Palo Alto Networks Stock price
Compare with Peer Group
📊 Peer Group
📈 What is it?
The peer group consists of the companies with the most similar business model. They serve as a benchmark for putting a stock into context.
🧮 How is it selected?
Based on similarity of business model, meaning companies from the same industry with comparable products and a similar customer base. That's the only way to compare apples to apples.
🏛️ Why does it matter?
Whether a stock is cheap or expensive is best judged by comparison. A P/E of 18 or an EV/FCF of 20 can look cheap or expensive depending on the yardstick. The peer group gives you the most accurate one: companies with a similar business model that operate under the same conditions.
🎯 What does it mean for investors?
When a metric sits below the peer average, the stock is valued more cheaply relative to its competitors, and above the average more expensively. A discount to the peer group can be an opportunity, but it can also have a reason (for example lower growth). The comparison is a starting point, not a verdict.
AI Insights on Palo Alto Networks
Insights
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Create a Free Account to create an Palo Alto Networks alert.
Set up alerts on Stock Price, Dividend Yield, Valuation (e.g. P/E or EV/Sales) or Strategy Scores and sit back and relax.
StocksGuide Free
Key metrics
📘 Market Capitalization
📈 What is it?
Market capitalization shows how much a company is currently worth on the stock market.
🧮 How is it calculated?
🏛️ Why is it important?
It helps classify companies by size (Large, Mid, Small Cap) and indicates their market presence and relative stability.
🧮 Calculation
🎯 What does this mean for investors?
- Large-cap companies tend to be more stable, often pay dividends, but may grow more slowly.
- Smaller firms may offer higher growth potential but come with more volatility.
- Market capitalization is a useful indicator of company size — but not a measure of whether a stock is undervalued or overvalued.
📘 Enterprise Value (EV)
📈 What is it?
Enterprise Value represents the total cost to acquire a company — including its debt and excluding its cash reserves.
🧮 How is it calculated?
(= Market Cap + Net Debt)
🏛️ Why is it important?
EV gives a more complete picture of a company's value than market cap alone and is used in key valuation ratios like EV/FCF or EV/Sales.
🧮 Calculation
🎯 What does this mean for investors?
- Enterprise Value shows the true cost of buying a company, including all financial obligations.
- It is more accurate than just looking at market cap, especially when comparing companies with different levels of debt or cash.
- Professional investors prefer EV-based multiples because they better reflect the company’s full financial footprint.
📘 Net Debt
📈 What is it?
Net Debt shows how much debt remains after subtracting a company’s available cash reserves.
🧮 How is it calculated?
🏛️ Why is it important?
It indicates how dependent a company is on borrowed money and how easily it can service its debt in the short term.
🧮 Calculation
🎯 What does this mean for investors?
- Low or negative net debt signals financial strength and flexibility.
- Companies with strong cash positions are better positioned in crises.
- High net debt increases financial risk — especially in environments with rising interest rates or economic downturns.
📘 Cash
📈 What is it?
Cash represents all liquid assets a company can access immediately — including cash, bank deposits, and short-term investments.
🧮 How is it calculated?
🏛️ Why is it important?
It reflects a company’s financial flexibility and resilience — enabling investments, buybacks, or buffer in downturns.
🧮 Calculation
🎯 What does this mean for investors?
- A strong cash position means greater room for maneuver and crisis resistance.
- Cash-rich companies can invest, pay down debt, or repurchase shares.
- But excess idle cash might indicate a lack of growth opportunities.
📘 Shares Outstanding
📈 What is it?
Shares outstanding represent the total number of a company’s shares currently held by investors — excluding treasury stock.
🧮 How is it calculated?
🏛️ Why is it important?
It’s the basis for key metrics like Earnings Per Share (EPS), Market Capitalization, or the Price/Earnings ratio (P/E).
🧮 Calculation
🎯 What does this mean for investors?
- Fewer shares in circulation typically increase earnings per share — making each share more valuable.
- Share buybacks reduce the number of shares and boost per-share metrics.
- Issuing new shares does the opposite — diluting shareholder value and lowering per-share figures.
📘 Price-to-Earnings Ratio (P/E)
📈 What is it?
The P/E ratio shows how many times a company's earnings per share are reflected in its current share price — in other words, how "expensive" the stock appears relative to its profits.
🧮 How is it calculated?
🏛️ Why is it important?
The P/E ratio is one of the most widely used valuation metrics. It helps investors assess whether a stock appears cheap or expensive compared to its earnings power.
🧮 Calculation
📊 P/E (TTM) = Based on earnings from the last 12 months (Trailing Twelve Months):🎯 What does this mean for investors?
- A low P/E may indicate undervaluation — or signal underlying issues.
- A high P/E may reflect strong growth expectations — or an overvalued stock.
📘 Price-to-Sales Ratio (P/S)
📈 What is it?
The P/S ratio shows how much investors are paying for $1 of the company’s revenue – regardless of profitability.
🧮 How is it calculated?
🏛️ Why is it important?
P/S is especially useful for evaluating growth companies or businesses not yet profitable. It reflects how the market values the company’s sales.
🧮 Calculation
Market Cap = $297.41b | Revenue (TTM) = $11.48b
Market Cap = $297.41b | Estimated Revenue = $14.06b
🎯 What does this mean for investors?
- A low P/S may indicate undervaluation — or low profitability.
- A high P/S can reflect strong growth expectations — or excessive optimism.
- Especially helpful when evaluating companies where profits are low, volatile, or negative.
📘 Enterprise Value to Sales (EV/Sales)
📈 What is it?
EV/Sales shows how much investors are paying for $1 of revenue — considering not just equity, but also debt and cash. It’s the capital structure–adjusted version of the P/S ratio.
🧮 How is it calculated?
🏛️ Why is it important?
It’s ideal for comparing companies with different levels of debt. It reflects a company's true cost relative to its revenue.
🧮 Calculation
Enterprise Value = $295.65b | Revenue (TTM) = $11.48b
Enterprise Value = $295.65b | Forward Revenue = $14.06b
🎯 What does this mean for investors?
- EV/Sales allows for capital structure–neutral company comparisons.
- A lower ratio may indicate undervaluation; a higher one may signal strong growth expectations or overvaluation.
- Especially helpful when evaluating high-growth companies with low or negative earnings.
📘 Enterprise Value to Free Cash Flow (EV/FCF)
📈 What is it?
EV/FCF shows how many years it would take for a company to "pay back" its enterprise value using its free cash flow.
🧮 How is it calculated?
🏛️ Why is it important?
It focuses on real cash generation, ignoring accounting noise — ideal for assessing profitability and value based on liquidity, not earnings.
🧮 Calculation
🎯 What does this mean for investors?
- A low EV/FCF may signal undervaluation and strong cash generation.
- A high EV/FCF might reflect weak recent cash flow or aggressive growth expectations.
- Best suited for stable, mature businesses with predictable free cash flows.
📘 Price-to-Book Ratio (P/B)
📈 What is it?
The P/B ratio compares a company’s market value to its book value — showing how much investors are paying for each dollar of net assets.
🧮 How is it calculated?
🏛️ Why is it important?
P/B is commonly used for asset-heavy industries like banks or industrials. It helps assess whether a stock is trading above or below its net asset value.
🧮 Calculation
🎯 What does this mean for investors?
- A P/B below 1 may signal undervaluation — or weak profitability.
- A P/B above 1 implies the market expects future value creation (e.g., brand, IP, growth).
- Best used for companies with tangible assets and strong balance sheets.
📘 Equity Ratio
📈 What is it?
The equity ratio indicates what portion of a company’s total assets is financed by shareholders’ equity – in other words, how much it relies on its own capital.
🧮 How is it calculated?
🏛️ Why is it important?
A high equity ratio reflects financial strength and stability, especially during downturns. It’s a key indicator of a company’s solvency and long-term risk profile.
🧮 Calculation
🎯 What does this mean for investors?
- Companies with high equity ratios are generally more resilient and less dependent on external debt.
- Low equity ratios can signal higher risk or aggressive financial strategies.
- Important: Always assess the equity ratio in combination with the return on equity (ROE). This shows not just how stable the company is – but also how efficiently it uses shareholder capital.
📘 Return on Equity (ROE)
📈 What is it?
Return on equity (ROE) shows how efficiently a company uses its shareholders’ equity to generate profit. In other words: how much net income is earned per dollar of equity.
🧮 How is it calculated?
🏛️ Why is it important?
ROE is a core profitability metric. It helps investors understand whether a company delivers attractive returns on the capital provided by its shareholders.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROE indicates that the company is using its capital efficiently and profitably.
- It’s especially meaningful for capital-intensive businesses or firms with high equity bases.
- Important: A very high ROE can also result from high debt levels – always interpret it alongside the equity ratio to assess financial health.
📘 Return on Capital Employed (ROCE)
📈 What is it?
ROCE measures how efficiently a company generates profits from its total capital – including both equity and interest-bearing debt.
🧮 How is it calculated?
It evaluates the return on all capital employed, regardless of how it’s financed.
🏛️ Why is it important?
ROCE is ideal for comparing companies with different financing structures. It shows how well management uses capital to create value for both shareholders and creditors.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROCE means the company uses its capital efficiently – regardless of whether it's funded by debt or equity.
- The higher the ROCE compared to peers, the more value the company creates with its invested capital.
- Especially relevant for capital-intensive sectors like industrials, energy, or infrastructure.
📘 Return on Invested Capital (ROIC)
📈 What is it?
ROIC measures how efficiently a company generates returns from the capital invested in its core operations – regardless of whether the capital comes from equity or debt.
🧮 How is it calculated?
- NOPAT = Net Operating Profit After Taxes
- Invested Capital = Operating assets minus non-interest-bearing liabilities
🏛️ Why is it important?
ROIC is one of the most accurate indicators of capital efficiency. Unlike return on equity, it is not distorted by leverage and shows how much value is created for all capital providers.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROIC shows how effectively a company uses the capital that is truly invested in its core operations.
- Unlike ROCE, ROIC focuses only on the capital that is actively used to run the business – and that requires a return (i.e. interest-bearing).
- Especially useful when comparing companies with large amounts of excess cash or non-interest-bearing liabilities – giving a more realistic picture of capital efficiency.
📘 Leverage Ratio (Debt-to-Equity)
📈 What is it?
The leverage ratio indicates how much a company relies on interest-bearing debt (such as loans and bonds) relative to its shareholders’ equity.
🧮 How is it calculated?
🏛️ Why is it important?
This ratio helps assess a company’s financial structure and risk profile. High leverage can enhance returns – but also increases exposure to interest rate changes and financial stress.
🧮 Calculation
🎯 What does this mean for investors?
- A low leverage ratio signals financial strength and independence.
- A higher ratio can improve returns in good times but increases risk during downturns or rising interest rate periods.
- 👉 Always interpret in the context of industry, capital intensity, and interest rate environment.
📘 Revenue
📈 What is it?
Revenue shows how much a company earns in total from selling its products and services – the gross income before any costs are deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Revenue is one of the key figures to assess a company’s size, market position, and growth potential.
🧮 Calculation
🎯 What does this mean for investors?
- Growing revenue indicates rising demand and can be an early signal of future earnings growth.
- Comparing actual and expected revenue reveals trends in the market environment and analyst sentiment.
- Note: Strong revenue alone isn’t enough – margins and profitability matter just as much.
📘 EBITDA
📈 What is it?
EBITDA stands for “Earnings Before Interest, Taxes, Depreciation, and Amortization.” It reflects a company’s operating profit before the effects of financing, taxes, and accounting depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
EBITDA is widely used to evaluate a company’s operating performance – especially across capital-intensive sectors or international comparisons.
🧮 Calculation
🎯 What does this mean for investors?
- A high or growing EBITDA indicates strong operational profitability – independent of taxes, interest, or accounting methods.
- It’s especially useful for comparing companies across sectors or geographies.
- Important: EBITDA is not a net income figure – it excludes key costs like depreciation and interest.
📘 EBIT
📈 What is it?
EBIT stands for “Earnings Before Interest and Taxes.” It reflects a company’s operating profit after depreciation, but before interest and tax expenses.
🧮 How is it calculated?
🏛️ Why is it important?
EBIT is a core profitability metric that shows how well the company performs in its main business operations – independent of capital structure and tax environment.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT indicates strong profitability from the company’s core business – before financial and tax effects.
- It allows better comparison between companies with different debt levels or tax structures.
- Compared to EBITDA, EBIT already accounts for depreciation and reflects capital intensity more clearly.
📘 Net Income
📈 What is it?
Net income is the company’s total profit – the amount left after all expenses, taxes, interest, and depreciation have been deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Net income is the most comprehensive measure of a company’s profitability – showing how much actual profit remains after all business and financing costs.
🧮 Calculation
🎯 What does this mean for investors?
- Growing net income indicates that the company is managing all of its costs efficiently.
- It directly influences valuation metrics like P/E ratio and the company’s dividend capacity.
- Over time, net income trends reveal how resilient and profitable the business model really is.
📘 Free Cash Flow (FCF)
📈 What is it?
Free Cash Flow shows how much actual cash remains after a company covers its operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Calculation
🎯 What does this mean for investors?
- High free cash flow means the company generates real, usable cash – independent of reported net income.
- It’s often the most reliable base for sustainable dividends and buybacks.
- Declining FCF can be an early warning sign – even when profits appear stable.
📘 Revenue Growth
📈 What is it?
Revenue growth shows how much a company’s sales have changed compared to the previous year – both on a trailing basis (TTM) and based on forward projections.
🧮 How is it calculated?
Forward = (Expected revenue ÷ Revenue in prior year − 1) × 100
Forward growth is based on analyst estimates for the current fiscal year.
🏛️ Why is it important?
Rising revenue signals growing demand, business expansion, and market share gains – especially important for growth-oriented companies.
🧮 Calculation
🎯 What does this mean for investors?
- Growth is the engine of long-term value creation – especially in tech and growth sectors.
- What matters is not just current growth, but its sustainability.
- Forward projections reflect whether analysts expect continued momentum – or a slowdown.
📘 EBITDA Growth
📈 What is it?
EBITDA growth shows how much a company’s operating profit (before interest, taxes, depreciation, and amortization) has increased or decreased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBITDA ÷ EBITDA from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
Growing EBITDA indicates improving operational profitability – regardless of financing or accounting effects.
🧮 Calculation
🎯 What does this mean for investors?
- Strong EBITDA growth signals operational efficiency and scalability – especially during growth phases.
- EBITDA growth can be an early indicator of margin and earnings expansion – but should be assessed alongside revenue and EBIT.
📘 EBIT Growth
📈 What is it?
EBIT growth shows how much a company’s operating profit (after depreciation, but before interest and taxes) has increased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBIT ÷ EBIT from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
EBIT growth is a direct indicator of a company’s business performance – taking into account capital intensity through depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- Rising EBIT signals improving operating profitability – even after accounting for depreciation.
- It’s especially important for evaluating companies with significant capital expenditures.
- Combined with revenue and EBITDA growth, EBIT growth provides a well-rounded view of operational progress.
📘 Net Income Growth
📈 What is it?
Net income growth shows how much a company’s bottom-line profit has increased or decreased compared to the previous year – both on a trailing basis (TTM) and based on analyst projections.
🧮 How is it calculated?
Forward = (Expected net income ÷ Net income from prior year − 1) × 100
The forward estimate reflects analysts’ expectations for the current fiscal year.
🏛️ Why is it important?
Net income is the ultimate measure of profitability. Growing net income signals stronger efficiency, cost control, and sustainable earnings power.
🧮 Calculation
🎯 What does this mean for investors?
- Stronger net income boosts valuation, dividend potential, and investor confidence.
- If profits stall while revenue grows, it may signal margin pressure.
📘 Free Cash Flow Growth
📈 What is it?
Free cash flow (FCF) growth shows how a company’s available cash – after covering operating expenses and capital expenditures – has changed compared to the previous year.
🧮 How is it calculated?
🏛️ Why is it important?
Free cash flow reflects real financial strength. Growing FCF indicates more flexibility for dividends, share buybacks, and reinvestment.
🧮 Calculation
🎯 What does this mean for investors?
- Declining FCF may point to rising investments, increasing costs, or weaker operating performance.
- Especially for dividend investors, FCF growth is critical – since dividends are paid from actual available cash.
- A negative trend isn't always bad, but it deserves closer attention.
📘 Gross Margin
📈 What is it?
Gross margin shows how much of a company’s revenue remains after deducting the direct costs of goods sold (like materials and production). It represents the company’s “raw profit” before fixed costs, taxes, and interest.
🧮 How is it calculated?
Or simply: Gross Margin = Gross Profit ÷ Revenue × 100
🏛️ Why is it important?
Gross margin indicates how efficiently a company can produce or procure what it sells. It is a key measure of product-level profitability and pricing power.
🧮 Calculation
🎯 What does this mean for investors?
- A high gross margin suggests strong pricing power and efficient production.
- Falling margins may signal rising input costs or competitive pressure.
- Compared to peers, gross margin offers insights into the quality of a business model.
📘 EBITDA Margin
📈 What is it?
The EBITDA margin shows how much of a company’s revenue remains as operating profit before interest, taxes, depreciation, and amortization.It reflects operating efficiency without being distorted by financing or accounting factors.
🧮 How is it calculated?
🏛️ Why is it important?
The EBITDA margin reveals how much operating income a company generates per dollar of revenue – independent of capital structure and tax effects.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBITDA margin reflects strong core profitability – before accounting distortions.
- It allows for effective comparisons across companies and sectors.
- A stable or growing margin signals efficient cost control and business scalability.
📘 EBIT Margin
📈 What is it?
The EBIT margin shows what percentage of revenue remains as operating profit after depreciation but before interest and taxes.
🧮 How is it calculated?
🏛️ Why is it important?
The EBIT margin reflects a company’s core profitability while accounting for capital intensity (e.g. machinery, infrastructure). It’s especially useful for comparing businesses with different levels of depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT margin shows that the company remains efficient even after factoring in depreciation.
- It’s especially relevant for capital-intensive industries.
- Stable or rising EBIT margins over time are a strong indicator of pricing power and business quality.
📘 Net margin
📈 What is it?
Net margin shows how much of a company’s revenue remains as bottom-line profit after deducting all costs, interest, taxes, and depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
Net margin reflects a company’s overall efficiency – across operations, financing, and taxation. It shows how much actual profit is generated from each dollar of revenue.
🧮 Calculation
🎯 What does this mean for investors?
- A high net margin means the company is not only strong operationally but also manages financing and taxes efficiently.
- Peer comparisons reveal business quality and competitiveness.
- Declining margins despite revenue growth can be a red flag for rising costs or inefficiencies.
📘 Free cash flow margin
📈 What is it?
The free cash flow (FCF) margin shows how much of a company’s revenue remains as actual free cash after covering all operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
This margin reflects the true liquidity generated by the business – independent of accounting rules or depreciation. It’s especially relevant for dividends, buybacks, and reinvestment decisions.
🧮 Calculation
🎯 What does this mean for investors?
- A high FCF margin means a company consistently generates strong cash flow.
- It’s a positive signal for financial stability and shareholder returns.
- The long-term trend is key – a declining margin may indicate rising investments or weakening operating efficiency.
📘 Earnings per share (EPS)
📈 What is it?
Earnings per Share (EPS) shows how much profit is attributable to a single share – and is one of the most important metrics for evaluating a company's performance.
🧮 How is it calculated?
The diluted share count reflects potential new shares that could be issued through options, convertible bonds, or other rights.
🏛️ Why is it important?
EPS is the basis for many key valuation metrics like P/E ratio, PEG ratio, or payout ratio. It enables comparisons of profitability across companies, regardless of their size.
🧮 Calculation
🎯 What does this mean for investors?
- EPS captures per-share profitability and is especially useful for comparisons over time or with analyst estimates.
- Rising EPS may signal consistent growth or share buybacks.
- Important: Always use diluted EPS for more realistic valuations – especially in companies with stock-based compensation.
📘 Free cash flow per share (FCF per share)
📈 What is it?
Free Cash Flow per Share shows how much free cash flow a company generates per outstanding share – after investments, but before dividends or debt repayments.
🧮 How is it calculated?
Free cash flow is calculated as operating cash flow minus capital expenditures (CapEx).
🏛️ Why is it important?
FCF per Share reveals how much real cash is available per share – useful for dividends, buybacks, or reducing debt. Unlike net income, free cash flow is harder to manipulate and often seen as a more reliable metric.
🧮 Calculation
🎯 What does this mean for investors?
- High FCF per share signals strong financial flexibility.
- It shows how much capital the company can effectively reinvest or return to shareholders.
- Particularly relevant for dividend payers and capital-efficient businesses.
📘 Short interest
📈 What is it?
Short interest indicates how many shares of a company are currently sold short – that is, borrowed and sold by investors who expect the price to decline.
🧮 How is it calculated?
It reflects the percentage of a company’s shares that are being shorted relative to the total shares available.
🏛️ Why is it important?
Short interest serves as a sentiment indicator: A high value may signal skepticism or bearish expectations – but also increases the potential for a short squeeze if prices rise unexpectedly.
🧮 Calculation
🎯 What does this mean for investors?
- Low short interest usually indicates market confidence in the company.
- High short interest can be a warning sign – or an opportunity if sentiment shifts.
- Especially relevant in volatile markets or ahead of key earnings releases.
📘 Employees
📈 What is it?
The employee count shows how many people a company employs worldwide – offering insights into its size, structure, and business model.
🧮 How is it calculated?
🏛️ Why is it important?
It helps assess operational scale, labor intensity, and cost structure. Combined with revenue and profit, it enables key metrics like revenue per employee or productivity.
🧮 Calculation
🎯 What does this mean for investors?
- A high headcount can signal operational complexity – but also significant growth capacity.
- Revenue per employee is a key indicator of efficiency.
- Especially useful for comparing tech, industrial, or service-heavy companies.
📘 Turnover per employee
📈 What is it?
Revenue per employee indicates how much revenue a company generates on average per employee – a key measure of efficiency and productivity.
🧮 How is it calculated?
The employee count is typically taken from the most recent annual report.
🏛️ Why is it important?
This metric helps compare business models – especially between labor-intensive and technology-driven companies. A high value suggests automation, operational efficiency, or strong value creation per head.
🧮 Calculation
🎯 What does this mean for investors?
- A high revenue per employee indicates a scalable and margin-strong business model.
- A low figure may reflect labor-intensive operations or lower value-add.
- Especially helpful when comparing tech companies to industrial or service sectors.
Palo Alto Networks Stock Analysis
Analyst Opinions
63 Analysts have issued a Palo Alto Networks forecast:
Analyst Opinions
63 Analysts have issued a Palo Alto Networks forecast:
Palo Alto Networks Events
Past Events
|
SEP
10
Goldman Sachs Communacopia + Technology Conference 2026
10 days ago
|
|
SEP
1
Q4 2026 Earnings Call
19 days ago
|
|
JUN
2
Q3 2026 Earnings Call
4 months ago
|
|
FEB
17
Q2 2026 Earnings Call
7 months ago
|
|
DEC
2
UBS Global Technology and AI Conference 2025
10 months ago
|
|
NOV
19
Q1 2026 Earnings Call
10 months ago
|
|
SEP
4
Citi’s 2025 Global Technology
about one year ago
|
StocksGuide Free
Palo Alto Networks — Goldman Sachs Communacopia + Technology Conference 2026
1. Question Answer
Good afternoon, folks. We're really excited to have Nikesh Arora on stage with us, hot off the plane from Geneva. Thank you for taking the time to be with us today.
My pleasure.
Nikesh, there's a lot of noise in the market as you can appreciate. When you read and look at some of the -- fearmongering is -- may not be the right word, but some of the more...
I like fearmongering.
There's a little bit of...
I spent 8 years trying to convince people cybersecurity is important. Dario did it in 1 week. Better than me, clearly. Mythos has been more useful for me as a marketing tool than anything I did for 8 years. I hope to have new models, which are more capable than scare a lot of people.
Let's talk about the flip side of the fearmongering. Let's talk about the flip side of the fearmongering.
The flip side of fearmongering. Yes.
So you have CEOs that call you and say, I'm scared about XYZ agentic threat.
Buy a Palo Alto network.
Nikesh, please solve this for me. How do you solve that problem?
Well, first of all, I'd love to see you guys. Thank you for staying in the room. I saw a lot of people leaving as I was walking in. So I figured nobody was interested in cybersecurity or anything that needed to be said had already been said so far at this conference. Or the bar is open, any of those above.
When CEOs call now recently, since Mythos, I think we've talked about 2,000 companies between CEOs, CIOs and Chief Security Officers and obviously, they want to know what is Mythos, how does it impact my life? What do I need to do about it? And I think Mythos is the first incarnation of showing us the capabilities of AI and how it can find vulnerabilities in our organization's technology stack.
So what would take us weeks or months or things we wouldn't care to go look for, AI can do it pretty quickly. So you've certainly seen this peak of vulnerability finds. We found 1,200 at Palo Alto when we first tested it when Mythos came out. It took us 3, 4 months of cleaning to understand which ones are real, which ones are not, and go fix them. Now we're back to steady state. We find pretty much a few every month like we used to find before Mythos was out. But we have to go through a huge learning curve and a discovery phase and fixing it.
So a lot of companies haven't been through that. And what's happened now is Mythos has become available to Defenders. So we have a service. We can go to customers and would and say, "You want us to test you. We'll test you."
But what's interesting is I'd say 60% of what we found was through Mythos, 30-odd percent using OpenAI and 10% using other models. So we actually have to use a multi-model harness to find all the vulnerabilities that current AI will help you find as opposed to using any 1 single model. That's what we're doing.
But very quickly, that conversation evolves, that's great. What does this mean for the future? How do I make sure that I can respond to finding vulnerabilities quicker? And what do I need to do to my tech stack to make sure that I can find attackers quickly in my infrastructure and fix it before the shit hits the fan. That's usually when the platform conversation begins and the SIM conversations begin and we start telling them stop upgrading your stack in a multi-vendor solution, try and consolidate because you need the data to be able to stitch together and make it work.
Talk a little bit about that data advantage. What are some of the things that you can do now with AI with your own road map because you have visibility across the different pieces of the platform?
Well, look, it's still true that every customer runs about 30 or 40 cybersecurity vendors in their stack. Cybersecurity is, in my mind, can be simplified as you have to stop that stop at the perimeter, right? Anything bad -- if you know it's bad, you're going to stop it. It's like stopping a bad guy wearing a mask and carrying a gun at the door. That's easy to do. If you know it's bad. Most of the cybersecurity problems are when you don't know it's bad and gets into your infrastructure, you've got to find it quickly to stop it because actually you're not a guy on a mask because but a guy wearing a suit sitting on the conference, he's about to pull out a gun. Sorry, I'm using non-cybersecurity analogies because you guys probably heard about all the agentic harnesses that [indiscernible] is building.
But -- so the challenge is, how can you find that bad actor as quickly as you can? To find the bad actor as quickly as you can, you need a seamless sort of layer of data behind it, which is consistent, which can talk to each other and they understand the nuances to take any attack, right? If an attack starts at your laptop and you're running a SaaS e-vendor in your laptop, then the attack migration of laptop heads to your data center, hits your firewall in a data center. Now you're running a different vendor in data center. It goes from there to your database, which is sitting in AWS under a different firewall in AWS. So you've traversed 4 or 5 cybersecurity vendors and all of them will give you an alert saying, go figure out something bad is happening. But because they don't have the context of the other vendor, they can't stick -- stitch it together and say, "Oh shit, I found this thing. It went through these 3 different enforcement points. I control all enforcement points, I know what this bad thing is, because somebody has to collect all the data then go make sense of it. You're running 1 vendor through the entire life cycle of that particular tech vector, you can solve the problem within that vendors data lake or you can solve that problem using agents that, that vendor runs. Otherwise, let's assume that I saw something bad at the endpoint, but I don't know what it's going to do or it did something bad or not, right?
Take an example. You got an e-mail, you clicked on the phishing link, you went to a bad website. The moment you left the e-mail vendor, that e-mail vendor has nothing they can do anymore. You're out of the e-mail vendor stack, you don't -- they don't have the data. You probably went through your corporate firewall that allowed you to go to a bad Internet [indiscernible]. So now the firewall has the data, but they don't have the e-mail data that you clipped on e-mail. So somebody has to collect all the data in the SIM and go make sense of it, which is done by SOC analysts. You have to be able to solve these problems in flight using agents. The only choice is if you not have a single vendor managing, at least part of your stack, each agent has to talk to other agent, which means all of us to build agents that need to talk to each other. It is a complicated solve. So you actually have to eventually start reducing your footprint of cyber vendors over time. And that's where the -- I think AI is -- the best way to say is, AI is advantage incumbents with platform stacks.
Some of your products are relatively straightforward to consolidate up and displace vendors. Other things like network security and Cortex SOC does a heavy lift. And so to your point, when customers go on this modernization journey, do you already have visibility into multi-quarter, multiyear network transformation, SOC transformation type cycles?
To solve transformations are typically 1 shot. You can do a 6-month engagement with the customer, and they'll tell you we want to and they'll do a 6-month engagement and replace somebody else. Network stack evolves over time. Like walking in here, and I hadn't seen my e-mail for the last 4 hours, and I saw 2 emails about 2 different customers who wanted to replace a certain network vendor in their stack because they already have 2 out of the 3 pieces we do with them. And the third 1 is coming up for a renewal for a sector vendor. And they said, but we already have 2 out of 3 from Palo Alto. Let's just go with Palo Alto and harmonize the stack. So that typically takes the process of evolution. There's no but he's sitting there and saying, let's take useful things and rim them out. They wait for the evolution on certain stack. The revolution is happening in the SIM because of Mythos. The revolution is happening on the observability stack because of cost, the revolution will happen on AI security stacks that are going to be built, which are also built in the market. If anybody sat here and told you they can solve the security, there's a bunch of marketing going on, but I'm sure they've said it.
Let me ask you a derivative of that question, which is we had Jensen on stage earlier talking about the commercial opportunity that may exist for the frontier models in security.
And what is that opportunity?
I would love to hear your thoughts, he could not elaborate.
[indiscernible] Jensen told you so.
The question -- I'll ask it from your industry perspective.
Jensen is wonderful. He's an amazing guy. He's benefiting the entire AI industry and everybody associated with it.
Let me ask you what role you think Frontier models play in security?
Look, the biggest value of AI over time, it's his reasoning capability. It can reason and try and look for different alternatives. All software is deterministic. Design is input and output. Traditionally, when we buy software, we ask you the question, we expect the answer to come back in a certain format in a certain way, and it follows a certain process. So if it's not doing that, either say, I have no idea, bad entry or says, I have nothing in the back to give you, I have no particular view. Well, actually reasons for it, I didn't find anything here. Let me go look over there. Let me go over look there, let me go look at it and exhaust every possibility, a human being would have tried from the outset. You literally have to tell at the outcome you want, NAI has just capture the flag mentality. It tries every technique until eventually gets to the answer or as close to the answer you can get. That makes it nondeterministic in the back. And that's the value of AI. So anywhere where tremendous amounts of human time is spent interpreting things and looking for alternatives and analyze things, AI is useful, right? So same thing. It did a wonderful job of -- that's 1 property. The second property is AI is not trained for the edge case. It is strain for the mainstream case, right? Just the way when you get in the way mill, it doesn't have every edge case figure out. Somebody has to anticipate that edge case, train Waymo for their edge case to make sure that it performs the edge case. AI has the same property today. So we take those 2 capabilities and understand the reason we've got so good at vulnerability management or volume be detection is, what is the #1 use case of AI, coding, which means we're teaching it what good core looks like. Well, guess what? It's not figured out what that core looks like because we've talked a lot hundreds of billions of dollars of ARR of coding, not figure out what that looks like. So I can tell you what bad code looks like, hence it determines a vulnerability because the core is not in the way it should be in, but has vulnerabilities. It's great. It finds the 80% mainstream, but it doesn't understand the intent of the code. For example, if you look at Par Auto Code, you will find core in our company, which is designed to attack people because we're testing people. But if it sees that outside the context of Palo Alto says that's bad code. That's fix it. No, stay away. We got this. Don't fix it, right? It doesn't understand the false positive people does not understand business context. So it needs some degree of context with it to make it useful. That's where harness is, that's where domain knowledge comes into play. To the extent that it can assist us in getting through a lot of mundane tasks or reasoning task was very helpful, but you still need the edge case on the harnesses. That's one. Two, LLM do not sit in enforcement points. You do not want it sitting in your laptop at the edge case. If you remember the cloud strike incident, you really want to open a managing the endpoints and pushing updates at the end point, they haven't built that product. So I think the long-term answer is that all cyber companies will use some form of AI in their products because it will make it faster. It will look at edge cases, it look at classification, whole bunch of stuff. And we're all working on it. I'm sure different people come talk about. They're all working on it. I don't think the economics of frontier models make it useful for AI work, for example. We sit on people's end points, so discuss [indiscernible]. The average price in the industry is probably $30 to $40 an end point. And on a day, about 160 megabytes of data goes through your laptop every day. If you put a frontier let to inspect 160 megabytes a day at the edge laptop, I suspect it's going to cost you more than $40 a year. Not the customer wants to pay $4,000 a year to predict an end point, hallelujah, go for it. I'd like to be in that business, too. But if it's $40, you want a cheap alternative. So you have to build a replacement product that only -- not only is better than the product that is currently in the market, but it has to be cheap in the full I don't think that it's going to be a huge takeover by LLM of the cybersecurity industry. I think it will work in certain categories where they'll have to work with our enforcement points to make the enforcement points faster and smarter. And that's par for the course. We will all work with them together. We probably become consumers of frontier LLM and we'll do our part and we'll train edge cases and they'll power some of our models. At Palo Alto, we spent north of $1 billion in buying cloud. We don't run our own cloud I'm done on data centers. Could I be spending a few $100 million buying tokens? Sure, I could buy them for all my customers and make their products much better over time.
Do you have a view on the right way to orchestrate tokens between leading edge and not leading edge?
So there are 2 scenarios. One scenario is where I don't need leading edge, right? If I need to run AI at your laptop, it needs to run in a 20-megabyte footprint. There's no frontier LM that runs on a 20-megawatt footprint. However, I can buy I can go get 5,000 models of hugging phase, which can be shrunk to a 20-megawatt footprint and do a very specific task at the yet. So yes, I can use what I call small language models to do task specific things in cybersecurity, which are much more efficient in doing it than using machine learning, that's where I would use it. But I wouldn't be orchestrating amongst different models. In the case of vulnerability management, I am orchestrating across 5 models because we all find different vulnerability. So I'm literally running the same thing 5x to different models to see which 1 of them finds I don't know if in the long term, we should be orchestrating across multiple models. I think it's an economic argument. It's an extremely complicated technical argument. And I don't think the frontier LLMs are sleeping at the wheel. They understand where the industry wants to do and they're building interim modes, which are called instant memory. Those moves up to instant memory, which is very stored.So you can't actually arbitrate models over time. Eventually, I think what is going to happen is, I said this differently. I think average intelligence will become free, but you will still have to pay for compute. What I mean by that is I can buy a model running a laptop trading for $5,000 to run it for free marginal cost on your compute. So I think what will happen is older models will become cheaper and cheaper over time. We use a lot more of them. But the hardest thing to find right now is compute. Even if you get yourself open source model, you want to run it for $1 billion a year, you have to go buy $1 billion of compute. So set cost to you. I think people are mistaking that front M come country LLMs come with compute plus intelligence. If you go find intelligence for free, you still have to go buy the compute, which meant to end up costing you probably more or as much as you pay for, for LLM perspective. And some of these LLMs are way more efficient than what you find in open source. It costs you a lot more money to train them. They're not as efficient, and the portability is not there. So I don't know if the economics are there in the market yet for frontier tasks to start arbitrating between models just yet, but people are trying. That's great.
Let's talk about network security?
Sure. These people want to talk about AI. But we should [indiscernible].
We can talk about AI and network security.
Sure.
The hypothesis that we're experimenting with is how an increase in network traffic impacts the firewall cycle impacts throughput going through the firewall. And I think there's a bunch of different flavors. The data point you gave on the earnings call was agentic traffic on SaaS was up times. Maybe if we just take a step back, this idea that more agentic traffic drives more network traffic drives more firewall. Where would you push back on that? Or when do you think we'll start to see it?
So I think it's important to understand if we believe that $5 trillion will be spent in the next 5 years to build compute. In the end, at the most basic level, that means more traffic. Before we get into what the traffic is used for, more data flowing between pipes and trying to get to enterprises or end consumers. So you've -- if we spend $5 trillion in the last 25 years and build traffic through this traffic is x, you expect the next 5 years traffic becomes 6x, right? So if your traffic is up 6x in the next 5 years that all that traffic has to be inspected. SAS is a form of inspection, software firewalls is a former inspection, hardware pro forma inspection. Pretty much every enterprise bit is inspected today. You can't run a bit in any enterprise without being -- without inspecting it. It doesn't matter where you live. It could be in Google Cloud, it could be in AWS, it could be in a data center, inspected. The bits that are not getting fully inspected or coding bids right now, right? That's the biggest kind of buying spot. If you say $100-plus billion of ARR being generally coating, most coating instances are not secured. So we have to go fix that first. That hasn't been fixed. But let's assume that eventually over the next 2 years that all the traffic that's going around the world is going to get inspected. It doesn't matter if it's human traffic or agenetic traffic, it's traffic.
