month basis. Including current revenues from Chronosphere and CyberArk, we estimate pro-forma trailing 12-month revenues of $10.8bn.
If Palo Alto achieves total platformisations of 2,500-3,500 at current economics, platformisation alone could deliver an incremental $2.1bn-4.4bn revenue opportunity, with pro-forma revenues of $12.9bn-15.2bn, implying 20-40% upside from the current base.
Quantifying platformisation for FY30E
Extending this analysis to FY30E, the timeframe in which management is actually targeting 2,500-3,500 platformisations, our calculations show that at the mid-point, Palo Alto’s total platformisation revenues could reach $9.2bn, with a range of $7.6bn-10.7bn. Including $7.8bn of non-platformised revenues, $0.5bn from Chronosphere, $2.5bn from CyberArk and $0.6bn of revenue synergies, our calculations show that Palo Alto could reach $20.1bn of revenues at the mid-point, with a range of $19.0bn-22.1bn.
As a cross-check, our platformisation revenues of $7.6bn-10.7bn is 50-70% of NGS ARR target of $15bn (pre-Chronosphere and CyberArk). This is broadly consistent with management’s expectation that 60-70% of the $15bn organic NGS ARR target is expected to come from platform customers.
Based on this analysis, we estimate 6% upside to FY30E consensus revenues if the group reaches the mid-point of 3,000 total platformisations, and 14% upside at the upper end of 3,500.
Our detailed assumptions are as follows.
- We compute platformisation revenues based on 2,500-3,500 total platformisations and an average ARR per platformised customer of $3.05m, reflecting an 7% compounding rate from the current $2.25m – reflecting rising deal sizes as customers deepen their platform commitment.
- For non-platform revenues, we assume a 8% compounding rate from the current run-rate of $5.7 bn to $7.8bn by FY30E.
- We assume $0.5bn of revenues for Chronosphere by FY30E. For CyberArk, we assume $2.5bn of revenues, broadly in line with the consensus growth trajectory on a standalone basis.
- On revenue synergies, given that we have not included Chronosphere or CyberArk within the platformisation count (we use the organic definition), we include $0.6bn of revenue synergies equivalent to 20% of combined Chronosphere and CyberArk FY30E revenues. This takes into account additional platformisation opportunities from identity and observability that these acquisitions could unlock.
Consensus estimates do not reflect the strength of Palo Alto’s platform
Consensus estimates for Palo Alto are looking for FY30E revenues of $19.4bn. Keeping all other assumptions, if we reverse-compute, our calculations show that consensus are implying ~2,600 platformisations by FY30E, which is closer to lower end of management’s 2,500-3,500 target range.
Consensus estimates underappreciate the strength of Palo Alto’s platform
On an organic basis excluding CyberArk and Chronosphere, we have included the impact of platformisation from identity and observability within revenue synergies.
The current quarterly run-rate of ~100 new platformisations already supports the upper-end trajectory. As we highlight above, management’s target of 2,500-3,500 platformisations implies penetration of only ~17-23% within the top 5,000 customer base, giving Palo Alto a large white-space platformisation opportunity not only with its largest customers but also with the wider installed base of 70,000+ active customers.
We would expect 6% upside to FY30E consensus revenues if Palo Alto reaches 3,000 of total platformisations (the mid-point of the range)…
Our calculations show 6% upside to consensus if Palo Alto gets to 3.0k platformisations by FY30E (midpoint of target)
…and 14% upside to FY30E consensus revenues if Palo Alto reaches 3,500 total platformisations (the upper end of the range), and with potential for further upgrades if there is faster acceleration in number of platformisations
Our calculations show 14% upside to consensus if Palo Alto gets to 3.5k platformisations by FY30E (upper end of target)
Enterprise software provides a clear historical precedent
The enterprise software market offers a clear historical precedent for the cybersecurity sector. Nearly every major software category has transitioned from fragmentation to platform consolidation, with the winners taking significant market share. For example, Salesforce has consolidated the global customer relationship management (CRM) market with a 34% market share, ServiceNow commands a 36% market share in IT service management (ITSM) and Adobe has a nearly 58% market share in creative software. These vendors have demonstrated that integrated platforms can deliver superior results at lower total cost of ownership. By contrast, cybersecurity remains a highly fragmented market. In contrast, Palo Alto with $11bn of revenues (trailing 12 months pro-forma) has only a mid-single-digit market share in cybersecurity.
Cybersecurity is a highly fragmented market compared to other enterprise software segments
Consolidation in cybersecurity is far more nuanced
While the pendulum is currently swinging towards platform consolidation, integrated platforms do not mean that entire cybersecurity budgets go to one vendor. We acknowledge that cybersecurity is structurally more complex than other software categories, with multiple sub-domains that each require technical depth. No CISO, in our view, wants to trade effectiveness for simplicity. This is especially true for larger organisations that are technology-savvy with complex IT requirements, and which are looking not just for best-of-breed point products but best-of-breed platforms with the right architecture.
Different organisations will adopt different levels of consolidation. Some will favour a single platform provider for cloud, networking and security operations, while running a separate platform for end-point, identity and data security. Others will continue with a best-of-breed approach in specific domains. According to McKinsey, 45-55% of organisations still prefer the best individual vendors for each product, while the remainder favour integrated platform solutions. The direction of travel, however, is clearly towards fewer vendors with deeper integration.
As such, while we do not expect the leading cybersecurity player to command a 40-60% market share, like we see in other software categories, a mid-single-digit share for the leading player is still too low, in our view. In our view, the platformisation thesis is not a two-year trade but a multi-year structural story, with Palo Alto still in the early stages of its platformisation strategy. Our FY28E revenue estimates for Palo Alto (excluding Chronosphere revenues and TAM in observability) imply approximately only a 6.0% market share for the company.
Key investment point two: M&A-led expansion
- M&A has been at the forefront of Palo Alto’s expansion, with the group completing more than 30 transactions since 2013 for a total consideration of $29bn. These acquisitions have been technology-led, focused on building capabilities rather than acquiring revenue streams.
- The acquisition of CyberArk ($19bn) in February 2026 is the largest strategic transaction in Palo Alto’s history. As CyberArk is integrated as the fourth platform pillar (identity security), Palo Alto is extending its architecture into identity, strengthening its end-to-end zero-trust positioning and reinforcing its platformisation strategy.
- The acquisition of Chronosphere expands Palo Alto’s TAM beyond cybersecurity into the fast-growing observability market (~$25bn TAM), adding deep telemetry and monitoring capabilities and positioning Palo Alto as a scaled platform spanning both security and observability.