So right now, of course, the explosion is going to come from agents because humans cannot humanly consume that much traffic. So the traffic is coming from agents. But that's the second order problem. The first order problem is every bit still has to be inspected because it's coming from somewhere. So you should expect that network security has this constant tailwind as the traffic continues to grow up that form of inspection will be applied. The gap right now in the market is not all air traffic is being inspected because enough air security tools don't exist because you can't do anything beyond inspection. You don't have the tools to do it. The second layer post inspection is I'm inspecting the traffic, I run value-added software, right? What do I do on top of it? What do I expect it for? For example, I inspect traffic and do observability, great. That's a value-added service, I pay for observability on top of inspection. I take the traffic and I run a SIM on top of that, which means I get paid for running security analysis on top for which I get value-added services.
In net for firewalls, I inspect the traffic I get paid for various cloud services where are on sandboxing, UR filtering, et cetera, et cetera. So the AI value-added service haven't been built. They are being built as we speak. No vendor, including us has the full stack, because if you tell me you have a full stack, Facebook announced Muse 2 days ago. Muse comes a totally different sort of security architecture than any other agent that's out there. They run the agentic action, they run central, which is an operating system, which is security. That's a new architecture. Do you expect that all of us have built security products and anticipation is foolish. It's going to take us 3 to 6 months to understand the books. In fact, most AI implementations don't have security hopes on them. You can't automatically secure cloud code because you don't have hooks that are available from anthropic. You can't secure codex yet because they haven't delivered the hooks to run in-line security from an API perspective. They are saying, we're going to build the secured debt that's not going to work. Historically, no company is going to buy a technology product from company A and this and secure it using company-based product. Typically, you will use companies best product to secure company as technology. So that industry hasn't been built. The whole entire AI secure industry has still to be built. The entire value of the service player is being built, there are 3,000 targets got fund last year with something to do with AI, of which 2,000 will not survive, but that's a different order. This is the wrong audience. That's the venture capital guys.
But -- so that stack is being built. They're all rushing towards it. When that stack gets built, it will add a whole new TAM on top of existing [indiscernible] will be AI security TAM, like we did $100 million in Prisma Airs, which is real-time AI security. We've intercept traffic and inspected for prompt injection or model sort of the same model manipulation, right? But there's a whole new stack that we build for agent security over time, and it's not going to be -- customers are not going to be able to stitch it themselves. They're not going to buy agent identity from Okta and something else from somebody else in and saying, "I'm going to stitch it all together." They're going to wait for a stack that does to the entire life cycle of the agent.
You gave a 3- to 6-month data point in there on how long it takes to build the AI security.
At speed. If you get it right because remember, 3,000 companies are using 3,000 different hypotheses where the world is going to evolve to anticipate the world and build it. Some will get it right. Many will get it wrong.
So walk us through when you think we get to some sort of steady state?
You tell me when AI hit steady state, and I'll tell you we had security steady state. Remember, we're trying to secure a technology that is in flux. Every 3 months, something new happens. We thought we had LLMs. That was cool. We had it figured out. Damn, these agents showed up. We had to go figure out agents. And then the OpenAI couldn't constrain their own agents. They'll let them off to hugging phase, right. So when that industry reaches some point of stability will give you a stable security architecture. This funny analogy that they didn't invent TSA when they invented planes. TSA took a long time to torture us. So it will take a while to get to torture the AI guys.
One of the stack that's being built as we speak, is the Neocloud infrastructure stock.
It's beautiful, yes.
Tell us a little bit about your opportunity securing some of the neocloud infrastructure.
Well, NeoCloud is data centers, right? They just data centers. Data centers need firewalls, especially if you can have multiple tenants. The ones you don't get business from is single-tenant cloud. So if somebody is building a hyperscaler, it's a single purpose data center does 1 thing. It runs AI training and AI inference, and it runs usually as an extension of the hyperscaler stack. Hyperscalers is inefficient for them to buy firewalls because we are a Swiss-Army Knife for what is a very single purpose task. But if you're going to run multiple tenants and you do segmentation and you do all those things, they need a firewall. So I'm guessing, I don't know the answer. I don't think more than 10% or 15% of the business in the world of building data centers is multi-tenant. I think 80%, 90% of single tenant, like entropic goes and buys the entire capacity for data centers, this is mine. In which case, they don't need to secure the firewalls because Anthropic hit a big pipe and run it between their multiple data centers themselves.
There is another piece to this, which is enterprises, I guess you would call it sovereign AI where enterprises say we want to have our own data centers where we run our own AI. [indiscernible], for example, talks about Caterpillar doing this type of implementation.
Who?
[indiscernible]? Caterpillar? So my question is, is there an enterprise angle to this where enterprises build their own proprietary data centers to do single tenant?
Sure. I think the struggle right now is, the people who understand AI really well and how to work with it are working it frontier labs. We have 9,000 engineers and I suspect 5% to 8% are good enough to get a B+ grade in AI, and it's probably 1% or 2% will get an A grade in AI. And that's great. I think 92% of the people will not get a -- it's like the teacher will have to rework their homework right now. I think in that environment, when things are moving so fast, it's dangerous to DIY. I think it's just -- you have to wait for the industry to stabilize. So sure, I'm sure there are examples of people trying different things. I think the industry is in too much of a state of flux and things haven't stabilized or you might find these bets are wrong bets. I think 2 years from now, as I said, you should be able to get average intelligence for free. I should be able to do simple tasks or average costs for no money, right? I mean you can buy instinct or use without spending any money, which means it's going to do my book me an airline ticket, find me a vintage card or find me a clip of a video on the Internet for $0. That's average intelligence. That's for free in the consumer use case. Why shouldn't that average intelligent free and enterprise use [indiscernible] the ability to buy compute, right? As long as I pay for the cost of compute, I should be able to buy that intelligence free. There's no value for me to pay opinion of that. I will pay a premium for premium intelligence with harnesses and data training and for cost. Now that's a combination of an LLM and domain knowledge that is hopefully in the domain of an enterprise, unless enterprise commoditize that by mistakenly training a public model, which also happen. Like you can solve Napier stokes by having mathematicians use free models.
You've been very consistent in talking about when there is a disruption in an existing security vector, like network like endpoint, like identity, Palo Alto takes advantage of that disruption and can actually sell something better and different into that market. Given that we're in a period of time where technology is in a period of flux. How do you stop someone out Palo Alto networking you?
That's what I -- you never used to asleep this life. Now I think about this before I go to sleep.
When did that change?
It changed because every morning on our wake up, there's new shit, that didn't understand until yesterday, and I got to learn just like literally, I learned about news on the new architecture on the plane back from Geneva as we had to read like for half an hour, different posts and then I had to go out and talk to Gemini and then talk to ChatGPT say what's going on here? Why did they do this and trying to understand it.
Now if that's the level of knowledge you have to have -- because remember, our jobs are hard. Our jobs are trying to figure out where is AI going to go? What does that mean for security? What do we need to build from a security perspective? What is that going to destroy structurally from a market perspective? And how do you position the company over there? So if you're going to get all these signals every day, which you're going to have to revisit your thesis every day or every week, it's hard. And at this point in time, if leaders don't pay attention, understand where the market is going, and get stuck in where you are because you haven't thought about where the market go or you could try and need your title and build your own data center now new cloud and start trying to control the outcome and say, "Oh my god, I went down the wrong path." So you have to be sort of nimble and be able to validate your thesis on a consistent basis.
So what do I know? I do believe that most software will get [indiscernible] the next 10 years. I think enterprise software will get [indiscernible]. Now unless you have use moats. Even then, our UI and our software at Paolo is being rewritten as we speak. We're becoming more AI native. You will be able to talk to my software and have AI models behind them, assist you in navigating my software and the findings of our software. That will become par for the course. Every software piece of software will have to do that.
Now the question was then, what moat do you have? People said system of record is a lot. I think that's a short-term moat after a point in time, the system record becomes just an obstructive database, it doesn't become moat anymore because your UI has been modified over time. So the moat is, I'm deployed 180 million sensors around the world. Somebody has to physically replace those 180 million endpoints of Palo Alto from data centers from firewalls from endpoints. That's a moat. It will last for a while. Could I go acquire another $120 million endpoints in the meantime, so I can build a bigger moat, Hopefully, that's my moat. My moat is I run 19 petabytes of data through Google Cloud every day. right? It requires a big firehose for you to come and take that out and find someone else, you could got 19 petabytes of data, where you don't have compute. That's my moat. So within those moats, I have to keep building my business to make sure that what gets commoditized needs to be reinvented by my team, I have to protect my moat. That's what I had to day every day. So I'm sure somebody will out Palo Alto Networks, but not going to give up without trying to give them around for their money.
What was it about the due diligence on we could pick any 1 of your acquisitions. [indiscernible] actually my favorite. What was it about Coronasphere that made you think this asset has a moat that is not going to be disrupted by next-gen observability?
Look, if I want to be a bigger business in the next 5 or 10 years. I have to get in the token flow. If you believe the world is going to spend $5 trillion and they're going to try and monetize that $5 trillion somehow in ARR using AI in some way, shape or form, I'm a security business. Security is typically a 2% to 5% attach to IT businesses. If I can find a way to just give a little parasite that sits on the back of the whale or whatever you said, just suck out 2% of the money. I'm in good place because you're going to have $1 trillion of ARR 2% a trillion I heard is a lot of money. It's more than I make today. So I just need to find something to get into token flow. A proxy for token from me is data, right? If I'm in the data flow, at least I'll be in the data inspection business. So what are the 3 largest businesses in data, observability, SOC and endpoint inspection. That's why on observer business. That's why I live in the SoC world, and that's why I have an endpoint boat. So if I can just make sure my endpoint moves and my security data and my absorbability data allows me to be in the token floor, I'm in a good place. There's more. There's internal IT data, which also is interesting. That's why console is interesting, because console actually builds on top of internal IT databases. So if I can build Palo Alto and a place where I collect the data once and I analyze it for multiple use cases, multiple times, I can optimize the cost for my customer. So we have to spend less money, and I can then charge for the intelligence nature of that verticals over time. So that's what we're trying to build.
Are there other markets that fit or other adjacencies that look like an observability or [indiscernible]?
Just telling the company, I'm going to buy next and [indiscernible].
I'm not asking for company. I'm asking you an abstract philosophical question about how you think about the IT world?
So when I was at Google in 2004, Larry Pason came and told the story. Steve Jobs told him that the only thing lady could do differently was he should focus like Apple does because that's how you build a gate product and you have a lot of people use it. Larry posited alternative hypos thing. If I have competent people and access to a lot of capital, I can have a lot of competent people try a lot of different things, and many of them are work. And you can see both strategies work. right. So we've tried the second strategy. We try and do multiple things. We try and see how many we can do well. We have access to capital and we try and find the best people to do them. And sometimes the best people work for companies that are not ours, and we buy those companies and they can work for us. So when I started 8 years ago, we were a hardware firewall company, we were able to use our internal resources to build the last product innovation also did before I got there in 2018, it was in 2015. Today, we do 70 product deployments every year, right? So we've changed our pace of innovation, and then we acquired 47 companies so far that allows us to deliver we live. So console pattern. We'll keep looking at the market to see how do we get access to great people and great markets and away from markets to inflect. We have to be ready. Five years ago, run on the SIM business. We have a $70 million ARR SIM business, which is now taking down both into the market. We had no SaaS business 7 years ago. Today, we were second in SaaS with growing faster than the largest player and taking share from them. So if you set your mind to it, over time, security markets commoditize, customers start looking at each other and saying, your product looks very much like their product, why should I buy yours, guess what, mine works seamlessly with my hardware stack and software stacking [indiscernible]. So over time, as software commoditizes, platforms become more important. So that's where we're trying to play is work out so far, hopefully keeps working.
I think it leads to a little bit of a question on industry structure. Tell us -- so with this view of the world where platformization, I think there's enough evidence at this point that suggests the largest cybersecurity companies are compounding at scale. The M&A is proving to be successful from a cross-sell from a technology, from a load standpoint. Do you think that the industry continues to concentrate in terms of profits over the next few years? Or is there a part of the security stocks at fragments?
Well, history should suggest -- so in 2012, the market cap of cybersecurity is $40 billion with Symantec had the largest share at that point in time Today, the industry is $670 billion of market cap, we're close to $300 million of it. So it does seem like it does consolidate over time. You just have to make sure you don't sleep at the wheel. So you have to be constantly paranoid to make sure our products are beating the top of the market. So we have 20-plus Gartner Magic cordons who are at the top to the right, which is good, which tells which is it's an arbitrary metric, but at least gives me comfort that in 20 categories, our products are as good as anybody else in the market, which is always a good sign. The idea is you don't want to become somebody who's not in the leading quadrant and out of 27 categories we play in '20 on the right. So as long as I keep aspiring to have the best products in the market, I'm going to have heft as long as I have a good sales force, which keeps driving more value for customers, hence, getting our customers open more is great. And then you have to run the business deficiently. I can run a $10 million or $15 million on coke project and not impact my P&L, smaller companies can't. We're doing tons of work on using AI to be more efficient. And if we do that, we're probably going to run our business at a 500 to 600 basis point differential that smaller companies in the market. If you can on a profitable business at scale, it becomes a competitive advantage.
You gave us a couple of examples on how your day-to-day has changed with sleeping lots and doing more research on AI.
Just more e-mails to my team. I only have 12 people to work me, everybody else is like literally like people get e-mails.
Any other wisdom you would leave us with as to how your day-to-day has changed and what we should be paying attention to? You spend more time on X as well [indiscernible] avenue has changed.
Yes, that has changed because I went to do this podcast. And I told this guy, he's building his own brand in the back of intern all of us and getting us to speak for an hour and he does 20 month or whatever he does, and he's becoming more popular. I'm like too, this is unfair. It's like, well, yours too, but I'm not. That's why [indiscernible] says, you could build your own brand by treating once a day. And then, of course, I started reading once a day and then Ale, Head of comm said that's too much, don't do so much. you put your foot in your mouth. I said that is -- it doesn't matter now that once a week, and I can [indiscernible] my mouth. So I'm trying to balance putting my foot on my mouth, once or twice a week at a building.
How do you pick what to tweet about?
I don't really pick. I just like -- I don't really want to say that you have to protect your IP because it looks like I'm having -- I have something to say about that Napier stokes thing, which I don't. So I sort of made it more generic. That kind of inspire me just to talk about how we to people to secure their AI. I saw people getting all excited about Neo Cloud. So I kind of said NeoCloud is going to trade at the same price 2 years from now. Then they're raising money at today. It's like I get all the [indiscernible] lovers come after me quickly. Like that's a neo scaler that's not neo cloud, then they got to come down. So the watch out where I put [indiscernible].
Well, you're one of the few CEOs that has an investing background.
Yes, sometimes that [indiscernible].
Multiple perspective.
I used to maintain my CFA, but then they started questioning, I'm not paying you $2,000 a year.
I don't have the key age or CFA to have an opinion on Neo Cloud.
Well, I don't want to -- see like they send me a letter 1 saying, "Oh, we just saw it in a public profile."
yes, it's a membership. It's a subscription model.
Yes, I stopped paying for it because I didn't use it and then said, "Oh, somebody on your CV says, you have a CFA, you owe us $2,000. I send them $2,000. And now I can say I'm CFA. And then say you have to do training to do professional services, conduct or something like it, shit I don't want to [indiscernible]. So I stop paying like, I still do not write CFA in my CV anywhere. So I'm gone, I'm good. I think the artist -- I could say former CFA, I think. I wonder how that would go legally, but I could say former CFA.
I don't know if that would give you more or less credibility with the Navios people.
No, they're very passionate. I think look, [indiscernible], like eventually long-term data centers have an 18% IRR. So in the meantime, you can take funding CapEx with equity is a bad economic decision, but you guys can tell me that. I don't think so. But for now it's working.
I think that's all the time we have. Please join me in thanking a wonderful Nikesh [indiscernible].
Thank you guys. [indiscernible].
Palo Alto Networks — Goldman Sachs Communacopia + Technology Conference 2026
Nikesh Arora framed AI (Mythos/LLMs) as a catalyst for more vulnerability discovery and faster platform consolidation, favoring vendors with data and enforcement footprints.
📊 Key Message
- Message: AI is dramatically accelerating vulnerability discovery and shifting security buying toward platforms that control data and enforcement points. Palo Alto argues incumbents with broad telemetry and enforcement can stitch detections together and win consolidation deals as customers modernize.
🎯 Strategic Highlights
- Service push: Palo Alto offers testing and remediation services using Mythos (an AI vulnerability finder) and a multi-model harness to surface issues for customers.
- Platform focus: Management is pushing customers to consolidate multi-vendor stacks into fewer vendors to enable cross-layer context (endpoint, network, cloud, SOC).
- Data strategy: Investments in observability, SOC and endpoint capture token/data flow (they cited acquisitions like an observability asset) so Palo Alto can monetize AI-driven inspection and value-added services.
🔭 New Information
- AI findings: In Palo Alto’s tests they initially found ~1,200 issues; after cleanup they now see a few genuine finds monthly. About 60% of discoveries came via Mythos, ~30% via OpenAI, ~10% from other models, so they run multiple models in parallel.
- Economics: Frontier large language models (LLMs) are unlikely to sit on endpoints due to cost and compute; smaller task-specific models and hybrid orchestration are the practical path today.
❓ Analyst Q&A
- Frontier models: Arora said LLMs add reasoning power but miss edge-case context; companies will harness multiple models and add domain context rather than rely solely on frontier LLMs.
- Network demand: He expects firewall/network inspection to gain tailwinds as overall traffic (agentic + human) rises, creating ongoing demand for inspection and value-added cloud services.
- NeoCloud & data centers: Multi-tenant “neo-cloud” operators need firewalls; single-tenant hyperscalers less so. Enterprise sovereign AI experiments exist but are risky while the space is fluid.
⚡ Bottom Line
- Implication: Short-term: AI drives immediate demand for vulnerability discovery and services; Palo Alto’s telemetry and enforcement footprint position it to capture consolidation and new AI-security spend. Medium-term: incumbency, data scale and targeted AI models are likely advantages, but execution and continued investment matter.
Palo Alto Networks — Q4 2026 Earnings Call
1. Management Discussion
Good day, everyone, and welcome to Palo Alto Networks' Fiscal Fourth Quarter 2026 Earnings Conference Call. I am Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, September 1, 2026 at 1:30 p.m. Pacific Time.
With me on today's call to discuss our fiscal fourth quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q4 '26 supplemental financial information and Q4 '26 earnings presentation.
During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation.
This presentation also contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis.
I will now turn the call over to Nikesh.
Thank you, Hamza. Good day, everyone, and thank you for being with us to discuss our progress. As you can see, our execution fueled a record finish to the fiscal year. We exceeded our guidance across every financial metric in Q4, with bookings momentum accelerating for the second straight quarter. This performance is a direct result of record-breaking platformization adoption and the growing urgency among customers to fortify their defenses as AI fundamentally redefines the security landscape.
We achieved record RPO, surpassing the $20 billion threshold for the first time to close the year at $21.2 billion, representing a growth rate of 34%. NGS ARR reached $9.1 billion, up 63%, enabling us to report one of our most substantial Next-Generation Security outperformances to date. Most notably, we added nearly $1 billion in net new NGS ARR this quarter alone.
I remember my first Analyst Day in 2019. Shortly after I arrived, we set a high bar to reach $1 billion in Next-Generation Security revenue by fiscal 2022, just as we were initiating our pivot from a single product firewall vendor and a unified security platform. That transformation journey has reached a pivotal inflection point, and the scale of our current success is a testament to that vision.
We delivered broad-based strength across our platforms in Q4, with Network Security, our largest business, reporting exceptional results across SASE, software and hardware firewalls. XSIAM maintained its strong momentum, while Prisma AIRS achieved a significant milestone, surpassing $100 million in ARR within 4 quarters of general availability. This represents the fastest scaling product in the history of Palo Alto Networks.
Fiscal 2026 marked a pivotal inflection point in our transformation journey. We closed the two largest acquisitions in our history with CyberArk and Chronosphere, both of which are exceeding our initial expectation. Both businesses are gaining significant traction within our platformized architecture and are scaling at an accelerated pace compared to their previous standalone performance. These achievements are a testament to the execution and deep collaboration the thousands of new colleagues who joined us this past year. We look forward to continuing to [ share ] momentum into FY '27.
Q4 was the very first quarter in which we witnessed the profound implications of cyber capable models. As I've said before, AI is a long-term tailwind for cybersecurity. While these models are becoming increasingly proficient at uncumbering vulnerabilities, detection is merely the opening act. Truly validating, interpreting context and resolving these issues requires broad cybersecurity platforms working alongside frontier AI. This synergy is essential to stress test environments, manage agentic actions and trigger machine speed remediation during an active threat.
Defending at that speed necessitates a unified data architecture where AI processes every signal, collapsing response times from days to just minutes. Platformization is the only viable strategy for real-time defense, fighting AI with AI. And that philosophy continues to gain significant resonance with our customers in Q4.
During the fourth quarter, we achieved approximately 220 net new platformizations, surpassing our prior record and representing more than twice the volume from when we initiated this metric 2 years ago. The performance validates that our philosophy of real-time defense [ to ] unified architecture continues to gain significant resonance. Beyond initial adoption, standardizing our platform yields superior retention and expansion, with NRR or net revenue retention exceeding 120% for our platformized cohort in Q4.
As we look forward, we remain on track towards our long-term objective of over 4,000 platformizations by fiscal 2030, which serves as a bedrock for reaching our $20 billion Next-Generation Security ARR target. Our largest Q4 wins show platformization in action. During the fourth quarter, we secured a $126 million agreement with a global telecoms leader. This organization moved to standardize on our network security platforms, bolstering their next-generation firewall footprint while displacing legacy proxy providers with Prisma Access for SASE.
We also closed a $72 million transaction a premier IT service provider. This client has fully embraced platformization across network security, Cortex and Idira, making 8-figure investments in each, serving as a powerful validation of our cross-sell momentum in Q4. A further highlight was a $53 million platformization deal with a leading global payments platform. Beyond standardizing their network defense on our architecture, they committed high 7 figures to Prisma AIRS as they accelerate their enterprise AI initiatives.
Fiscal 2026 has emerged as a landmark period in the rapid evolution of AI, marked by 3 distinct inflections over the last 6 months. Each of these shifts fundamentally redefines how AI interacts with the enterprise, and by extension, how it impacts the cybersecurity landscape. For us to effectively lead and protect our customers, maintaining our position of the vanguard of these structural changes is paramount.
The first inspection was the arrival of OpenClaw. Earlier this year, OpenClaw served as the catalyst for the transition from standard LLMs to agentic action, fundamentally altering the dynamic between human operators and AI systems. Just a year ago, AI was largely defined by individual human prompting, a synchronous multiturn dialogue, a task was completed to the [ person ] of the loop. Virtually overnight, we witnessed the emergence of fully autonomous agents. These are persistent entities that operate for extended durations, executing complex workflows without direct supervision.
For a single employee that wants to manage 1 task at a time, the same individual can now orchestrate thousands of autonomous agents. The implications for the enterprise are profound. Each of these agents generates continuous traffic, interacting with models, creating internal data and communicating with other tools and agents around the clock. This creates a massive volume of telemetry that must be observed while every agent requires its own set of credentials. We're now securing a whole new cast of machine identities with autonomous permissions. The surge in traffic, data and identity complexity represents a significant long-term tailwind across every one of our platforms.
The second was the Mythos moment, which prove that deep domain training enables AI to achieve unprecedented proficiency. In our sector, this is manifested as the weaponization of AI to identify and exploit vulnerability to scale. This shift has exposed to deep technical debt within the enterprise or legacy flaws and persistent risk configurations that once took months for a human to uncover are now exploited in minutes.
In an AI-driven threat environment, there is no longer anywhere to hide. For our customers, the Mythos moment reframes the security challenge from visibility to velocity. Organizations must now identify exposures before they are weaponized and respond at machine speed. This is why real-time defense has shifted from a future road map item to a present day requirement.
To address this, we expanded our Frontier AI Defense Service last month, introducing a multimodal harness that enables enterprises to stress test their environments. This service leverages the most sophisticated cyber capable models available, and we are proud to be the first certified commercial partner for [ Mythos 5 ].
The third involves an emerging inflection point that we expect will dominate the cybersecurity dialogue in the coming quarters. For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of [ open weight ] and open source architectures. Enterprises are increasingly prioritizing sovereign control over their AI, leading to the deployment of specialized models deeply integrated with proprietary data. We expect a major acceleration as organizations utilize internal telemetry to fine-tune models for bespoke enterprise use cases.
While frontier models will continue to set the high watermark for intelligence, the broader market is heading towards a rapid fragmentation and proliferation. Crucially, each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platformized protection is expanding dramatically. Three pivotal moments, each with a unique impact, yet all leading to a single conclusion. As the relationship between humans and AI evolves and deployments multiply, the necessity for unified real-time defense has never been greater.
It is early days, but we are beginning to see the signs of how these trends are impacting our business, starting with our largest business, Network Security. AI represents a significant long-term tailwind that is expanding our total addressable market in Network Security while reinforcing that platformization is the only viable strategy for the modern enterprise. As the global AI build-out continues, every new data center becomes critical infrastructure that requires robust fortification through hardware and software firewalls, whether delivered natively by cloud providers or via a unified security platform. The ecosystem driving this infrastructure expansion had reached a pivotal inflection point, and now we're seeing a new vanguard of buyers emerge spanning sovereigns, neoclouds and frontier labs, all racing to deploy massive computational capacity that must be secured. We achieved strong early traction with this cohort in FY '26, including multiple 7-figure bookings in the fourth quarter.
In total, our firewall execution drove accelerated bookings for the fiscal year, fueled by robust demand for latest Gen 5 hardware and the continued momentum of our software offerings as customers scale their cloud and AI workloads. As this infrastructure matures and autonomous agents are deployed, we expect a dramatic proliferation of agentic traffic across every network and cloud environment.
The impact on our SASE platform is already evident, where agentic traffic has surged 9x over the last 9 months. Defending at this scale requires machine speed inspection or competence, a core competence we have refined for 2 decades, enabling us to block more than 30 billion attacks in a single day. Ultimately, AI is underscoring the urgent need for unified platforms that deliver real-time defense.
In FY '26, our platform advantage drove exceptional results in our SASE business, where bookings grew 40% with broad strength across [ access ] SD-WAN and secure browser. We successfully displaced legacy incumbents in nearly 100 accounts representing over $400 million in total contract value, nearly double the volume of displacement from a year ago. While we have rapidly ascended to the #2 position in this market, we're playing to win and remain on a clear trajectory to become the SASE leader in the next 5 to 7 years.
One of the early chapters of the shift with the future necessity securing both human and machine identities through unified architecture capable of providing defense at machine speed. Organizations are transitioning AI initiatives from experimentation to full-scale production significantly, widening the defensive perimeter with each new deployment. Prisma AIRS has continuously adapted alongside these adoption cycles, evolving to mitigate the unique risk emerging from every phase of the AI journey.
While our initial focus addressed the chatbot-centric era of generative AI, our vision has expanded towards proving a comprehensive architecture of agentic security. This unified approach begins with securing machine identities and credentials, incorporates deep observability of agentic footprints and extends to the endpoint where we analyze behavioral intent. By funneling this traffic to our AI gateway, we ensure that security policies are enforced real-time across every interaction.
Prisma AIRS achieved a remarkable milestone in Q4, surpassing $100 million in ARR within just 4 quarters of general availability, marking the most rapid scale out of any product in our history. Our momentum is reflected in a growing base of our 800 customers for this product, with the majority of our largest transactions now featuring multi-module adoption in Q4.
We're also seeing significant early validation of our agentic endpoint strategy following the Koi acquisition. We believe the endpoint is reaching a critical inflection point as AI development tools migrate to the desktop environment. This shift as an expanded surface area where agents autonomously manage files and access sensitive credentials. Legacy security tools often remain blind to the underlying intent and reasoning behind these machine speed actions. In this landscape, visibility without action is insufficient.
Our platformized approach delivers end-to-end transparency from the initial prompt to the final execution, enabling in-line prevention and machine speed. This capability is becoming a fundamental requirement for the enterprise. We've already secured over 100 logos, representing a 2.5x increase since finalizing the Koi integration earlier this year.
Ultimately, the synergy of detection and prevention is most effective when unified as a single platform, with XSIAM serving as a central nervous system for this critical telemetry. Earlier this year, our Unit 42 researchers demonstrated the staggering speed of modern threats by simulating a comprehensive AI-driven attack in under 30 minutes. Contrast that with the industry standard defense report response of 4 days, and it's clear that legacy approaches are no longer sustainable.
Customers standardizing XSIAM are transforming their operations, reducing their mean time to respond to less than 10 minutes, massively from the days of weeks acquired previously as we continue our relentless push towards true realtime defense. In the fourth quarter, XSIAM maintained its exceptional momentum, concluding the year with over $700 million in ARR, up 70%, while surpassing the 1,000th customer milestone in the platform.
The power of our architecture lies in the fact that live telemetry is already resident within XSIAM, allowing us to seamlessly unlock new value through our unified data lake. Expanding deployment does not require the friction of new product integration. It simply involves [ curing ] existing data in new ways. As of Q4, the majority of customers have embraced this platform advantage, utilizing multiple modules, including exposure management and cloud security.
Turning to observability. We continue to see the world's premier AI native and cloud-first organization standard in our technology. The entire entities pioneering the AI frontier generate telemetry to scale that traditional tools cannot withstand. Chronosphere has engineered specifically for these massive data volumes, capturing every training run in [ Agent Blue ]. This quarter, we signed a $20 million deal with a hyper-growth AI inference provider that processes tens of trillions of tokens a day. This is no longer -- there is no stronger validation of our platform than when the architects of the AI ecosystem trusts us to monitor their own infrastructure.
Since finalizing the Chronosphere acquisition in Q2, our observable ARR has more than doubled, eclipsing the $500 million mark. This performance has significantly outperformed our initial targets and represents the most rapid post acquisition scaling in our history. Our cross-sell strategy is delivering tangible results, with XSIAM contributing to 50% of net new cross-rate logos this quarter through multiple 7-figure agreements.
We are further enriching the stack with the acquisition of Embrace, integrating real user monitoring to complement our core metrics, logs and traces. This expansion enables us to provide a comprehensive end-to-end observability platform that spans from the core infrastructure to the final user experience. Collectively, XSIAM and observability now represent over $1 billion in ARR, a remarkable achievement for data-intensive platforms that were not part of our portfolio just a few years ago.
A [ consort ] of our success throughout my tenure at Palo Alto Networks has been our ability to identify premier technology and world-class talent and seamlessly integrate them into our culture. While the complexity of our integration effort naturally increased scale of this year's acquisitions, result has been extraordinary. In Q4, the success was most evident in our performance with CyberArk, or now called Idira.
Just 2 quarters after finalizing our largest acquisition date, we are accelerating growth while capturing synergies ahead of schedule, a rare feat that demonstrates the power of our integration engine. These results are a testament to the deep collaboration with our new colleagues. From a go-to-market perspective, our joint efforts yielded over 400 shared leads, driving more than 200 net new logos from our installed base. We are also seeing a significant move towards larger commitments, with $5 million-plus TCV deals up 50% year-over-year in the fourth quarter.
Yet the most significant challenge and opportunity remains the rise of agentic AI. By definition, an agent possesses agency, necessitating a machine identity with the precise context and permissions required to execute its workflow. As enterprises deploy thousands of these autonomous entities, many remain outside of formal governance often lacking property scope permissions. This summer served as a wake-up call as rogue agents compromised environments at several frontier AI labs.
In 1 notable instance, an agent escaped its sandbox and exploited system vulnerabilities because its access has never been properly restricted. At its core, this represents a fundament identity crisis for the enterprise. This is a strategic imperative behind our Idira platform. Idira extends sophisticated identity security and privilege controls to our agents, ensuring every machine action is authorized, scoped and fully auditable.
As we integrate these agentic controls of our AI gateway into Prisma AIRS, we're empowering organizations to enforce security policies and maintain defense in real time. Fiscal 2026 was a transformative year for Palo Alto Networks and the broader industry. We remain convinced that the AI tailwinds catalyzing cybersecurity demand will only intensify as we look towards the future.
First, the global AI infrastructure build-out is drawing trillions in investment. We anticipate more capital expenditure in the next 5 years than the preceding 2 decades. This massive expansion is fueled by demand that continues to outstrip supply. For AI to deliver on its promise, both traffic and data volume must scale and has to do every bit requires inspection, and every byte requires observability.
This surge in critical infrastructure is a permanent tailwind for cybersecurity, a trend already manifesting in the accelerated momentum of our network security and observability businesses this year. Second is a strategic imperative transition towards real-time defense. With cyber attacks now operating at machine speed, fragmented legacy tools are no longer viable. There's approximately $1 trillion of global cybersecurity debt that must be modernized to defend against automated threats. Because AI operates instantaneously, this modernization must occur on unified platforms. Platformization is the only solution for real time defense, ensuring the telemetry policy are harmonized across every control point. We're still in the early chapters of the structural change.
Third, AI has inaugurated a fundamentally new market for cybersecurity. The rise of autonomous agents will dramatically expand the network surface area that requires fortification. Robust governance and security guardrails for AI have shifted from optional features to essential enterprise requirements. While this market is evolving rapidly, we believe the future belongs to architectures providing end-to-end controls, a vision we are delivering through Prisma AIRS.
Lastly, I do want to mention, in breaking news, we closed our acquisition of Console today. Console brings an AI-first approach to product development in the IT and security operations space. [ Andre ] and his team are going to work as part of our Cortex effort to identify our capabilities and drive us faster into the AI era. I want to welcome both the Embrace and Console teams, acquisitions we closed this quarter, to Palo Alto Networks.
As we move into fiscal 2027 with significant momentum, we understand that our continued leadership must be earned through disciplined execution every quarter. I want to express my gratitude to our employees for their performance during this milestone year and to our customers for their enduring partnership.
With that, let me hand over to Dipak.
Thank you, Nikesh, and good afternoon, everyone. We delivered a strong close to a record year, driven by the broad-based strength across our platforms and the early success of our integration efforts. Our teams executed with discipline, and we exceeded guidance across every metric. Before walking through the details, please note that I'll be speaking to our results both on a reported and a pro forma basis to provide a normalized growth comparison where applicable. All growth percentages will be on a year-over-year basis unless stated otherwise.
Starting with the top line, Q4 RPO exceeded $20 billion for the first time, ending the year at $21.2 billion, up 34%. Our bookings growth accelerated for the second consecutive quarter on a pro forma basis, driven by the success of our platformization strategy. Current RPO reached $9.3 billion, also up 34% as contract durations remained steady year-over-year. We also delivered a record result in NGS ARR, which reached $9.1 billion in Q4, up 63%. As Nikesh highlighted, most notable was that nearly $1 billion of net new NGS ARR in Q4, which almost doubled year-on-year and is a milestone that only a select category of technology companies have ever achieved.
I still recall my first quarter as CFO in Q3 of fiscal '21, when we surpassed $970 million in total NGS ARR. We've now added approximately that amount in a single quarter. That's a testament to the multiple growth drivers in our business. five years ago, SASE was still in its infancy, and XSIAM had not yet launched. Today, those will either surpass or approaching $1 billion ARR businesses.
To provide more visibility into our growth drivers, we're introducing new revenue disclosure by platform, as I previewed last quarter. Those 3 platforms are Network and AI Security, Cortex and Idira. We provided historical periods as well as product composition to these platforms in the appendix of our earnings presentation published on our website.
Before diving into our revenue by platform, please note that Network and AI Security includes the certificate life cycle management business we acquired with CyberArk, which has since been rebranded to Next-Generation Trust Security or NGTS. NGTS contributed approximately $85 million to Network and AI Security revenue in fiscal year '26. Additionally, the revenue by platform I will discuss excludes certain items like professional services, which are reported in the category titled Other, as shown in the earnings presentation appendix.
Let's start with Network and AI Security. Our revenue here grew 17% for the full fiscal '26, reaching $8.35 billion in revenue. We continue to deliver above market and double-digit growth in network security, which speaks to our strong competitive position and the large market opportunity still ahead of us in our largest platform. As an example, we continue to gain share in SASE, with bookings and ARR growing well ahead of the overall market. Our software firewall business accelerated once again, reaching 29% ARR growth in Q4. And Prisma AIRS surpassed $100 million in ARR within its first year of general availability. Finally, we had another strong quarter in our hardware firewall business, driven by the adoption of our latest Gen 5 appliances.
Turning to Cortex, which includes our security operations and observability platform. Revenue grew 25% in fiscal year 2026 to $1.92 billion in revenue. As noted earlier, XSIAM continues to be a key driver of Cortex, with ARR growing 70% in Q4. On the observability side, our ARR surpassed $500 million and more than doubled since we closed the acquisition of Chronosphere in Q2. Keep in mind, and as we noted last quarter, our Q4 net new ARR includes a 9-figure benefit from a large LLM customer migrating to Chronosphere from an incumbent vendor.
Lastly, we have Idira, which consists of our identity security platform from the CyberArk acquisition closed in early fiscal Q3. As noted earlier, Idira excludes revenue from the certificate life cycle management acquired from CyberArk. On a pro forma basis, Idira revenue reached $1.26 billion in fiscal year '26 and grew 21%. Our bookings grew faster than revenue in Q4, which is a testament to our early integration success and go-to-market collaboration.