A defining feature of Palo Alto’s strategic evolution has been its disciplined use of targeted acquisitions, with the group completing more than 30 transactions since 2013, with an aggregate consideration of $29bn, although much of this is attributable to the recently closed CyberArk ($19bn, closed in February 2026) and Chronosphere ($2.9bn, closed in January 2026).
While CyberArk (identity security) and Chronosphere (observability) clearly dominate recent headlines, Palo Alto’s earlier acquisitions were instrumental in transforming its origins, which were rooted in network security appliances, enabling entry into adjacent domains including cloud security, security operations, and SASE.
While M&A has been at the forefront of Palo Alto’s expansion, in our view, Palo Alto should not be treated as an M&A roll-up story. The rationale underpinning its acquisitions has been technology-driven, rather than focused on purchasing revenue streams or extracting cost synergies. Instead of operating acquired technologies as standalone products, management has done an exceptional job of integrating these capabilities within its three core platforms — Strata (networking), Prisma (cloud security), and Cortex (security operations).
M&A has been at the forefront of Palo Alto’s expansion
For M&A transactions spanning multiple domains, we have allocated to the primary domain based on deal description and our judgement
Cloud security: building Prisma cloud security portfolio
Early transactions including Evident.io and RedLock (both 2018), followed by Twistlock and PureSec (both 2019), established Palo Alto’s initial presence across CSPM and runtime protection. More recently, Dig Security (2023) added DSPM capabilities, while Protect AI (2025) extended coverage into securing AI models and inference pipelines. Together, these acquisitions have progressively built Prisma into a comprehensive cloud security platform spanning posture management, workload protection, data security, and AI security.
Security operations: from end-point security to autonomous security operations
Within security operations, early acquisitions such as Cyvera (2014) and LightCyber (2017) introduced behavioural analytics and advanced threat detection at the end-point layer. The acquisition of Demisto (2019) laid the foundation for Cortex XSOAR, while Expanse (2020) added external attack surface management. More recently, the IBM QRadar SaaS assets (2024) have accelerated migration of legacy SIEM customers to Cortex XSIAM. Collectively, these capabilities underpin Cortex’s positioning as an AI-driven, automated security operations platform.
SASE: extending Strata beyond the firewall
Within SASE, the acquisition of CloudGenix (2020) added SD-WAN13 capabilities, enabling Palo Alto to converge networking and security and extend the Strata platform beyond its firewall origins. This formed the foundation for Palo Alto’s entry into zero-trust network access. The subsequent acquisition of Talon Cyber Security (2023) added enterprise browser capabilities, further strengthening Palo Alto’s SASE offering.
CyberArk’s acquisition extends the security fabric into identity security
The acquisition of CyberArk for $19bn is the largest strategic transaction in Palo Alto’s history. The deal was completed in February 2026 (announced in July 2025) and funded with $2.3bn in cash and 112m shares. In our view, the CyberArk deal represents a decisive departure from the group’s established M&A playbook. Historically, Palo Alto acquired best-of-breed point solutions in the $100m-400m range and integrated them organically into its platform. CyberArk, by contrast, is a category leader in identity security with a scaled technology platform, ~$1.2bn of ARR and an installed base of over 10,000 customers.
Identity completes the security architecture: Prior to the acquisition, Palo Alto addressed roughly 60-70% of a typical customer’s cybersecurity vendor estate, with identity representing the largest remaining gap. With CyberArk now embedded as the fourth platform pillar alongside network security, security operations and cloud security, the group offers a more complete, end-to-end security platform.
Identity is a critical control layer: Identity layer governs access across users, devices and applications, and compromised credentials remain one of the most efficient attack vectors (with a majority 88% of breaches involving identity-based techniques, according to CrowdStrike). As identity becomes the central pillar of zero-trust architectures, it is increasingly integrated across end-point, cloud, network and application security, reinforcing the case for platform-level consolidation.
A large addressable market for privileged access management: While identity security begins with authentication (SSO, MFA), these controls alone cannot prevent lateral movement. CyberArk’s core technology addresses a more fundamental problem: securing privileged accounts and controlling post initial authentication behaviour. Historically, higher deployment costs limited PAM solutions to a narrow user base, primarily IT administrators (~8m global privileged end-points). As delivery costs decline, the opportunity set broadens materially. If Palo Alto can extend privileged access controls across the broader employee base, the addressable market could expand from ~8m to ~1bn users.
Machine identity represents an outsized opportunity: Beyond human users, AI is introducing a rapidly growing class of non-human identities. As AI agents operate with autonomous credentials, they must be governed in a similar way to human users. Today, according to CrowdStrike, there are an estimated~5bn digital identities across users, end-points and workloads. Over time, machine identities are expected to outnumber human identities by a significant margin, with estimates ranging from 80:1 (SailPoint) to 100:1 (CyberArk). While pricing per machine identity is likely lower, the scale implies a substantially larger long-term market opportunity.
Identity security is highly fragmented market with opportunities for consolidation
Deploying privileged access solutions across the wider employee base could increase TAM to 1.0bn users
Governance of AI agents will be a significant market opportunity for cybersecurity companies in terms of the sheer volume of assets to be managed
Agentic AI could potentially increase the addressable market by 80:1 for cybersecurity companies with 150bn more managed assets
Platformisation within identity: The identity market remains highly fragmented, spanning privileged access, access management, identity governance, identity security posture management, access management and identity threat detection – with ~100 vendors across these domains. According to SailPoint, ~40% of organisations use more than four identity platforms and ~10% use more than 10. As complexity rises and identity-related breaches increase, we expect consolidation towards integrated platforms.
Revenue and cost synergies: Palo Alto’s installed base of ~75,000 customers provides a significant cross-sell opportunity for CyberArk’s products. While cost synergies are not the primary rationale, management expects CyberArk’s ~20% operating margins to converge towards Palo Alto’s ~30% margin profile within 24 months as go-to-market functions are streamlined and R&D is rationalised across the combined platform.
Platform effect: Strategically, CyberArk extends beyond a standalone identity pillar. It introduces identity telemetry that can be integrated across network, cloud and security operations data, enabling a closed-loop architecture across four security domains – a platform effect that few vendors can replicate at scale.
From cybersecurity to observability
The acquisition of Chronosphere for $3.0bn extends Palo Alto into the observability market, securing an early position in a large and growing data infrastructure segment and positioning the group at the intersection of data and security.
According to management, the high cost of existing observability platforms remains a key barrier to broader adoption. Chronosphere is positioned as a lower-cost alternative, operating at approximately one-third of the cost of incumbent solutions while maintaining high gross margins (~70%). Early traction is encouraging, with a multi-year, nine-figure deal signed with a leading AI model provider in Q226 and period-ending ARR reaching $200m (up from $160m flagged during the Q126 earnings call).
Unlike CyberArk, Chronosphere is expected to remain largely independent, preserving its founder-led engineering culture while leveraging Palo Alto’s go-to-market capabilities, particularly across large customers.