In total, our revenue grew 34% to $3.41 billion in the fourth quarter. And for the full fiscal year, revenue reached $11.5 billion, up 24% year-over-year. From a geographic perspective, we delivered robust growth across all of our regions. The Americas was up 33% year-over-year, EMEA was up 39% year-over-year and JPAC was up 34% year-over-year.
Moving down the P&L. Total gross margin in Q4 was 74.8%, down 100 basis points year-over-year. For the full fiscal year, gross margin was 75.8%, down 60 basis points year-over-year. This decline reflects a mix shift towards our faster-growing SaaS offerings, which continue to scale with our platforms and have yet to reach their gross margin maturity. Looking ahead, the growing majority of revenue is cloud and SaaS, and we anticipate that mix shift will drive our cloud hosting costs faster than total revenue in fiscal year '27.
Turning to the supply chain. We expect rising commodity costs to persist in our hardware business, particularly as it relates to memory and storage. As a reminder, while we're pleased with the strength that we're seeing in our hardware demand, revenue from hardware represents approximately 10% of the total company. We continue to manage our component cost exposure through our strategic supplier relationships and selective pricing actions across our portfolio of hardware products. Ultimately, our primary focus remains on optimizing the business for total operating income and margin, and this focus was reflected in our Q4 results and our full year results.
Q4 non-GAAP operating margin came in at 29.6%. And for the full fiscal year, we achieved operating margin of 29.2%, an increase of 40 basis points year-over-year. This annual expansion is particularly notable, as it includes a partial year of our largest acquisitions, which operated in much lower operating margins at stand-alone entities.
We're making excellent progress on this front. Regarding CyberArk synergies, our integration synergy targets remain 3 to 6 months ahead of plan. Looking ahead to fiscal year '27, we anticipate Higher cost of goods sold will be more than offset by continued operating leverage as we scale efficiently and deliver on M&A synergies.
Our focus on operating leverage drove Q4 non-GAAP EPS of $1.02, exceeding the high end of our guided range by $0.04. Adjusted free cash flow for the fourth quarter reached 1.9 -- sorry, reached $1.29 billion, growing 35% year-over-year. For the full fiscal year '26, adjusted free cash flow was $4.41 billion, delivering a margin of 38.4%, an increase of 40 basis points year-over-year. As a result of our strong free cash flow generation, we ended fiscal '26 with a robust balance sheet, including $7.9 billion in cash, cash equivalents and short-term investments.
Stepping back, over the past 3 years, we've proven our ability to deliver durable and profitable growth. Our execution has driven over 500 basis points operating margin expansion. We've achieved this whilst capturing market share across new categories, driven by our industry-leading R&D investment.
Our operating leverage has also translated directly to cash flow. Adjusted free cash flow margin has been 38% or better in each of the last 4 years. And we sustained the strong cash flow generation even while absorbing the impacts of large M&A and as our customers moved increasingly from multiyear to annual billing. This track record of scaling profitably is the bedrock of our financial model. It provides us with the ability to neutralize potential cost headwinds while simultaneously fueling our innovation engine, our ultimate competitive advantage and the catalyst for our customers' platformization journeys.
Looking ahead, we continue to have increasing visibility into our free cash flow. This has been driven by a combination of steady operating margin expansion as well as a smooth transition to deferred or annual billing in our core business. To provide some context, annual billings increased significantly from 6% of bookings in fiscal '20 to 27% in fiscal '25. Now we're seeing a steady rise with the percentage of annual billings having increased by low single digits year-over-year in fiscal '26 to about 30% of total bookings. With this structural transition now largely stabilized, we have highly predictable compounding cash engine going forward. This cash flow visibility, paired with our continued focus on margin expansion and durable double-digit bookings growth, reinforces our confidence in achieving our 40% free cash flow margin target in fiscal '28.
Before we turn to guidance, I also want to step back and frame the growth opportunity ahead. As I mentioned earlier, our industry-leading R&D investment over the years has fueled our innovation engine and expanded our market opportunity into new categories. That ongoing commitment has earned us leadership recognition in nearly every major category that we operate in. What began predominantly as a stand-alone firewall business is now a platform with multiple billion dollar ARR businesses and several more approaching that milestone.
We continue to remain underpenetrated against a total addressable market of $340 billion by 2030. We believe that AI will only expand our opportunity whilst reinforcing the need for platformization and real-time cyber defense. This puts us on track to achieve our target of $20 billion in NGS ARR by fiscal year 2030.
With that long-term framework in mind, let's turn to our Q1 and our fiscal year '27 guidance. Note that our recently closed acquisitions of Console and Embrace are immaterial to our fiscal year '27 guidance. For the first -- for the fiscal first quarter 2027, we expect -- for Q1, we expect NGS ARR of $9.54 billion to $9.56 billion or 63% growth. We expect RPO of $20.8 billion to $20.9 billion or 34% to 35% growth, and we expect revenue of $3.3 billion to $3.31 billion or 33% to 34% growth, fully diluted share count of 837 million to 844 million shares and diluted non-GAAP EPS to be in the range of $0.96 to $0.98 per share.
For the fiscal year 2027, we expect NGS ARR of $11.075 billion to $11.175 billion or 22% to 23% growth. We expect RPO of $25.2 billion to $25.4 billion or 19% to 20% growth, and we expect revenue of $14.1 billion to $14.2 billion or 23% to 24% growth. We're guiding operating margin of 29.5% and diluted non-GAAP EPS to be in the range of $4.16 to $4.19 per share, fully diluted share count of 844 million to 847 million shares and adjusted free cash flow margin of 38%.
We've included our typical modeling points in the appendix of our presentation for your review, but I would like to point out a few things. First, as previously mentioned, our fiscal year '26 net new NGS ARR included a 9-figure benefit from a large LLM customer migrating to Chronosphere from an incumbent provider. Our outlook assumes the tail end of this migration will last through Q1 of fiscal '27 and that the net new ARR contribution from this migration will be less than what was added in Q4. This will impact the seasonality of the net new NGS ARR for fiscal '27, making Q1 larger than normal. We expect 60% to 61% of the net new NGS ARR to fall in the second half for fiscal year '27.
Second, while we do not intend to give revenue guidance by platform, we are providing initial modeling points to help you establish the revenue growth trajectory for each of the platforms within the context of our total company guidance. For fiscal year '27, we expect Network and AI Security revenue growth of low double digits year-over-year. We expect Cortex revenue up approximately 30% year-over-year, and we expect Idira revenue of approximately $1.5 billion, representing pro forma growth of high teens to 20% year-over-year.
With that, I will turn it back to Hamza for Q&A.
Okay. Thank you, Dipak. [Operator Instructions] First question will be Rob Owens from Piper Sandler, followed by Brian Essex from JPMorgan.
2. Question Answer
Great. Thank you, Hamza. Nikesh, your prepared remarks spoke to a lot of the tailwinds that you guys are seeing across cyber right now. And I think that was evidenced in your booking strength, and you mentioned the second straight quarter of acceleration. But this has been uneven throughout the environment. And obviously, scaled players and players with breadth of coverage really has mattered here.
So to that end, as you look at the new fiscal year, how are you thinking about M&A? How are you thinking about something else that could be transformational to Palo Alto, just given that the market is shifting so quickly? And while you have had an ability to take advantage of it, given what you've done in the past, what are you contemplating moving forward?
Rob, thank you for your question. I'll just send you the names of the company so it makes it easier. I don't have to answer that -- you appreciate that, right? As I always maintain that M&A is not a strategy. M&A is a consequence of stuff that we do from a product development perspective.
To give you a sense, if you -- I talked about the 3 major pivots we've seen in AI already in the last 7 months. You've seen people go from LLMs to agents to now open weight models. And every one of these technological shifts on the customer side obviously requires a slightly different security architecture. How do you protect these agents? How do you ensure that [ open weight ] models are protected, they just don't go rogue?
And obviously, we have a point of view internally, and we're building towards that from a product development perspective. But sometimes you can get caught flat-footed because you're going down 1 path, and suddenly the market shifts elsewhere. This is where I -- we have the privilege of looking at the entire cyber security landscape and seeing 40 or 50 companies that have been funded in this category. And then you suddenly realize that some other company had the strategy right, and that's when you step in and make an acquisition.
So the acquisition happens because they've got a technology trend right and we'd rather embrace it quickly and get on that so our customers can have that capability much faster. Because, honestly, as you can see, after Mythos, what has happened is customers are willing to experiment with a lot of AI implementations. But before they deploy, they want to ensure a robust security harness around it. The most sort of common questions we get are what do I do about the vulnerability that Mythos is going to find in my environment? How do I solve it today and how do I follow it for the long term? Or what happens if we deploy agents and our agents go rogue, how do we make sure our agent doesn't go running to Hugging Face.
All right. Thank you, Rob.
I'll keep your request, and I'll send you the company's name as soon as I buy it.
All right. Thanks for the question, Rob. Next, we have Brian Essex from JPMorgan, followed by Saket Kalia from Barclays.
Nikesh, look, it's great to see the acceleration in CyberArk performance. And only 200 net new logos from the Palo Alto installed base. Would love to get a sense of what those conversations are like? How big are those deals relative to the rest of the CyberArk platform?
And you still have a substantial amount of your installed base. I think a lot of people focus on the cost synergies, they forget about the revenue synergies. How much penetration do you think you can get into your installed base with the CyberArk platform?
Look, I'm really excited about CyberArk. I think if you look at both ends and you rightfully articulated, we have been able to really hit the ground running. On the cost synergy side, you've seen that our margin is reverting back to what our stand-alone margin was in just about 2 quarters. And we think we'll be at a stable point coming into the next quarter.
So to be able to transform a large company like CyberArk in 9 months and get their margins up by 1,000 basis points or more is already good work on the cost side. But like you said, we didn't buy it because we had cost synergy. We bought it because we felt there's a need in the market for identity security, and this was an inflection point.
I think the Phase 1 from our perspective was don't break it, accelerate their momentum. And you've seen we've been able to do that. We just hired new leader last quarter, [ Sunny Sing ]. He's right now at our sales conference in Asia, rallying the troops in CyberArk. The team has taken really well to joining Palo Alto. I think there's been phenomenal collaboration between the 2 teams. I'm excited. We just launched a new product called Modern PAM. So CyberArk was in traditional PAM, Modern PAM is an expansion category for PAM, something they hadn't spent a lot of time on before. The product team at CyberArk has been -- or Idira now, I should say, has been amazing at being able to embrace it. That product is generally available now. We expect to try and upgrade all of the existing traditional PAM customers to that.
So there's a lot of activities we have going on in both on the upsell and expansion side as well as a net new sell side. So as long as we can run at a faster growth rate than CyberArk ran individually, independently and expand the margin by [ 110 ] basis points, I think that's a phenomenal acquisition for us, not to mention that they have a pole position in being able to help with nonhuman identities and agents going forward because that is a whole new field where there is no established leader.
Thank you, Brian. Next, we have Saket Kalia from Barclays, followed by Fatima Boolani from Citi.
Great finish to the year. Nikesh, maybe for you, you said that Mythos isn't a moment, but it's rather at the beginning. And so maybe the question here is, how are you seeing buying behavior change as the AI threat becomes the new normal? And what I mean by that is, do you see more of a willingness to platformize? Do you see more pipeline growth than you would expect? Do you see more appreciation for value, less sensitivity in pricing? I guess I'm just curious if you can translate this new beginning with some of the deal dynamics that you saw in the quarter -- over the last couple of quarters?
Please make sure the suite show up at Hamza's house a week before. Otherwise, you won't get your first spot to ask questions in the future. In terms of the momentum, look, I did say Mythos is the beginning because what is happening is, I've strived for 8 years to go and get CEOs' interest in cybersecurity. I couldn't, but [ Doro ] did a phenomenal job by having Mythos. Because every CEO and I want to talk about what does this mean to us? How do we get access to it, how do we test ourselves from a vulnerability perspective.
But they're wise. They sit down and say, listen, I get it that this is the new normal. People will be able to find vulnerabilities much faster, how do I solve this problem in the long term. That's really where the conversation starts about. The only way to solve this problem in the long term is if something escapes, boss to your perimeter, you got to find it quickly and shut it down. That talks about modernizing their cyber estate. That talks about platformization. That talks about having an AI-driven SOC.
So that's why we've been able to have so many conversations around the modernization of infrastructure. And every conversation is not about fragmenting their estate and buying yet more smaller vendors. It's more about finding a consolidated way of sort of standardizing our platform, evaluating a platform. I think this is a big tailwind for the larger players in the sector. I don't think this is a moment where -- you will see, obviously, startups with some unique products, niche products which they are able to bring to market faster, which customers will use in the interim. But I think this is definitely a long term, I'd say, duration changing trajectory change to our growth rate.
Because you think about it, open source models are now already able to compete with the capabilities of Mythos. And this thing is going to get better, not worse. If that happens, and this capability becomes commonplace, we have a short window by when to get all the cybersecurity technical debt which hasn't been paid over many years up to the mark. And I suspect there will be some major breaches over the coming years because customers have not been able to get their transformation act in place. And that's generally going to be a tailwind for all of us in this space.
Thank you, Saket. Next, we have Fatima Boolani from Citi, followed by Matt Hedberg from RBC.
Nikesh, you brought up this concept of technical debt. So I wanted to zoom out and ask you a question in the context of something you announced earlier this week or a couple of weeks ago, Frontier AI Critical Defense. So one thing we haven't necessarily heard you talk about is this notion of operational technology and the use case here potentially gaining critical mass and especially in the context of your own platformization strategy.
So now that we know what the models are capable of in terms of insane vulnerability chaining against a part of your technical environment that has historically been underinvested in, again, with a lot of technical debt, what are some of the gating factors here still for you to be able to accelerate wallet capture? And then relatedly, how does that cooperation versus competition continuum with some of the frontier lab partners that you have get expressed in this market opportunity with OT that seems like it would be ripe for more capture?
A lot of questions in there. Look, first and foremost, I think 9 months ago, we were all guilty and convicted of near death as cybersecurity and software because frontier AI was going to eat all of our lunch and breakfast and dinner. Clearly, in the last 6 to 9 months has become apparent that that's not happening. We're all going to be enjoying this feast together.
And we've seen both OpenAI and Anthropic and Google come to the table in terms of partnerships. We have early access to these models. We're able to test them. We able to test their cybersecurity capabilities. As I said in my prepared remarks, we are -- we were the first or are the first commercial partner allowed to use Mythos as part of our testing harness. We already use OpenAI 5.6 as part of our testing harness. We are able to bring multiple models to customers.
Because the customers are quickly disincented from this notion of finding more vulnerabilities. They all know what do I do about them. The last thing they want is more security problems, they have enough already. So the conversation is quickly shifting from what do I do about this. And in that conversation is where the need for platforms, as I mentioned earlier, comes up.
In terms of OT specifically, I think the challenge is even more pronounced because OT is hard to patch. Even if you found a vulnerability in an OT instance or deployment, imagine patching an oil rig out in the ocean or imagine patching a bunch of technology which does not have more access cannot be remotely patched, you'd have to go there and fix it. The good news is -- Lee is not here this week, so I'm going to do Lee right now. So we have actually built a capability where we can build signatures for OT vulnerabilities and open source vulnerabilities and deploy them in under 4 hours. So we can find an open source vulnerability and OT vulnerability, deploy the fix in 4 hours and propagate that to our software and hardware firewalls so that will stop the bad actors in their tracks, which is a far cry from the current standard of 55 days, take 55 days to patch open source vulnerabilities or routine vulnerabilities in the world. This will allow our customers to have the ability to block the bad actors for any network-related OT or open source vulnerability in under 4 hours.
So it's a good thing you asked me what the gating factor was. The gating factors really the customers taking the time to understand what major changes do they need to make, doing POCs, assessing what the environment looks like, thinking about who they want to deploy, then eventually getting down deployment. This is not something customers are -- they take their time to go to the deployment. That's why I think it's a long-term tailwind, and you will start seeing that in constant sort of overperformance in the industry on a quarterly basis. But it's not going to be coding agent style ARRs that we're seeing in the AI space, which have [ Envios ] software.
Good answer, but not good cyber leased.
Well, that's easy to fix.
Okay. Thank you, Fatima, for the questions. Next, we have Matt Hedberg from RBC, followed by Michael Turrin from Wells Fargo.
Nikesh, you guys have a long-standing vision of being the #1 vendor in a category. I mean, you don't enter a market unless you think you can be the share leader. And so I guess, putting Lee's hat on again, you've had a lot of success, obviously, in observability. With stand-alone Chronosphere, you added a brace synthetic or you develop synthetics. Where are you from a functionality perspective now versus some of the sort of the historic market leaders there? And how much of this is share shift versus just like this market just getting bigger with AI, and we think we can take a lion's share of it?
Well, look, the premise of Chronosphere has been that it was designed for the AI era. It is a net new technology. The premise of Chronosphere is that because of the large volumes of data that are being sort of spit out in the observability space, it is designed as a architecture that allowed you to have a lower total cost of ownership. So Chronosphere is on average, 30% or 40% cheaper than any of the leading incumbent observability solutions out there.
From a parity of capability perspective, we started off being very good from an AI-native perspective from tracing logs and metrics. So a majority of Chronosphere's customers are AI-native customers, including a very large frontier AI lab. With the absorption of Embrace and the development of [ synthetics ], that will put us at par with some of the leading players on a cross sort of capability perspective, which allows us to go after the enterprise space. So that will allow all the Palo Alto sellers to start selling. For now, we're restricting Chronosphere just to AI-native sales because it's where it's more suited. But I expect the next 6 months, we'll get to a point where Chronosphere will be a competitive product in its category vis-a-vis other enterprise players.
And then we have both an AI-first capability and as well as a cost advantage. So that should allow us, over time, as the space normalizes to have a multibillion-dollar ARR business. Very excited is we bought it when its $85 million ARR. It's already crossed the $0.5 billion ARR. We can clearly see line of sight for that to keep getting bigger over the next few quarters. And then hopefully, address the enterprise market with it as well. Because remember, for us to reach our aspirations of a bigger business, we need to have multiple multibillion-dollar ARR businesses. Observability is such a TAM, [ XSIAM ] is such a TAM. And obviously, our Network Security business and Identity business are similar TAMs.
Thank you, Matt. Next, we have Michael Turrin from Wells Fargo, followed by Gray Powell from BTIG.
Great close to the year. Maybe just on the initial fiscal '27 guide, I'm curious how you approached that exercise given the inflection point taking shape across cyber? You mentioned three major AI inflections you've seen, 4 of them were still early in the overall 2027 cybersecurity budget discussion. So maybe just walk us through what you're assuming as a baseline and any key drivers of upside you see on the horizon we should focus on as well?
Michael, we take the guidance very thoughtfully. And we look at where you are from a consensus perspective. We make sure we look at the underlying business plans of our businesses, evaluate if we are able -- going to be able to meet, beat or exceed your consensus. We're delighted to see that we expect with that execution and the tailwinds, we are going to be able to exceed your consensus. And that's how we guide.
It's very clear. We look forward to it.
Dipak?
Yes. No, I think, Michael, look, we do look at a lot of different inputs. If I just look at a number of the different trends, we will look at what's happening to pipeline, are we seeing traction? Do we see a trend in terms of what's going on with some of the new areas that we have? We take all of that ingest it all, look at the resource requirement, it requires territory planning, et cetera, et cetera. And that's effectively how we do it.
It's a pretty well-established world-class process. I wouldn't say much has changed from a process point of view in the last 5, 6 years that I've been here as the CFO. And I think we've been pretty transparent and there have been a number of inflection points that we've been able to kind of like capture within our forecast criteria.
Thank you, Michael. Next, we have Gray Powell from BTIG, followed by Meta Marshall from Morgan Stanley.
Great. Congratulations on the really strong results. So I just want to make sure that I was looking at something correctly. I think last quarter, you called out $200 million in competitive SASE displacements for the last 9 months. This quarter, that number jumped to $450 million. So I just want to make sure that those are comparable with statistics? Because if so, well, you had a really big Q4. Either way, what's -- as the way the numbers are impressive. What's driving the improved pace of displacements and just overall strength in SASE relative to peers?
Gray, I think the number is $400 million, if I remember correctly. 450? Okay, $450 million. Good. Well, clearly, we had a good Q4. That's evident in our numbers. So yes, we did have a good Q4.
Look, the displacement is a consequence of 2 events. One, when SASE as a category came about early, it was a very Internet-driven phenomena. It was Internet access driven. But COVID changed all of that. When we hit the COVID mark, people wanted sort of access consistently both to the private access as well as in access, which is where we come from. We come from a private access space. And obviously, our product on the Internet access space is now at par or far exceeds the competitive landscape we have in front of us.
It's really the sort of integration of SASE with SD-WAN, which we were early in, we were the first player to go acquire [ CloudGenix ], integrated SASE fabric. Having our SASE fabric be consistent with our hardware and software fabric allows our customers to use Palo Alto firewalls to actually gravitate towards our SASE solution as opposed to elsewhere. And not just that, it also makes it an easier choice if they're looking to consolidate and have 1 platform because they already are using our consoles, our Strata Cloud Manager, our services for the hardware and software follow use case. And it doesn't feel like a big sort of change or to go adopt us on the SASE front as well because we already also have our agents in many cases, which do the VPN product is now a consistent agent of SASE.
So we've surrounded the SASE set of incumbents with effectively a complete platform where the choice of standardization of our platform is a simpler choice for them if they choose to just replace the SASE piece because they already have the other element loss. So sometimes is that, sometimes it's just perhaps customers want to modernize their SASE infrastructure.
And just for clarit, Gray, it was 200 year-to-date at Q3, and it's 450 for the full year.
All right. So it's a pretty big number for Q4. Thank you. That all makes a lot of sense.
Okay. Next, we have Meta Marshall from Morgan Stanley. And our last question will be Brad Zelnick from Deutsche Bank.
Great. Nikesh, you were mentioning kind of this addressing of the $1 trillion of technical debt. Platforms can help enterprises pay for that in some ways. But just how do you think either about ways that you can help them in terms of professional services, investment or other things that can help from just speeding up the amount of technical debt they can address in a compressed period of time?
So as you know, Meta, a few years ago when we launched the platformization strategy, we have had very clear models in the market where we're willing to take staggered payment or align their contracts or deploy before the existing vendor has to be replaced to drive faster platformization. So we make all that available.
Honestly, the constraint that you always run into it, the customers always have a full deck. They're already working on a series of things that they would like to get done in their enterprise. And today, with AI, there's a very large contingent of AI transformation that's out there. People want to transform customer support, they want to go do coding on an aggressive basis, they want to deploy LLMs. So this is yet another priority that must be managed in the context of that overall priority.
So it's just a balance the customer strike. That's why they don't go whole hog and so let's go replace everything tomorrow. They do sit down and say, let's have a more cohesive and intelligent transformation plan. As a transformation plan, it's going to take 5 years is too long, you got to get it done sooner.
So you typically end up in the 1 to 3 range, but it's not something that gets done in 1 quarter. And they want to sort of all walk ground. They want to get some stuff done as other vendors sort of fall off their sort of end-of-life periods or their contracts are up renewal. So all I can say is the desire to standardize or platformize on larger vendors where products are at par or better than the state of the art of the market is becoming more and more of a trend, and that's generally in our favor.
Thank you, Meta. And last, but certainly not least, we have Brad Zelnick from Deutsche Bank.
Wonderful. Thanks very much, Hamza. Nice to see everybody. Nikesh, you have strong credibility doing M&A at this point. And today's Console acquisition seems directionally consistent with moving closer to autonomous security operations. And I can ask the simple why Console, but if you fast forward 5 years and Palo Alto has succeeded beyond your wildest expectations, what's the most valuable activity that customers have completely stopped doing themselves because Palo Alto Networks is doing it for them?
It's a great question, Brad. I think that's why I know what Hamza saves you for last. So if you believe that we're going to spend $5 trillion of CapEx in the next 5 years building data centers and AI capability, I have to believe that AI is going to be adding tremendous value to our lives in the enterprise space. Otherwise, it makes no sense to deploy $5 trillion in the ground.
So I'm an optimist and believe that we will be using a lot of AI to do a lot of agentic tasks. And if that's true, cybersecurity has to become less manual and more agentic and more done by us than the customers themselves because the bad actors will be using AI from their angle, which means we have to make sure our customers are as agentified or AI-fied as the bad actors are. Now that is not possible as you're discovery in every industry category, you cannot deploy AI effectively until we have the right data in place, the right training data, the right data, you have to break the silos and have things talk to each other.
That leads itself towards a cohesive, unified data lake of some sort, whether it's an enterprise IT data lake, observability data lake, a security data lake. If you see strategically where we have been pivoting the business over the last 2 or 3 years is we're a very data first company. Now we ingest a lot of data in XDR. We ingest 19 petabytes a day in the XSIAM product already, and we have just barely north of 1,000 customers. We have observability data which is now the data of an entire frontier LLM that is being ingested to provide them observability.
So we are becoming a data-oriented AI-first cybersecurity company. Our aspiration is to reduce the amount of human intervention in the act of detection, prevention and remediation in the cyberspace. So if you would ask me what's that North Star, that's our North Star. The question is, how do we get there? And that's where the whole company is focused on trying to get there.
So 5 years from now, if you were far exceeding our expectations of ourselves, I would be able to walk in to a company and say, you want to place x, Guess what? I have agents that can understand your deployment. My agents would replace that product. I can do that in under a week. And when I deploy my product, you will need a lot less people. And our products would actually just look for validation from you and get the task done without having you to get into the nits and grits of how to configure things, what policies to write because we've seen that across thousands of instances and we can bring that intellection knowledge to bear.
Today, we look at enterprise products, every enterprise product starts dumb for the next customer despite being deployed for 100,000 customers. I think AI gives us the opportunity of learning for the multiple deployments we do and the multiple customers we have and show up more intelligent for the next customer every time. And that's the aspiration we have.
All right. That concludes the Q&A portion of the call. I'll hand it back to Nikesh for any closing remarks.
I just want to take the opportunity to once again thank all of you guys for being here, thank our customers, our shareholders and all of our employees for what was a spectacular FY '26 for all of us at Palo Alto Networks.
Palo Alto Networks — Q4 2026 Earnings Call
Palo Alto Networks — Q4 2026 Earnings Call
Palo Alto finished FY'26 with accelerating bookings, record RPO and NGS ARR, strong free cash flow, and constructive FY'27 guidance.
📊 Quarter at a Glance
- RPO: $21.2B (+34% YoY) — Remaining Performance Obligations, a measure of contracted future revenue.
- NGS ARR: $9.1B (+63% YoY) — Next‑Generation Security annual recurring revenue; nearly $1B net new added in Q4.
- Revenue: $3.41B (+34% YoY Q4); FY revenue $11.5B (+24% YoY).
- Profitability: Q4 non‑GAAP operating margin 29.6%; Q4 non‑GAAP EPS $1.02 (beat guide by $0.04).
- Cash/FCF: Adj. free cash flow Q4 $1.29B (+35% YoY); FY adj. FCF $4.41B (38.4% margin); cash & equivalents $7.9B.
🎯 What Management Says
- Platformization: Customers are standardizing on a unified security platform to defend at "machine speed"; 220 net new platformizations in Q4 and platform cohort net revenue retention >120%.
- AI as tailwind: Agentic AI and model fragmentation expand telemetry, identities and attack surface — driving demand for real‑time, unified defense and observability.
- M&A & integration: Chronosphere and CyberArk (Idira) integrations are ahead of plan, accelerating observability and identity revenue growth and cross‑sell motion.
🔭 Outlook & Guidance
- Q1 FY'27: NGS ARR $9.54–9.56B (≈63% growth); RPO $20.8–20.9B (34–35%); revenue $3.30–3.31B (33–34%); non‑GAAP EPS $0.96–0.98.
- FY'27: NGS ARR $11.075–11.175B (+22–23%); RPO $25.2–25.4B (+19–20%); revenue $14.1–14.2B (+23–24%); operating margin ~29.5%; EPS $4.16–4.19; adj. FCF margin 38%.
- Model notes & risks: FY'26 net new NGS ARR included a large Chronosphere migration benefit; tail of that migration assumed into Q1. Watch mix shift to SaaS (pressures gross margin) and rising hardware commodity/cloud hosting costs.
❓ Analyst Q&A
- M&A strategy: CEO framed M&A as opportunistic — acquire companies that already have the right tech/trajectory; declined to name targets but signaled continued active inorganic strategy.
- Idira/CyberArk integration: Management highlighted faster‑than‑expected cost synergies, new "Modern PAM" product, ~200 net new logos from cross‑sell and larger average deal sizes.
- AI & platform demand: Analysts probed how Mythos/agentic AI change buying behavior; management sees accelerated platformization, larger SASE displacements (~$400–450M TCV/year) and described rapid OT/patch mitigations (fixes/signatures deployable in ~4 hours).
⚡ Bottom Line
Palo Alto reported a powerful close to FY'26: rapid NGS ARR growth, margin expansion and robust cash generation underpin an ambitious FY'27 guide. Key risks are margin pressure from faster SaaS mix, hardware commodity and cloud costs, and reliance on continued large deal momentum and post‑acquisition migrations. For shareholders, the call reinforces execution on platform strategy and AI‑driven demand, while requiring monitoring of margin mix and the sustainability of recent large bookings.
Palo Alto Networks — Q3 2026 Earnings Call
1. Management Discussion
Good day, everyone, and welcome to Palo Alto Networks' Fiscal Third Quarter 2026 Earnings Call. I am Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, June 2, 2026 at 1:30 p.m. Pacific Time.
With me on today's call to discuss our fiscal third quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. Following our prepared remarks, Lee Klarich, our Chief Product and Technology Officer and Board member, will join us for the question-and-answer portion.
You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q3 '26 supplemental financial information and Q3 '26 earnings presentation.
During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation.
Our presentation also contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures made in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless otherwise noted, all results and comparisons are on a fiscal year-over-year basis.
I will now turn the call over to Nikesh.
Thank you, Hamza. Good afternoon, and thank you, everyone, for joining us today for our earnings call. As you can see, our Q3 performance was exceptional, as we delivered a record quarter. Our results surpassed every guided metric, fueled by an acceleration in organic bookings momentum, the sustained tailwinds from our platformization strategy and surging cybersecurity needs as AI transitions from experimental stages to enterprise-wide production.
Within our core portfolio, we achieved significant traction in network security in XSIAM, while Prisma AIRS continues to establish itself as the fastest-scaling product in our history. Altogether, we delivered $8.13 billion in NGS ARR during the third quarter, representing 60% year over year growth. This is our most significant quarterly outperformance to date and surpassed our guidance.
Our RPO reached $18.4 billion, up 36% compared to last year when adjusting for recent CyberArk and Chronosphere acquisitions, both of which are exceeding expectations in the first quarter post close. Our organic NGS ARR and RPO rose 28% and 22%, respectively. These results are materializing as AI fundamentally redefines the enterprise tech stack, elevating cybersecurity to a mission-critical priority for every organization.
Much has been said about [ Mythos ] over the last many months. Over the past quarter, frontier AI development reached a critical inflection point. We have entered the era of truly cyber capable systems where models like [ Mythos ] possess the autonomous capability to execute comprehensive attack campaigns from start to finish. This represents a fundamental paradigm shift for the cybersecurity industry.
The most critical factor in this transition is speed. When weaponized by adversaries, these frontier models can identify and weaponize vulnerabilities in mere minutes, a process that previously required months of manual effort. Earlier this year, our [ Unit 42 ] research has demonstrated the acceleration by simulating a comprehensive [indiscernible] campaign from initial entry to data exfiltration in just 25 minutes. In contrast, the typical enterprise still requires days to identify a breach.
These existing latency gaps are already a concern, but the emergence of these latest models makes them completely unsustainable. We believe this is merely the opening act. As frontier AI development continues to accelerate, we anticipate a 3- to 6-month window before these systems evolve into more sophisticated hacking entities globally. Within a few years, we expect Agentic AI to reach a level of autonomous execution that is truly unprecedented, scanning environments, generating bespoke exploits and orchestrating [ entering ] campaigns at machine speed without human intervention. That is a trajectory of the modern threat landscape.
However, the same technological leap provides a powerful defensive advantage. We evaluated this potential during the quarter, leveraging our strategic partnerships with leading frontier labs, we utilize early access to their most advanced models to complete the equivalent of years' worth of [ pen ] testing in less than 3 weeks. This unique vantage point allowed us to introduce [ Unit 42 ] frontier AI defense, enabling our customers to fortify their environments against AI-driven attacks.
Market reception has been exceptional. With north of 1,200 customers asking to meet us, we have already completed 800 meetings in the last 6 weeks to help our customers think through their cybersecurity future. These meetings are driving conversations across the platform. In fact, we're already seeing strong interest in our Agentic endpoint security offering since the acquisition of Koi and have already generated interest for over 150 customers. This is critical for securing rising AI coding tools and agents as they proliferate our endpoints.
While identifying vulnerability is a critical first step, true mission-critical production is achieved at run time. Real-time, in-line defense is the only way to shield even unpatched infrastructure as an attack sequence unfolds. This is where the cybersecurity battle will be won or lost.
Countering the next generation of adversaries requires a comprehensive architectural vision that goes far beyond simple large language models. While the capabilities of these frontier systems are impressive, they are not a silver bullet for cybersecurity.
We currently see 2 major structural challenges: First, the prevalence of false positives, with error rates often received reaching 25%, forcing manual intervention that destroys the speed advantage of automation. Second, these models always fail at the last mile of complexity, leaving critical gaps in remediation and vulnerability management.
In today's threat landscape, the most subtle 1% of novel attack techniques are what lead to the most devastating breaches. For every enterprise, the defensive bar must be perfect, while an attacker only needs to succeed once. The probabilistic nature of even the most advanced systems leads to inaccuracies. And in a mission-critical environment, the cost of a false positive is simply too high. One wrong enforcement decision can take down a global production network. Just as autonomous vehicles require constant real-time validation, an automated defense must be built on high fidelity telemetry and battle tested against every edge case to be mission-ready.
An AI model is only as effective as the data it can see. As frontier models become available to everyone, the real competitive advantage shifts 1 model to the data fuel. That is why having sensors that sit in line with live traffic is so vital. They provide the telemetry and context needed to outmaneuver bad actors while serving as a critical enforcement point.
The logic is simple. The more you integrate, the more you see, the more data you unify. The better the AI performs, the more you inspect your run time, the faster you can stop an attack. Our global footprint now exceeds 125 million sensors across network, endpoint and cloud, ingesting over 17 petabytes of daily telemetry. This scale creates a powerful flywheel. Every new sensor makes our entire platform more intelligent, which leads to more deployments, more data and even stronger real-time protection.
This reality is why platformization is the only sustainable answer. The legacy approach of query based tools that wait for human reaction cannot keep up with machine speed threats. We are transforming the industry by consolidating data onto a single platform, reducing breach response times from days to minutes through AI-driven pre-analysis. Point products that silo data and increased latency are becoming obsolete. As the battle moves to fighting AI with AI, we believe Palo Alto Networks is in pole position, and our Q3 results proves that momentum.
As AI compresses attack time lines, only a platform that gets smarter with scale can respond fast enough. During the third quarter, we secured 110 net new platformizations, a figure that includes 20 from our CyberArk and Chronosphere integrations. These strategic additions expand our reach into large addressable markets within identity of observability. Given the fragmented nature of these sectors, they are perfectly aligned with our overarching platformization vision.
We concluded Q3 with roughly 2,280 total platformized customers, bolstered by the inclusion of our latest acquisitions. These engagements represent deep architectural commitments rather than simple transactions. When organizations reach this integration milestone, they standardize their infrastructure on our platform, yielding superior long-term retention expansion. This is reflected in our 120% net retention and single-digit churn rates amongst this cohort.
Moving forward, we remain confident in surpassing 4,000 platformizations by fiscal 2030, providing the primary momentum towards our $20 billion target for NGS ARR. The scale and quality of our customer business this quarter reflect how strategic these platform commitments have become and how customers are increasingly bringing us in to secure their production AI deployments to scale.
Let me share a few examples. In Q3, we surpassed $200 million in ARR with a leading frontier AI lab that relies on us for observability across its most depending training and inference clusters. We expect that to continue to grow again next quarter as they complete their migration to Chronosphere. One of our largest Q3 deals was an $80 million transaction with the leading power producer in the United States, an organization in the center of the AI infrastructure expansion. They selected our [ next change firewalls ] and also adopted SASE to secure distributed workforce over 25,000 employees. A global consulting leader signed a deal for over $20 million, selecting Prisma AIRS, our AI security platform, to secure its rapidly growing fleet of AI apps and agents, now running more than 2 trillion tokens per month on our platform. This was an existing platformized customer who spent several months working closely with us to secure this entirely new frontier. It is also a record Prisma AIRS win and speaks to our customers, partners with us for the AI transformation journey.
As AI raises the stakes, these deals further validate our position as a cybersecurity partner of choice. That is particularly notable in our network security business, where we had our strongest Q3 in several years. Our largest business unit, network security, delivered its most robust third quarter performance in years. This momentum underscores the mission critical role of real-time network traffic inspection as enterprise-wide AI initiatives continue to transition to production.