In our view, the Chronosphere acquisition positions Palo Alto as one of the few scaled vendors with the capability to combine observability and security within a single platform, enabling attribution of system failures to either performance issues or security events.. However, given Chronosphere’s modest scale relative to the group and the more immediate strategic importance of CyberArk, we expect limited near-term revenue synergies from the transaction.
Listed peers in observability space are delivering strong double-digit revenue growth
Observability is a $28bn market (2026E) and according to Datadog is expected to reach $39bn by 2029E at a 12% CAGR
Despite closing two large acquisitions during FY26E, we continue to model net cash for Palto Alto throughout our forecasting period reflecting its strong free cash flow generation (~78% of CyberArk’s consideration was paid in form shares by issuing 112m shares). We forecast period end net cash of ~$7.7bn at the end of FY26E, rising to ~$19bn at the end of FY28E.
Palo Alto has strong free cash flow generation
We forecast net cash to increase from $7.7bn in FY26E to $19bn by FY28E
Key investment point three: multiple growth engines
- Palo Alto is a rare quality compounder in enterprise software, increasing revenues from $13m in FY09 to an estimated $13.7bn by FY27E – which would represent a 1,000x increase in under two decades. Revenue quality has been transformed, with a growing subscription and support mix. We use NGS ARR as the best proxy to gauge the success of the company’s platformisation strategy: NGS ARR increased from $0.7bn in FY20 to $6.3bn in Q226, with management targeting $20bn by FY30E.
- In network security, growth has decisively shifted from hardware-based firewalls to virtual firewalls and SASE, with Palo Alto now less tied to the hardware refresh cycle as the business model reflects structural tailwinds within networking (ie the expansion of remote working, cloud migration and SaaS adoption). The software revenue mix has risen to 45% of product revenues in Q226 (from 22% in Q323) and is growing ~2.5x faster than hardware appliances. Prisma SASE is the key revenue driver in network security, with $1.5bn ARR in Q226, a 3.75x increase since Q222.
- The next leg of growth in security operations will be driven by legacy SIEM displacement and SOC consolidation. Cortex XSIAM is one of the fastest product ramp-ups, scaling from zero to more than $500m of ARR (Q226) within three years. With a ~$1.0m average ARR across ~600 customers, penetration of Cortex XSIAM within Palo Alto's 75k installed base is still at an early stage; however, we think a total of $1.5bn in ARR is possible by FY28E.
A quality compounder with an improving revenue mix
Palo Alto is a rare compounder in enterprise software, with its revenues increasing from $13m in FY09 to $9.2bn in FY25. Management is guiding to FY26E revenues of $11.28bn-11.31bn. Given FY26E will include only six months of revenue contribution from CyberArk and Chronosphere, FY27E will be the first full year to capture the pro-forma impact of both acquisitions. We estimate FY27E revenues of $13.7bn (consensus: $13.6bn) – a more than 1,000x increase versus FY09 and 4x versus FY20 levels.
Palo Alto management’s strong execution is reflected in its revenue trajectory
Nikesh Arora joined Palo Alto Networks as CEO in June 2018
Revenue quality has shifted structurally
It is not just the scale but the quality of revenues that has changed over the years. Historically, Palo Alto’s revenues were driven by appliance-based firewall deployments, with revenues tied to hardware sales. Over the past decade, expansion into SASE, cloud security and security operations has decoupled the revenue base from the hardware refresh cycle. As of Q226, subscription and support revenues accounted for 80% of group revenues, up from 32% in FY12. Within that, higher-quality subscription revenues have risen to 54% of total revenues in Q226, up from 18% in FY13.
Palo Alto has moved its business model away from hardware refresh cycle towards a recurring revenue business model…
….with software and subscription mix at 80% of total revenues in FY25, up from 38% in FY13
Palo Alto is a quality compounder: revenues ($m)
NGS ARR is one of the most important KPIs
Beyond the absolute number of platformisations, we view NGS ARR as the best proxy to gauge the success of Palo Alto’s platform strategy. NGS ARR primarily captures the recurring revenue associated with software and cloud-based security platforms. Management incentives are directly aligned with NGS ARR, with 25% of executive performance stock units (PSU) tied to NGS ARR performance (with 25% linked to non-GAAP EPS and 50% to a relative total shareholder return (TSR) modifier).
Next-generation security ARR is the most important KPI for Palo Alto as it reflects the success of its platformisation strategy
Pro-forma Q226 includes $1.2bn NGR ARR from CyberArk.
In Q226, Palo Alto reported NGS ARR of $6.3bn, up by 32% yoy (~28% organic). Management is guiding to FY26E NGS ARR of $8.52bn-8.62bn, implying 53-54% reported growth. Adjusting for $200m of NGS ARR from Chronosphere and ~$1.2bn from CyberArk, the guidance implies ~26% organic NGS ARR growth for FY26E.
Looking further ahead, management had previously articulated a target of $15bn of NGS ARR by FY30E. Following the CyberArk and Chronosphere acquisitions, this was raised to $20bn, implying organic CAGR of 24% between Q226 and FY30E. Given consensus estimates are only looking for NGS ARR of $18.2bn by FY30E, there could be 10% upside to consensus expectations here. We are looking for $18.8bn NGR ARR by FY30E, 4% ahead of consensus.
NGS ARR is a forward indicator of revenues
NGR ARR increased to 61% of revenues in FY25 (19% in FY20)
NGS ARR by product domain
While Palo Alto does not disclose its NGS ARR by product category each quarter, we estimate the following breakdown by security domain.
- Network security: Palo Alto generated NGS ARR of $3.9bn in FY25, up by 35% yoy; we estimate $4.3bn in Q226. Prisma SASE ($1.5bn ARR in Q226, up by 40% yoy) is the fastest-growing sub-category.
- Security operations (including cloud): NGS ARR amounted to $1.7bn in FY25, growing by 25% yoy. Within security operations, Cortex XSIAM is the primary growth engine, with ARR greater than $500m.
- Observability: Chronosphere’s ARR was ~$200m in Q226 (included in Q226 reported figures).
- Identity security: CyberArk generated ARR of $1.2bn in Q226. Given that the CyberArk deal was closed in February 2026 (after the Q226 reporting period), it is not included in Q226 NGS ARR. On a pro-forma basis including CyberArk, we estimate Q226 NGS ARR at $7.5bn for the group.
Product examples that are included within NGS ARR
Network security: Prisma Access; Prisma SASE; Prisma SD-WAN (Software component); VM-Series; Cloud NGFW; Cloud-delivered security subscriptions (Advanced Threat Prevention, Advanced URL Filtering, DNS Security, IoT Security, etc.).