We saw strong growth in hardware, SASE and software firewalls during the period. However, in the early innings, we anticipate that AI will serve as a structural catalyst for deeper traffic inspection requirements. The initial pace of AI adoption was primarily conversational, but the shift towards Agentic AI represents a fundamental change. Unlike simple chat bots, autonomous agents trigger a massive volume of secondary machine-to-machine interactions, consistently accessing tools and data to complete complex workflows. This creates a surge in nonstop high-volume traffic that must be secured at run time.
This evolution directly translates into heightened demand for high-throughput hardware, expanded cloud-based software capacity and the necessity for unified policy enforcement across the entire platform. Our Q3 results featured the strongest hardware performance in a decade, with next-generation firewall booking rising nearly 40% year-over-year. This was supported by our latest Gen 5 appliances and early access and AI data center build-outs.
We're seeing early adoption from a new class of buyers, including sovereign infrastructure providers in AI labs, representing a significant new market as deployments move beyond traditional hyperscalers. A key differentiator for our hardware portfolio remains the strength of our subscription attach, illustrating how customers are standardizing the security stack on our platform. Within our installed base, we currently average more than 4 subscriptions per device.
Our innovation engine continues to expand this opportunity. We now provide 11 advanced subscriptions, including our next-generation trust security, which utilizes CyberArk's [ certificate management ] to address emerging compliance standards for shorter certificate lifespans.
Palo Alto Networks remains the fastest-growing provider in the SASE market. In Q3, SASE ARR reached $1.6 billion, growing 40% year over year as customers prioritize unified protection across hybrid workforces and AI applications. Competitive momentum remains high, with nearly 50 displacement wins totaling $200 million in contract value year-to-date. Secure browser also achieved a major milestone, scaling to 11 million licenses, a fourfold increase that cements its status as a critical control point for the AI enterprise.
Furthermore, software firewalls remain a high-growth pillar of our strategy. ARR rose 25% in Q3, accelerating as organizations expanded their capacity to inspect growing traffic between cloud and AI workloads. As these environments scale, the requirements for high fidelity telemetry only increases.
The carbon architecture approach is also increasing -- is driving increased customer growth in Prisma AIRS, which continues to be the fastest-growing product in our history. Organizations are aggressively moving beyond the experimental phase, deploying AI agents and applications to production. This transition creates entirely new mission-critical security demands. We believe we are the first in the industry to embrace AI security platformization, yes, AI security platformization capable of securing and monitoring AI end-to-end. We have effectively doubled our capabilities in this space in just over 9 months.
Our journey began with securing models and runtime defense. We then integrated identity security to govern agent access and observability to create agent behavior across complex infrastructure. Most recently, we expanded to Agentic endpoint security as AI tools proliferate across the edge. Our recent acquisition of Portkey marks yet another strategic milestone. As a leading AI gateway processing trillions of tokens monthly, Portkey provides a critical enforcement point to monitor every request to apply real-time policy to agent-to-agent interactions at scale.
This relentless innovation has established Prisma AIRS as our fastest-growing product ever, reach over 300 customers in Q3, tripling our Q2 count, and have clear visibility towards $100 million in ARR with the next couple of quarters for a product that was not in the market 1 year ago. Ultimately, securing the AI enterprise generates a massive volume of run-time telemetry. The data is only actionable if processed at machine speed, which is a core mission of our Cortex platform.
XSIAM remains our primary response to the emerging frontier model threat. As attack cycles compress to machine speed, organizations can no longer rely on legacy [ co ABS-based ] architectures or manual dashboards. Effectively countering AI necessitates a defensive strategy powered by AI. Upon the introduction of XSIAM 42 months ago, we entered the sector as a disruptive innovator, engineering our platforms to ground up to redefine security op centers. Today, our platform processes more than 17 petabytes of daily telemetry, a volume unmatched by any other pure-play security vendor.
We ended the third quarter with more than $600 million in ARR, representing 100% year-to-year increase across a growing base of 740 customers. The most significant metric, however, is the outcome. The majority of our customers are now responding to threats in under 10 minutes. This is a dramatic reduction from the days or weeks previously required and serves a blueprint for the modern SOC.
In observability, our Q3 performance was well above our initial expectations. As the AI initiatives generate a surge in telemetry, Chronosphere is a purpose-built capability to scale alongside these workloads. Our observability ARR surpassed $300 million this quarter, nearly doubling since our acquisition announcement last autumn. Furthermore, 80% of our net new customer acquisition this year adopted multiple products, reinforcing our platformization momentum.
The world's leading AI natives, including 2 of the top 5 frontier labs, have adopted Chronosphere, validating our ability to provide observability at AI scale. Beyond our early investments in markets where AI would drive a positive inflection, we also recognized early where AI would overhaul existing security categories. Consider posture management, traditional periodic scanning is insufficient when attack time lines are measured in minutes. As a result, we proactively transitioned our cloud portfolio from static post to real-time detection to Cortex Cloud. We're making steady progress and anticipate most Prisma customers will be migrated to Cortex Cloud by the end of the fiscal year.
Now as these agents proliferate, every autonomous entity represents a new identity that must be managed, what leads directly to our progress with CyberArk. In our inaugural quarter post close, CyberArk has surpassed our internal benchmarks as we move to execute our unified vision for identity security. Last month, we launched Idira, our next-generation identity platform for the AI-driven enterprise. For years, the industry operated under the [ IM Fallacy ], the belief that he only needed to secure a handful of privilege administrators.
In the era of Agentic AI, that distinction has vanished. Every identity, whether human, machine or software agent, now possesses the potential to access the sensitive systems at machine speed. Idira addresses this shift by democratizing modern TAM controls across all users and extending protection to Agentic entities, which represent the primary attack vector of the future.
Our execution in Q3 was strong. Joint go-to-market efforts have already initiated approximately 1,000 [ cross org ] engagements. We have sustained CyberArk growth trajectory while improving its profitability profile through our integration initiatives. Given our rapid progress, we are now 3 to 6 months ahead of our original time line for converging CyberArk profitability with our own, a milestone we expect to reach within the next 12 to 18 months. This acceleration reinforces our path towards a 40% free cash flow margin in fiscal 2028, which Dipak will talk about more.
The events of the third quarter represent a watershed moment for cybersecurity and has elevated our category even higher on the CIO priority list. Mark my words, [ Mythos ] has increased the terminal value of the entire cybersecurity industry. We are identifying several structural catalysts from the AI cycle driving growth across our platform.
First, AI creates a massive surge in traffic and connection points requiring real-time inspection. As agents trigger hundreds of secondary actions, network security becomes indispensable foundation for safe AI adoption. Second, countering machines to be adversaries requires real-time automated defense. This is a core mission of XSIAM consolidating data onto a single platform, so AI can respond to threats in minutes rather than days.
And third, in an environment populated by both human and agents, [ identity ] serves as a primary defensive layer. And autonomous entities can execute actions independently, securing access via Idira becomes mission-critical. The conversion of these trends validates our platformization strategy. Managing fragmented data and silo point products is no longer viable in an AI-driven landscape. A unified platform that gains intelligence with scale is the only path forward. While we're still in the early stages of the shift, we remain committed to innovating ahead of the threat landscape and earning our customers' trust every day.
I will now turn the call over to Dipak to discuss our financial results in greater detail.
Thank you, Nikesh, and good afternoon, everyone. We delivered a record Q3 with broad-based demand across our platforms and geographies. We exceeded our guidance ranges across the board, driven by an acceleration in organic bookings growth and outperformance from our recent acquisitions as we made early progress on our integration efforts. Please note that during my remarks, I will discuss results with and without the impact of Chronosphere and CyberArk. The financial impact of our acquisition of Koi, which closed later in the quarter was immaterial to our Q3 results.
Starting with next-generation security ARR. We delivered 60% year-over-year growth in Q3, reaching $8.13 billion. This included $1.63 billion from CyberArk and Chronosphere. We surpassed $300 million in ARR for Chronosphere, our next-generation observability platform. That was an over 50% increase from Q2 and far exceeded our expectations, driven by an existing LLM customer increasing consumption as they continue to migrate from the incumbent vendor. Excluding the impact of CyberArk and Chronosphere, NGS ARR was $6.5 billion, up 28% year-over-year, and net new NGS ARR was $370 million, up 18% year-over-year. Please note that this excludes ARR attached to our hardware backlog that also reached record levels for a Q3 quarter.
We saw notable strength in network security, which is our largest segment and accounts for approximately 70% of our total revenue. All [ net set ] factors delivered sustained or accelerating growth in Q3. In SASE, ARR reached $1.6 billion, up 40% year-over-year, more than 2x the overall market growth rate. We have seen a nearly 50% increase in SASE net new NGS ARR over the trailing 12 months, driven by continued scale, strong performance in net new logos and displacement wins. Software firewall showed strength once again this quarter, with ARR up 25% year-over-year, driven in part by the increase in Prisma AIRS and firewall [ Flex ] deals.
As Nikesh highlighted, Prisma AIRS continues to be our fastest-growing product ever. We have over 300 Prisma AIRS customers as of Q3, up from just 100 at the end of Q2. As AI adoption grows in the enterprise, we believe AIRS is becoming a foundational infrastructure for secure AI deployment.
Turning to remaining performance obligation or RPO. We ended the quarter at $18.4 billion, growing 36% year-over-year. Excluding $1.8 billion from CyberArk and Chronosphere, RPO grew 22% year-over-year, which we believe is a direct result of our platformization strategy, driving deeper customer commitments across our platforms. Current RPO was $8.3 billion, up 34% year-over-year. Excluding the impact from CyberArk and Chronosphere, current RPO was $7.2 billion and grew 17% year-over-year, an acceleration versus 15% in Q2.
Total revenue for the quarter was $3 billion, growing 31% year-over-year. Product revenue was $594 million, and total services revenue was $2.4 billion, both growing 31% year-over-year. As I've highlighted in previous quarters, software and recurring revenue now represents a large and growing portion of this line item. Today, product revenue includes major growth drivers, including software firewalls and Prisma AIRS, SD-WAN and self-hosted identity security subscriptions.
As a result, 46% of our trailing 12-month product revenue in Q3 included recurring software revenue, a significant increase from just 22% 3 years ago. Hardware, which is approximately 10% of our total revenue, delivered its best quarter in a decade, fueled by strong demand for our next-generation firewalls. And we saw early AI data center wins, contributing to record Q3 backlog. Our next-generation firewall bookings grew nearly 40% year-over-year in Q3 as we continue to gain share.
AI data centers and AI-driven enterprise networking needs are driving a new market opportunity for us, which could potentially be additive to our long-term growth for firewall appliances. From a geographic perspective, we saw a broad growth across all of our major theaters, with the Americas growing 32% year-over-year, EMEA up 32% year-over-year and JPAC growing 26% year-over-year.
Moving down the P&L. Our Q3 strength was not confined simply to our top line metrics as we continue to drive profitable growth across the P&L and executed against our M&A integration strategy. Total gross margin for the quarter was 75.8%. This included services gross margin of 75.1%. We continue to balance services gross margins by driving efficiencies in cloud hosting, whilst the mix shift of our high-growth SaaS offerings increases. Within this, product gross margin was at 78.8%, which was a 40 basis point improvement year-over-year.
Turning to the supply chain. We are closely monitoring rising component costs, particularly in memory and storage. Please note that we have approximately 1 million firewalls in the field, and our acquired component volumes are not as significant to some of our peers. Furthermore, we remain well positioned to navigate these dynamics for the following reasons. First, our higher recurring revenue mix acts as a natural hedge. Hardware today accounts for approximately 10% of our total revenue compared to 20% in fiscal year '21.
Second, our vendors view us as a critical infrastructure provider, and we have a track record of leveraging our prior supply chain experience and expertise to mitigate these impacts. This includes evaluating alternative sources of supply, extending purchase commitments with our suppliers. Thirdly, we continue to evaluate further pricing actions. As a reminder, we implemented a 10% price increase on hardware in early April. The impact to pricing and rising component costs are reflected in our Q4 and fiscal 2026 outlook. These dynamics, paired with the continued operating efficiency, resulted in non-GAAP operating margin of 21.3% in Q3, flat versus Q3 of '25. Looking forward, we expect to drive operating leverage as we scale and continue to make progress against our M&A integration plans.
In Q3, we made a lot of progress on our integration plans. This was driven by strong execution and collaboration by our teams across every function, including our new colleagues from our recent acquisitions, who have truly risen to the occasion. This is already driving tangible results.
Our integration philosophy starts with product and our relentless focus on driving innovation. Just months after closing the CyberArk transaction, we introduced Idira, our next-generation identity security platform. This includes the key innovations Nikesh highlighted, including modern PAM and Agentic identity security integrated with Prisma AIRS as well as deeper integration of identity signals with our core [ net sec ] and Cortex platforms. Early go-to-market collaboration has also been encouraging, with more than 1,000 cross-organization engagements initiated between the core and identity sales organizations to date.
On the expense side, we're leveraging our combined scale to drive improved cloud hosting economics for the acquired CyberArk business. Post close, we're optimizing our organizations to deliver a unified 1 team culture that is future ready. We are carefully reviewing every single line item across each of our financial statements to drive operating leverage across vendors and functions. This includes streamlining our combined real estate footprint, which includes over 40 new facilities from our acquisitions, to enhancing and fostering collaboration post close.
Additionally, we're optimizing our marketing and our IT vendor footprint. To date, we have identified more than 300 IT vendors to streamline and have already dispositioned approximately 20%. All of these factors combined will enable us to hit our CyberArk synergy targets about 3 to 6 months earlier than we initially anticipated. This visibility, paired with our continued operating leverage across the overall company, reinforces our confidence in reaching 40% free cash flow margin in fiscal '28.
In Q3, we generated adjusted free cash flow of $910 million, a 57% increase year-over-year. On a trailing 12-month basis, we generated $4.08 billion in adjusted non-GAAP free cash flow. This represents a margin of 38.5%, a 430 basis point improvement year-over-year, even with the inclusion of CyberArk and Chronosphere. We will, of course, have a full year of CyberArk and Chronosphere expenses next year, but these results solidify our continued ability to deliver best-in-class free cash flow margin and enabled us to raise our fiscal '26 guidance.
The strong cash flow generation supports our opportunistic share repurchase program. During Q3, we utilized $1 billion to buy back 6.8 million shares at an average cost of $147.69. We currently maintain $1 billion of remaining capacity under our existing repurchase authorization.
Moving to the non-GAAP items. Stock-based compensation increased sequentially to 17% of revenue in Q3, primarily driven by SBC related to our recent acquisitions. While M&A-related SBC will continue to be amortized in future quarters, we expect stock-based compensation as a percentage of revenue to return to pre-acquisition levels on a run rate basis in approximately 12 to 18 months. Beyond stock-based compensation, our GAAP results also reflects transaction and integration costs from these acquisitions, further detailed in our SFI.
These nonrecurring charges resulted in a GAAP net loss per share of $0.22 for the quarter. Our diluted non-GAAP EPS, which adjusts for SBC and onetime items, reached $0.85, which came in $0.05 above the high end of our Q3 guidance.
Reflecting on my 5 years in the seat, I've always maintained that our business model scales well across every line item of our P&L. This financial framework is precisely what allows us to execute our broader corporate strategy from a position of strength. When you look at our M&A trajectory, we initially proved this execution capability by integrating over 20 tuck-in acquisitions to build out our platforms. Today, we are successfully integrating larger, highly strategic acquisitions, all while driving durable growth and balancing against our profitability commitments.
Now turning to guidance. Given the acceleration in our Q3 organic bookings growth, our early progress on M&A integration and the strong Q4 pipeline, we are raising our full year fiscal 2026 guidance across all metrics for both our core and acquired businesses. This quarter and last, we provided a breakout of performance for both our core business and our recent acquisitions. Our intention was always to make this a onetime in nature and move our disclosures closer in line to how we run the business. Therefore, we'll be moving to total company guidance moving forward.
Beginning in fiscal 2027, we intend to provide segment-level revenue disclosures across network security, Cortex and identity. This will align our reporting with how we run the business and our platform strategy post integration.
Now let me take you through guidance in detail. For the fourth quarter 2026, we expect NGS ARR of $8.9 billion to $8.95 billion or 59% to 60% growth. We expect RPO of $20.9 billion to $21 billion or 32% to 33% growth, and we expect revenue of $3.345 billion to $3.355 billion or 32% growth. Fully diluted share count of 830 million to 840 million shares, diluted non-GAAP EPS to be in the range of $0.96 to $0.98.
For the fiscal year 2026, we expect NGS ARR of $8.9 billion to $8.95 billion or 59% to 60% growth. We expect RPO of $20.9 billion to $21 billion or 32% to 33% growth. We expect revenue of $11.415 billion to $11.425 billion or 24% growth, operating margins to be in the range of 28.9% to 29.2%, diluted non-GAAP EPS to be in the range of $3.77 to $3.79, fully diluted share count of 763 million to 766 million shares and adjusted free cash flow margin of 37.5%. We've included our typical modeling points in the presentation for your review.
And with that, I will turn it back over to Hamza for Q&A.
Okay. Thank you, Dipak. [Operator Instructions] First question goes to Saket Kalia from Barclays, followed by Brian Essex from JPMorgan.
2. Question Answer
Okay. Excellent. I have a little trouble with video, but I'll ask the question. And congrats to the team on the results and the guide. Nikesh, maybe for you, there's tons to talk about, but I'd love to dig into your network security business just a little bit more since you mentioned a potential multiyear tailwind there. Maybe the question is, can you talk about how much AI data center demand is contributing to that? And outside of AI data center builds, how are your other customers thinking about their network security needs as AI traffic grows?
Thanks, Saket. I thought you're going to ask me about the 40% free cash flow question you mentioned on CNBC. But anyway, we'll save that one.
It speaks for itself.
Okay. Look, you saw across the board we've always maintained that as more traffic traverses networks, more inspection is needed. When more inspection is needed, hardware is the cheapest and fastest throughput mechanism to inspect the data. I think the multiyear tailwind will come from the fact that more and more data needs to be stored both by organizations needs to be used for training all these frontier labs out there. and you can see the explosion of data centers being built, whether it's by hyperscalers, frontier labs or neoclouds out there. And you're seeing that demand fall through to some of the hardware vendors in the space.
I think couple that with the -- so the scarcity and component pricing, you've seen some price increases, we've seen some of that mixture of price uplift as well as demand uplift. But I think maybe the number has gone from 5% to 8% to 10% to 12%. So that's a 50% increase in demand for the industry, I think. I think you'll see that. And I think you'll tell me before I can tell you when you see when data center growth starts to taper off or plateau, this thing is going to come to roost. But I expect that this trend should continue for the next few quarters, if not a few years. Lee, do you want to -- Lee thinks I gave a good answer.
All right. Thank you, Saket. Next, we'll go to Brian Essex from JPMorgan, followed by Matthew Hedberg from RBC.
Yes. Nikesh, I'd love to ask you about Prisma AIRS. Great to see the traction there, and would love to understand from a customer perspective. One of the things I thought was very important that you mentioned was the ability for a platform to have more effective speed or mean time to detection and response. How are your customers evaluating that as they look at kind of the elevated threat environment they have following the emergence of like Mythos and GPT and Glasswing -- Project Glasswing announcement?
So let's do a double deep with this. I'm going to start off and then I'll have Lee talk about some of the capabilities that were needed in the AI future. Look, 1 of the things which we have done, as many of you know, over the last many years, we actually built native VM capability in many of the hyperscalers.
Now you're seeing that is where a lot of the models are being hosted. A lot of the AI artifacts are sitting for customers because, AI is not an on-prem event. It's typically a cloud of it, hyperscaler. And the fact that we have native firewalls sitting in those hyperscalers allow us to inspect traffic, not just regular cloud traffic but also AI traffic. I'm going to have Lee talk about all the capabilities we've built at [indiscernible] the last 12 months, which have allowed us to provide all the security capabilities that AI needs.
So there's -- like every cybersecurity sort of space, I'll call it, there's an end-to-end component. There's a sort of shift left, which is even before you deploy AI in what you do in terms of model scanning and AI red teaming and validating the application itself and the AI usage of that all the way through the runtime components, which are sort of very focused on real-time threats, how to detect and prevent them. And then all of that also becomes a feed into the SOC, and the SOC has to be able to ingest data from all of these different sensors, analyzing real-time, using AI and then apply automation in order to achieve the mean time remediation that Nikesh was talking about earlier in the prepared remarks, where we can't be operating in a model where sort of legacy model of mean time to detection of days when attackers, particularly with these new models, are able to carry out attacks start to finish in tens of minutes.
And so they're the -- they feed into XSIAM, the amount of data that XSIAM can ingest, speed of processing, AI, automation and response. That ability to prove to customers of all the rest that have already been deployed that we can achieve MTTR in minutes is a very powerful proof point for them of believing that they will be able to achieve the same outcomes as well.
Great I'll leave my follow-up for later.
Thank you, Brian. Next, we'll go to Matt Hedberg from RBC, followed by Meta Marshall from Morgan Stanley.
Great, guys. Very impressive results, to say the least. I guess within your observability platform, the $200 million AI frontier lab customer, $100 million of net new ARR added this quarter, super impressive. I guess, can you talk about how observability in security is converging and how that positions you really to take share versus competitors that primarily start with an observability first solution?
Yes. Matt, I think, first of all, it's important to note that these are each specialized environments. So meaning you have to be really, really good at observability regardless of any potential integration with security, and the same is true with security. And I start there because if you look at all of the previous attempts to try to expand from 1 to the other, what you saw was perhaps a strength in 1, but then trying to apply the same logic to the other. You can't take an observability platform, just to add a little bit and all of a sudden say that it's a good security platform and vice versa.
And so I say that because it's very important. XSIAM is best-in-class in what it does, and we've proven that. Chronosphere from observability perspective is best-in-class, and we've proven that. And in both cases, we have very strong road maps of capabilities that we'll continue to add to them.
What you'll see over time going forward is data collected for the observability use case will be valuable as a sensor to the security use case, meaning XSIAM will start to leverage that data to expand the data can analyze for security purposes. And importantly, vice versa, data collected for the security use case will be valuable to having additional context, broader context for the observability use case.
So the first part is the data that is collected for each of these independent use cases start to cross-pollinate to the other. The second part is really related to [ AgentiX ]. And what you're seeing across these spaces is a need for AI-driven automated response. And AgentiX, we believe, is that foundation that will be leveraged across all of our platforms, obviously, starting with Cortex and expanding to Chronosphere. And so AgentiX becomes the other key point where you'll start to see increased integration across the observability and security space from us. But again, in both cases, this is starting from a position of strength independently, and the cross-pollination adds to those capabilities.
Thank you, Matt. Next, we'll go to Meta Marshall from Morgan Stanley, followed by Shaul Eyal from Cowen.
Great. Maybe the question for me is just filling on the $200 million opportunity that you guys have with the frontier lab. How does that change how you're thinking about the opportunity with the AI native? And just can you give a sense of the breadth of the platform that they were kind of buying within that deal?
Well, look, each of the models has a different approach in terms of how they do with observability. So have their own approach on a DIY basis. Some of them are using third-party vendors like us. So I don't think it's 1 size fits all.
What we are seeing that Chronosphere is particularly good at AI and native platforms, whether it be frontier AI labs or whether it's be SaaS software, I call them modern SaaS software companies and not older SaaS software companies. Typically, what's happening is the observability market is maturing. Companies are beginning to realize as volume scales, it's not okay to DIY. I think the general reluctance in the observability industry historically has been cost. I mean, even at Palo Alto, when we were deploying a third-party vendor, we chose to turn it off because it is prohibitively expensive.
And what Chronosphere has done has been able to deliver that same capability at approximately half the cost of what the industry charges. So it starts to meet the number at which you're better off not building your own or using open source with some enterprise capabilities, you're better off using platforms like Chronosphere. So it's early days. As Lee said, we have a road map that requires us to bolster a few more capabilities on the platform to make sure it's competitive in its space. But the -- I call it the -- the advanced practitioners already see the capability and the ability and are happy to use it. And we continue to make progress on the road map to make sure that it becomes a full comprehensive platform. And hopefully, it becomes another mainstay platform for us in the future.
Thank you, Meta. Next, we'll go to Shaul Eyal from Cowen, followed by Fatima Boolani from Citi.
Congrats on results and guidance. Nikesh, I know most are focused on the ongoing progress of CyberArk and Chronosphere, great results on that front. I actually want to ask a double-click on Koi and the Agentic endpoint and progress and interest that you guys are seeing on that angle. There's definitely some sort of a renaissance taking place in endpoint. Can you tell us what's driving that?
Sure. The -- I think it has been maybe a little while since the endpoint really changed. The types of application deployed seem to be pretty similar. The types of attacks seem to be kind of similar. They evolve. But what's happened really -- and it's very quick in the last 12 months is the -- all of the activity now on the endpoint, I should say, all, but most of it now is becoming Agentic. And so you think about some of these vibe coding tools, think about things like [ Open Clad ] in its brief sort of history, it's not just a new application gets deployed there. It's the application, and it brings a whole ecosystem with it, right?
So you look at these vibe coding tools, it's not just a vibe coding application. You have skills and hooks and scripts and MCP servers and all sorts of other stuff that come with it. And so it's almost like you have a whole new endpoint ecosystem on top of the 1 that already existed. And that requires specialized functionality. It's not as simple as just adding a couple of features and claiming to be able to secure the new Agentic endpoint.
And that's what we observed. We observed this starting last fall. And as we started to look around, we identified the Koi was very unique in their ability to provide this type of security capability. That is what got us excited about enough to actually deploy the Palo Alto Networks. That is what led to, obviously, the acquisition. And now with the advent of what we're seeing with these new AI frontier models, that is adding to the already high level of interest because it's very clear that vibe coding and AI development and Agentic endpoints in general are going to be critical to the success of every organization, and it has to be secured.
Thank you, Shaul. Next, we have Fatima Boolani from Citi, followed by Michael Turrin from Wells Fargo.
Nikesh, this 1 is for you. There is a voracious appetite for any large company that basically had the rug pulled under them as it relates to the risk of novel AI attacks. So in the context of Unit 42, I wanted to get a sense how much incremental investment do you expect to put behind that franchise? How capacity constrained are you? And maybe to take it up another level, this whole notion of the Agentic SOC and Agentic remediation, if you will, how much of that are you dog fooding or champagne drinking, you can choose your flavor, inside Unit 42, whereby you can drive both scale and efficiency and a strong product feedback loop into the portfolio?
Fatima, thank you for the question. Look, we have repurposed our Unit 42 team to focus primarily on frontier AI defense. As I mentioned, we've had north of 1,200 outreaches from customers, both -- with both directions where we reached out to our customers and they have to us. Both Lee and I and a lot of people in my team have personally done tons of meetings. I've done close to 100, Lee's done close to 100.
We're doing these meetings to talk to our customers on how they want to strategize, not just about how to react to models like Mythos because we believe it's real, but also to prepare for something that can get better and better and how does the infrastructure need to change that 6 to 12 months from now. We are firmly of the belief that people will have to deploy the newer endpoint capability like Koi, go to Prisma Access browser or secure browsers, they will have to go put virtual patching capability in the firewalls and fundamentally reimagine their SOC and use XSIAM.
So all of that is true. But the conversation usually start with Unit 42 trying to help them test their code, make sure their code is safe, their code is robust, test their configuration to help them with some form of, I'd say, managed patching for their environment because every vendor is going to show up with lots of patches that need to be done this time. So that's probably where Unit 42 is focused short term. Long term, they're focused on transforming architectures, where, again, all [ Apolitus ] focused on delivering that capability.
As it relates to Agentic dog fooding or champagne drinking or dogs drinking champagne, I think we have -- and I don't want to say this is sometimes better be lucky than good. we did design XSIAM with the idea of pre-analyzing everything before we ingest the data. So XSIAM is turning out to be a great tool in this regard in terms of reducing the median time to detect intermediate for our customers. And it has agents running in it to give you that capability.
I think that capability will increase, and we can have a long concession what exactly the agent is. I think there's a lot of deterministic workflows that run to reduce the task of a SOC analyst, a lot of automation that exists in XSIAM. And over time, perhaps our customers will trust those agents to act independently. For now, the customers want to sort of see, observe and approve, which is where it's set up. I think as customers get comfortable with the deployment, they'll get to give it agency.
So we're not seeing that rush demanding agency. I think right now, our customers are in Phase 0. We're just saying, "Should I better collect all my data because if I don't have all the data, I don't have all the context, but I don't have all the context, I can't actually react to an AI attack."
Next question is Michael Turrin from Wells Fargo, followed by Adam Borg from Stifel.
Great. And congrats on the strong results here. Nikesh, you had some useful details throughout the prepared remarks, but hoping you could expand on some of what you're seeing in terms of AI-driven demand, specifically how some of the larger customer conversations you had account in terms of customer conversations you're having have evolved since Mythos and if there's a greater sense of urgency there heading into fiscal Q4? And in terms of the metrics, is it RPO platform wins or -- what are the key metrics you'd point us to, to help us gauge progress as you continue to work towards those opportunities?
So Michael, I want to make sure all of you understand. 6 months ago, cybersecurity stocks were doomed because AI was going to protect every 1 of us, and we were all out of a job, right? And suddenly, we're hiring more people, AI is not taking jobs away. And suddenly, you can't execute a cyber protection scenario without using a platform cybersecurity vendor.
I mean think about it, I think the part of which you must pay attention to Michael, as I said there's a 25% false positive rate, which means an AI model can say, "Oh my God, I see a vulnerability." And 1 time out of 4, it's not seeing the right vulnerability, which means if you let AI do the job, it could try and patch something that was working perfectly fine. And if you let AI go protect that, you might have screwed up something else.
So I think you got to take this as a grain of salt to understand that the big takeaway, if I was in your shoes, I would take from this is if you thought that the terminal value of cybersecurity was gone like many SaaS companies, this terminal value is here to stay. You actually just created a longer-term G in your model for long-term growth rate for cybersecurity.
And I think to the extent you felt that demand was going to get weak in Q4 or Q1 or Q2 for someone, it's not going to get quick. Now I wouldn't get ahead of my skids and start throwing the kitchen sink at numbers for cybersecurity companies because there is still a process, a mechanism, a cycle that people buy in and there's execution and deployment. So to the extent that do I see good demand, yes. To the extent I believe that this demand will continue for longer, yes. To the extent do I expect a windfall next quarter, the following quarter? No, I expect robust growth.
Next, we'll go to Adam Borg from Stifel, and we'll end with John DiFucci from Guggenheim.
Awesome. Thanks so much for taking the question. Great to see the continued traction. Nikesh, maybe go deeper into SASE? I mean, these results have been great, outpacing the market. Talk more about the traction you're seeing overall? And maybe help us just rank order is that traction across SSC, SD-WAN, Prisma Browser, et cetera? Any more color there would be really helpful.
Look, I think, Adam, we are what I think I'd like to call the second wave of SASE. Right? The first wave SASE was Internet access or VPNs. And that's what -- you could call them SASE, but they would effectively feature capabilities in that market. And you saw the VPM people like the firewall guys win the VPN battles. You saw the Internet access companies, which are the early SASE players win the SASE battle.
I think as we evolve from there, what we're seeing is the desire for a comprehensive network stack. What I mean by desire for a comprehensive network stack, people call it 0 trust, people count a single policy across multiple network capabilities. People call it network re-architecture. People are figuring out that if you want to secure your traffic, you want to dynamically route your traffic, there's a lot of contention between SD-WAN and security, you need to have this come platform.
Now we bought SD-WAN many years ago, and we only sell it as part of the SASE platform because we don't believe we should be in the solo SD-WAN business for the most part. And that was the strategy. Now we're seeing network architecture projects show up or people say, oh my God, I really understand Palo Alto's security framework because we use Palo Alto firewalls, amazing. You're telling me I can just duplicate those policies across my entire network stack and not have to go learn a new stack, right set of policies? That's cool. Oh, wait, I can do that in software firewalls and Prisma AIRS now as well.
So I think what we're seeing is the benefit of consolidation. Now I think 1 more thing has changed in the mind as a customer. This is my eighth year -- 8 week anniversary in 4 days, I'll hit 8 years of Palo Alto, surprise, surprise. And I'll tell you, there was a lot more willingness to take best-of-breed 8 years ago. I think that willingness has slowly subsided, where the customers see the value, perhaps if products have normalized, perhaps the companies have matured, but customers are much more comfortable talking about a consolidated strategy with hardware, software and SASE.
And I think what you're seeing is our ability to present that capability as a platform. We are taking share from some of the I'd say SASE only customers. And unfortunately, to their chagrin, firewalls are not dead. And just the way hardware is not dead and PCs aren't dead. The storage isn't dead, firewalls aren't dead either. So having a firewall leader who has the ability to deploy world-class SASE is helping in the market, that's what you're seeing.
Thank you, Adam. And our last question will go to John DiFucci from Guggenheim.
Thanks, Hamza. Nikesh, everything looked pretty good this quarter. Like everything. Like you had some -- 1 of your competitors on the hardware side did well. So I think people kind of expected that. But everything was good. So the 1 I wanted that wasn't asked here is CyberArk. I mean we all modeled CyberArk [indiscernible] we had models. And I know it's a month off. But geez, that looked like better than I had modeled it before, and CyberArk was 1 of the...
You don't trust me, John.
I do. I do. I trust you. And I wish I was not where I am right now. But I guess if you thought -- think about CyberArk. Is that something -- is it just like, okay, this first quarter that you have your all go-to-market behind it? Or have you even done that yet? And is it -- are we seeing -- is it really the core PAM from CyberArk? Are you seeing any machine identity actually taking hold yet? Or can you talk a little bit about CyberArk and how come it was so strong?
Look, the 1 which I think we talked about fleetingly John, and I'll tell you a lot of things are going well, and we continue to toil through migrating our Prisma Cloud customers to Cortex Cloud. I wish that was behind us, but that is still ahead of us for the next 6 months. So we'll keep grinding through that. That was not contributing as well as some of the other products are. So that's fine. That's why you have a portfolio of platforms, and some do amazingly well, and they cover up for their slightly slower brethren and the slower brethren come from behind and go win after that.
So I think we feel not everything is perfect, John, but a lot of things are doing well. So thank you for that part. As far as CyberArk is concerned, I think we have a very, very measured strategy around CyberArk. Remember, this is our first large acquisition. The biggest fear in large acquisitions people think is that we will break it. And I think the most important part is we did not break it. Look, mommy, I didn't break it. It's working, okay?
We worked with the company. We made sure that we talk to every 1 of the leaders. In fact, the entire CyberArk product team is in Palo Alto right now in our offices. We spent most of yesterday and this morning with them, and we'll continue to spend the next 2 days with them. The plan was just the way when I found Palo Alto 8 years ago, it was a great company. It is a great company. So was CyberArk. We have to make sure that, that product gets more modern and more innovative. And that's what the team is very focused on.
And what we're seeing is commitments. We're now going out to customers, showing them the road map, promising them that the PAM product is going to even get better than compared to what it already is, and we're going to show them great outcomes. There are Palo Alto customers are asking to meet CyberArk. There are CyberArk customers asking to meet Palo Alto. We said we've done 1,000 meetings where Palo Alto and CyberArk people are talking to each other and going to the customer together. 2 independent sales teams, but they are connected in a 1,000 different places, which is already creating some degree of momentum.
So our plan is don't hurt the top line, make sure that the existing customers still love us, want to buy, want to upgrade, and they're going to see better product. That's Phase 0. Take out all the places that could be friction overlap, which allowed us to streamline and get better operating margins.
I just got an e-mail this morning. We have migrated 1 of our critical systems from CyberArk independent system to Palo Alto and CyberArk on the same system. We have 4 more major systems to get through in the next 4 months. We think we'll get there before the end of this calendar year. If we can integrate their back-end systems to common systems, we're using AI to write a whole bunch of new coding capabilities, sales capability.
So topic number one, trim the fat or trim the overlap and don't break the top line. We think we're on track not to break the top line, improve the profitability, which we've done. As we said, we think we're going to be 6 months ahead on profitability because we found ways to get there faster. Our job is then to make sure that if we can deliver the next capability of products, which is incremental to what they already had that allows us to look at the following fiscal year and say, how do we go out and hit the ground running in the following fiscal year to deliver better top line.
So CyberArk is our chance at Palo Alto to prove that we are capable of doing amazing large acquisitions. We're capable of integrating large teams. And if I can prove that, the market will give me the license to go in again. So this is existential for me, it's existential for my team, and they know it. So we're going to work hard to make sure CyberArk succeeds, allowing us to do more and more of that in the future at Palo Alto Networks. Thank you for the question, John.
Thank you, John. This concludes the Q&A portion of the call. I'll pass it back to Nikesh for any closing remarks.
So I just want to say thank you. We officially declare [ Sazali ] for cybersecurity dead. I want to thank our partners and employees and all of you guys for supporting us. See you guys next quarter.
Palo Alto Networks — Q3 2026 Earnings Call
Palo Alto Networks — Q3 2026 Earnings Call
Record Q3: beats across metrics, AI-driven platform demand accelerates ARR, RPO, margins and cash flow.
📊 Quarter at a Glance
- NGS ARR: $8.13B (+60% YoY)
- Revenue: $3.0B (+31% YoY)
- RPO: $18.4B (+36% YoY)
- Adj. free cash flow: $910M (+57% YoY; trailing 12‑mo $4.08B, 38.5% margin)
- Gross margin: 75.8% (product 78.8%)
🎯 What Management Says
- Platformization: Management argues customers standardize on a unified security platform — more sensors, unified telemetry and inline enforcement create a data flywheel that improves AI defense and retention.
- AI as catalyst: Frontier/Agentic AI compresses attack timelines to minutes, driving urgent demand for real‑time inspection (network, endpoint, observability) and new products like Prisma AIRS and Agentic endpoint security.
- M&A integration: CyberArk and Chronosphere are accelerating cross‑sell and profitability; Koi and Portkey add endpoint/AI gateway controls.
🔭 Outlook & Guidance
- Q4 FY26: NGS ARR $8.90–8.95B (59–60% YoY); RPO $20.9–21.0B (32–33%); Revenue $3.345–3.355B (≈32%); non‑GAAP EPS $0.96–0.98.
- FY26: Revenue $11.415–11.425B (+24%); NGS ARR same as Q4 target; operating margin 28.9–29.2%; non‑GAAP EPS $3.77–3.79; adj. FCF margin 37.5%.
- Risks: component cost pressure (memory/storage), hardware supply mix, and AI model false‑positive/remediation limits could affect timing and margins.
❓ Analyst Q&A
- Hardware tailwind: Analysts pressed on AI data‑center demand; management sees multiyear upside as AI traffic drives higher inspection needs and 40%+ NFW bookings growth.
- Product convergence: Questions on Prisma AIRS, XSIAM and Chronosphere focused on reducing mean time to remediation to minutes; management highlighted cross‑pollination of observability and security telemetry.
- M&A execution: CyberArk integration seen as ahead of plan (3–6 months); Koi/Agentic endpoint interest noted but customers currently prefer observed/approved automation over full autonomous remediation.
⚡ Bottom Line
- Investment thesis: Strong beat, raised guidance and exceptional cash generation validate Palo Alto's argument that AI is expanding cybersecurity TAM and favoring platform leaders. Execution risks (supply chain, integration, AI false positives) remain, but momentum, product traction and buybacks support shareholder value near term.
Palo Alto Networks — Q2 2026 Earnings Call
1. Management Discussion
Good day, everyone, and welcome to Palo Alto Networks Fiscal Second Quarter 2026 Earnings Conference Call. I'm Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, February 17, 2026 at 1:30 p.m. Pacific Time.
With me on today's call to discuss our fiscal second quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. Following our prepared remarks, Lee Klarich, our Chief Product and Technology Officer and Board member will join us for the question-and-answer portion.
You can find the press release and other information to supplement today's discussion on our website at investors.paloalto networks.com. While there, please click on the link for quarterly results to find the Q2 '26 supplemental information and Q2 '26 earnings presentation.
During the course of today's call, we'll be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in the presentation today.
This presentation contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial measures and reconciliations are in the press release and the appendix of our investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis.
I will now turn the call over to Nikesh.
Thank you, Hamza. Good afternoon. Thank you, everyone, for joining us today for our earnings call. We delivered a strong Q2 fueled by robust demand for cybersecurity and continued execution against our capitation strategy. This led to strong organic results in Q2, with NGS ARR up 28% and revenue growth of 15%, excluding the impact of recently closed on. We saw broad-based strength across our products from SASE, software firewalls and in through our emerging leadership in security and Prisma Air.
We [indiscernible] this growth with improving profitability achieving a 30% loss operating margin for the third consecutive quarter. We're excited to head into the second half of the year having closed both the CyberArk and [indiscernible] acquisitions, and I want to extend a warm welcome to both teams. Both companies continue to deliver record numbers in their most recent quarters, and we look forward to building on the momentum as we hit the ground running on our integration plans. These investments are a direct response to the inflections we see taking shape in the market.
And while it's still early, initial feedback from our customers has been very encouraging. We believe we are now entering the next phase of AI adoption. While enterprises are moving beyond experimentation and beginning to integrate foundational models into real workflows. As I becomes embedded in day-to-day work, the central question that organizations face is shifting from capability control. That shift has meaningful implications of security.
As AI becomes more pervasive across the enterprise, it expands the attack surface area, more agents, more infrastructure, more machine-to-machine activity and new classes of risk that simply did not exist before. In that environment, security cannot set the sidelines. Despite the current sentiment about AI and software, we firmly believe that security is enabling layer that allows innovation to move forward safely and at scale. And as the agents become autonomous employees, the old security playbook is not just slow, it's obsolete. Security must operate in real time at the critical control points where decisions are made across network, endpoint, cloud, browser and identity. This is where Palo Alto Networks operates.
And as BAI becomes more embedded across the enterprise, those control points are converging. A fragmented defense of disparate products is no longer a viable strategy. The risk is simply too high and adversaries are moving at machine speed. Our latest Unit 42 research confirms this end-to-end attacks are now 4x faster than a year ago. And in nearly 1/4 of the cases, attackers were able to break in and accelerate data in under an hour. The good news is that 90% of those breaches were preventable caused by basic gaps in visibility and controls across multiple attack vectors. This is why we committed to our platformization strategy a few years ago.
A platformized approach built on a real-time data-driven model that gets smarter with scale is the only way to secure the modern enterprise and our results continue to prove that out. In Q2, we delivered approximately 110 net new platformizations, a quarterly record outside of our seasonally strong Q4. This brings our [indiscernible] count of approximately [indiscernible], up 35%.
The success of this strategy is also reflected in our best-in-class net retention rate amongst platformized customers, which stands at 119% with low single-digit churn. This proves that once customers adopt our platform, they not only stay, but continue to invest more with us over time. This momentum isn't accidental as a result of a deliberate 5-well motion we've built. When we committed to our platformization strategy years ago, we're betting the shift that has now become an industry standard. This approach allows us to not only solve these problems, but also provides the foundation to address new ones as they emerge.
It starts by providing multiple clear landing paths. In network security, customers can begin with SASE, hardware or software firewalls and now AI security with Prisma. In the SOC, they can land on our core platform via XDR cloud security or directly under IM. From any starting point, customer experienced the superior outcomes of an integrated platform, which leads them to adopt more deeply across our ecosystem.
In a market changing this quickly, we believe our responsibility is to anticipate the next inflection and ensure our platform is ready. That philosophy guides our strategic investments and results give us the confidence to continue. A secure browser, for example, was one such early investment that is now accelerating our SASE business with over 9 million licenses sold to date.
Similarly, in [indiscernible] Prisma AIRS, launched just a few quarters ago and already rapidly scaling with over 100 customers ending in Q2. This is the discipline we now plan to apply to 2 large established markets poised for inflection, identity and observability. If AI becomes a new interface for how work gets done, identity security will be required to create the permissions and boundaries that teams can trust. And as I introduce unprecedented scale, observability is essential for building resilient systems that can operate reliably. By bringing our platformization discipline to these new pillars, we believe we can deliver even greater value to our customers and solidify our role as a trusted partner to navigate the complex security and data challenges in the AI era.
Let me share a few examples of how this strategy is translating into deeper, more strategic customer relationships. First, a global automotive leader selected us for a major security transformation. Their goal was to modernize their security architecture and dramatically improve efficacy. This resulted in an over $50 million deal, including $30 million for SASE and $20 million for XSIAM to run their global [indiscernible]. Similarly, a global technology supplier selected us for our transformation initiative for over $40 million, choosing Exim to modernize their security operations globally while expanding their investment in SASE.
Finally, a transaction with a leading IT service provider perfectly illustrate [indiscernible] building on existing investments, they committed for a $20 million expansion centered on XSIAM and have now platformized across network security and security operations. These aren't just transactions, they're architectural decisions. When the stakes are highest, these wins validate that industry leaders are choosing the superior outcomes delivered by Palo Alto Networks.
With that, let's dive deeper into the individual performance of our platforms, starting with our largest segment. Our Network Security business delivered a standout quarter demonstrating the power of a platform designed to meet customers wherever they are in their hybrid journey. In Q2, our SASE business continued to go from stand to stand, surpassing the $1.5 billion ARR milestone while growing approximately 40% year-on-year, solidifying our position as the fastest-growing SASE provider at scale.
What's particularly telling you the shift we are seeing in the market, many early adopters of SASE, who made choices 4 or 5 years ago during the pandemic are now finding that those early solutions are not comprehensive enough for today's stretch and complexity. As a result, they are reconsidering their first-generation point products in favor of a platform approach that provides a single unified architecture to secure an entire hybrid environment. from the data center to the cloud and the remote workforce.
A key driver of these wins is also our secure browser, which stems from a strategic bet we made a few years ago with the acquisition of talent. Our thesis was that the browser is the most critical unmanaged edge for users, data and now AI agents intersect. The results show our customers agree. As of Q2, Prisma Browser has been adopted by over 1,500 customers 10% of which are in the Global 2000, with an additional [indiscernible] in licenses [indiscernible] sold in Q2. This success has clearly not gone unnoticed. It's encouraging to see others in the industry waking up to the idea that they must secure the browser layer, validating the importance of this increasingly critical control point.
While many of these approaches similarly extend existing architectures into the browser, we continue to believe the browser itself should function as a native security platform. architecture for real-time control rather than retrofitted through extensions. We also continue to see strong momentum in our software for business. Last quarter, we called our hidden gem. That was validated once again in Q2. Our ARR growth was approximately 25%, driven by the need to secure increasingly dynamic multi-cloud environments, a need that grows as AI workload scale. This is complemented by our strongest hardware performance in several quarters revenue up nearly 10%, driven in part by early adoption of our latest Gen 5 firewalls.
Finally, we remain focused on where the market is going, and that includes preparing our customers to the post [indiscernible]. [indiscernible] is already here. [indiscernible] are using a harvest now to [indiscernible] strategy, stealing encrypted data today to break in the future. seeing this become a key level priority in our early customer conversations. The broader interest in this topic was confirmed by nearly 5,000 attendees at our quantum set last month. This is a critical part of our customers' long-term road map, and we believe we are uniquely positioned to guide them through this coming architectural uplift and shift.
Now moving to Cortex. Customers continue to partner with us on their AI SOC modernization. In Q2, XSIAM surpassed the $0.5 billion ARR milestone. We welcomed almost 150 new customers, bringing our total base to over 600 paying an average of nearly $1 million in ARR. But the key story here remains not just the growth, it's the outcomes. Over 60% of our deployed customers are now achieving meantime remediation of less than 10 minutes, a profound shift from the days or weeks they measured before. The success of Xome is a great example of our ability to identify a market inflection early, invest aggressively and execute to scale.
We made a bet on the [indiscernible] became an industry-wide team. the results are showing at scale just 3.5 years after GA. The same focus on what's next led us to develop Agentic. The simplest way to think about it is we're enabling our customers to build a workforce of autonomous agents as a key differentiator and what makes us a real breakthrough is where these agents can operate. Unlike traditional security tools confined to their own ecosystem, our agents can securely extend into first and third-party infrastructure. This means an agent can not only detect the issue XSIAM, but then can go out and or to remediate it directly in a cloud console, an identity provider or a firewall machine speed. This capability already enabled by 200 XSIAM customers is the key to delivering true enterprise-wide automation.
This is a powerful example of how we use to create better security outcome. But that's only one part of our AI security strategy. Over the last couple of years, we have expanded our AI security capabilities aligned to what our customers need as they deploy AI at scale. We're bringing those capabilities together as part of a universal AI security platform. when designed to protect AI deployments of models, agents and the environments in which they operate. It starts with [indiscernible] to secure AI models and power applications across our life cycle from model selling and [indiscernible].
We launched this platform just a few quarters ago, and its adoption has been remarkably strong. From Q1 to Q2, we more than tripled our customer count to over 100. While bookings also doubled during the same period with the 9-figure pipeline already materializing is clear, the market has been waiting for a comprehensive platform to secure. At the same point, we're also seeing a new class of autonomous agents emerge software can perform [indiscernible] and interact with local systems on it so.
This naturally extends secure requirements to the endpoint. This is why I'm excited to announce our intent to acquire COI, a pioneer in securing the next major inflection point in security the genic endpoint. Core will enhance our endpoint capabilities within XDR 2.0, while also becoming an integrated part of our universal AI security platform, extending security and governance to autonomous agents at the device player. We are witnessing a dramatic chip now software is on the endpoint, traditional security tools are often blind to the new AI layer of software, the massive rise of MCP servers, browser extensions, plug-ins, and [indiscernible] code that bypasses standard security controls. This represents a significant unmanaged attack service.
We identified this new threat vector early and Palo Alto Networks has been a customer of coil since summer of 2025. On my recent trip in December, [indiscernible] met with the [indiscernible] team and were immediately impressed by their foresight into the next generation of endpoint threats. Since then, we've seen the [indiscernible] intensify, including security concerns that have been recently [indiscernible] by the widespread adoption of open call. We [indiscernible] the latest example of what the future of an AI attack surface will look [indiscernible] our XDR platform remain well positioned to provide the most innovative security solutions to our customers. After closing, Core will also be able to buy unique extensions to Prisma AIRS and Prisma browser to ensure that our customers have visibility to any software and browser that are only present on the endpoint, resulting in the most comprehensive visibility to the AI attack surface.
Over time, this will help ensure that the end point becomes more Agentic our customers will remain fully protected. Now this focus on visibility is critical. But to active precision, you first need to see with clarity. This is why a new level of observability is so essential which brings me to Chronosphere. In the HFI, Chronosphere offers a unique value proposition, deliver [indiscernible] at a massive scale, proven in production today by many of the world's leading born-in-the-cloud [indiscernible] companies. During Q2 and after we closed the [indiscernible] acquisition, we signed a multiyear non-figure expansion deal with the leading AI model provider, a testament to crosses ability to scale in the largest and most complex environments. The momentum is clear in the numbers with the company generating approximately $200 million in ARR as of Q2, well above our expectations.
The [indiscernible] platform is also getting traction with over 80% of new logos last year, landing with multiple products such as metrics, logs and traces. By combining Chronosphere deep visibility with the automated reaction of Agentic, we are enabling our customers to build a self-healing autonomous enterprises in the future. So we have prevention, we have visibility and we have automation. But every action, whether by a human or any agent is governed by an identity, which brings me to our newest major pillar. We're delighted to have closed the acquisition of CyberArk early in Q3 and are ready to execute on what I believe is a massive opportunity in identity security. As many of you noticed earlier this month, CyberArk is coming off an exceptional December quarter the record net new ARR and 30% of subscription art growth at scale. We've been rigorously building and refining our integration plans and we're moving fast to put these plans into execution.
This includes aligning our go-to-market engines, we're already well underway on detailed account planning and aligned sales incentives to ensure our teams are collaborating from day 1. From a product perspective, innovation road app here is massive. We aren't just looking at legacy IM which, in our view, is basic [indiscernible]. We're building a next-generational identity security platform that protects across humans, machines and AI edits. We also look forward to delivering machine identity and certificate life cycle management to our 65,000-plus firewall customers longer term, we remain excited about the opportunity to address the growing needs of identity to secure AI agents.
We bought CyberArk because when [indiscernible] start logging in at machine speed, logging in becomes a primary attack factor. We believe we are now the only company that can verify the who has secured the what simultaneously. Given the momentum in the business currently and our innovation road map, we believe we are well positioned to become the largest energy security player over time. In summary, we continue to execute against our platformization strategy in Q2 with momentum building across multiple areas of business. Our core innovation engine remains strong with great traction in new products like AIRS and [indiscernible] and are ready to put our integration plans into action with CyberArk [indiscernible].
Before I hand over to Dipak, I want to take a few minutes to reflect on the recent advancements in AI. We're seeing significant innovation in new agent platforms targeting the enterprise. And while it's still early, it is causing some companies to reassess how the applications are built, our workflows are automated and our decisions are made. Long-standing assumptions about system [indiscernible] are being revisited and perhaps even more so, the analytics layer built on top of them. In many enterprise applications, data reflects structured business processes within defined workloads. Security data is different.
In our case, it is real-time threat activity generated at the control point where our platforms operate and continuously refined through more than 30 billion attacks block daily and 15 petabytes of termite processed in our AIS. That distinction matters. When we say Precision AI and not [indiscernible] onto a feature set. It is AI-trained our proprietary asset and embedded directly at those critical control points. begins interacting autonomously across application infrastructure, fragmented security introduces a delay at precisely the wrong moment. Security must operate as according to system, unified, consistent and real time. Because our platform sits at these control points, we see these shifts as they have it.
They generate across the network, cloud, identity, endpoint and browser continually informs our models, creating a feedback move that compounds at scale. But scale is not enough sustaining leadership requires a willingness to adapt and challenge our own assumption. Technology cycles change. architectures evolve. For the past 7.5 years, we have consistently aimed to invest ahead of inflection points and technology even when the part is not fully defined. Maintaining this discipline is vital to ensuring that we remain the digital [indiscernible]
However, the technology stack would evolve. With that, I will hand over the call to Dipak to view the quarter results in detail.
Thank you, Nikesh, and good afternoon, everyone. As Nikesh noted, our strong Q2 results reflect the consistent execution of our platformization strategy, coupled with a robust demand environment. The increasing adoption of our platforms is most evident in our next-generation security ARR, which grew 33% to $6.33 billion. This includes a $200 million contribution from our recent acquisition of Chronosphere.
On an organic basis, NGS ARR was up 28% year-over-year and net new ARR was up 11% year-over-year. This performance was driven by an acceleration in SASE and software firewall ARR, alongside continued momentum in XSIAM. A key contributor to our software firewall growth in recent quarters is Prisma AIRS as customers increase their AI deployments, they're looking for a trusted partner to secure this critical transformation. Prisma AIRS directly addresses this need. And as Nikesh mentioned, it is scaling rapidly with over 100 customers and in Q2.
Our remaining performance obligation, or RPO, grew 23% to $16.0 million. This includes approximately $150 million of RPO from our Chronosphere acquisition. It's important to note that RPO balances for Chronosphere can fluctuate from period to period given usage-based pricing with ARR and revenue being more representative of business performance. Our current RPO, which represents a near-term revenue realization was $7.1 billion, representing 18% growth.
Total revenue was $2.59 billion and grew 15%. Given the close of our Chronosphere acquisition came near the end of fiscal Q2, the revenue contribution was immaterial during the quarter. Product revenue was up 22% and with 45% of the product revenue coming from software form factors over the trailing 12 months, which was up from 38% in the trailing 12 months ending Q2 '25. This was driven in part by strong demand for software firewalls as noted earlier. Our software growth was complemented by improving hardware demand led by the adoption of our latest Gen 5 firewall appliances and SD-WAN. Total services revenue grew slightly above 13%. Within this, subscription revenue was up 14%, while support revenue grew 12%.
From a geographical perspective, we saw broader strength across all of our major theaters with the Americas growing 14%, EMEA growing 17% and JPAC growing 17%. Moving further down the income statement, our disciplined focus on profitability and operational leverage continued to deliver strong results in Q2.
Given the timing of the Chronosphere acquisition, the impact of this transaction to our P&L financials was immaterial. Our total gross margin for the quarter was 76.1%. Within this, product gross margin was 78.2%, an increase of 150 basis points year-over-year, driven by a higher software mix compared to last year. As noted earlier, we did see improvement in our hardware business during Q2. Therefore, on a sequential basis, the higher mix of hardware and product revenue resulted in a 180 basis point decrease to product gross margin versus Q1.
The Services segment delivered gross margin of 75.6%, down 100 basis points year-over-year. The year-over-year change in services gross margin reflects a positive mix shift towards a high-growth SaaS offerings, which remain in the earlier part of their scaling curve. We continue to be pleased by the growth SaaS offerings and remain focused on driving efficiencies here.
Now turning to the side chain. We observed a marginal impact on product COGS this quarter from higher memory and storage pricing, but we believe we are well positioned to manage through these dynamics. First, our high and growing software mix provides a natural hedge. Second, we will leverage our scale, deep supply chain expertise and lessons learned through COVID and prior supply chain constraints. And third, pricing actions taking effect later this fiscal year will help offset corresponding cost increases.
We have proactively factored these considerations into our Q3 and full year outlook. We delivered our third consecutive quarter of 30%-plus operating margins with Q2 operating margin of 30.3%, a 190 basis point expansion versus Q2 of last year. The strong expansion reflects our ability to drive consistent scale and efficiency across all OpEx line items. Our diluted non-GAAP EPS reached $1.03, which once again came in above the high end of our guidance. Q2 adjusted free cash flow was $502 million.
On a trailing 12-month basis, we generated $3.75 billion an adjusted non-GAAP free cash flow, representing a margin of 37.9%. Our cash and cash equivalents for the period was $7.9 billion, reflecting a $2.6 billion cash consideration for the Chronosphere acquisition. Given the recent close of our CyberArk acquisition, we expect the $2.3 billion cash outlay in Q3. This results in a total combined cash outlay of $4.9 billion. In connection with our acquisition of CyberArk, we guaranteed the payment obligations on the CyberArk's convertible senior notes due 2030.
The acquisition resulted in a make-whole fundamental change under the notes, and we will be making an offer to repurchase the notes in the coming days. We also issued 112 million shares in consideration for the CyberArk acquisition. Before I turn to guidance, I also want to extend the warm welcome to the over 4,000 talented individuals from CyberArk and Chronosphere.
We're thrilled to have them on board and excited to execute on our integration plans to unlock the full value of these acquisitions. Our focus is on a frictionless onboarding experience for our new colleagues. And within just the first few days, we've provided access to collaboration tools for every individual to work as one cohesive team. We remain confident in our ability to deliver significant scale and leverage across every line of each of our financial statements.
From an operational standpoint, integration is being executed with the same rigor that we apply to running our core business. We've established clear governance defined work streams across all functions, including IT, finance, IT, HR, product and go-to-market and implemented measures to ensure continuity for customers, partners and employees. Our priority is maintaining business momentum while methodically bringing platforms, we're putting structures and operating rhythms together.
Taken together, we believe this disciplined approach to integration reinforces our confidence in delivering sustained growth and operating leverage, enabling us to achieve our target of 40% free cash flow margin by fiscal 2020. And our longer-term goal of $20 billion in NGS ARR by fiscal 2030.
Now let me take you through the guidance. Please note that our Q3 and full year 2026 guidance is inclusive of both the CyberArk and Chronosphere acquisitions, which have been aligned to our fiscal year and our definitions of certain non-GAAP metrics. This includes NGS ARR, which reflects only the subscription portion of CyberArk's ARR and has been conformed to our standard revenue-based definition.
Our Q3 and full year 2026 guidance assumes reported NGS ARR for CyberArk will be approximately 2% to 3% lower than the equivalent on the CyberArk previous bookings-based ARR definition. Please see the appendix of our earnings presentation for more detail on the comparison of the 2 ARR definitions. For the fiscal third quarter 2026, we expect NGS ARR to be in the range of $7.94 billion to $7.96 billion, an increase of 56%. This includes a $1.47 billion contribution from M&A., remaining performance obligation of $17.85 billion to $17.5 billion, an increase of 32% to 33%. This includes a $1.6 billion contribution from M&A.
Revenue to be in the range of $2.941 billion to $2.945 billion, an increase of 28% to 29%. This includes a $340 million contribution from M&A. Our fully diluted share count of 81 million to 817 million shares, which accounts for the close of the CyberArk acquisition on February 11.
Diluted non-GAAP EPS to be in the range of $0.78 to $0.80. For the fiscal year 2026, we expect NGS ARR to be in the range of $8.52 billion to $8.2 billion an increase of 53% to 54%. This includes a $1.52 billion contribution from M&A, remaining performance obligation of $20.2 billion to $20.3 billion, an increase of 2% which includes a $1.6 billion contribution from M&A, revenue to be in the range of $11.2 billion to $11.31 billion, an increase of 22% to 23%. This includes a $760 million contribution from M&A.
Operating margins to be in the range of 28.5% to 29%, diluted non-GAAP EPS to be in the range of $3.65 to $3.70 per share, our fully diluted share count of $768 million to $773 million shares, which accounts for the close of the CyberArk acquisition and adjusted free cash flow margin of 37%. We have included our typical modeling points in the presentation for your review, but I would like to highlight a few now.
First, note that under our accounting policy, the upfront portion of term licenses and any perpetual license revenue from CyberArk will be recognized as product revenue, all of our Chronosphere revenue will be included in services. For Q3, we expect product revenue growth of 25%. And for the year, we expect product revenue growth in the low 20s. With that, I will turn it back to Hamza for Q&A.
Thank you, Dipak. [Operator Instructions] First, we've got Rob Owens from Piper Sandler, followed by Brad Zelnick from Deutsche Bank.
2. Question Answer
Nikesh, looking back at 2018, 2019, the prevailing fear that cloud computing would render parts of the the Cyrsecurity stack obsolete, at that time you leaned in via M&A, and repositioned the portfolio. Obviously, the business has tripled since that today. Now we entered this AI here and the narrative fuel is oddly similar. Could you compare that existential nature of this AI shift to what we saw in cloud and maybe what areas you think will be obsolesce. And then specifically, is M&A the primary lever again this time around? Or does your starting position differ at Palo Alto from where you were, let's say, at the start of the cloud cycle.
That's the long one question. Nice to see you again. So that's a good question. Look, I think when we looked at in 2018, '19, you were trying to manage 2 challenges. One challenge was, how do we get customers to get off on-prem to cloud and then deliver them cloud security. And the other challenge was how do we deliver services off the cloud, the customers would accept because they're being delivered from the cloud. And that's kind of where us, we had to refactor our entire security service in the firewall delivered them from the cloud, which was a huge opportunity. We've made a lot of acquisitions to deliver cloud security. We fundamentally architected XSIAM at that point in time as a cloud-delivered SOC, which is generally not a prevailing trend. I think this time, I'm still confused why the market is treating AI as a threat to at least cybersecurity, and I can't speak to all the software because 1 thing we're definitely seeing that customers have figured out that they need to drive more consistency in their security stack to be able to respond faster using AI. You cannot respond fast if you've got 70 different vendors who have different data, different logs, different APIs running. So we are seeing a trend towards more consolidation, more platformization and that's evident in what we said. We did our best number of [indiscernible] this quarter, and we've ever done, barring to Q4, which is seasonally strong. So I think that's one trend we're seeing. And the other trend arcing is slow adoption on the enterprise side, slower than the consumer side of AI, but as the adoption is beginning to happen, we're begging to hear conversations around security, which as you see with Prisma AIRS, we delivered 100-plus customers. This is much faster than we did in cloud security [indiscernible] people are adopting it [indiscernible]. So from my perspective, AI is inevitable. It's going to be used by enterprises. As enterprises start putting more critical functionality in the hands of AI, they will want control of AI agents or of their AI infrastructure. that requires more security. So I think generally, it's a positive trend towards more security adoption. I particularly believe it's a bigger trend towards platformization and consistency of data and harmonization of data in the enterprise. We're not collecting enough data right now to get good security outcomes.
Next, we have Brad Zelnick from Deutsche Bank, followed by Saket Kalia from Barclays.
Great. Nice to see everybody. Nikesh, I pay close attention to the acquisitions you make and the things that you tell us because you've proven very astute at identifying future opportunities. As we think about IM and the AI-driven SOC, I've heard investors concerned lately that LOMs are going to kill SIM tools. How do we think about the balance of opportunity and threat of LLM is doing a lot of the things that we relied upon [indiscernible] for. And even if you're competitive from a product standpoint, is there a risk that you now face a new strong competitor for these modernization opportunities?
So I think, Brad, the elements are a net positive and additive to our capability to diverse security, like LLMs are very useful for data classification, we're doing DLP because we've relied on very traditional approaches towards matching exact matching data and trying to DLP, and LLM are much able to understand context and say this definitely looks like something that is data that is restricted or PII. So I think there are certain examples where generative AI and LMs are extremely old. All the examples you see, they're really good at looking at patterns and finding gaps and you'll see an offensive security or red teaming, LLMs are being helpful. I think the challenge that will face or do face in providing comprehensive security is it's not the [ 95% ] of the time they're right [indiscernible] the 5% of the time they're not right, you need to be right. right? This is like we're fighting bad guys who had to be right at once. We have to be write 100% of the time. So at until they get to 99%, 99.9% accuracy are not a threat to delivering security. They are tools that can be used to summarize capabilities. There will be a genetic actions that can be used to get a lot of the prework done from a precision AI perspective and get data together. So I think AI helps to cause every security company is going to have to use AI to deliver the capabilities that they deliver today. So I think it's not a secret. Every one of us is working hard. Almost every security product has some version of a copilot that now runs in tandem with the product. This helps you understand the pattern, the understand the capabilities and be able to add questions faster. I don't think it's going to replace the security product anytime soon. And don't forget that, one more thing is, in most cases, our security products sit at edges and create new data and logs that didn't exist for everything that's around them. So to the extent we are creating proprietary data and security, that is not going to be replaced by a lot. We're not a system of record. We're not a system of work. We are generating specific domain specific data based on threats we see out in the environment and then using that analytically to figure out how the customers to protect themselves.
Next, we have Saket Kalia from Barclays followed by Meta Marshall from Morgan Stanley.
Congrats on closing Chronosphere and CyberArk Nikesh, maybe on that point, I'd love to dig into the joint pipeline opportunity with CyberArk a little bit. You have a big go-to-market machine that we can leverage here. So I'm just kind of curious how you think that opportunity unfolds. And maybe relatedly, depot for you, you gave some breadcrumbs earlier on CyberArk, but -- or on inorganic. But wondered if you could help us bridge maybe how much ARR we can include for CyberArk this year as we kind of think about that buildup of organic versus inorganic?
So, the good news is that CyberArk has a phenomenal team out there in the field, so [indiscernible] all the networks. We have very carefully sort of been working with them after the close. Both teams have been made aware of how to pursue joint opportunities together. We understand our pipeline. We understand their pipeline. We've built a road map for overlapping pipeline. [indiscernible] customer has opportunities in the free in the next 3 to 6 months. And we've already and the teams with plans as to how to address the joint opportunity. But what's fascinating is just anecdotally, as you were informing the teams, we already have had CyberArk reps coming us to have an opportunity for Palo Alto's products in an account. They're particularly strong at. And I know that Peter Jenkin our President, was on a call over the weekend, trying to help close a customer for CyberArks with Palo Alto capability. It's happening in both directions. I think it's early days, but I think the opportunity is real. And as the teams get to know each other as each of these processes, I think we're going to see more and more momentum with both the teams. It is going to be a bit of a crawl walk run because right now, both our systems are different. So we have to do this stuff manually, and we have people helping us build sort of a central acceleration team. which drives both as CyberArk teams understand more and more of the Palo Alto products and the capability in the platform and as the politic teams understands the [ CyberArk ] capabilities and also as we work with CyberArk team to build the next generation of products that we've been sort of ideating with them recently, I think we're going to see continued momentum in both those pursuits.
Yes. And then if I can just take the breakout. So look, we're not breaking out every M&A deal that we do separately all the time. However, just as a baseline Saket, we did say that CyberArk NGS ARR was about $1.2 billion at the -- as of December 2025. And I said that in my prepared remarks that $200 million of ARR came from Chronosphere. And then I've also guided what the total M&A contribution is. So I think it's -- hopefully, you'll agree that it's a lot more than becomes to be able to allow you to do the math [indiscernible]
Next, we have Meta Marshall from Morgan Stanley, followed by Josh Tilton from Wolfe Research.
Great. congrats on the quarter. Maybe just a question for me on the SASE business. we saw nice reacceleration in that business in fiscal Q2. Just any commentary about what you're kind of seeing driving some of that strength?
Good question. We're obviously very excited by seeing that business accelerate at scale. The -- I think Nikesh said it fairly well when he talked about sort of this notion of a first-gen adoption of customers that was tended to be more sort of point product type adoption. They're trying to solve a particular problem. And the existing solution at the time, we're pretty good at solving that one problem. And now we're seeing both new customers as well as many of those customers come back and look for a more comprehensive solve. Their employees my all in 1 day, show up to an office and work, work from home and work well traveling. And if they get 3 completely different experiences and application access and everything else, it doesn't work for them from a productivity perspective. And so what we're able to do by delivering this as a platform is we can bridge how we apply network security from a hardware perspective, software perspective, SaaS protective and even all the way down into the browser with Prisma browser, all in a very consistent way, both for security outcomes as well as the end user experience and the productivity they achieve. Like that is the overarching trend that I see and what's driving the the business right now in SaaS and the customer excitement about what we do.
Next, we have Josh Tilton from Wolfe Research followed by John DiFucci from Guggenheim.
Maybe just a high level one for me. What are you guys seeing in regards to the volume of network traffic from your customers as they move more out of the experimentation phase and actually start to really adopt agents enterprise-wide. And how, if at all, will that impact the demand for the broader network security suite, whether that's firewall or SASE.
It's too early to tell. I think if you look at the AI adoption in the enterprise, there is a surge of adoption in the coating space. So people using codecs, cursor, cloud code and equivalent. You're seeing a lot of that. Those are very application-specific. And actually, that fits exactly where Koi operates because when you start doing coding and [indiscernible] on your desktop, you'll see server MCP servers and clients spun up on edge edges, you'll see a whole bunch of code that is sitting at the edge, which is not visible to traditional XDR capability. And that's why that was a solution we were using [indiscernible] and there's where we saw the head traction, they had 40, 50 customers, and we were [indiscernible], oh, this is an unsolved problem in security, and this is kind of where all the action is from an enterprise adoption perspective. Outside of that, there is now enterprise adoption that we're beginning to see where customers are running perhaps millions of tokens in 1 or 2 particular applications they're working with some of the LLM providers on, and that's where we see the traffic. That dropping is again more within the network. I don't think it's traffic that networks cannot handle. I think the challenge right now is consolidating that traffic. How do you get all the AI traffic to be in one place so you can understand it, profitability look at the ability to control it and be able to act on it. So I think that's going to be the next question as to how do we figure out the solution for all this traffic that is beginning to have a different nature in enterprise, and it needs a different set of controls and tools, but it's not really impacting the network level traffic yet. And I say yet because as an option grows, I fully expect, I mean, you can't build $600 billion worth of data centers and not expect traffic to grow and you can't expect that not to happen. So I think that's going to happen. The data centers being built. It's early days, and consumer actually are outstripping enterprise for the moment, but we expect enterprise will surely and slowly get on that bandwagon.
Next, we have John DiFucci from Guggenheim followed by Gabriela Borges from Goldman Sachs.
I agree with you on everything you're saying about AI. It's positive effects on security. I actually really like the acquisitions you've done here. But if I is going to be good for surety. And I think it will -- in both cases, both you need to secure AI. So AI is going to -- I could be a hacker if I want to be. But if that's the case, -- when are we going to see it? Because it doesn't show up in the number -- it doesn't show -- I mean not that it doesn't show up in your numbers yet. It doesn't show up in any ad's numbers yet, really, maybe a couple, but not really. I mean, when -- is this...
No. I think that -- look, I think, John, if you -- I think the best analogy I can give you is we look at cloud security. You didn't see cloud security numbers for a while because typically, cloud adoption in enterprises lag consumer. And then even then, it was literally a 2-year cycle, 3-year cycle before enterprises fully got all their applications and workloads moved onto the cloud. So I expect the -- right now, if you look at it, tell me how many enterprise AI apps are you using which are driving tremendous amounts of throughput. And I can't think of anything but coding apps. Now coating apps are not resource-intensive on your infrastructure, the resource intensive on the endpoint. So like endpoint capability and LMs are where all the action is. I think it's early days. What I'm heartened by the fact is that our number of customers with Prisma AIRS kind of following the same trajectory as XM. The volume isn't there because the [indiscernible] not coming through lens right now. So I think it's early days. Look, you have to have 1 or 2 belies John, you have to be in 1 camp or the other. Either you have to believe that the $600 billion of data centers are being built are going to be consumed. And if you believe that, which most people seem to do, so that consumption is going to be 80-20, 80% consumer, 20% enterprise. But those data centers is yet to be built. I think what's happening is we're all laying the groundwork right now is a bit of a sort of an arms race to try and see who can get the AI security sort of platform up and running as quickly as we can. And you can see innovation is happening in every direction. That's why you see us by protect AI, which is now well integrated. We do the firewall, made an AI firewall. Now we're taking [indiscernible]. We see that that's where the action is. The next question is going to be how you consolidate all the eye traffic in 1 place. So I think you're seeing the piece parts being built, mid-flight, I think you had to be a bit patient.
Next, we have Gabriela Borges from Goldman Sachs, followed by Adam Tindle from Raymond James.
This one is for Lee. It's a fiber question, but it's a product-based CyberArk question. If we think about CyberArk historically being strong for privileged users at the high end, what is the technical lift that has to be done to make that technology more accessible for every user. And curiously, you've learned in the last 6 months or so from your customer based on the method to securing agentic identity between PAM IG and IM. Any learnings from the last 6 months, we'd be curious to hear.