Security operations: Cortex XSIAM; Cortex XDR; Cortex XSOAR; Cortex Xpanse; Prisma Cloud.
Observability: Chronosphere.
Identity: CyberArk.
The company defines NGS ARR as the annualised revenue of all active contracts related to product, subscription and support offerings, excluding revenue from hardware products, legacy attached subscriptions, support offerings and professional services
Network security: the core franchise for Palo Alto
Network security forms the core of Palo Alto’s business, accounting for over 75% of group bookings (FY25). The network security capabilities sit within the Strata platform and span next-generation firewalls (physical and virtual), Prisma SASE, cloud-delivered security subscriptions and the AI security platform (Prisma AIRS).
Within network security, the growth engine has shifted from traditional appliance firewalls towards software firewalls, SASE and increasingly AI security and the enterprise browser.
Market-leading positions across sub-segments
Palo Alto holds leading positions across network security sub-segments with a 19% market share in physical appliances14, a 50% market share in software firewall15, a 13% market share in SASE16, and with a combined network security market share of 28%17.
A core differentiator versus competitors within network security is Palo Alto’s proprietary operating system (PAN-OS), which analyses traffic at the network layer and combines this telemetry with data from security operations and cloud security to enforce policies with broader contextual awareness, a core competitive advantage over point-solution products that lack cross-domain visibility.
Palo Alto has a leading position in each of the networking segments
Software firewall and SASE are driving growth in networking portfolio
Historically, Palo Alto’s networking business was anchored on hardware firewalls. While this remains a large and strategic market, the underlying architecture of networking has shifted materially over the past five years. The expansion of remote working, cloud migration and SaaS adoption has dissolved the traditional network perimeter, moving security enforcement away from physical appliances towards distributed, software-defined environments. As a result of this structural shift, Palo Alto has aligned its portfolio with software firewalls and SASE, which are now emerging as the primary growth drivers in networking.
- The software firewall business is growing more than 2x faster than hardware: Software firewall ARR grew by 25% yoy in Q226, materially outpacing hardware growth of ~10% yoy, with the software mix increasing to 45% of product revenues (from 22% in Q323). Management describes the appliance market as a low-growth (0-5% pa) segment, with incremental growth increasingly driven by software, multi-cloud environments and AI workloads.
- SASE represents the fastest-growing segment within network security: Palo Alto’s Prisma SASE platform reached $1.5bn ARR in Q226, growing by 40% yoy, and now accounts for ~15% of TTM revenue (versus 7% in Q222). Besides cloud and SaaS applications, growth in Prisma SASE is increasingly being driven by competitive displacement of legacy point SASE solutions.
Product revenue mix: an accelerating mix shift towards software firewall is driving product revenue growth
SASE ARR has grown by nearly 4x to $1.5bn and continues to grow by 40% yoy as the primary growth engine in network security
Product revenue includes sale of hardware products (primarily Next-Generation Firewall) and software licenses (including SD-WAN, VM-Series, and Panorama)
Palo Alto’s SASE ARR growth accelerated in Q226
SASE customers have grown at a 33% CAGR to reach 6.8k customers in Q116
Palo Alto's SASE ARR is growing faster compared to its peer group
Based on like-for-like reporting period end. For Zscaler we have used group ARR as a proxy given the company does not separately disclose SASE ARR
Palo Alto’s network security portfolio
Prisma SASE. Domain: Secure Access Service Edge (SASE). SASE combines networking capabilities of SD-WAN with security services as a single cloud-based platform (SSE+SD-WAN). Included in NGS ARR: Yes.
Prisma Access. Domain: Cloud delivered security services (SSE). Combines various security elements under the Security Service Edge (SSE) umbrella including secure web gateway (SWG), cloud access security broker (CASB), firewall as a service (FWaaS), and zero trust network access (ZTNA). Included in NGS ARR: Yes.
Prisma SD-WAN. Domain: Networking technology (SD-WAN). Networking technology to connect users, applications and data across multiple layers. Virtualized approach to manage wide area networks (WAN). Included in product revenue: Software license. Included in NGS ARR: Software.
Prisma Access Browser. Domain: Enterprise browser. SASE-native enterprise browser. Included in NGS ARR: Yes.
Next-Generation Firewalls (NGFW)
Hardware and software firewall with built-in networking and security features.
Hardware firewalls
PA-Series. Domain: Appliances/physical firewall. Physical firewalls to secure data centers (e.g. PA-7500) and branch offices (e.g. PA-400). Included in product revenue: Hardware products.
Software firewalls
VM-Series. Domain: Software firewall. Firewalls for cloud environments (virtual firewalls). Included in product revenue: Software license. Included in NGS ARR: Yes.
CN-Series. Domain: Software firewall. Firewalls for cloud (container environments). Included in NGS ARR: Yes.
Cloud NGFW. Domain: Managed NGFW. Secure applications on public cloud (Amazon Web Services/Microsoft Azure). Included in NGS ARR: Yes.
Cloud-Delivered Security Services (CDSS)
Suite of Cloud-Delivered Security Services (CDSS) that complements SASE and Firewall solution. These are available either as individual subscriptions, bundles for particular use case or as an enterprise license agreement (ELA) to cover the entire network security solutions. Included in NGS ARR: Yes.
Services: Advanced Threat Prevention; Advanced WildFire; Advanced URL Filtering; Advanced DNS Security; IoT/OT Security; SaaS Security API; SaaS Security Inline; GlobalProtect; Prisma Access Agent; Enterprise DLP; AI Access Security; AIOps. Each is included in NGS ARR.
Prisma AIRS (Protect AI). Domain: AI security platform. To protect entire AI ecosystem. Included in NGS ARR: Yes.
Strata Cloud Manager. Domain: Network security management solution. To centrally manage network security under single interface. Included in NGS ARR: Yes.
Panorama. Domain: Policy management and device management. Centralized security management solution. Included in product revenue: Software license. Included in NGS ARR: Yes.
While traditional, networking market was firewall based…
….with a distributed workforce, increase in cloud workloads and SaaS applications, the industry has moved towards cloud-delivered solutions combining networking with security
Networking has evolved from hardware-based appliances towards SASE and is moving towards integrated AI solutions
SASE combines networking capabilities of SD-WAN with security services into a single cloud-based solution.
SSE uses cloud-based services to enforce security policies e.g. inspecting, filtering and security traffic data and apply zero-trust principles by verifying user identities and access rights.
SD-WAN technology manages the connections between data centers, remote offices, and cloud resources, and routes traffic.
Secure web gateway filters and monitors web traffic to enforce corporate policies, detecting and blocking threats in real time
SASE is a cloud-native framework that combines network security functions with SD-WAN
Palo Alto has a first-mover advantage in agentic browser
Agentic browser space is another emerging growth area within network security. Palo Alto describes the browser as “the new operating system” and expects it to become an integral component of the SASE stack. According to Gartner, agentic browser penetration is at less than 10% currently and is expected to increase towards 25% by 2028E.
Palo Alto moved early with its ~$625m acquisition of Talon Cyber Security in 2023. CrowdStrike (Seraphic, ~$420m in 2026) and Zscaler (SquareX, 2026) have since followed, underscoring the competitive importance of the browser as a security layer. Progress has been rapid: Palo Alto reported ~9.0m Prisma Access Browser licences in Q226, up from ~3.0m in Q325, deployed across more than 1,500 customers.
AI to drive Prisma AIRS adoption
Runtime security for AI models remains at an early stage of adoption. While organisations are actively deploying AI, most lack a dedicated platform to secure the entire AI infrastructure stack. Palo Alto launched Prisma AIRS in Q325, providing security capabilities across AI models, AI agents and LLM applications. Early traction has been meaningful, with Prisma AIRS being adopted by over 100 customers with a nine-figure pipeline by Q226. While still at an early stage of monetisation, this pace of adoption has been encouraging. As AI deployment accelerates, we expect AI runtime security to emerge as next growth area for Palo Alto.
Redefining the SOC: security operations and cloud convergence
Security operations ARR grew by 25% yoy to $1.7bn in FY25. While historically security operations and cloud security operated as separate platforms, Palo Alto integrated as a single platform from Q225 onwards. This aligns with the group’s broader platformisation strategy, driving multi-module adoption, higher ARR per customer and platform stickiness.
Cortex is structurally displacing legacy SIEM
Palo Alto delivers security operations through the Cortex platform. Security operations centres have historically relied on SIEM platforms to aggregate logs and investigate incidents, but traditional SIEM architectures are widely regarded as inefficient characterised by high volumes of alert, fragmented data and manual workflows.
Cortex XSIAM addresses these limitations directly. Approximately 60% of Cortex XSIAM customers achieve mean remediation times under 10 minutes, compared with days or weeks under legacy SIEM. Since its launch in late 2022, Cortex XSIAM already become a meaningful contributor scaling to ~600 customers. With more than $500m of ARR as of Q226, Cortex XSIAM represents roughly 30% of security operations ARR and ~6% of group trailing 12-month revenues.
At ~$1.0m average ARR across ~600 customers, penetration of Cortex XSIAM within Palo Alto's 75K installed base remains early-stage. We see Cortex XSIAM as the next leg of growth in security operations, with potential to approach $2bn ARR by FY30E, driven by legacy SIEM displacement and SOC consolidation.
Cortex XSIAM already become a meaningful contributor scaling to ~600 customers in Q226
Cortex XSIAM is a cloud-delivered security operations platform that unifies key functions including EDR, XDR, SOAR, ASM, UEBA, TIM, and SIEM
EDR (Endpoint Detection and Response), XDR (Extended Detection and Response), SOAR (Security Orchestration, Automation, and Response), ASM (Attack Surface Management), UEBA (User and Entity Behaviour Analytics), TIM (Threat Intelligence Management), and SIEM (Security Information and Event Management)
Traditional security operations operate on siloed tools and data
NTA (Network Traffic Analysis), CDR (Cloud Detection and Response), TI Feeds (Threat Intelligence Feeds)
Modern AI-driven security operations platform (Cortex XSIAM) have an automated data integration, analysis and triage
Palo Alto’s cloud security portfolio
Security Operations
Cortex XDR (launched in 2019). Domain: Extended detection and response (XDR). XDR tools gathers data across domains including endpoints, networks, and cloud applications in a single platform for threat detection and response.
Cortex XSOAR (launched in 2019). Domain: Security Orchestration Automation and Response (SOAR). SOAR tools enables security teams to manage incidents across their security product stack and automate repetitive security tasks for the security operations team.
Cortex Xpanse (launched in 2020). Domain: Attack surface management (ASM) solution. Asset discovery across organisation's entire digital estate including IT infrastructure, applications, and cloud resources.
Cortex XSIAM (launched in 2020). Domain: Extended Security Intelligence and Automation Management (XSIAM). Next-generation SOC platform combining SIEM capabilities with SOAR, EDR, ITDR, ASM, CDR, EPP, TIP to automate threat detection and response.
Cloud Security
Cloud-native application protection platform (CNAPP): Unified cloud security solution under single platform.
Cloud Security Posture Management (CSPM): Monitoring of Cloud Infrastructure for misconfigurations.
Cloud Workload Protection Platform (CWPP): Runtime security for cloud workloads (Containers, VMs, and Serverless).
Cloud Infrastructure Entitlement Management (CIEM): Managing access and permissions across cloud services.
Data Security Posture Management (DSPM): Secures data in cloud environment.
Kubernetes Security Posture Management (KSPM): Cloud security for Kubernetes (microservice architecture within cloud).
AI Security Posture Management (AI-SPM): Cloud security for AI models and AI infrastructure.
DevSecOps Integration: Embedding security into application lifecycle during development processes.
API Security: Protecting application programming interfaces (APIs) from cyberattacks.
Repositioning in cloud security
Cloud security remains one of the fastest-growing segments within cybersecurity. Gartner estimates that the market will grow from $10bn in 2024 to $32bn by 2029E (a 26% CAGR), broadly tracking cloud infrastructure expansion.
Cloud security ARR including Prisma Cloud reached ~$700m in ARR by Q424 (the latest period for which disclosure is available). As cloud security posture management faces increasing commoditisation and pricing pressure, Palo Alto has shifted its strategic focus towards higher-value runtime security.
The integration of Prisma Cloud with Cortex enables unified visibility across cloud, endpoint and network layers, allowing cloud-detected threats to be investigated within the SOC. We believe with this integration Palo Alto arguably has one of the most integrated cloud and security platforms which fundamentally differentiates Palo Alto in an increasingly crowded and fast-growing cloud security market.
Aggregate cloud revenues from three major cloud providers is expected to reach $765bn by 2029E (a 29% CAGR)
Quantum computing is expected to share the next S-curve for cybersecurity
We are still here: Early stages of AI; Zero Trust, Cloud and SaaS adoption still have legs.
Positioning for quantum era
Palo Alto has historically demonstrated an ability to position early for structural inflection points within cybersecurity, and quantum security is the latest example. Cyber attackers are intensifying their efforts, using a “harvest now, decrypt later” strategy. Recognising these threats, the US government is mandating post-quantum cryptography standards, and quantum security has now become “a C-level priority”.