Good question. First, let me start with the first question. The I think just the general space of Privileged Access Management has largely been a more sort of sophisticated category. And as such, it's been the more sort of security-conscious enterprises have been the biggest adopters. And there's already sort of a transformation of sort of this notion of modern PAM and moving to just-in-time controls and 0 standing privileges and things like that. And Part of that is actually improving security, but part of it actually is also about making it easier for the end user to actually interact with these systems. We -- so that's already happening. The further we have ideas for how we can leverage integrations between CyberArk and, for example, Prisma Browser in terms of how do we great capabilities in the place where the user is already doing work in order to make it even easier for them to take energies capabilities. So -- we -- there's already a lot of progress and we have more ideas for how we're going to continue to make that easier, so we can drive broader adoption across the existing customers but also make it easier for noncustomers to adopt. And ultimately, we think that leads to the broader sort of full human identity solution that we're excited about. Now as that is happening, yes, there is the Agentic identity sort of market that is rapidly forming. And look, the -- my view on Agentic identity is it's going to have sort of aspects of machine identity and privileged users sort of wrapped into one. And this is partly why I think CyberArk is well suited for being able to go after this because of their leadership in both of those foundational spaces. And then it's how do we adapt, add to and then optimize for Agentic use cases. And again, some of that will be sort of call it, send alone CyberArk from an identity for perspective. And some of it will be how we think about that in concert with Prisma errors where we already have hooks into the AI infrastructure, and we'll have, again, integration opportunities to be able to bring solutions to our customers.
Next, we have Adam Tindle from Raymond James, followed by Shaul Eyal from Cowen.
Nikesh, in your comments, you talked about it with Chronosphere, a 9-figure expansion deal with a leading AI provider I just want to pick on that and just ask about the key attributes that help Chronosphere get that level of commitment. Were you displacing an existing vendor, the timing for that, the rationale for it? And maybe even the pipeline beyond that and just a quick clarification, Dipak, just because I know this is coming up in after hours after you talked about ARR in total think investors are shipping out the $1.47 billion from Q3 NGS ARR and looking like organic net new NGS ARR is down a lot. I think there's probably some flaws to that, but I just want to toss that out there to have you clear the air.
All right, Adam. First thing first, look, Chronosphere is a highly scalable solution and its scalability is dependent on a net new architect of design for observability, which is different from what the current incumbents in the space have. So that capability allows them to deliver those capabilities at approximately half the price, if not more, than or less than some of the other players out there. So they are displacing another vendor in that space. They have been partnering with the large language model over the last 6 months or so, and they have passed every technical hurdle, which allowed them to make a commitment to Chronosphere. We expect the full transformation over the next 6 to 12 months or a full transition from the other vendor [indiscernible] of the $200 million ARR is from one of those large L&M vendors. We expect that to continue to grow. In addition to that, they have other customers who are significant customers, and they are going to pursue significant customers over the next 3, 6 months in partnership with us. But that's why we bought the company because of the scalability, because of the capability from a technical as well as a commercial perspective. And we're at least [indiscernible] we can talk more about the product capabilities that we're going to give it. But we hope that that allow to be a full sort of full-scale replacement option for both DIY many customers do DIY in the situation as well as being able to compete effectively with some of the big [indiscernible] plays out there.
Look, I'll just give you a high level. There's -- look, they've built something very unique for that very high end of the market, scalability and the economic aspects even the start of some of the AI analytics and that will complement with [indiscernible]. The next phase is going to be how do we build out a lot of sort of enterprise sort of off-the-shelf kind of features that make it just really easy to do integrations to basically replace existing income into structure, whether that's commercial products or open source, we think in both cases, Chronosphere will scale down into that large enterprise segment very nicely.
And then, Adam, just on your question on NGS ARR just to be clear, organic NGS ARR is roughly in line with consensus for Q3 and we reiterated the full year. So maybe folks just haven't fully appreciated that Chronosphere closed for 4Q, but we'll make sure that's all cleared up.
So next, we'll go with Adam Borg at Stifel, followed by Gregg Moskowitz from Mizuho.
Great. Maybe, Nikesh, you talked about a little bit in the prepared remarks about the Quantum opportunity. You talked about a little bit last quarter. love to hear more about kind of the early learnings from kind of the discussions with the customers from the panel a few weeks back and ultimately how you're thinking about the opportunity in coming years.
As part of the CyberArk deal, we've acquired [indiscernible]. I don't have -- Lee talk about a new capability or building called the next-generation subscription plus our quantum capability, we have been in discussion with 100 customers who are experimenting or beta customers a product. We have tremendous feedback for them. Our quantum capability is not just for firewalls. It actually looks at the enterprise capability. So we have actually integrated 10 other vendors worth of quantum data into our quantum sub, but I'm going to let Lee talk about this up.
I think the [indiscernible] in both of these cases, whether it's cryptography and PUC or certificates and managing the -- the alternative is largely a very manual sort of human-centric repetitive kind of task approach. It's either some poor person or people that have to constantly sort of mainly go look at certificates, look at the renewal dates and ages and other things like that and then redo them manually or we can do it through technology. The same is true with quantum proton. It's either a lot of manual consultation going through and trying to figure out what exists or we can use technology. And so in both cases, we figured out obviously, identify in one case that we'll be joining the team [indiscernible] and then the [indiscernible] team is how do we use technology, largely our next-gen [indiscernible], but not only our [indiscernible], other data sources as well to do that discovery to be able to technologically discover everything that is needed and then through automation to then also be able to automate the process of remediation. And so this has obviously security benefits, but it also has reliability and uptime benefits as well because you have to remember in both of these cases, these are fundamental to how production systems operate.
We'll end it here with Gregg Moskowitz from Mizuho.
All right. Last question. Thank you, Hamza. So closing in Palo Alto's 2 largest ever acquisitions within a couple of weeks of each other. It's exciting. The potential is tremendous. But it could also add an unprecedented amount of stress on the management team, engineering, go to marketing, et cetera. Nikesh, how do you keep everyone's eye on the ball yourself included and not be subject to execution or distraction issues?
Well, Gregg, these acquisitions, at least in the case of Chronosphere, has been the work the last 2 or 3 months, and CyberArk has been the work for the last 7 months. I've visited the Boston facility spend days there with them. Lee and I were in Israel with the team and spend time with them. So CyberArk just didn't come upon us this week. It has been in the works for the last many 6 or 7 months. As you might have read, we had worked for the management team to fully understand what role every employee at CyberArk was going to have. So we were able to, on the date of close, inform every employee with their rule in the future, joint organization was going to be, what their plans are. give OKRs, give targets to every one of them. So they all have that within the first 48 hours. So it's not like we've been waiting. There are some system transitions that we do in the case of CyberArk, which the teams are working in hard, fast and furious on. We have had the opportunity to plan will they need to be so where we have our eye on the ball. That's our job, right, from a CyberArk perspective. And Chronosphere is, honestly, other than the fact that the price tag was big, that it's still a 250 people engineering team that does applicability, which is finally different from anything we've done. The only point of product interaction is they're working hard with the Cortex team to figure out how to incorporate [indiscernible] into their platforms, so they can have agents solve the observability problem just not just sort of be an observability company. And separate to that, because they are sort of their [indiscernible], they go after big observability clients. We are able to selectively and surgically help them on a client-by-client basis to help them drive what they can do. So this is our second or third acquisition between 2 of them. We have a lot of lessons from prior acquisitions, which we have brought to bear. Our teams have been working really hard over the last many months, and we have been actually adding capacity at our end to make sure we can handle some of these transitions that are required.
That concludes the Q&A portion of this call. I'll pass it back to Nikesh for any closing remarks.
Well, I just want to say thank you to all of our customers, all of our employees around the world and thank you to all of you for joining us on our conference call. We will see you guys next quarter.
Palo Alto Networks — Q2 2026 Earnings Call
Palo Alto Networks — UBS Global Technology and AI Conference 2025
1. Question Answer
All right. We will get going. Thank you all for being here on day 2 of the UBS Tech and AI Conference. I'm Roger Boyd. I cover cybersecurity. Very happy to have Nikesh Arora, CEO and Chairman of Palo Alto Networks. Thanks for being here.
Thank you for having me.
I wanted to start with a little fun. I want to rewind back to 2019. You were relatively new to the role, relatively new to Palo Alto Networks. You're making a lot of acquisitions that I think investors had questions about. And in hindsight, all those played out pretty well, I would say. I think when you look at -- if you fast forward to today, you've now announced 2 fairly significant acquisitions in the past 6 months and are once again kind of poised to expand the TAM of what Palo Alto looks at. I guess can you compare and contrast these time frames? And at a high level, what's different? What's the same? And how much of the cash of 2019 compares to the cash of 2025, '26?
I don't know, he's older. Hopefully, wiser. But look, if you peel back to 2019, we were 1 of 7 cybersecurity companies in the, give or take, $10 billion to $20 billion market cap range. And we had to figure out how do we break out of that over the next 5 years. I believe in enterprise, if you are not aspirational, don't get to $10 billion in revenue at some point in time in your line of sight, you are subscale, give or take. You start plateauing. And there's ample evidence of plateau to enterprise companies, which go sideways for many years. And you can plateau at up to $20 billion market cap, sometimes you plateau in a $100 million range, too.
So the question as a CEO, your job is to figure out where is the next leg of growth going to come from? Is it going to come from natural evolution in my TAM? Am I going to add more TAM to it and when and where and how to do that. So at that point in time, our job was to reinvigorate the innovation pipeline in Palo Alto, which is what we did. It takes 4 years to build a decent product. I didn't have 4 years, so I wouldn't found companies which have been around for 3 or 4 years who are building interesting products, and I must have seen about 350 companies to decide which ones are going to fit the portfolio. That's kind of point one.
So we got ourselves to, I'd say, product parity and perhaps product superiority in certain categories because when you work at Google, you get told by Larry Page every day, if your product sucks, you're never going to win. So you basically come and say, my product cannot suck. That's going to be generally a good idea. So we got enough of that done. That allowed us to go to our customers and go do a better job of selling to them.
So the second insight in enterprise is that if a customer likes you, likes your product, it's a lot easier to sell them more stuff than to find a new customer to like you. So how do I go sell more to the same customer than constantly having to need new customers at $100,000 or $200,000.
2019, our -- our average customer -- our largest customer spent $4 million a year with us. Now it's $60 million a year with us. So the question is how do you take that $4 million customer and translate them to a $50 million to $60 million customer; it requires both, requires stuff that you can sell them and requires them to like you and trust you. So that's what got us to where we are. And we are, give or take, $130 million market cap company, and we can't just keep bolting on products to what we do.
So then you look and say, where else can I expand my business? Where is the incremental TAM? The most significant inflection in cybersecurity in the last 2 or 3 years has happened in the SIEM and SOC space. This is a $40 billion TAM. People like ArcSight, LogRhythm, QRadar, Splunk; they are all 17-year-old technologies. They were ripe for, let's say, innovation that allowed us to build a product called SIEM. We got to $1 billion TCV, faster than any company in the world in that space. We have 400 customers. We're happy with that.
Then this wave of AI showed up 2.5, 3 years ago, I think ChatGPT turned 3 yesterday. And that spurred on a whole different sort of conversation on infrastructure, speed, scale, which means it will create more inflection in cybersecurity in places like observability. We identified identity as the missing sort of platform in our portfolio. We think CyberArk is the best asset in the category. It is a security asset. And we're lucky enough to be able to conclude a deal with the founder, Udi. And I think we paid a reasonable price, 20-plus percent premium for an asset, which is #1 asset in the identity space.
And having spent now 4 months, and I show my way to Israel next week with them, I feel even stronger that what we can get done with them is going to be better than what we thought. We're going to be able to get done and we're looking at from the outside.
Now while all this was going on, I [indiscernible]there's a concept in security called security data pipeline. It seems to the rage. People are trying to figure out how to ingest less data. It's kind of silly, which means that we must not be doing an efficient job to let a third party come and tell people what data we should ingest. So we decided to fix our product instead of buy something, but I saw some of our peers bought some stuff. And in that process, we found Chronosphere.
What is fascinating about Chronosphere is I learned that observability is 10% to 15% of infrastructure spend. If I believe half of what is out there in terms of all the compute and infrastructure that is going to get unleashed by AI with the $1 trillion of infrastructure coming on an annual basis, that must mean there's a TAM of $100 million out there. Let's even say it's overpriced, let's say, it's $50 billion. There's 5 players in observability, AppDynamics, Dynatrace, Datadog, Chronosphere and maybe Instana from IBM, pick your favorite fifth one.
Most of the others other than Datadog target the on-prem market, not the cloud market. And I was intrigued when I found Chronosphere is going to become the underlying observability platform for one of the largest AI LLMs out there. So I talked to the founder of that and management has said, look, it scales and it's $0.40 of dollar of competitive options. So do the math, I like $0.40 of dollar of somebody else's revenue. It's better than 0. And it works at a 70-plus percent gross margin, which is what I like to lift.
So we decided to do one more acquisition. And we think the 2 biggest inflections or 3 biggest inflections in the next 5 years are going to be in identity and continued inflection in SIEM and possibly continued migration to cloud-delivered observability. So it was a very long answer to your question.
Perfect. And maybe just to translate it back to the numbers. You took your long-term fiscal '30 NGS ARR target from $15 billion to $20 billion. Obviously, big numbers here. How much of that was attributed to CyberArk or Chronosphere? I think there was also an organic expansion component to that. And even when you look at $15 billion of organic business, what gives you the confidence in that number?
So look, our ARR is roughly 1/3 of that today. There is some part of that is migration from existing on-prem behavior to ARR. Most of that is net new business in our core business. I think part of that is bolstered by our comfort and success around our core business. I'd say 1/3 of that is about Chronosphere, give or take, and probably 2/3 is the CyberArk current growth expectations. So $20 billion is a big number. It hasn't been done in cybersecurity before. In fact, $10 billion revenue has been in cybersecurity before, unless you look at fuzzy math from large players who segment their cybersecurity spend.
Cool. Maybe to touch on identity. You mentioned this earlier, but just greater confidence in that acquisition having spent a few time -- spent a few months with it. I mean what's -- can you expand on that? And when you think about kind of the 3 pillars of the deal, it was bringing TAM to more users internally. It was being able to include identity within your broader platformization sale. And then this third idea of securing AI agents. Like how have each of those pillars kind of expanded after spending some time with?
Yes. Look, if you go back and correlate to the idea that my belief is that companies which are not generating $5 plus, $7 billion, $8 billion of revenue are subscale in the long term in the enterprise space. We think a lot of the scale, innovation, activities, processes we have, we can apply. It's not CyberArk's fault. We have scale. We can spend $10 million running AI experiments. $10 million is not a lot of money for them to run to optimize 20 people. We can have 200 there.
So we can take all the leverage we have from scale, deploy it to them. I see no reason why after spending time with them that our margins shouldn't converge in 24 months with their, or their margin shouldn't converge with ours in 24 months, which would mean going from about 20% operating margins to 30-plus percent operating margin. That's a really good thing in math. So that's kind of helpful, one.
Two, we think we can really help them on the go-to-market side with the customer base because they usually don't have the relationships with the CIOs and CSOs that we do, given our larger scale with them. So that's kind of hopefully -- and anecdotally, having talked to some of their customers and our common customers, the fear always is you get bogged and customers says s*** I don't want to deal with this company.
But in this case, we have received positive affirmation. The customers like the idea. They like to work with Palo Alto. They like us to have an identity portfolio, and CyberArk is the best asset in the space. So that was the second sort of insight.
And third, I think in a way, and I said this at the foundry yesterday and saw Moody, and I said like, you guys got a little happy and fat too soon. You have to go innovate. This is kind of where Palo Alto was in 2019. We kind of lost the innovation idea saying, this is my turf. I want to play in my turf. I make a lot of money in my turf. Well, we're going to light a bit of a fire under their innovation cycle. And that's why Lee Klarich, our Chief Product Officer, and me are spending a lot of time with them heading to Israel. And if you can do all 3 of those, it allows us to actually deliver the ARR uptick that we talked about. Yes.
And then just on Chronosphere, I think a lot of investors may be a little more surprised by that acquisition relative to CyberArk.
Investors were surprised by me taking the job at Palo Alto. They were surprised by me buying [ 17 ] companies. It's like their surprise is not my concern. My job is to deliver ARR growth. I promise investors will be happy if I keep delivering my growth rate and my margin and my free cash flow.
In terms of the rationale, you touched a bit upon this, but in terms of a data pipeline product versus the organic TAM that they have in their installed base versus the idea of bringing that into platformization, how do you balance those pillars of acquisition?
Look, the 2 largest third-party infrastructure data requirements are in observability and security. Everything else is on-prem customer data, et cetera, which is kind of what your core business is. From a third-party perspective, customers can't do their own observability. They need somebody else to watch their run time and infrastructure and tell you if it's working or not. They can't do their own security.
We ingest 15 petabytes a day, even with our 450 customers in XSIAM, which are not fully deployed, all of them, 15 petabytes a day. Chronosphere does somewhat similar across the 450 customers. We're the largest ingesters of data in the world, a third-party company. That was possibly the top 5 customers of BigQuery at Google.
So we're taking a large data problem, solving it at the right economics for our customers. And I'm pretty sure all of us have varied opinions on how much of this AI spend is going to be realized. We're going to spend $8 trillion or not. But everybody believes in this room, I hope that the data is going to keep compounding across enterprises. The more we spend time on AI, the more we run applications, the more people use it, data is going to compound. If you believe data is compounding, you need observability, you need security. So from that perspective, we think those are the right swim lanes to play in, then it's a matter of execution.
Yes. Just on the Chronosphere customer base, you mentioned 2 of the top 5 LLM providers. It's been pretty well reported that the largest LLM provider is a customer.
We're all shy of taking the name, right? Okay, sure. Artist formerly known as Prince, yes.
Yes, exactly. I mean, to your point, there's $1 billion, $1.5 billion of compute spend -- $1 trillion of compute spend that's coming online over the next 5 to 10 years. So how do you think about that market for observability expanding with AI? And how do you think about selling into that ecosystem?
Look, the observability world, the customers fall in 3 buckets, right? One bucket is where people have a lot of existing applications on-prem, which is where, as I said, Dynatrace, AppDynamics have built their business and they serve that use case. The second category is born in the cloud companies, SaaS companies that sell cloud-based services, which are pick your favorite SaaS company, pick your favorite consumer company, your DoorDash, your Uber, your Airbnb, they all have to have -- if their app is down for 10 minutes, it lost revenue. If your app is down for a few hours, the SEC will come and shut you down because you're not in compliance with some requirement to be available as a storefront for your financial customers.
So from that perspective, observability ensures 99.9% visibility into availability. So if your stuff goes down, you're in trouble. What are you willing to spend to make sure that you can see when something goes down? As I said, the numbers in the market are 10% to 15%. I'm not saying Gemini tell me that or ChatGPT tell me that. So I take 10% to 15% if you believe that's an overpriced market and the right answer is 5% to 7%.
If your numbers in $1 trillion, that's $50 billion, $70 billion. That's a $50, $70 billion TAM. I don't see that revenue in the market today. All that tells me is that, that market will keep growing, which means if I go spend the time and effort to spend -- sell -- I know like the second largest customer at Chronosphere is going to spend $20 million this year for start-up, $20 million of one customer. I like those businesses. I like small number of people spending a lot of money. I'd rather be like LVMH than Walmart. Small number of people spending a lot of money is a good idea because I can serve them better, keep them happier and make sure they get the value that they need. And that's where we play, and that's where platformization plays. That also reduces my cost to go to market across the board.
Okay. Maybe last question on the 2 recent acquisitions or pending acquisitions. I've gotten this question from investors, but how do you get comfortable integrating, managing fairly large integrations over the next kind of year, 1.5 years? And I know you mentioned Lee's recently promoted and spearheading a lot of this, but what does that look like internally?
Well, I think they're both different. I think Chronosphere is a great product. It has good traction. Customers like it. They want to spend money. So I don't have to go do like open heart surgery and fix the product. It's just -- it's working. We have to help them go to market. They have 7 salespeople, I have 3,000. I think we'll find a way of getting more people at Palo Alto sell it outside of the 7 they have. It's a very targeted sale. So integration in the case of Chronosphere is letting Martin do his job, give him more resources and support them where we can to let them off the races, right? So give them the comfort.
Large companies make a mistake. They buy companies and then try and smother them. We're not going to smother. We're going to give them more money, more resources to run faster. One asset we have, which startups don't have, we have money, we have distribution. Our job is to figure out how to unleash that asset onto the acquisitions we have and not constrain them with our policies and processes. So that's what we're going to do. Martin is going to report to me. He's going to have full ability to go run as fast as he can because he has an open lane, he can run really fast.
CyberArk is different. CyberArk is a reengineering, restructuring and make it work and fit. That's why I've spent a lot of time in the last 3, 4 months. My teams are all working on it. And that's why that's where our focus is. And at the same time, we're going to make sure our core business continues to deliver because that's kind of what gives us a right to play.
So keep running our core business. We don't have any small acquisitions to integrate. We haven't done any. CyberArk has been thoughtfully done. We've spent 4 months. We'll spend another 2, 3 months before it gets closed. That's why we're flying to Israel. That's why we are working on plan. That's why we have stuff to figure out on a function-by-function basis. We have the top 50 people we like. We're talking to them about continue to stay at Palo Alto. So it's kind of like -- and we found the opportunity areas. Could there be a bump for a month or 2 months? Sure. happens. But do we believe that the long-term thesis is even more robust than we thought? Yes.
Great. Okay. Maybe shifting over to Bitcoin.
Investors always need something to worry about, for sure. Otherwise, it's like show me a stock that doesn't have a concern.
Okay. Shifting to the core business. SASE, you've got $1 billion, $1.3 billion of revenue, growing 34%. I think you're now in 1/3 of the Fortune 500. The growth there has been pretty steady. What's going right there? And competitively, have you seen any changes in the market? There's obviously more vendors that are talking about that.
I thought the market leader in SASE was here this morning. What did they say?
It's going well.
Great. So I'm glad it's going well for them. It's been going good for us too. It's great. 5, 6 years ago, we didn't play in this space. We were not -- we didn't have a right to play in SASE with 0 customers. We had to build it one customer at a time. We're now north of 6,000 customers. They have very large deals, which is good, which to me is a validation that we can come from behind, build the product, compete with the biggest players in the market and get to #2 in the category. #2 is a good place in a category, #3, #4 is a dangerous place because you spend all the money and you don't make the returns.
So I like being at least #1 or #2 in the category. So we're happy we're #2. It's a steady business growing faster than the biggest business, which means it's good because it gives you -- the spread is narrowing. We believe our product is at parity or better in certain spaces, and that takes time because every time we go to a customer, you don't do this, you don't do that. So you do those things. So I think we have the right amount of investment and return going on. We have the right amount of happy customers.
And we have done some things technically that allow us to tell our customers -- and our VPN customer Palo Alto, you can actually turn on SASE capability right off. So the biggest problem with SASE is every laptop has to be brought in and a new agent has to be put on it, which customers are scared of because you really want to stop your workflow and say, my God, I am going to deploy 200,000 new things. It is the last thing they really like IT coming is like, I'm here to install something in laptops, it is a holy s***. It's not working.
So if you say it's already on your laptop, I'm going to turn on from the back. That's a much happier feeling. So we've gotten to a point where we have 80,000 firewall customers, many of them are VPN customers. We can turn their VPN client into a full SASE client without having to bring in the laptop and do open heart surgery. And the back ends are already configured. So the implementation is a lot easier for us than it was 2 or 3 years ago. So it makes it harder and harder for other people to come in and steal those customers. That's all. We'd be very happy if we had a $3 million ARR business in 3 to 5 years. That should deem that business, which you built in the last 5 years, itself should be worth $40 million.
You mentioned feeling like you have technological advantages in certain areas. And it seems like Prisma Access Browser has been one of those areas. It's been a pretty material element to new seat count growth in SASE. How important is that? How differentiated is it? And like big picture, the idea of like browser wars, AI browsers, how do you think about enterprises trying to secure AI through a browser?
I wish I could tell you that we anticipated secure AI, AI browser and cloud and Anthropic building browser and that sort. We bought a company because we thought we could manage devices in companies which were not being managed through a browser acquisition. We paid somewhere around $600 million for Talon. We have seen phenomenal adoption. Browsers are sort of the hidden threat. We did a 30-day pilot, a large company with 20,000 employees. We discovered through a 5,000 browser pilot that 167 browsers are compromised, which means attackers were in their browsers, 167 of them. Next week, they put out 210,000 browsers in the company. So that's the threat.
Now if you carry that forward and think about the idea that you will have employees download the AI browser from OpenAI or Claude or from pick your peer at perplexity. -- the reason these guys are building browsers is I think the next battle in AI will be consumer agents. I think we confuse ourselves in this world to be agentic behavior enterprises. The real battle is consumer agents where we can all conceive that I should be able to tell my phone get me an Uber at the Phoenician, get me on whatever flies from Southwest to San Francisco. And when I land, get an Uber at the other end and make sure you make a dinner reservation for me and my wife tonight at 7:00 in Palo Alto. You can all imagine that seems possible if Sam Altman is going to raise $100 billion and Ali going to come tell us $134 billion, they must be doing some [indiscernible], right?
If you believe that, how do I activate the agent? How does it know what my Uber account is? How does it know what my DoorDash account is? How does it know my -- whatever OpenTable account is? The only way it does that is if it has my credentials. If I'm on the phone, the iPhone controls your credentials to some degree. If I'm a laptop, the only place to harvest credentials is your browser. That's the only place when you log in and you click it, stays logged in.
So actually, what you're seeing is a land grab for credentials on the desktop. That's all that this browser business is doing for the consumer guys. The problem is what's great for that scenario, sucks for Spotify, Uber, DoorDash, they're going to fight it [indiscernible] . That's bad news for enterprise. I don't want your browser to be logged into Salesforce and Workday and my trading app and portfolio management, I'm doing s*** which I don't know. So you will want to secure your browser as quickly as you can. So I am betting in the next 6 months, enterprises ban consumer browsers that you can't use OpenAI browser at JPMorgan or at Home Depot or at Walmart because I don't know that browser is going to take your credentials and do something in the back with an agent, I don't know how to control it. I have no security in place to control these agents. So what do you do, you ban them. But you ban Chrome. You ban Safari. What do you use? Now you say, there is my browser from Palo Alto. I supposed to say that...
That's a good pitch. There. All right.
It's like an ad, you'd like do it together.
All right. I wanted to switch gears to software firewall. You called it a hidden gem last earnings call. I don't think it's that hidden. ARR is growing 20% plus. You've got pretty material acceleration in product revenue. Can you talk about what's underpinning that strength and we'll go from there?
Yes. So the reason software firewalls are hidden gem is that I think the most fundamental thing for all of you guys to understand is that Security is pretty straightforward. Security means every bit must be inspected. It doesn't matter where it comes from. It comes from a laptop, comes from an application, comes from micro services, comes wherever, every bit should be inspected because that's where bad should happens, okay?
You inspect bits in data centers using hardware, which is where firewalls come in. You inspect bits on your laptops using SASE or browsers, that's where SASE and browsers come in. When you're sitting in Google Cloud or AWS or OCI or IBM cloud, your bits have to be inspected. There's no boxes in the middle. You put a software firewall around your application, you inspect bits. For a while, people were using the cloud providers' software firewalls, whether using AWS or GCP. We slowly over the last few years have deployed a single form factor that works in every cloud.
So if you're a Walmart, you can run the same firewall at GCP, AWS, Azure and you get a pane of glass. It's better than managing 3 different firewalls. And of course, we might have slightly more feature-rich firewalls because that's all we do for a living. Those guys do a lot more other stuff. So what's happened is there is realization, a, many customers are multi-cloud. They're not single cloud. So if you're multi-cloud, you want a common firewall, you don't want multiple firewalls. That's helped us.
Two, they want more feature richness because they're discovering their attacks coming into the firewall architectures. And three, we made them work natively in the environment. You can spin up our firewalls just like you can spin up a Google or AWS firewall. So in that context, we probably have 50% market share in software firewalls from nowhere.
We have 39% in hardware, 50% software. And our competitors are only individual cloud service providers. There's no large third-party cloud firewall business that competes with us. So that allows us to go in and show the value prop. What's really interestingly aiding the conversation is AI because our firewalls have been upgraded to protect model hijacking and the attacks we heard about a few weeks ago. So that's also helpful because we show them the AI firewall, then they buy the software from us, that is where the volume is. So it's kind of been helpful.
Yes. I want to double-click on that. And the concept of an AI firewall, you introduced Prisma AIRS earlier this year. You have model scanning, AI posture management, red teaming. Should we think about those as kind of attached services to an AI firewall? Or does it get sold separately? How does that work?
When you look at a company, how do they deploy AI? The company says, I'm going to put my own LLM into my company. And now you can talk to the LLM as a customer and decide if I can give you a recommendation and pick your favorite company and you set up your own LLM, it does a bunch of things called vector DBs, databases and has an Internet connection. And then I, as a consumer, talk to the chatbot. I can talk to the Bank of America chatbot and it does stuff in the back.
Now every door you open to talk to your LLM is a door for it to be attached. So for example, in the very early days, every chatbot had this thumbs up or thumbs down. Do you like my answer or do you not like my answer. Guess what? I can spam you by saying, I didn't like your answer. I didn't like your answer. I didn't like your answer and force you to give a different answer. This was being used to manage perception. Like should I vote for President A or President B?, I said "No, no, no, no." And suddenly, you spam and then the model starts recommending President B because they didn't like the first answer.
So you can do all kinds of things like it's called data poisoning in the model. It's got LLM hijacking, it's called prompt injection. You can inject prompts in the back in the middle of your question. So they come and say, "Hey, monkey" every time you ask a question. So you can do all kinds of bad things, which you need to look at bidirectional traffic. So we built all those controls into our software firewall, and it gets shown as an AI firewall to our customers. So that creates the desire for them to protect their AI LLM. So that's kind of what we sell.
We have about 50 customers who deployed it. Every customer wants to talk about it. Again, it's a great conversation to have because every customer is bothered about AI security, but it lease back the [indiscernible] sale of software problems behind it.
Cool. Maybe to close, we're at the AI conference. There's been a lot of talk about potential AI bubble out there. I want to leverage your purview, your lens into the broader technology landscape. What's your opinion there? What do you think investors are potentially missing? And how do you think about security potentially enabling that or not enabling that?
Look, at a macro level, if you look at everything and you cut through the noise, there's hundreds of billions of dollars more that will be spent in the next 3 to 5 years than were anticipated last year or 2 years ago, right? It's going to be spent, whether you like it or not. Whether it's going to be $2 trillion or $1 trillion, you can decide, but it's going to be a lot more than we thought 5 years ago, which is causing a huge boom in everything related to infrastructure spend.
It's unleashing IT budgets because everybody is spending more money on experimenting on AI than they ever plan to. So are we, so is everybody else. The consumer end will consume more AI capacity than you think is possible. Every new Nano Banano that comes out, every Gemini-III that comes out, you're going to suck out more and more AI compute than you think. So there is demand out there for that compute to get sucked out.
And maybe your question about where the money is going to come from, but that's not my problem that's there. So that's going to happen. There will be compute builds and people will suck out the consumer stuff. Enterprise will be slower in adoption. There will be hidden gems of things that show up and people do it. That is not going to stop experimentation. And all I need -- all they need is 10 million companies to spend $1 million each and you get to a lot of money.
So we're going to spend more money than we thought we're going to spend at Palo Alto. We spent a few million dollars this year from 0. Everybody is going to spend it. So it's all there. Now does that take the market cap of the biggest company down by $1 trillion or goes up by $1 trillion? It doesn't matter to me. There's a boom.
AI does 2 things from a security perspective. One, it once again increases the attack surface. Now it can attack agents. I can attack browsers. I can attack a lot of things. The more -- the bigger the attack surface becomes, the more you have to spend to protect the attack surface, right? The bigger house you buy, the more you spend on security. The bigger attack surface in IT enterprise, the more you have to spend. So the attack surface is getting bigger.
Two, as you saw in the attack 2 weeks ago, speed is getting faster. AI is going to -- attacks will happen in AI speed, which means defense has to happen at AI speeds. The entire cybersecurity plant is still outdated in the world. There's tons and tons of opportunity for all of that to get, let's call it, AI speed ready, which is where we point our guns. I'm sure many other companies will do better. They have 8% market share. We lose 92% of the time. Maybe we'll get to 16%, and we'll lose 84% of the time. That should double our company.
Awesome. We'll wrap it there.
Thanks, Roger.
Thanks for being here.
Thank you, everybody.
Palo Alto Networks — Q1 2026 Earnings Call
1. Management Discussion
Good day, everyone; and welcome to Palo Alto Networks' First Fiscal Quarter 2026 Earnings Conference Call. I'm Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Wednesday, November 19, 2025, at 1:30 p.m. Pacific Time.
With me on today's call to discuss our fiscal first quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. Following our prepared remarks, Lee Klarich, our Chief Product and Technology Officer and Board member, will join us for the question-and-answer portion.
You can find the press release and other key information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for Quarterly Results to find the Q1 '26 supplemental information and Q1 '26 earnings presentation.
During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's pending acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in the presentation today.
This presentation contains non-GAAP financial measures and key metrics relating to the company's past and future expected performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation.
Unless specifically otherwise noted, all results and comparisons are on a fiscal year-over-year basis. We also note that management is scheduled to participate in the UBS conference this quarter.
I will now turn the call over to Nikesh.
Thank you, Hamza. Good afternoon, and thank you, everyone, for joining us for our earnings call today.
As you can see, we had a strong start to the year in Q1. We exceeded expectations across every guided metric. Demand across our core business remains robust and customers continue to platformize with us. Year-over-year, RPO grew 24% and GSR was up 29% and total revenue was up 16%. We saw strength across our portfolio in SASI, XSIAM, software firewalls and even saw early traction in our AI security platform, Prisma AIRS.
Our top line growth was complemented by continued improvement in profitability, achieving our second straight quarter of 30-plus percent operating margin. These results are a direct outcome of our strategy, too. By delivering better security outcomes, our platform is earning more and more of the trust that used to be fragmented across dozens of point products. At the same time, the threat landscape continues to evolve faster than we expected because of AI.
As many of you saw last week, with one of the major AI platforms, AI hackers aren't a future threat they're here now. This is the first reported case of an AI agent autonomously conducting a large-scale nation-state cyber attack. The attacker was able to manipulate an agent to take steps on its own with minimal human intervention.
This is a turning point, proof that attackers are already weaponizing AI agents at scale, even more importantly, they are able to attack fast and will be able to exfiltrate faster. AI is exposing the cracks in our enterprise architectures, which do not have robust security. Patches are incomplete, platforms are missing. There is a plethora of point products across the enterprise.
This gap is exactly where attackers thrive. They're testing how far they can exploit a model. They're running prompt injections, jail breaks, model manipulation. And now we're seeing the next phase, autonomous AI agents being leveraged into the attack chain. AI is here. And with it, AI attackers are here, too.
Our messages to customers is clear: real-time visibility and security are essential for our infrastructure. This reality necessitates a paradigm shift to the industry. We must move away from today's fragmented security landscape and towards platformization.
AI requires a seamless cyber data strategy. This platform approach allows securities to be utilized effectively by the good guys to detect attacks, protect customers and immediate security concerns. Fragmentation creates friction, which in turn causes latency. Latency is a critical enemy of real-time cybersecurity. This is the backdrop that informs our strategy as we go forward.
Now let's get into the quarter. In Q1, platformization once again drove large deals across multiple industry verticals. This included U.S. Federal, where we had a strong quarter and notable competitive wins. One example is a $33 million SASE deal with a U.S. cabinet agency securing 60,000 seats. This agency displaced the major SASE incumbent as they needed a platform to provide unified visibility across both their firewall estate and remote endpoints.
Another example was a $100 million deal with a large U.S. telecom provider. This included an $85 million commitment to XSIAM, which is our largest XSIAM deal ever. This customer chose us to consolidate the disparate point products based on the ability of our platform to deliver materially faster meantime to respond.
The common theme across these large transactions is clear. Customers are moving from managing vendors sprawl to demanding superior, demonstrable security outcomes to itemization. The natural place for customers to start their journey in network security, which remains our largest business.
In Q1, we continued to see strength in our next-generation software form factors. SASE had a phenomenal quarter. ARR grew 34% year-over-year and surpassed $1.3 billion in Q1, making us the fastest-growing SASE provider at scale. We now have approximately 6,800 SASE customers, including 1/3 of the Fortune 500, including leading technology companies like IBM and Oracle.
Even though it's early days, we continue to see strong momentum with secure browsers. The arrival of AI and agentic browsers were exposed security cracks on them and focus the enterprise and ensuring widespread adoption of secure browsers.
In Q1, we crossed 7.5 million browsers sold while our bookings nearly quadruple year-over-year. One more product, which I'm getting more and more excited about recently, is a shift I'm observing and our customers deploy more and more software firewalls and it's beginning to show in our results.
Product revenues grew 23% year-over-year. Today, nearly half of our product revenues are driven by the software form factor. We now have over 12,500 customers and maintained our leading market position in software firewalls. As the AI transformation accelerates, growth in cloud workloads, the software firewall provides essential runtime protection with new AI data center and with its recent ability to step up Protect AI, we expect continued momentum.
Talking about protecting AI, let's talk for a bit about Prisma AIRS. As I mentioned earlier, AI is moving faster than expected. This creates a critical moment for enterprise innovation. The reality is that while 78% of organizations are embracing AI transformation, a staggering 94% still lack the necessary security guardrails, presenting a massive risk.
With our acquisition of Protect AI now fully integrated, we introduced Prisma AIRS 2.0 in Q1, the industry's most comprehensive end-to-end platform to secure AI, protecting everything from autonomous agents to model the power them. that AI agents will become a problematic insider threat, if not secured. Prisma AIRS is the essential circuit breaker layer to stop them.