During FY26, management articulated Palo Alto’s quantum security strategy for the first time, with initiatives spanning PAN-OS 12.1 Orion (a cryptographic inventory tool that maps encryption risk across an organisation’s digital estate), fifth-generation firewall appliances optimised for quantum-safe encryption standards, backward compatibility solutions for legacy systems and a partnership with IBM on quantum-safe readiness.
While quantum security is expected to drive the next S-curve for cybersecurity, we consider quantum security as an early-stage strategic positioning rather than a near-term revenue driver. These early-stage capabilities position Palo Alto ahead of the competitive curve in preparation for a post-quantum threat environment.
Key investment point four: operational gearing
Palo Alto has delivered ~1,100bp of non-GAAP operating margin expansion since FY20, scaling from 17.6% to 28.8% in FY25. Over the same period, free cash flow margins have increased from 24.0% to 37.6% in FY25. Two structural forces have driven margin expansion: 1) operational gearing with an increasing revenue base; 2) an ongoing mix shift towards a higher-margin, software-led business.
Operating margin expansion been achieved even as gross margins have compressed, with gross margins declining from 77.6% in FY24 to 76.4% in FY25. The pressure reflects higher costs associated with cloud-based subscription delivery and AI-related inference costs. While traditional cloud-delivered security services (eg next-generation firewalls) run on CPU 18-based infrastructure where per-unit marginal costs decline with scale, AI-driven products such as Prisma AIRS, Cortex XSIAM and Prisma SASE carry GPU 19 intensive workloads where costs scale up directly with usage. This is visible in Palo Alto’s increased cloud hosting costs, which rose by $190m in FY25 compared with a $116m increase in FY24 and a $101m increase in FY23.
Gross margin pressure reflects higher costs associated with cloud-based subscription delivery
The cost of subscription and support has increased driven by cloud-delivered security services
At ~76.4%, Palo Alto’s non-GAAP gross margin sits nearly 350bp below the cybersecurity peer average of ~80%. We view this gap as largely transitory. Over time, we expect gross margins to recover as the absolute cost of AI inference declines with hardware improvements, GPU utilisation rates improve at scale, AI-driven features are more explicitly monetised and the initial gross margin dilution from platformised bundles normalises as cohorts mature.
In the near term, however, operating margin expansion will be tempered by recent acquisitions. CyberArk currently operates at ~20% non-GAAP operating margins, meaningfully below Palo Alto’s ~29% operating margin. Chronosphere is also likely to be margin-dilutive, although the absolute impact is less material given its scale (~$200m ARR).
FY26E guidance reflects this margin drag, with management guiding to limited margin expansion, and forecasting a FY26E non-GAAP operating margin range of 28.5-29.0% compared with 28.8% non-GAAP operating margin in FY25.
We view margin pressure as largely transitory: as AI inference costs normalise and headwinds from platformised bundles normalise, we expect Palo Alto’s gross margin to improve
Management expects CyberArk’s margin to converge towards the group average within approximately 24 months, driven by cost synergies and integration onto Palo Alto’s go-to-market infrastructure.
Management’s long-term ambition is to reach non-GAAP operating margins in the low to mid-30s. On free cash flow, management is guiding to at least ~37% FCF margins in the near to medium term, with a target of ~40% by FY28E.
The structural gap between operating and FCF margins reflects the cash flow dynamic inherent in subscription models (cash is collected upfront while revenue is recognised over time). Historically, Palo Alto FCF margins were 800-1,000bp above operating margins and we expect this this gap to persist as the subscription mix continues to increase.
Management has consistently delivered score greater than 50 on the Rule-of-40 metric
The combination of sustained double-digit revenue growth and margin expansion has kept Palo Alto consistently above 50 on the Rule-of-40 (revenue growth plus FCFE margin), placing it among the highest growth-plus-profitability cohorts within the cybersecurity peer group.
Financials
Revenue bridge for Palo Alto
The following discussion outlines Palo Alto’s revenue bridge, with headline growth split between M&A contribution and organic growth.
- FY26E revenues: We forecast revenues of $11.31bn (the top end of the $11.28bn-11.31bn guidance range; consensus: $11.29bn), implying 22.7% yoy growth. This includes $760m from CyberArk and Chronosphere (a six-month contribution), with organic growth of 14.4% yoy (versus 14.9% in FY25).
- FY27E revenues: We forecast revenues of $13.69bn, implying 21.1% yoy headline growth. Excluding ~$936m M&A contribution, we estimate organic growth of 12.8% yoy.
- NGS ARR: We forecast $8.61bn of NGR ARR in FY26E (top end of $8.5bn-8.62bn guidance range; consensus: $8.58bn), implying 54.3% yoy growth, including $1.52bn from M&A. On an organic basis, we estimate 27.0% yoy growth in FY26E (versus 32.9% in FY25) and 24.0% yoy in FY27E.
Our revenue estimates are 2-4% higher than consensus
Our FY26E revenue and operating profit estimates are broadly in line with consensus. However, our FY27E-30E forecasts are 2-4% ahead, reflecting higher NGS ARR assumptions and increased platformisation.
Our analysis suggests that consensus models assume only ~2,600 platformisations by FY30E, below the mid-point of management’s 2,500-3,500 target range. We would expect ~6% upside to FY30E consensus if the company reaches the mid-point of this range, and ~14% upside at the upper end.
Valuation scenarios
The valuation discussion uses an illustrative DCF scenario to examine the long-duration nature of the business, with EV/sales comparisons against peer and historical multiples.
Palo Alto has de-rated from average EV/sales of ~13x during 2024-2025 to ~9x despite no deceleration in organic growth run-rate, improved revenue quality and greater scale. Palo Alto trades at a 10% discount to large-cap software market cap weighted EV/sales multiple of 11x despite higher score on Rule-of-40 metric. While the stock trades at a premium to wider cybersecurity median EV/sales multiple of 4.9x, we believe this is justified by platform scale, long-term compounding potential, and consistent execution.
Upgrades have been a consistent feature at Palo Alto: change in FY1 consensus sales and operating profit expectations
The stock has de-rated despite no change in organic growth revenue run-rate and improving revenue mix
Illustrative DCF assumptions
The illustrative DCF assumptions are as follows.
- Discount rate: We use a 9.0% discount rate, based on a cost of equity (CoE) of 9.0% (100% weighting). Our CoE assumes a 4.0% risk-free rate, 4.5% equity risk premium, and a 1.1x beta.
- Explicit stage (FY26E-31E): We model 15% revenue CAGR, with operating margins expanding from 28.7% in FY26E to 32.2% by FY31E.
- Consolidation stage (FY32-35E): We assume 10% revenue CAGR, with operating margins reaching 33.0% by the end of the period.
- Fade stage (FY36E-39E): We model 7% revenue CAGR, with operating margins trending towards ~35% by end of fade stage, in line with mature software peers.