It unites deep model inspection, real-time agent defense against threats like prompt injection and continuous autonomous AI red teaming in one platform. And once our acquisition of CyberArk closes, the addition of identity security will be critical to this mission, providing the essential to govern these new autonomous insider threats and prevent agent identity impersonation.
Our commitment to security is driving new high-value partnerships, including a collaboration with NVIDIA to secure the AI factory with Prisma AIRS on BlueField, and tight integrations with platforms like Glen, IBM, Factory and ServiceNow and securing the exploding number of agentic AI workflows. Early customer traction is strong, reflecting the general market need in the number of AIRS deals in Q1 more than doubled versus last quarter. We believe we are the furthest ahead in AI security with marquee customers signing up with Palo Alto Networks.
As they move from traditional to AI workloads, we believe we are going to continue to be in the pull position. And the same way AI surprised the world at this pace, I want to talk about something else that is going to become relevant from a technology shift and security perspective, quantum.
Quantum computing has seen significant innovation over the last year. We are getting more and more optimistic on the arrival of quantum and expected to be commercialized by 2029. As is widely known, quantum computing has the ability to break current encryption across technology stacks. Enterprises have less than 5 years to get their states to quantum readiness, that is a fear that some nation states will have quantum compute capability sooner than 2029.
Just last month, our partner, IBM announced they were able to run a key quantum error correction algorithm on commonly available chips. The U.S. government and many other nations are emphasizing PQC or post-quantum cryptography to drive new cryptographic standards that are resistant to attacks from future large-scale quantum computers.
To address this, we have launched and are going to be delivering a complete quantum-safe strategy. First, we help you discover. In August, we launched our new version of an PAN-OS 12.1 Orion, which provides a quantum readiness solution to give customers an automated inventory of their cryptographic risk.
Second, we help you protect. We launched our new fifth generation firewalls, which are optimized for quantum security.
Third, we help you accelerate. Our platform's unique cyper translation capability can make legacy systems quantum safe immediately, even if the application itself cannot be upgraded. Beyond this, we've just announced that we're deepening our partnership with IBM to deliver the quantum-safe readiness and remediation service, a complete end-to-end solution for PQC migration.
Now moving to Cortex, which is a pillar of our security operations center strategy. XSIAM continued its incredible trajectory in Q1. We now have approximately 470 customers with the average customer paying over $1 million in ARR. This includes large referenceable customers in every major industry.
The success of local incidence XSIAM was built for large-scale data processing, organizing it, normalizing it and making sense of it in real-time. Today, we're processing 15 petabytes of telemetry on a daily basis. The result is demonstrable security outcomes. Over 60% of our deployed XSIAM customers have reduced their MTTR or median time to respond from days or weeks down to minutes.
I'm also thrilled to announce the launch of agentics this quarter. Agentics brings powerful AI agents directly to the core of enterprise security challenges. In the future, the only effective countermeasure against hacker AI will be our own AI agents, purpose-built for advanced security detection and remediation.
For years, the industry has struggled with 2 defining issues, overwhelming alert fatigue and a massive global talent shortage. Agenetic is our definitive answer. This is a leap beyond mirror automation, this is true autonomy. The ability to use predefined agents or build customer agents to secure enterprise is a step change in how security will work in the future. We are fundamentally transforming security operations and optimization by deploying autonomous air agents that deliver enhanced speed superior efficiency and greater control for security practitioners.
Right out of the box, Agentic leverages a broad integration ecosystem, connecting with thousands of existing secured and IT tools and third-party environments. It provides customers with an intelligent, fully governed and completely transparent teammate across the enterprise. Ready to operate on day 1, Agentic accelerates response, elevates quality and frees up scarce human talent to focus on higher order strategic work.
Now shifting gears, I am pleased to announce our CyberArk integration plans remain fully on track, and we're proud to have received overwhelming shareholder support for the acquisition, which is now expected to close in fiscal Q3. Since our announcement in July, we spent more time with the CyberArk team. We are even more excited about the growth opportunity in the future product road map. This includes our vision of democratizing entity security across the enterprise and making identity the next platform for Palo Alto Networks.
Anecdotally, our customers share in our enthusiasm and the early feedback has been encouraging. As many of you saw, CyberArk's business continues to execute, achieving record net new ARR in their most recent quarter. And even as we invest ahead of the curve, our long-term financial model remains intact. The scale of our platforms and operating leverage in our business reinforces our confidence in achieving 40-plus percent free cash flow margins by FY '28, inclusive of both the pending CyberArk and Cronosphere acquisitions.
We are executing from a position of strength, and we see a clear path to drive both innovation and financial discipline.
Now let's talk about our new announcement. I'm sure all of you are wondering why Palo Alto Networks, who is in the midst of a large acquisition of CyberArk, would engage in an acquisition at the same time of Chronosphere. I think it's important to understand where we are in the AI cycle. The e-Cycle is moving fast. There's never a day that goes by without significant announcements on investments in AI data centers, AI infrastructure.
This large search towards building AI compute is causing a lot of the AI players to think about newer models for software stacks and infrastructure stacks in the future. The 17-year-old observability industry was not designed for the AI era. AI requires always on comprehensive observability 8 gigawatt scale. The challenge so far has been that full observability is cost prohibitive for the customer.
Chronosphere is one of the fastest-growing software companies in history. The observability solution for Chronosphere has already been deployed and has demonstrated scale at a large frontier model where they continue to move workloads across. Leading cloud consumer platforms are applying full comprehensive observability offering 99.9-plus percent availability to their customers. Chronosphere is able to deliver this capability at 1/3 of the cost of other industry-leading solutions.
Yes, 1/3. With $1.5 trillion of compute coming online over the next few years, there will be continued demand for next-generation observability led by Chronosphere. I'm really excited about the possibility of delivering remediation to the observability category by bringing together capabilities of Chronosphere and our newly announced Agentics platform. Chronosphere also recently had acquired a company called Calyptia, a data pipeline provider. That was complementing their focus on observability and ensuring the right data got on to the observability platform.
Calyptia integrated with XSIAM will enable us to offer our XSIAM customers comprehensive security data pipelining capabilities in line with current industry trends. This acquisition perfectly aligns with our strategic playbook. We acquired the best technology at an inflection point in industry, we invested as development and utilize our go-to-market scale to quickly deliver this game-changing innovation to our customers.
Remember, this is barely 2.5% of our market cap, which is consistent with our tuck-in strategy over the last 7 years of acquiring companies.
To summarize, we had a strong start there. Our core business is firing on all cylinders, platformization continues to take hold and overall demand is strong. Over the last years, we have shown our ability to scale $1 billion-plus ARR business in SASE and Cortex. Looking ahead, we think software firewalls is our hidden gem and possibly the next billion opportunity. We maintain a relentless focus on innovation by tackling new challenges in AI, security and quantum.
Finally, our ambitions continue to grow. This year, we'll be significantly expanding our opportunity in new markets as we closed the acquisition of CyberArk, Chronosphere in both categories of identity and observability, which we believe are in the midst of inflection due to AI. We are less than 5% penetration into a TAM reaching nearly $300 billion in the next 3 years. As such, we are raising our expectations from $15 billion to $20 billion in ARR for FY '30.
With that, I will hand over the call to Dipak to review the quarterly results in detail.
Thank you, Nikesh, and good afternoon, everybody. We have an exciting opportunity ahead of us. We continue to execute with excellence and our TAM is expanding through the pending acquisition of 2 category leaders in CyberArk and Chronosphere.
Given that, I would like to provide some additional color around our announced acquisition of Chronosphere as well as an update on the CyberArk integration planning before moving into detail on our Q1 financial results and guidance.
As Nikesh mentioned, we announced our intent to acquire Chronosphere for a total consideration of $3.35 billion in cash and replacement equity awards. Chronosphere's Co-founders, Martin and Rob and their employees will join Palo Alto Networks post close.
While Chronosphere does have significant ARR relative to most of our other acquisitions, we view this transaction to be more in line with the tuck-in acquisitions that we have done over the past 8 years. The business has just over 250 employees with a customer base focused on large AI and born-in-the-cloud enterprises.
The momentum Chronosphere has achieved to reach over $160 million in ARR with triple-digit growth has been impressive. For that reason, we expect Chronosphere to remain largely stand-alone post close and in the near term, enabling us to balance integration time lines with the pending CyberArk acquisition. We expect this transaction to close in the second half of our fiscal year 2026.
On CyberArk, our integration planning is proceeding exceptionally well, reflecting the strong collaborative spirit between our teams. We've had excellent cross-functional collaboration at multiple levels, including dozens of integration planning workshops across various functions. We are firmly on track to hit the ground running post deal close, which we expect in fiscal Q3, subject to customary closing conditions. As you can tell from our Q1 results, we're pursuing these acquisitions from a position of strength.
With that, let's dive deeper into the quarter. Remaining performance obligation, or RPO, grew 24% to $15.5 billion. This metric is a key indicator of long-term revenue predictability and the scale of our committed business. Note that our RPO from Q1 last year included $68 million acquired from our QRadar acquisition, which took place in that period. Our current RPO, which reflects near-term revenue realization, stood at $6.9 billion, representing 16% growth.
Reflecting stability in both the quality of our IPO and customer commitments, the average new contract duration remained consistent at approximately 3 years. NGS ARR ended the quarter at $5.85 billion, achieving 29% growth and exceeding the high end of our guidance. Adjusting for the $74 million contribution from the QRadar acquisition in the comparable prior period, our net new ARR in Q1 grew over 20%.
The momentum was broad-based with strength from software firewalls, SASE and XSIAM. It is important to note that our NGS offerings drive all of our revenue line items, including product revenue, nearly half of which is from software over the last year; subscription revenue; and a growing portion of our support revenue.
Total revenue reached $2.47 billion, representing 16% growth which exceeded the high end of our guided range. Product revenue grew 23% year-over-year, 44% of our trailing 12-month product revenue came from software form factors, an increase from 38% in in the trailing 12 months ending Q1 '25. This acceleration is fueled by growth in our software firewalls and PAN-OS SD-WAN within product revenue.
We continue to see stability in hardware appliances and early interest in our newly launched Gen 5 firewalls. Total services revenue grew 14%. Within this, both subscription and support revenues grew 14%. Geographically, we saw broad growth strength across all major theaters with Americas growing 14%, EMEA up 18% and JAPAC growing 22%.
Having discussed our top line strength, I'd like to take a moment to give an update on our platformization in Q1. As Nikesh highlighted, platformization continues to take hold as customers look for a strategic security partner that can continually adapt and innovate with shifts in the cybersecurity threat landscape.
Our ability to deliver best-in-class products through our unified platforms, Palo Alto and quantum security in Q1, for example, is a critical motivation for customers to platform is with us. We completed approximately 60 net new platformization this quarter. This momentum was driven by strength in XSIAM, where platformization more than doubled year-over-year affirming that customers are actively moving towards simplicity and integration to have real-time outcomes.
We now have nearly 170 customers with NGS ARR over $5 million and 50 customers with NGS ARR over $10 million, both growing about 50% year-over-year. These results reinforce our target of $20 billion in NGS ARR by fiscal year '30, inclusive of the pending CyberArk and Chronosphere acquisitions.
Moving down the income statement. Our disciplined focus on profitability and operational leverage is clearly visible in the performance metrics we delivered. Total gross margin for the quarter was 7.9%. We delivered product gross margins of 80.2%, an increase of 50 basis points year-over-year and reflected a significant sequential improvement of 340 basis points compared to Q4 '25.
The Services segment also demonstrated positive margin trajectory reaching 76.2%, which constitutes a sequential increase of 70 basis points. We continue to be pleased by the continued growth of our SaaS offerings and remain actively engaged in executing cloud cost efficiencies. We delivered an operating margin of 30.2% achieving expansion of 140 basis points year-over-year and our second consecutive quarter above 30%.
This strong expansion reflects not only improvements in gross margin, but critically our ability to drive sustained scale and efficiency across all of the OpEx line items. We continue to apply an AI-first lens to all of our processes and functions. Notably, we have been able to deploy AI in our global customer support organization to drive 3 consecutive quarters of case volume reduction and reduce time to resolve for 11 consecutive quarters.
As a direct outcome of this disciplined leverage, our diluted non-GAAP EPS reached $0.93, which exceeded the high end of our guidance. This execution provides the basis for strong adjusted free cash flow, which came in at $1.7 billion, up 17%. Our cash and cash equivalents at the end of the first quarter is now over $10 billion.
Finally, regarding capital allocation, our approach remains prudent. We do not repurchase any shares in Q1, our buyback strategy remains opportunistic. We have $1 billion in share repurchase authorization remaining through December 2026. Ultimately, we remain focused on leveraging this efficiency to maximize long-term shareholder value.
With that, I will move on to Q2 and fiscal '26 guidance. For the second fiscal quarter 2026, we expect NGS ARR to be in the range of $6.11 billion to $6.14 billion, an increase of 28%. Remaining performance obligation of $15.75 billion to $15.85 billion, an increase of 21% to 22%; revenue to be in the range of $2.57 billion to $2.59 billion, an increase of 14% to 15%; and diluted non-GAAP EPS to be in the range of $0.09 or $0.95, an increase of 15% to 17%.
For the fiscal year 2026, we expect NGS ARR in the range of $7 billion to $7.1 billion, an increase of 26% to 27%; remaining performance obligation of $18.6 billion to $18.7 billion, an increase of 17% to 18%; revenue to be in the range of $10.50 billion to $10.54 billion, an increase of 14%; operating margins to be in the range of 29.5% to 30%; diluted non-GAAP EPS to be in the range of $3.80 to $3.90, an increase of 14% to 17%; and adjusted free cash flow margin in the range of 38% to 39%.
As Nikesh mentioned earlier, we are also reiterating our 40%-plus adjusted free cash flow margin target for fiscal year '28 inclusive of both CyberArk and Chronosphere. Furthermore, whilst we will provide more detailed guidance after closing the transaction, we expect to maintain an adjusted free cash flow margin of at least 37% for fiscal year 2026, inclusive of both CyberArk and Chronosphere depending upon timing of close.
We've included our typical modeling points in the presentation for your review, but I would like to highlight a few now. One, as we noted last quarter, we expect to -- we continue to expect our net new NGS ARR and revenue to be second half and Q4 weighted, as we continue to platformize with our customers.
Two, we expect product revenue growth for Q2 to be approximately 17% to 18%. And finally, we expect $130 million to $140 million in CapEx in Q2 '26, which is inclusive of a $90 million nonrecurring real estate CapEx. This $90 million will be removed from adjusted free cash flow in accordance with our typical treatment for these nonrecurring items.
With that, I will turn it over to Hamza for Q&A.
2. Question Answer
Okay. Great. [Operator Instructions] With that, we'll start with Brad Zelnick from Deutsche Bank, followed by Rob Owens from Piper Sandler. .
It's great to see vintage Nikesh coming out strong in Q1 even after a blowout Q4. So congrats to you and the team.
position, Brad. First question.
I love it. I love it. Nikesh, 2026 is setting up as a perfect AI storm where every vendor has a story to tell, and it seems all roads lead back to identity where you clearly are in process of acquiring the best asset out there. But stepping back, it's rare that the winner in 1 technology generation remains the winner in the next. So what is it that you're doing outside of smart M&A to disrupt yesterday's Palo Alto to ensure success into an AI and quantum future?
Thank you, Brad. Well, I think there are enough examples in history of technology companies, which have sustained multiple technology waves and continue to win. And I think you're seeing some of the multitrillion dollar companies out there have been around for 4, 5, 6, 7 decades. So we hope you're one of those evergreen companies that's persists and is able to execute on a similar trajectory.
We are -- as you can see, we are very, very aware of the 2 biggest technology trends ahead of us, both AI and quantum. What's fascinating is the need for network inspection does not go away. From our perspective, AI and quantum are going to drive a lots and lots more volume, so as the more bits that fly around, the more than to be inspected, which means the need for bid inspection technologies is not going to go away.
Just the way the need for server hasn't gone away since the time servers were created. So I think we don't have a threat to our core business a bit inspection, which is how I broadly describe our network security business. And AI is driving more volumes. I was just talking to the CEO of a large cloud service provider earlier today and the conversation was about how they go deploy gigawatts of capacity in short order, given the large sort of thrust towards building AI compute and how do we make sure those bits are secured.
So I guess we are going to see sustained demand over time from a network security perspective. If you couple that with the trend that AI is driving is the idea that now data can be sensed real time and actions can be taken quickly as we discuss the recent cyber attack, that was an attack, which was based purely on online availability of data and the ability of persistent access.
So from that perspective, we think the solution on the other side has to be a data-driven problem solution. And if you look at what we've been doing from an XSIAM perspective, we have 470 customers. Three years ago, I remember you and I talking about XSIAM as new product categories in the SOX space. And your question to me was, what makes you think you will succeed in a space you've never played in before? Well, Brad, we prove that we can get to close to 500 customers with $1 million ARR. I don't think I know any company in recent history in cybersecurity, which has an average ARR per customer $1 million on a product category.
So I think we've proven that we are able to execute on the back of -- last, but not the least, I'll give was like, don't underestimate quantum. Quantum is going to break every key which means every piece of infrastructure hasn't been upgraded, has to be upgraded. And I just learned to something the other day, which Lee talked to me, is you don't happen to have to have a quantum computer to start breaking keys.
You can actually start storing data today and break it later. So you can imagine nation states getting forward and saying, "Let's just ingest the data, hold on to it, nobody is paying attention and I've got the data, we'll crack it later." So I just think all these technology trends are in the right direction.
We have products positioned in this category. And I'd tell you that in 3 years from now, we'll look back and say, dan, that Consort acquisition was a very smart move because you need observability. If you want your stuff to work 99.9% of the time, you need to know if something goes down ASAP. You can't know that if you don't have the data.
And if you go back historically, the question has been the 2 largest category of data are security and observability. And that's where Splunk started, by the way. All we've done is we are now the new platform for security and observability once we close Chronosphere. But thanks, Brad, for the question.
Next, we have Rob Owens from Piper Sandler, followed by Saket Kalia from Barclays.
Great. Nikesh, just building on those comments, I wanted to touch on Chronosphere. And it has been challenging, I think, for a lot of vendors in security to get into observability. So I'd love to see or hear from you your perspective on: Number one, that convergence happening right now. And number two, I think Chronosphere has shown success with some of the largest AI-native companies out there, having 2 of the top 5 frontier models.
Are there elements behind their product set that are applicable to some of these other large AI natives that are growing rapidly that you think you can have success with?
So Rob, I've -- me and the team, actually, story -- we actually found Chronosphere because we were looking around to see, "Oh, my God, everybody is going and abstracting data pipelining and everybody is going to have to have a data pipeline and capability in the future in the SIM."
And honestly, as a category, we think data pipeline in is sort of an interim category, which is there because of data inefficiency, but we don't think it has a sustainable future. So we kind of like walked away from data pipelining vendors, which I know that some of the industry has tried to ingest as part of their SIM solutions. But when we look harder, and we ran the Chronosphere, we discovered -- it's very rarely when your engineering team comes back and says, "These guys are good." Generally, engineers have too much pride to tell you that somebody else is good. But our team came back and said these guys are the best in genes to run into.
Now to be able to scale observability, when you're ingesting petabytes of data at LLM model scale and be able to not create latency, provide observability in that kind of environment at a cost, which is 1/3. Look, right now, if you go to talk to every customer, even we turn down our durability vendor because it's too expensive at Palo Alto, right?
We can't afford to have real-time observability on this product platform because it's too expensive. The problem is you can't run financial services apps. You can't run large e-commerce businesses. You can run large food delivery businesses without persistent observability. So what Chronosphere has done has changed the observability model by a combination of open source and techniques where they can do scale sort of data observability at the right price.
So we think every born in the cloud company, every company that has a platform that requires customers to access it '24 is a potential customer. I think, again, it's going to be another business like xx, which we have an average out of $1 million at some point in time.
Okay. Great. We have Saket Kalia from Barclays, followed by Matt Hedberg from RBC.
Okay. Great. Nikesh, it's interesting to see you sign larger and larger XSIAM deals. I think you called out an $85 million deal in the quarter. While at the same time, incumbents in the space are really struggling to grow. And in the past, you've talked about how XSIAM...
Saket, it makes sense. Incumbents don't grow, we take market share, which means we grow and they decline. That's how it works.
Totally understood. But maybe from a spending perspective, maybe the question is, do you find that XSIAM is able to capture at least what those customers are spending on incumbents? Or is there an opportunity to capture more because of that faster mean time to respond. Does that make sense?
Makes sense, Saket. I think the way to think about it differently is we do capture at least what the incumbent is the customer is spending on the incumbent. But in the process of delivering XSIAM, we're able to consolidate multiple products. So not only do we get the incumbent spend of the SIM provider, but you have UEBA, you have other categories. Maybe Lee, it's a good time for you to say something.
[indiscernible] ITDR, recent launches around e-mail security, exposure management. So we're able to consolidate these sort of surrounding product categories back onto a single platform. So customer saves money, but we expand the overall footprint that we can deliver.
Okay. Next, we have Matt Hedberg from RNC followed by Talliani from Bank of America. .
Congrats from me as well on the results. Obviously, a lot of really positive developments here. The 30 -- the $20 billion fiscal '30 NGS ARR target is obviously super impressive relative to the prior target that you had outlined. Obviously, there's some tuck-in sort of M&A assumptions in there. But I guess I'm curious, like from a high level, Nikesh, what are some of the biggest moving pieces that give you the confidence since you talked about the prior target just last quarter to raise it to such a significant margin?
Well, that's a great question, Matt. So first of all, as I said, our core business continues to show strength. And as every time we're doing forecasting somebody says, oh, the law large numbers are going to start making these growth rates go down. But as I mentioned, SASE continues to be strong at $1.3 billion in ARR. We're growing faster than independent public companies, which runs SASE. So we feel that's a strong part of our business.
Software firewalls, I think, is our hidden gem. 50% of our product or 44-plus percent of our product revenue is coming from software. I don't think software for all is going to stop. As you put more and more cloud workloads out there, people are discovering the data software firewall. We've been waiting for that trend. It's arrived.
We are probably outside of the CSP is the only large vendor in the software firewall space. So we feel strong that our core business will keep performing, which allows us to sustain our current $7 billion target of FY '26 forward. If you take CyberArk, what we intend to do with it, we hope that business continues to transform from where they are to absorb more and more identity categories that we intend to do with them. And I think Chronosphere, if you add all 3 of them up, that gets us very close.
Will there be tuck-in between now and FY '30? Sure. We will have tuck-ins. But as you've seen in the past, tuck-ins don't move the needles by billions of dollars. Tuck-ins move build the needle by sustaining growth rates and giving you a few hundred million dollars. But I think the lion's share is going to come from the 3 categories you just outlined in our core business, in identity and in observability.
Great. Next, we have Tal Liani from Bank of America, followed by Meta Marshall from Morgan Stanley.
Two great acquisitions, long term, very promising. The question is the transitory period. What's the impact on dilution on margins or free cash flow margins? And then how long does it take to see the synergies. So the sum of parts is greater than 2.
Yes. I'm going to let Dipak answer the precise questions on the numbers. As I said, so Chronosphere, we will run independently. Martin and team has done a great job we will provide, obviously, the services from the HR finance marketing people, which is great because they don't have a large team in doing that. They are basically a lot of really small engineers and forward-deployed engineers as well as a few salespeople.
So we're going to give them some support by introducing the right customers in a very targeted fashion. But Martin is very capable. He will run the business with his team. We trust him to do that. We're just going to provide the sort of the rocket fuel the name to go out and be customers and execute on his plan.
That's sort of -- so it's kind of -- it's a low -- because for us, it's very important because all of our focus on integration perspectives on cyber. From a CyberArk perspective, as I said, we've had some great meetings. We understand what it is. There will be some rational synergies on day 1 because we don't need certain things in duplicate. We think by the time we get to the end of this fiscal year, our fiscal year FY '26, we have a much better handle. We'll be able to align their sales quotas and their teams and territories around our plans. So that's where I think a little bit of reshaping will happen. I will let Dipak talk about specific dilution and free cash flow margins.
Yes. So I think Tal Liani key part, just what I said in my prepared remarks is like with both acquisitions, we believe that we'll be able to get back to the 40% free cash flow by '28. Your question is really about what in the interim. And I specifically mentioned that we should be able to maintain at least 37%-plus free cash flow margin even in the interim, like barring the onetime costs, which I think just highlights the bottom of the floor. .
So we're pretty deep into -- at our scale, we're pretty deep into understanding how much we can do, how fast and it doesn't really move the needle as much as you think it might.
So putting 37% to 40% over the next 2 years and 40-plus percent by 2028.
Next, we have Meta Marshall from Morgan Stanley, followed by Brian Essex from JPMorgan.
Great. Apologize for the voice. Great traction with XSIAM and Prisma this quarter. Just what inning are you seeing customers in, in terms of AI adoption? And is it different on AI for security versus kind of security for AI?
Look, it's still early innings on AI adoption. I mean there's -- on 1 hand, what you see is this massive build-out of AI data centers and models and everything else. That's the leading indicator. But then when you start to look at enterprise adoption, there's huge scale of production pilots and early deployments and things like that. And that's really just the tip of the spear of what we think is coming. Having said that, though, the security of that tends to be trailing debt.
And so the recent attacks that we're seeing both of AI as well as AI launching attacks is obviously going to start driving more and more awareness of the importance really of trying to do both those things at the same time. It's -- what I see when I talk to customers is a growing desire for the production pilots of AI to be run in parallel to the production pilots of AI security, so that they're moving in lockstep.
And so that's going to require a bit more urgency, I think, on the security side to be up in lockstep with the IT deployment side. And that's starting to happen, but it's still early.
Thank you and feel better, Meta. Next, we have Brian Essex from JPMorgan, followed by Joseph Gallo from Jefferies. .
Congrats on the results, team. I wanted to circle back on quantum. I saw the partnership with IBM on quantum-safe readiness. I guess a question for Nikesh, are customers focused on this yet? Is this going to require some evangelism on your part? Or will this be kind of like a Y2K event where they wait till the end, to the last minute to address their exposure?
And then maybe for Lee, how do we think about the technology advantage that you have that gives you maybe a superior right to win for post-quantum readiness? Is it the depth of visibility that you have and observability into networks? Is it data protection, all the above? How do you frame that out?
Let's start with your question on timing. So the -- there's a couple of things that are driving a level of urgency. One is, as Nikesh was mentioning, this notion of harvest now, decrypt later is one of the concerns. So probably more nation-state level type attack, but collecting encrypted data and then waiting for quantum become real in order to decrypt it later and so there are certain types of data that will still be valuable years into the future, and so that's one reason for urgency now.
Second is it's not clear yet when quantum computers will be viable. And it's possible that they'll be viable before people are currently expecting. And so there's a certain -- that variability is also factored in. And I'd say third is this is likely for a lot of organizations, a multiyear effort. And so if they don't start now, they won't be ready 2, 3, 4 years from now.
And so all of that is adding up to, what I've noticed over the last, let's say, 6, 9 months, is a pretty significant inflection in the number of customers are starting to talk about this and plan for this from an urgency perspective. On the technical side, the look, part of this is really just related to we started working on post-quantum several years ago. So we did not wait to start working on this.
We've had capabilities rolling out in the last few years with the biggest launch being a few months ago with Orion. And that has put us in a very good position simply in terms of being ahead of many of the people out there. Two, the -- our ability to sort of see across hardware stack, software stack, SASE stacks, browser stacks now gives us I think probably one of the largest footprints where we can leverage existing deployments to get that visibility and to provide remediation versus having it all be net new.
And the partnerships we announced is really pretty powerful because it allows us to work with others that can complement the pieces that we already have.
And the only thing I'll say to that, Brian, is, look, I understand I used to be -- used to be on your side of the world when I have Y2K we're all trying to figure out which stock to buy, which one not to buy. But the good news is in Y2K like you had to go and reset everything, there is no quick fix across the enterprise. And in this case, yes, the long-term solution is to everything and make it more robust.
In the short term, we actually have a solution we're using techniques. We can actually take existing legacy enterprise infrastructure and secure for quantum. So as a customer CIO, would you rather take the risk or you just rather spend a few million dollars and say, "I am quantum secure until I can upgrade my infrastructure?" The answer is cybersecurity is insurance anyway instead of buy a little more insurance.
Yes. Are you seeing a compliance push yet or is that still on the horizon?
Early stages of that, Brian. Early stages. It's coming.
Thank you, Brian. Next, we have Joe Gallo from Jefferies, followed by Patrick Cole from Scotiabank.
You made some architectural changes to the cloud security products earlier this year. Can you just update us on that? How has that been received by customers? And any sense of how cloud security grew in 1Q versus 4Q?
Yes. The -- so we've made some changes, Joe, as you noted, with the launch of Cortex Cloud early in the year. This was made for a number of reasons. In large part, we were seeing a increased need from customers to be able to secure the full life cycle of their cloud deployments from code to cloud deployments to run time, even connected all the way into the SOX.
And so the -- that was the impetus behind this, and we've seen a lot of very positive feedback from customers in terms of aligning to their strategies as well. And then since then, we've been able to continue to drive further capabilities on that. Earlier this year, we announced ASPM. So this is basically allowing us to prevent application security issues from working the way into production.
And then most recently, we announced the new cloud security agents or CDR agent, we're able to be 50% more efficient in protecting cloud workloads with that. And so we -- we continue to drive more and more innovation. Actually, the last 1 was with the launch of Agentics, that is now natively available as part of the Cortez Cloud as well. So we're even bringing agents to the cloud security mix to help automate customer workflows in the cloud.
Thank you, Joe. Next, we have Josh Tilton from Wolfe Research, followed by Patrick Cole from Scotiabank.
I just want to follow up on the first question from Brad. I do think that today, the current investor view is that identity security is the market that is best positioned to benefit in an agentic future. But Nikesh, I think in response to his question, you did mention that AI is increasing volume and inspection. So what I'm trying to understand is how should investors expect the volume of network traffic to change in an agentic future? And what does that mean for the traditional firewall business and the SASE business.
Look, I think the way to maybe think about it, Josh, is the advent of AI is just created an extraordinary increase in the amount of data both data concentration, but also movement of data, right? So we're seeing environments now that are beyond any scale that we've ever seen before just in terms of the amount of data that's moving around.
For example, you think about how much training data has to be brought to bear to and train one of these models, let alone, all different models are being built in different versions and models. And so that by itself is creating a noticeable influx in the amount of network traffic, but it's somewhat concentrated, concentrated toward the AI platforms themselves.
The second part that comes with that, though, is as AI becomes more and more deployed across the enterprises that will also drive a similar pattern, albeit maybe at a slightly smaller scale and that's the part of what Nikesh was talking about both in terms of amount of data, but then that translates into the observability needs, the application criticality needs and, of course, security on top of all of that.
Yes. I think just -- I think you probably alluding factor, we didn't explain the identity thing well enough. Look, identity is a market that products were designed 15, 20 years ago. And with all respect, in our view, IAM is not identity security, it's hygiene and ID, it's IT capabilities, like the fact that you have a badge doesn't make me secure. I have badge to enter Palo Alto. That's not security, that keeps track of the fact that I'm in the building.
It doesn't stop me from doing anything bad that I want this. So we believe true security in the world of identity happens when you start enacting privileged access type controls across identities. And our view with CyberArk is that the fact that we are only 500,000 people in the enterprise privilege when pretty much the remaining 15,000 people at Palo Alto could cause equal amount of damage to other ways using systems.
So our view is, in the future, almost every identity will get some version of privileged access management. And CyberArk is the best platform from our perspective and assets in the industry to be able to leverage those capabilities. Now we have to do some joint product work which is not unlike the fact that came to Palo Alto, we had a network security company with 4 subscriptions; today, we have 10. May possibly we'll have 15 by the time the next 5 years come out.
So can I have an identity platform with 15 different capabilities of the underpinnings of what is a CyberArk Privileged Access Management platform? Yes. But that requires some degree of innovation, some degree of consolidation in the enterprise. And the more we look into what CyberArk has, the more excited we get, that there is an opportunity here. But yes, there's a bunch of work that needs to be done. As Lee and I were joking yesterday, we call it back to the future.
Thank you, Josh. Next, we have Patrick Colville from Scotiabank followed by Fatima Palani from Citi.
Right. My question is for Nikesh on Chronosphere. I mean we know many of the VC backers and I totally agree with your comments earlier that you're acquiring a top-quality asset with a toehold in a Tier 1 foundation model vendor. But my question is...
about to get to get there, Patrick.
Okay. Nice.
There's more than a toll already, but we're working on getting the whole foot in there.
Well, we're looking forward to seeing that. So I mean, maybe the -- I guess, why has the advent of AI driven you to pull the trigger right now on the Chronosphere deal? And then also, if I think about Chronosphere, the buyer is typically a dev or maybe a CIO, which is quite different to your current buyer profile. So just talk me through your thinking of how you're going to penetrate those new buyers?
So Patrick, what's interesting is that let me answer that in 3 different ways. One, the actual buyer for Chronosphere is very often the CIO is even the CEO. I had a conversation as part of our diligence was the CEO of a financial fintech company. I said, "Hey, we own a Chronosphere." He's said, "Yes." I said, are they good? He said, "Yes." I said, "How do you know them?" You looked at me staired at me said, "You think I don't know my tech stack?"
So I mean, these guys understand -- remember, if your restaurant app goes down, your ride hailing app goes down, every second is lost revenue. What observability does is make sure it keeps track of whether any element of that stack is decaying, is any element sharing latency, is there any performance issues across that stack.
So you need constant persistent observability. The problem is, it's expensive. The current vendors charge a lot of money for it. Now Chronosphere is able to figure out is how to do the same thing at 1/3 of the cost. So it's a combination of open source stack, it's a combination of enterprise-grade features, but they're pumping large amounts of data.
So the 2 biggest problems are scalability and cost. They solve both problems. Now the cherry on the cake or the icing on the cake is we plan to take what you find in observability, marry that with the agentics and provide remediation agents, which haven't been done before.
So if you can take that entire life cycle and say, find the problem, solve the problem, built an agent, fix the problem, right? Now these are agents were built in partnership with customers because no customers should allow us to independently resell their infrastructure, but they can now write capability on top of the platform saying, "I found a problem. I'm going to automate it. I'm going to build agent, fix the problem."
So I think this is a huge opportunity. And I'd say in the last year, 75% of my customer conversations are CIOs and 10% are CEOs. So I know the buyer. And that's why is going to run the company. Listen, there are 173 companies in the world, which all need persistent observability. We know all of the names. We know exactly who deployed. This is what does for a living. We'll go one at a time and convince as a platform they have. Each of those guys spends $5 million or $10 million a year with us, we're home.
Thank you, Patrick. Next, we have Fatima Boolani from Citi, followed by Greg Moscow from Mizuho. .
Nikesh, I was going to ask you an out-of-the-box question in accordance with how out of the box to your thoughts around Chronosphere...
I wouldn't never expect anything else.
It's my brand now. So what I wanted to ask you, you really have kept hitting home the point around TCO, scalability, cost efficiency as a conduit for this convergence of security and observability, right? So in terms of the Chronosphere rationale, I wanted to ask you, how much of the rationale there was for you to effectively modernize in-source, whatever terminology you want to use, to modernize or in-source the underlying fabric of your Cortex and XSIAM technology, right?
So in in the context of everything you and Lee have talked about an absolute explosion of data an explosion of telemetry that's going to be hitting your iron basically for all your clients. How much of the rationale for Chronosphere was that versus wanting to and right into a brand-new market where you're going to try to win budgets?
I think that the latter not the former. And if you go back, and I'm sure you've asked the question and many of you guys have asked me the question. There's always been this sort of fantasy that observability and security will come together at some level.
And I think this is what started when Splunk half the data is used for observability, half the data is used for security. So it started there. But it never progressed past that. Most of the observability vendors were so caught up in trying to solve the observability problem that they dip their toes in security. And I always say, if it was so easy to build security with 20 more engineers and God bless you, why do we exist?
And the same thing of to observability. Like if you don't -- these guys have spent -- they're like 200-plus engineers, they have spent the last 3 years doing this and a proven scale of the market. So yes, it's a phenomenal adjacent TAM, which is going to grow in double digits for the next 5 to 10 years. And yes, we want a part of that.
And if you look at it from our ambition to get a $20 billion ARR, we're not going to get there if customers are not spending a lot of their IT and cybersecurity spend with us. Now there is a connective tissue between data across enterprises, right?
Over time, the best enterprises will have seamless data access across many of their data lakes. What is the observability data lake, is there security lake, their IT data lake because eventually, you want agents to go and go figure out what's going on across multiple data lakes to solve your problems, sometimes problems cross across multiple data lakes, right?
If something is down in an application, maybe the firewall shut it down, so firewall was in a security delay. So if you want this agentic capability across data lakes, all we're trying to do is we're trying to build the enterprise fabric with our customers. So over time, we can provide more and more capability. When you think of what Lee XSIAM. We're building more and more modules on top because we can write more software on top of the existing data. Why does my firewall have 15 subscriptions in 2030? What is 10 today?
Same data, how do I get quantum cryptography visibility? I watch network data. I watch network data from malware, I watch it by your else, I watch you for quantum keys. So once you get the data right, you can build tremendous amount of software capability and 1 a time, take out slivers of the industry. This is the third data platform in the enterprise, which is observability.