- Terminal growth rate: We apply a 3.5% terminal growth rate.
Business drivers of valuation multiples
An illustrative DCF scenario corresponds to a 2026E EV/sales multiple of ~13x, broadly in line with the average EV/sales multiple at which the stock traded during 2024 and 2025. The following business-model drivers help explain the basis for a valuation premium relative to the broader cybersecurity peer group.
- First, improving revenue quality: Revenue quality has structurally improved, with subscription and support revenues now representing ~80% of total (versus 62% in FY19), while the higher-quality subscription component alone accounts for ~54% of group revenue (versus 36% in FY19).
- Second, superior growth-plus-margin profile at scale: Palo Alto’s combination of growth and profitability is exceptional for its scale, ranking just below Palantir Technologies on the Rule-of-40 metric among large-cap software companies (>$50bn market cap). Our implied 2026E EV/sales multiple of 13x remains ~21% below CrowdStrike (17x) and ~44% below Cloudflare (25), despite Palo Alto delivering a higher Rule-of-40 score of 56 : ~4% above CrowdStrike (52) and ~33% above Cloudflare (40).
- Third, platform premium driven by successful platformisation: Palo Alto has successfully transformed from a hardware-led firewall vendor into a scaled cybersecurity platform spanning network, cloud, security operations, identity, and observability. As enterprises consolidate vendors and prioritise integrated platforms, Palo Alto is well positioned to capture a disproportionate share of spend, justifying a platform premium.
On EV/sales adjusted for growth, Palo Alto is trading below parity (at 0.7x)…
…and trades below some of its software peer group despite its best-in-class score in the Rule-of-40 metric
Key risks
- Palo Alto’s strategy increasingly relies on acquisitions to expand platform capabilities, which introduces execution risk in relation to integration, product rationalisation and go-to-market alignment.
- While we view AI as a net positive in the longer term, there is a risk that certain use cases are commoditised faster than expected, affecting growth in specific segments.
- Premium multiples embed near-flawless execution. Any deceleration in NGS ARR or platformisation could trigger earnings downgrades and/or de-rating.
Sustainability
Mapping to the UN Sustainable Development Goals (SDGs)
Adjusted SDG Framework
The Adjusted Sustainable Development Goal framework is based on the United Nations’ (UN) Sustainable Development Goals (SDGs). The SDGs are a roadmap for sustainable economic growth, incorporating a balance of environmental, social and economic development factors. They are a “universal call to action to end poverty, protect the planet and ensure that all people enjoy peace and prosperity by 2030”.
The framework was created by analysing each of the 169 targets supporting the UN’s 17 SDGs, converting them into criteria that reflect corporate activities.
How does Palo Alto map to the adjusted SDG framework?
Palo Alto – adjusted SDG profile
Goal 8 – Decent Work and Economic Growth. Criterion: "Provide services, including financial services, to support SMEs". Provides cybersecurity solutions tailored for SMEs, supporting the cyber resilience of SMEs. Direction of travel: Neutral/Negative.
Goal 16 – Peace, Justice and Strong Institutions. Criteria: "Promote the rule of law and develop effective and secure institutions"; "Reduce illicit financial flows and reduce violence, terrorism, crime and exploitation of children"; "Strengthen national institutions to prevent violence, terrorism, crime and protect fundamental freedoms". Provides AI-driven security solutions for networks, cloud and security operations, helping to reduce exposure to cybercrime and supporting the development of effective and secure institutions. Direction of travel: Positive/Neutral.
We align ~95% of Palo Alto’s revenue to the adjusted SDG framework. We align ~95% of revenue to SDG 16 (Peace, Justice and Strong Institutions) ,relating to the provision of cybersecurity solutions for networks and cloud operations, helping to reduce exposure to cybercrime and supporting the development of effective and secure institutions. We also align ~7.5% of revenue to Goal 8 (Decent Work and Economic Growth), relating to the provision of cybersecurity solutions for SMEs. We have also negative flagged revenue exposure to oil and gas (~5%) and defence (~7.5%) end-markets.
Palo Alto is US-listed and therefore does not disclose EU taxonomy alignment.
Sustainability credentials
According to the SASB (Sustainability Accounting Standards Board) Standards (part of the non-profit International Financial Reporting Standards Foundation), the key sustainability topics for Palo Alto (using the software and IT services standards) are: environmental footprint of hardware infrastructure, data privacy and freedom of expression, data security, recruiting and managing a global, diverse and skilled workforce, intellectual property protection and competitive behaviour, and managing systemic risks from technology disruptions. In addition, we also consider greenhouse gas (GHG) emissions an important sustainability topic.
Compared to the wider cybersecurity sector, we believe Palo Alto provides a fairly detailed report on its sustainability performance although consistency in disclosures beyond GHG emissions is sparse. In terms of targets, Palo Alto has set a target to achieve net-zero emissions across Scope 1, 2, and 3 emissions by 2040 and this target has been validated by the Science-Based Targets initiative (SBTi) (using FY21 as a baseline). Beyond GHG emissions and renewable energy procurement, we note that minimal targets have been set.
GHG emissions
In terms of performance, Palo Alto’s Scope 1 and 2 emissions grew by a CAGR of 24% between FY20 and FY25, from 5,886 tCO2e to 17,208 tCO2e, reflecting expansion of workspace footprint, while its emissions intensity per square foot reduced by 2% (using FY21 as a baseline). During FY25, Palo Alto’s Scope 3 emissions increased 12% yoy to 966,466 tCO2e, driven by emissions associated with purchased goods and services, business travel, investments and use of sold products, and partially offset by lower emissions for employee commuting and upstream transportation and distribution.
In terms of its near-term targets, the company commits to reduce absolute Scope 1 and 2 GHG emissions 35% by FY27 from a FY21 base year. In the near term, the group is driving energy efficiency and supporting a reduction in emissions across its buildings and products and increasing its portfolio of green building certified workplaces. Palo Alto is also delivering energy-efficient hardware products and engaging in partnerships. Further, Palo Alto has committed to purchasing 100% renewable electricity for managed sites by FY30.
In terms of Scope 3 emissions, 51% of Palo Alto’s suppliers have now set or committed to set science-based targets. The company commits that 65% of its suppliers by emissions covering purchased goods and services will have science-based targets by FY27. Palo Alto also commits to reduce Scope 3 emissions from use of sold products by 40% per million USD value added within the same timeframe.
Further, Palo Alto has set a target to achieve net zero across Scope 1, 2, and 3 by FY40 and this target has been validated by the SBTi (using FY21 as a baseline). To achieve its net-zero target, Palo Alto is focused on operational efficiencies, procuring 100% renewable electricity, developing sustainable and efficient products, and engaging with landlords and vendors to increase renewable electricity procurement at leased sites and data centres.
Environmental footprint of hardware
In FY25, Palo Alto procured 100% renewable energy for its headquarters (Santa Clara, California) and one its office (Plano, Texas). At the end of FY25, 92% of its managed workplaces were green-building-certified.
Water withdrawals increased from 95 megalitres in FY24 to 100 megalitres in FY25, and percentage of water withdrawals in water-stressed regions increased from 23% in FY24 to 36% in FY25.
Data privacy and data security
Companies within the cybersecurity sector have strong compliance with various regulatory requirements, as well as industry-standard certifications in relation to both data privacy and data security. Palo Alto complies with various regulations to align its business with various data protection frameworks around the world, including self-certification to the EU-US Data Privacy Framework in the EU, the UK and Switzerland.
Palo Alto also provides various training programs for its employees. In FY25, 97% of employees completed annual data privacy training, and 98% completed annual InfoSec Compliance training.
That said, we note minimal disclosure of the quantitative metrics in relation to this SASB topic, including the number of data breaches and the total amount of monetary losses as a result of legal proceedings.
Recruiting and managing a global, diverse and skilled workforce
Being a tech company, Palo Alto uses data and behavioural science to improve its employee productivity, with 92% of its employees adopting AI tools in FY25, while the business also adopts a focus on hiring “AI-ready talent”. The company aims to support a thriving and engaged workforce and during 2025 undertook significant efforts to revamp its employee engagement and feedback efforts, to identify opportunities for improvement and drive action. We note that Palo Alto’s voluntary attrition rate has fallen, from 13% in FY23 to 7.9% in FY25. In terms of training, Palo Alto offers a range of tools for employees to expand their capabilities, including self-guided programmes through its learning centre. Supported by its broad offering, average hours of development per employee reached 36 in FY25, up from 12 in FY22.
In terms of gender diversity, we note that Palo Alto has not disclosed this data since FY23. Looking at the historical data, 26% of employees were female in FY23, up from 25% in FY21, while 24% of directors and above were female in FY23 compared with 22% in FY21. Palo Alto has not set specific targets on gender diversity.
Intellectual property protection and competitive behaviour
We note minimal disclosure regarding intellectual property protection and competitive behaviour. In its annual report, Palo Alto has disclosed that the group is subject to legal proceedings, including intellectual property and patent litigation, in the ordinary course of business, and the group accrues for contingencies when a loss is probable.
Managing systems risks from technology disruptions
While there is minimal disclosure regarding managing systems risks from technology disruptions, we note Palo Alto has a dedicated operational resilience team that annually validates and tests business continuity plans, and its security committee is responsible for enterprise cybersecurity and data protection risks, and overseeing the group’s cyber crisis preparedness, security breach and incident response plans. In the past, Palo Alto has experienced supply chain disruption due to changes in US trade policy, and the group closely monitors geopolitical developments, in particular between China and Taiwan and the US and China that could affect its supply chain.
Governance
Palo Alto meets 4 of the 10 governance criteria. Palo Alto could improve by increasing female board representation and linking ESG KPIs to management remuneration.
Palo Alto – governance profile
Board structure. Current: 10 members. Chairperson/ CEO, CTO, 8 independent directors. Criterion: At least six board members, more than half of whom are independent. Criterion met: Yes.
Male/female board representation. Current: 70% / 30%. Criterion: At least 40% female board representation. Criterion met: No.
Senior board positions held by women. Current: Co-Chair of Governance and Sustainability Committee. Criterion: At least one senior board position held by a woman. Criterion met: Yes.
Average board tenure. Current: 7.8 years. Criterion: Average board tenure of 2-7 years. Criterion met: No.
Separate chairperson/CEO. Current: No. Criterion: Separate CEO and chairperson. Criterion met: No.
Shareholder structure. Current: 99.05% free float. Large insider holders. Share classes. Criterion: Largest shareholder <50% voting rights. Criterion met: Yes.
CEO-to-worker pay ratio. Current: 442:1. Criterion: CEO-to-worker pay ratio <100. Criterion met: No.
Board committees. Current: Audit, Compensation and people, Corporate development, Governance and sustainability, Security. Criterion: Board sustainability committee. Criterion met: Yes.
Management shareholdings. Current: CEO 0.13%, CTO 0.12%. Criterion: CEO shareholding >0.5%. Criterion met: No.
Management remuneration linked to ESG?. Current: No. Criterion: Management remuneration linked to disclosed ESG KPIs. Criterion met: No.
Five key sustainability questions for management
1) What plans are in place to embed ESG KPIs within management remuneration?
2) Are there plans in place to set targets in relation to diversity?
3) Have there been issues relating to data breaches to date? If so, what policies have been established to help mitigate this risk?
4) The share of water withdrawals in water-stressed regions has increased yoy: what work is being carried out to manage this risk in future?
5) How does Palo Alto support its suppliers in setting SBTi targets in light of its 2027 target?
Notes and definitions
- Secure Access Service Edge (SASE), Extended Detection and Response (XDR), Extended Security Intelligence and Automation Management (XSIAM) Back to text
- Software as a Service (SaaS) Back to text
- Security Information and Event Management (SIEM) Back to text
- Security Operations Centre (SOC) Back to text
- Annual recurring revenue (ARR) Back to text
- Breakout time measures how quickly a cybercriminal moves laterally from an initially compromised machine to other systems within a network. Back to text
- Using security flaws in a software to infiltrate networks. Back to text
- Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), Extended Detection and Response (XDR) Back to text
- SSO (Single Sign-On); MFA (Multi-Factor Authentication); PAM (Privileged Access Management); IGA (Identity Governance and Administration); CIEM (Cloud Infrastructure Entitlement Management); ITDR (Identity Threat Detection and Response). Back to text
- CSPM (Cloud Security Posture Management); CWPP (Cloud Workload Protection Platform); CIEM (Cloud Infrastructure Entitlement Management); CDR (Cloud Detection and Response); CNAPP (Cloud-Native Application Protection Platform). Back to text
- Chief Information Security Officer Back to text
- The group reported greater than $2.0m average ARR per platformised customer in FY24. We have assumed mid-single digit compounding growth to get to $2.25m of average ARR per platformised customer. Back to text
- Software-defined wide area network (SD-WAN) Back to text
- Source: Appliance market share sourced from IDC, March 2025 market share report Back to text
- Source: Palo Alto Networks 2025 investor presentation Back to text
- SASE market share calculated based on $12.2bn global SASE market and $1.5bn of SASE ARR reported by Palo Alto for January 2026 Back to text
- Source: Omdia 2025 press release Back to text
- CPU (Central Processing Unit) Back to text
- GPU (Graphics Processing Unit) Back to text
Read the Palo Alto Networks company profile · Browse Companies · Back to top