Once we get that data, imagine the amount of SRE activities an agents can build over time. So I just think this is foundational to our ambition to be a very large tech company and 3 to 5 years from now, we'll be sitting back and saying, "Oh my God, we get it. Now you put a foray into the observability space, you got access to production data from enterprises that allows you to keep them running at 99.9% time." You can see I'm excited about this.
Thank you, Fatima. And as promised, our last question will be Greg Moskowitz from Mizuho.
All right. Nikesh, should we continue to hear more and more adoption for your secure browser, certainly, the data points you provided today, back that up. But how pervasive can this become amongst your NetSec installed base? And how strong is the monetization opportunity associated with that?
So I think, Greg, just connecting it back to what I was talking to Fatima about, I think browsers are going to get more and more prevalent in the enterprise. And if you look historically, browsers have been a threat vector and they're not secured, right?
Pretty much companies use the browser that come out of the box to the OS is. And there's a bunch of things like we did a test POC with a customer, 5,000 of their browsers were tested. We found 167 were compromised, right? So it's a wild wild west of browsers out there, and I think it's going to get worse when AI browsers come out of the gen capability, so you have much more of a flood of all kinds of browsers and enterprise. But browser has become I'd say 80% to 90% of the workspace are most white collar workers, even developers exclude the legacy guys, but 80%, 90% of the work is being done in the browser.
So browser does become a very strong entry point from a security set perspective. It has both opportunities and challenges. The opportunities are far higher from a security perspective, rather. So we just think the browser becomes an important part of the foundational fabric for us to deliver services in the future, right?
But we need to wait for is pervasiveness or its ubiquitousness in time. And that's why, again, it's one of those foundational things. If I can get 100 million browses out there, which are secure, I can deliver all kinds of security capabilities with great higher than that. So to that extent, I think the monetization opportunity is sort of in the future at scale.
Of course, there is monetization today. We don't get the browser away for free and effectively is fungible as an endpoint agent from a SASE perspective. So right now, we're very keen on deployment and adoption and ubiquity of the browser. It has obviously a financial impact on our SASE numbers, so you'll see it the $1.3 billion. But I think from a strategic perspective, the more we can get out there, the better security outcomes that can give them in the future.
With that, we will conclude the Q&A portion of our call. I will now turn it back to Nikesh for his closing remarks.
Thank you again, everyone, for joining us today to discuss our results and the opportunities ahead. I also want to thank our partners, our employees and everybody who contributed to these great outcomes for us in Q1. We continue to plod along for Q2 and beyond. And I just want to reiterate, really excited that we are now able to establish a toehold or perhaps a footprint in the spaces of identity and observability in the future.
Palo Alto Networks — Q1 2026 Earnings Call
Palo Alto Networks — Citi’s 2025 Global Technology
1. Question Answer
All right. Ladies and gentlemen, I think we're ready to get going for our halftime show here, day 2 of Citi's.
Give her some -- pay attention to Fatima.
I should use my outdoor voice, right, not my indoor voice. There we go.
I'm your mom voice.
My mom voice, there you go, my disciplinary invoice. I have a 4-month old at home. So I have a lot of practice and a 2-year old.
Good afternoon, everybody. Thank you so much for being here at day 2 of Citi's Global TMT Conference. I am excited for our halftime show today with our starting keynote with the CEO of Palo Alto Networks, Nikesh Arora, thank you so much for being here.
Thank you for having me, Fatima.
Well, we have lots to talk about, so I will dispense with the formalities. For those of you who don't know me, I'm Fatima Boolani. I jointly head up our software research franchise, and I'm very excited to delve into all matters of cyber and beyond.
Let's go.
Excellent. All right. I think a good place to start would be at the stratospheric level, very big picture, a state of the union, if you will, of the industry at large. Nikesh, I'm hoping you can opine on the budgetary climate, the budgetary competition. And actually, most importantly, talent acquisition, both from a sales and a technology perspective. And you know where I'm going with this because of the underpinnings of the AI wave, which we'll, of course, talk about. But I think that's a great place to start from the perspective.
All right. Well, good afternoon, everybody. I hope you're enjoying your meal. Look, every time we get worried about cyber spending, a new thing happens in technology and suddenly, we all get very excited. I think 24 months ago, we were not excited about tech spending and then this AI wave came about, and we can -- all of you are excited when you see another tech company planning to spend tens of billions of dollars to build AI clusters.
So I think from a spending perspective, the environment continues to be the same. I do think that AI spending has a bit of a free pass right now that every CEO wants their companies to experiment on AI, figure out how AI is going to impact their lives. And as long as we can call it cybersecurity AI, it's fine with us, too. But no, in all fairness, I think the AI wave is creating a bit of frantic behavior that everybody is trying to figure out. So I don't think, generally, broadly speaking, the hammer is coming down on IT budgets, let alone cybersecurity budgets. And cybersecurity budgets kind of like more often than not, end up being part operating, part transformation. The operating budgets are impact -- are intact.
I think it's fair to say that you'll always find a CIO and a procurement team, which wants to not have cybersecurity ongoing budgets go up. They like them flat. They like them growing a little bit, not a lot. And there's obviously net new budget for new ideas. And in that environment, because we are positioned ourselves as a consolidation play, we're fine with flat budgets because we expect to take share from other people and maintain our growth. So that's kind of where we feel from a spending environment perspective.
As a $10 billion player in the cybersecurity market, you were the largest...
$120 billion more than $10 billion, or use that.
The $120 billion in ballpark and cap asset with $10 billion in revenue, largest pure-play cybersecurity vendor in the market in the space, you naturally have a seat at every single large important organization in the world across verticals. So as -- probably not a fly on the wall, but with a lot of talking points sitting at these tables with these very large companies, what have you determined are and have been becoming the most common patterns and pain points and discussion threads on how some of your largest customers are tackling cyber hygiene against and in preparation for operationalizing an AI strategy. And I want to go back to something you said, there is a frantic AI spending frenzy right now. Everyone is throwing spaghetti on the wall as to how AI is going to improve their business and work for their business. So your seat at that table, what implications does that have from a cyber hygiene perspective?
All right. So I think let me break that down into 2 parts. Let's first talk about where we see AI and what I see -- how I see the AI landscape evolving because that actually dictates how we prepare for that environment from a cybersecurity perspective. I think if you look at the global AI reality or traffic, 80% to 85% of the traffic is in consumer right now, right? People are building the next version of ChatGPT, the next version of Gemini, Grok, Llama, Deep research, all these things. And the way they manifest themselves is consumers getting excited. The reason OpenAI raises it $0.5 trillion or Anthropic raised $180 billion is because there's a lot of people using these models to ask questions, whether they're search type questions, their videos they're making, asking questions on Grock, they're asking questions on Meta AI. That's where 85% of the traffic is. That's where the training is happening and that's where "the arms race" is on AI models.
And that's fine. We understand that. You can see the direct application. There's large distribution, billions of users who use some version of Meta's products or Google's products. They're all becoming natural users. My Gmail is summarizing things for me now. It's like in product. I mean last -- this past quarter, we have a secure version of Gemini deployed at Palo Alto. I ran my earnings scripts with Gemini and asked it, how many times am I repeating certain, it told me stop using the word momentum so many times. So it does stuff like that. It's kind of useful.
Pick test 7, the source there .
So it does a bunch of stuff like that, and that's -- you're seeing the consumer use case, that's where 80%, 85% of traffic is. That's why more GPUs will be sold and more models will be trained. So we get that. I think the second category, which is slowly emerging is let's call it the AI application category. This is where you see the cursor of the world, people doing wipe coding, you see Harvey, the legal sort of application stuff, Grammarlys of the world. There's about 1,200 applications which are using some version of a wrapper around the AI models to make some tasks, some workflow better, right? You're seeing that.
And they're also kind of like the best way to sort of create an analogy is it's like the drop boxes or the box of the world where they are generic for every enterprise. They're not specific to any one enterprise. There's a lot less customizability, but they're generic enough that they apply to a standard use case for enterprise. So you're seeing some traction there. I want to say that's 5% to 7% of the volume right now, including coding in the market. And the remaining 4%, 5% is enterprises experimenting with AI to see how can I make my application useful to my customer, which I think still ways off.
In that context, security only applies to the third category. If you're going to deploy your LLM in your company, you want to secure it, you want to make sure there's a firewall around it. It applies to the enterprise deployment of the Gleans of the world or the Harveys of the world, which they are slowly getting their arms around, but it's slow. It's like there are not many customers asking for a secure enterprise. That's how kind of cybersecurity plays into it. But I think the anxiety is more around AI deployment and cybersecurity. People all hear about agents saying, "Oh my God, if I have agents running around in my enterprise, who's going to manage them, who's going to control them? How are we going to give them credentials? How are we going to track them because these are nonhuman identities floating on my enterprise." So people want to hear the story. People hear the story of how am I going to protect my AI deployment with an AI firewall.
So the conversations as it relates to AI are mostly about securing models, securing my deployment, securing my employees from not sending my corporate data outside and making sure agents don't take over my enterprise without some version of a guardrail or a kill switch, right?
If I go to the regular discussion around cybersecurity, I think there is a growing understanding that some version of interworking consolidation commonality needs to start coming into play because the infrastructure is too disparate, too fragmented. And it's kind of interesting. It's not coming from an economic consolidation perspective. It's coming from holy****. I'm going to have to respond faster to cybersecurity events and with a fragmented architecture of 30 or 40 vendors, I can't do that fast enough, and I know these AI agents will be used against me who are going to come chase me down and try and attack it. And then a week doesn't go by where somebody doesn't get breached. In fact, as you might have seen in the last week, even some of our Salesforce data got compromised and so did that of 699 other companies. So 700 companies got breached in some way, shape or form because of an API or an agent of a third-party app that had too much access to our data and that's going to happen more and more.
Nikesh, what I'm hearing from you is -- and by the way, I think this is one of the most fervent debates in the investor community right now, specifically with the software investor community on who gets paid on AI. I mean, certainly, there is a case to be made on the application software side where maybe there's not that much inspiration on that side right now. But certainly, a ton of debate that's formenting on who is actually going to get paid on AI. And what I'm hearing from you is that there is a lack of maturation and frankly, critical mass of productionized AI environments for you to step in to wrap guardrails around that, right?
So with that precursor and that preamble in mind, you said something interesting, and I think I'm going to pull on that thread, you always say interesting things. So -- is there necessarily a prerequisite of an IT infrastructure and IT architectural evolution for you to then step in to provide the safeguards from an AI perspective, kind of like how we saw in COVID where the SASE transformations begot network transformations, which happened because of COVID, which created this impetus because all of us ended up working from home, right? So a long-winded way to ask you, is there a chicken and egg situation where we have to wait for the underlying infrastructure at most large organizations to evolve and modernize before AI security can be a juggernaut on its own?
You said a lot of things. Let me break it into 2 or 3 parts. One part is I think a lot of us have the impact of AI on software wrong, right? And we can talk about that if you want to or we can talk about security. There's going to be a whole revolution need over there, and it's not simple copilots that sit next to your products. I think products will fundamentally need to be reinvented. And what I mean by that is most software for enterprises designed in the end result in a series of dashboards, which then humans are supposed to look at and say, what's my problem? How do I solve the problem? What do I do with it? If you have the data structured right and you're able to create the dashboard, you should be able to now with some version of AI, figure out the anomalies, the next step is you should be able to fix it.
So I think you'll see a lot more software get reengineered where it will be more do this task for me, either at the prompt of a user or by itself, and that requires a full transformation of the software stack in a way to make it AI ready and make it work. So picking our book, we're working hard in every one of our products to see how can we turn from a dashboard and discovery product into a fix it product, so our customers actually get the benefit of the outcomes we can create as opposed to the analytics only. So I think that's going to happen across every space. And it's going to happen to most SaaS software that we use, and that needs to happen. It's not going to be copilot in the long term. So let's put that aside.
I think your question around when does the AI security wave hit, I think there is already an awareness and realization that if I don't get my infrastructure modernized, I will not be ready for AI-based attacks. So I don't need -- we don't need AI to productionize for people to start feeling the pain that "Oh my God, if I don't get my s*** together, now they are beginning to understand everything in IT is a data problem. Even security is a data problem. How do I transform myself? How do I get myself into a happy data space and solve the security cloud." In terms of AI security itself becoming a thing, the day you tell me that look at this cool AI app Home Depot has and look at this cool AI app JPMorgan has and look at this cool AI app Goldman Sachs have, trust me, they're going to have buy a lot of security.
Look at this cool AI app Citigroup has.
That's right. Right. right. Yes, that one, too.
I think you've had very strong and prescient views on the impact of AI. That's very apparent. You've also made very bold and early bets with prompt AI, which was a deal you did earlier this summer.
Protect. That's a different company, they have prompt, but same difference. It's like Citi, Goldman, Palo Alto, Cisco.
There you go. Tomato tomato. What does Palo Alto's portfolio look like from an AI security perspective? And is the ultimate vision to own the entire AI value/supply chain from a protection standpoint?
So there are 2 schools of thought. One school of thought says that everything will have to transform with AI. So it's going to be sort of -- it going to be across the entire enterprise. It won't be a separate thing, in which case, your SaaS app will have AI in it, your E-mail will have AI in it. So you can't take it out and say, AI, you sit over here, everybody else is here. Everything that you do in an enterprise will have AI. Today, if my Gmail is summarizing using Gemini, I need to make sure that Gemini is secure when it runs in Gmail. I don't have to wait for say, Gemini you sit here.
So I think there's going to be AI features built into every product that we have that will check if AI is not doing something different. So that's going to happen. Everybody has to enhance our products to take advantage of the AI use case. For example, we have a firewall that works on the data center, it works at the edge. Now our software firewalls has AI traffic inspection capability. It's not a new product. It's sitting in the product in the software firewall called AI firewall. Or if I write code using Cursor versus humans, do I have different product that checks the code that Cursor writes? Or do I have the same product that checks the code humans write and apply that product towards Cursor, more likely the latter than the form, right?
So every product that we do will have to make sure that it anticipates and inspects for the AI use case. In addition to that, the net new part will be every enterprise is going to build an AI stack. I'm going to have my LLM, I'm going to have my vector DB. I'm going to have some sort of prompt engineering or inference engine. And at last count, we discovered to our amusement and...
Dismay.
Dismay that within Palo Alto, we have 37 models being used. We didn't know that until we build an AI discovery product saying, go discover the models we have, holy****. 37 is a lot. If you'd ask me, I'd say 2, maybe 3. And I think that story will play itself out in every enterprise that enterprises don't know, a developer can go to Hugging Face and download an LLM and deploy it on their laptop and be doing an experiment and use your corporate data in that LLM. And you have no idea if the LLM was made in unfriendly countries, which is -- has a back door to the country with your data in it. So if I'm a chip designer, I say, you know what, my boss said, don't use a public LLM, but I can always go look at an open source LLM from Hugging Face, download in my laptop, run my chip design against it. You just don't know that it has an open connection here in the back. You just cut copy paste your chip design and do some database in some other country that you wanted to go to.
So at some point in time, when you start building your AI stack, you will have to ring-fence it with security. You have to make sure that has guardrails. And that's where I feel the AI security opportunity is in addition to transforming everything you do and ensuring that you're inspecting the AI use case.
Now imagine the very incipient and embryonic stage we are at with every single day, we have these mammoth innovations coming out of the foundational model companies and you alluded to Anthropic and they're around. So clearly a lot of value creation happening there. But how does that...
A lot of spending happening.
And spending up happening. How does -- as an allocator of research and development capital around AI, AI security and all of sort of the niches that you talked about, how does that complicate or empower your R&D strategy where you might be chasing innovation that might prove to be a flash in the pan in 6 months or becomes commoditized very, very quickly because we're having these very shallow cycles, right? So how are you thinking about that? And ultimately, from a dollars and cents perspective, driving yield and leverage from your R&D investments because you're obviously trying to skate to where the puck is going with respect to AI.
Yes. It's a good question. So let's break it down. The good news is we're not in the model business. And the best news is the people building the models are putting the tens of billions of dollars required to train them and letting us pay by the drink, which is great, which means somebody else has the capital-intensive model, we have the subscription model. So if I don't use it, I don't end up spending a lot of money. But a good thing. We like that because that allows us to experiment and not have to go deploy $1 billion to build a stack that allows us to train our LLM. So let's leave it there. That's one part.
I think there are 2 big transformations every enterprise will have to make. One is data, the other is talent. On the data front, most companies are not collecting AI-friendly data. And let me explain what I mean by AI-friendly data. If you take the example of a self-driving car, GM was not collecting mapping data on every street that GM drove. Like a GM car drove, they were not taking pictures of everything around the street and saying, what is a tree, what is the plant? Where is the plant? Where is the tree? They had something like [ scale.ai ] that was labeling $10 billion worth of data for every car company for 5 or 7 years before they actually got an AI-friendly data environment to be able to build self-driving cars because you had to know the true case and the false case from a data perspective. You need the same thing in every AI application you build.
If you want to use customer support, you need to know what a good solution looks like versus the wrong solution. You need to collect the data in such a way. So one every company will have to go through some version of a data transformation or data collection strategy. That is nonregrettable. You can invest money in that, and you will get a return when you get the data right. You can do it now, you can do it tomorrow, you can do it in 6 months. My data is no used to [ Jay Chaudhry ]. His data is no used to me. He's got his own products. I got my own. I have to do my own data collection, my own true case and wrong case. So that is a nonregrettable problem. We can solve the problem.
Two, 75% of our employees are not AI ready. They think traditional first, right? And I'll compare and contrast. So you're writing a software application today working at Palo Alto, Salesforce, Workday, you write it a certain way. If you're working at Cursor, you write a different way. Cursor doesn't have traditional UI. It has a UI, which is an AI UI. It's a prompt, you ask if you talk to it. And the good case, the bad case all built into that interaction. In our case, we get a dashboard. And sometimes the dashboard will say, here's the conclusion, because you solve with some, I don't know. So there are AI-ready talent that are out there, which we need to make sure that everybody in our company is AI ready, which is, I think, the hardest problem. Getting 4,000, 5,000 people who are in decision-making situations to start understanding the new technology and start getting them ready is a big challenge.
Outside of that, I think the third place is you got to watch out is don't start building internal AI productivity apps. There will be third-party apps like SaaS was, let them do it for you when they're ready, use them. So we don't want to spend money in building applications. We think the market is going to build. We are focused on the data transformation, the product development, mental transformation and the people transformation.
And what about the M&A process? Because you haven't been shy about being acquisitive in, again, very bleeding-edge areas? I mean you were...
Like CyberArk?
We'll get to that. Don't worry. You've definitely taken a very strong stance on acquiring bleeding-edge assets to drive velocity around category creation and category absorption, right? So how does, again, the rate and pace of innovation in the broader AI industrial complex influence the way you think about M&A from here?
Again, to emphasize the fact that the obsolescence factor and risk factor is so much higher.
Yes. If you subscribe to what I said that the harder problem in AI to be useful in the enterprise is a data problem and a people problem. I don't know if a third-party start-up in the enterprise software space can in 12 to 24 months, come up with such an amazing product that I feel that I must have it because they will need to build the product with access to my data. And by the way, anyone's data, not just mine, right? So if you want to build a better Salesforce or better Workday or better, whatever have you, you need access to data, you need to be able to come in and plug it in and understand all the use cases.
So I think the anxiety is misplaced that all this stuff is going to go away very soon. I think it's going to stick around for a long time. We have to build real value as a start-up ecosystem to be able to actually be useful. A lot of the start-ups you see in the AI space are solving a very small point problem. The risk is you just perpetrate the same fragmentation you had in the industry, which we're trying to get out of back again because you have this paranoia, this AI is going to fix it for me. There are some cases like data security where you might have some techniques which are never available before, but that's more innovative as opposed to just an AI rewrap or rewrite of -- yes. I think the opportunities will still have to be in systems that manage, process, understand large amounts of data from an AI perspective, less so people who are doing workflow sitting on top of my data.
I know investors like to -- and certainly, I do as well, like to think about transformations with some historical precedent and analogs, right? So as you think about the evolution within the AI security space, both security for AI and AI for security, so with both those lenses. How much of what we saw in the cloud realm and cloud security realm where there was so much alphabet soup of CSPM, CWPP, CIEM, how much of that are you seeing repeated in kind of this gold rush for AI security? And you kind of said it yourself, right? We're going down the path of sprawl before we consolidate it. Again, how much -- how valid of an analog do you think that is?
I think a lot of the things that we built for the cloud world will be applicable in the AI world. So you'll have to expand your product. But you still need, let's say, a new product called AI-SPM, AI security posture management. You need to understand your AI artifacts, your models, your databases, et cetera. So you need some of that. We'll need an AI firewall, which is an extension of a cloud firewall. So you can call it a cloud firewall with AI capabilities, you can go on the AI firewall. Depending if you're a start-up, you'll probably call it the AI firewall. If you're an incumbent, you call the cloud plus AI firewall, right?
So yes, I think that's where all the action is. I don't think the -- there is going to be agentic AI security, which is a whole different conversation. We can take 45 minutes. I don't -- I'm not there yet on agentic AI. I think there will be nonhuman identities which will need to be managed. That's more of an identity problem, and we'll talk about that in the context of CyberArk than an agentic security problem. And I'll do a segue here because I did that with a smaller group.
Look, I'm pretty sure everybody in this room is convinced that with tens of billions of dollars being spent every month in AI, something is going to come out of this thing. You can all see the impact on the consumer space. And yesterday morning, we launched an ad campaign. The entire ad campaign was built using AI. We built one last year with Keanu Reeves over 6 months. We built this in 30 days. Last time it was Keanu Reeves because we need a live person. This time, it's Benjamin Franklin, Marie Curie, Alexander Graham Bell. In order to [ consents ] about these people, they are no longer alive. We brought them all back to life using AI. They were kind of free. We didn't have to pay them $5 million, like we had to Keanu. And they did not want artistic control about what they said, interesting enough, which we had to do with Keanu. So we got it done in 30 days instead of 5 months, it cost us less than $100,000. The last one cost us millions of dollars, and we didn't have to build a set and shoot in L.A. for 30 days and nor did we have to go to the actors guild and get involved with them.
This ad campaign -- so this stuff is going to happen. There will be tons of use cases in the consumer space, the enterprise space they're going to build. So we believe that. If you believe all the hype around agentic AI, and you can imagine that Dario from Anthropic is building an Agentic browser, Google is going to turn Chrome into one, Perplexity is building one. There's going to be a few more. I think Atlassian just bought a browser company this morning. We bought one 1 year ago, 1.5 years ago now.
So if you can imagine a scenario that your Agentic browser is going to book your next airline ticket and get your restaurant reservation and get DoorDash delivered to your house and your grocery is done and pick your favorite activity, that Agentic browser can only do that with your credentials in your browser. It'll have to borrow your credentials to go do it, log into Uber Eats log into OpenTable, log into DoorDash. One constituency that hates that idea is CIOs. They don't want your credentials being used by any automated piece of software within the browser. So this is a tough prediction, and we'll see if I have egg in my face. But I think Agentic browsers become real, they will be banned in enterprises.
Well, speaking of credentials, we got to talk about CyberArk.
We'd get there in a second, but I'm telling you -- let me finish the last sentence on that one. If Agentic consumer browsers get banned in enterprises, a whole series of secure enterprise browsers will be needed. We bought one 18 months ago, with 1 of 2 players in the market. Now we can talk about CyberArk.
We'll come back to that. So it's actually refreshing to hear you're less hyperbolic about Agentic AI. But in the context...
But it's a great talking point. It gets into a lot of meetings.
It gets everyone all excited. There's so much sizzle, right? But let's get down to brass tacks. You announced your intention to acquire CyberArk this summer. By all accounts, it is your single largest, most transformational transaction in your 7 and change years at the company. Now look, I can fully appreciate that you've bucked conventional wisdom time and time again. But I think there is a lot of sort of trepidation on a number of different facets as to what this means for you? What bets are you making that CyberArk is better under the Palo Alto umbrella than independent. So just sort of help us understand what the bulls are maybe not bullish enough on and what the bears are totally getting wrong with $25 billion check to CyberArk.
Bulls and bears, people in your industry who don't like it and people who like it. Got it.
There's more bears than bulls.
Okay. Well, good for them. That makes it an opportunity for the bulls. That's why you make money. If everybody saw the same thing, we have a problem, right? It's good. It's good for the market. Anyway, look, 7 years ago, when we were probably sitting on a stage similar, there were more bears than -- there were no bulls when I took the job. And at that point in time, we decided we want to be a multi- swim lane cybersecurity company. The last 7 years, we have anticipated and built 4 swim lanes. And in 3 of those swim lanes, we have built $1 billion ARR businesses in under 7 years. Not a bad thing, a bad stick if you can get it.
And we have stayed away from identity for the entire period of time because we've said every time we want to enter a market and be big in it if there's an inflection point. And we didn't see an inflection in identity until about 8 or 9 months ago. We've been analyzing the market and understanding it. We believe with the conversation around agents and the fact that agents will start taking over credentials and start doing things is going to create a relook at the credential and identity infrastructure in the company, one.
Two, 89% of breaches still happen because of credential theft. Somebody's credentials get stolen and used to extract or exfiltrate data. Three, the way the identity industry has operated is in this world of what is called identity access management, IAM, think Okta or PAM, privileged access management which is in CyberArk. The fundamental difference is if you work in a company, which I think all of you do, many of you can get a badge. If it's only your first day of work, the badge allows you to enter the building. Once you're in the building, you can pretty much go everywhere, except perhaps a few rooms which have another badge against them, but everywhere else, you can go. That's called identity access management in the digital world.
You can log in, then you can do whatever you want in your enterprise systems. Nobody tracks you, nobody keeps -- follows you, nobody has a video of what you're doing. You just do what you want. It's called IAM. That's what single sign-on IAM is called. In an IT administrator, everything you do is logged and kept track of because you have access to the crown jewels. So you probably go into your server room. There's probably a camera in your server room in your company, but you probably know the CEO's office has a camera to make sure nobody goes in there. But everything else, you can go everywhere. We think that model is broken that needs to be changed. We think every identity needs to be tracked and followed and logged in the digital sense, which means we think everybody needs to become a privileged access user, not an IAM user.
Let's assume why did they start that way? They started that way because the cost of deploying these 2 models was 1 to 10. It took 10x more to deploy privileged access management and 1/10 the cost to go deploy identity access management. So you can buy an IAM seat for $8 to $10, you have to pay $100 to buy a privileged access seat. Interestingly, you have 2 different players in this space. It takes CyberArk anywhere from 6 to 9 months to deploy a customer. They have to build special connectors to every room, every server, every data room to make sure that you have the privileged access available. So they've already done the hard work. The question is, can we get them to be able to do all the work required to be an identity access user in addition to being a privileged. We think we can.
So we think CyberArk allows us to have a product that satisfies the user -- employee identity use case, not a type of user use case, which is the fragmentation comes in. I walk in, you follow everything I do. If I go to a privileged area, you have more controls in privilege, otherwise, still keep track of me as an employee. The breaches happen because there's a guy in finance who has access to your SAP system, who's not a privileged user, but he can take your earnings and release them 2 weeks before. Is that a breach? It's a breach. But in the traditional sense, not a privileged user. So we think every user should be followed. We think in the next 24 months, that is what's going to happen in the market. It will happen to every agent, every nonhuman identity for which we need an identity play.
Then the question is, why don't you buy a startup and do it like you did the last 24 times, why buy an incumbent? Because the value or the disruption in trying to replace the company's entire identity infrastructure is too high. CIOs will not replace their identity architecture infrastructure because they don't know what's going to break. And if you break identity, you shut down the company, right? If you broke the identity system and a trading system, identity got dislodged and your trading systems go down in your company, the CIO and CISO don't have a job. It's worse than a breach. So nobody wants touch the identity infrastructure. So you have to go in as an identity player in the market who's doing the harder job of identity, not the easier job.
So long story for sure, we bought CyberArk because we think -- and by the way, unequivocally, every customer we've talked to of CyberArk is delighted we bought them. CyberArk is delighted to be part of Palo Alto. So it's a good move from a customer perspective. They have 8,000 users with 8 million endpoints. We have 100 million endpoints we cover. We think we can take their 8 million endpoints and try and expand them into our user base and into their own user base. We think we can build incremental products. We think financially, we can gravitate them to our margins on cash flow and operating margins. So all in all, it's -- I think the industrial logic is very strong. I think time will tell if we got the inflection right. And then you have to trust that in 7.5 years, we have one of the better track records in M&A in cybersecurity and software across the industry, and you have to trust management that will do our job.
I don't know if you can stick...
For those who don't trust, they should sell their shares to the bulls and then they can buy them back and they become a growth stock from the bulls.
That how we make market.
Yes, exactly.
I don't know if you were conspicuous in not mentioning this, but how does CyberArk advance the AI strategic road map and the agentic AI product road map and maybe you can put Lee Klarich's hat on. You don't have a side burn, so I don't know if you could fit the bill, but...
Look, the other part of CyberArk business, they bought a company called Venafi, which is on the nonhuman identity part, the certificate lifestyle management. I think at the end of the day, if you believe everything -- I can't believe everything Mark Bennett or Bill McDermott say, but if you believe the idea that agents are going to get more prevalent in organizations and they will be fungible between humans and agents, then everything becomes an identity of either a nonhuman kind or a human kind.
The question is you still have to understand credential across both those instances and see how the identities mesh and work with each other. So I think the identity needs a platform approach. It needs an approach where every identity is managed from the beginning until the end and needs to understand that it needs to be tracking both human and nonhuman identities. So today, this is fragmented across 4 different products in the industry, 4 different categories. We think they all need to become one, and that's where the opportunity is with the Venafi acquisition, with the Zilla acquisition, identity governance that CyberArk did with their PAM product and the IAM product that they have.
Let's talk about keeping the lights on at Palo Alto. And what I mean by that is all this AI opportunity and the secular tailwinds are great, but you're running a core that is a [ staller ], right? And I think one of the pieces that gets a lot of investors hot and bothered is the firewall franchise, right? There is absolutely cyclicality in that business. I think you've not been shy about expressing that. But in terms of the whole notion of the death of the firewall being greatly exaggerated, where are we on this curve of dissolution after several years of atypical and aberrant trends? And when you think about, again, AI, what does that do to the medium- and long-term trajectory of how all of us should think about the firewall business?
Look I think thinking about the firewall business in piece parts is the wrong thing to do. And I said this before, and I apologize if I'm repeating myself. The amount of digital traffic in the world continues to compound every year. AI is only going to compound it further. To deliver security, all traffic has to be inspected by a security product, whether it's traffic coming from your laptop going to your company, whether it's traffic coming from a nonhuman identity, whether it's traffic coming from hardware, all traffic has to be inspected. It gets either inspected through a hardware firewall, a software firewall or SASE. That's how traffic gets inspected. Even AI traffic will be inspected by any of these 3.
If you believe that the traffic is going to continue to compound even faster with AI and all the data going in the cloud, you have to believe that inspection will continue. There's no other solution. Inspection doesn't go away. Like there will always be security scanners at the airport, unfortunately, if you're traveling. They're not going to go away. We're kind of like the same thing. We cause latency, we make it slow. It's a little irritating, but we're going to be around for a long time. So if you believe that, then the question is, where does the money come? Does it come in hardware? Does it come in software? Does it come in SASE?
From a product development, quality, delivery, margin perspective, my software and SASE business are way better than my hardware business because hardware, I got to go produce it. I got to get chips from some different parts of the world. I got to go do quality control. If it doesn't work, I got to bring it back, I got to send you a new one. It's hard to upgrade software because customers decide when to upgrade the software. In software and SASE, I do the upgrades. You can't touch it. So it's a much more efficient operating model. It's a much more secure model. So the more the business moves from left to the right, the happier I am. In 7 years, we have taken our hardware -- 100% hardware business and 60% of that has been migrated to software. And our hardware business still grows at 5% to 8% on average a year. So I'm happy. I don't know why people are not happy.
I'm pretty happy.
That's good. Because only you and I are happy. These guys are not.
And what I'm happy about is using that as the linchpin to build what is a $5.6 billion next-generation security business. This was, by my count, a $0.25 billion business 7 years ago when you came.
It was 0 when I came.
So virtually 0. We'll round down to 0. So sub-$300 million, closer to 0. You've 20x to this business in the last 7 years, in excess of 30% growth pretty consistently. You've got goals to 2.5x this franchise in the next 5 years, right? And this is, as a reminder, completely on an organic footing. This is...
Not including CyberArk.
Not including CyberArk. These are big numbers. So I want to get a better sense from you on the micro, the bottoms-up factors that are going to help you achieve these objectives of going from roughly 6 to 15 in the next 5 years?
Yes. I think, look, if you go back to 2018, when we first met, we had 0 in this business. If I told you, in 10 years, it will be a $12 billion to $15 billion ARR business, you'd laugh me off the face of the -- whatever, right? So what we've come to realize is that like every enterprise business, you want to sell more to the same customer. The scale of Salesforce is such that they sell more to the same customer. You look at every platform business and software, whether it's Salesforce, Workday, ServiceNow, the idea is to build more functionality, sell it to the customer, add value, create value, and that's what drives your outcomes.
Cybersecurity did not have such a [ player ]. So we -- after 5 to 6 years of product development, being #1 in 24 Magic Quadrants in Gartner, we came to the conclusion that integrating these much better from a technical perspective, giving the outcomes is what the customer needs. So we have them available in their own form factor, but also more effective integrated form factor. We started tracking the integrated customers, integrated sales, we've discovered that, a, these customers pay us a lot more than sliver customers because they have more products from us. They have the best NRR. Our NRR for our platform customers is 120%. We've never had 120% in any of our product categories because we've never been a platform business.
So if I can maintain my NRR in the 15-plus percent range, 115% plus range, take my number of platforms from 1,450, which we announced last quarter, take them to 3,000 or slightly more, we can take this business to that $15 billion range in the next 5 years. And we're very focused on the platform business. It's land one product, expand that into a platform, deploy the platform, show up and ask customers to give you more consolidation.
Platformization was a new vocabulary word. You coined about 1.5 years ago and really shook everybody up a little bit. So you got 18 months of platformization selling underneath your belt. The sales org is better, faster, stronger, more mature in articulating that vision to the customer. But I'm going to pause it to you that does that potentially come as a double-edged sword because what you are championing is a lot of your very large customers continue to incrementally consolidate their product footprint with you, but also their risk footprint with you, right?
So on the one hand, how are you mitigating some of the natural maybe pushback you're getting on, well, I can't have one vendor do so much of my cybersecurity because that's systemic risk issue just from a cyber hygiene perspective? And please feel free to disagree. And then secondarily, from a financial model perspective, these are potentially multiyear, very large deals that you're doing, right, $50 million, $100 million-plus deals. Just from a financial model volatility standpoint, how do you mitigate some of the effects of, hey, you're going to have some renewal cliffs happen every 3 to 5 years where you have these big chunky customers do for $100 million plus renewal?
So many questions. Let me start from the last one because that's the one I remember. We've discovered once you platformized a customer, there is no road back. because you have a software firewalls from Palo Alto, hardware firewalls from Palo Alto, SASE firewalls from Palo Alto. If you ever decide to rip us out, you'd have to replace us with 3 vendors and build the entire control pane between the 3 and make the integration happen. And like I start with a customer, it took them 3 years to replace 500 firewalls, we put them in. You have to decide at your last renewal that you don't intend to renew with me and you just start them. You can't replace a network security platform from Palo Alto in under 3 years if you are fully platformized across the board or you can't replace a SIEM platform in less than 12 to 18 months if you are fully platformized.
So I don't know what a renewal cliff is. I think it's a renewal opportunity to give them more functionality and sell them more as opposed to renewal cliff. So the NRR at 120% is that's the reason it's 120%. We don't see churn. So I don't think there is a renewal risk. You did say there's a, let's call it, the consolidation risk. I was trying to find the best analogy. I guess perhaps the best analogy, which is old is I started my career at Fidelity in the technology team, and we had 23 applications, which made up what is today called CRM. And over time, 3 or 4 vendors emerged between Oracle, Microsoft, Salesforce and others who provided you a single platform did 23 functions that allowed you to consolidate those 23 applications. I'm pretty sure somebody had a conversation, "Oh my God, we're consolidating a risk," but the value of that being together is so high that you say that's the right answer. This was the wrong answer. And that same movie is played out in HR systems, same movie is played out in financial systems.
Cybersecurity is the youngest industry in technology. We only came about when connectivity came about. Until your iPhones were connected to the Internet, there was no need for cybersecurity. It was all data center-driven, all terminal-driven in the office. You walked in IBM gave you a frame, mainframe, but terminals, you need security. Who needed security then? You did client server architectures, you did liberal security and did firewall inspection. Now with the sprawl of the technology infrastructure, you need security every juncture. I think it's just the stage of the industry where it is. I think 10 years from now, you will not be buying sliver products, which are small products based out of startups. I think that consolidation is happening. And I will say, look at our industry, 7 years ago, everybody played in the swim lane. Today, everybody is trying to cross swim lanes. If you take a look at the top 10 cybersecurity companies in the world, they are trying to get a product in the other swim lane, and you can ask -- I'm pretty sure you have everybody.
So I think that's the trend. I don't think that's a risk the customer sees. The customer sees the value of these things being on one control pane and then they are not gonna go back.
Nikesh, my last question for you is 3 years ago, you made a prediction that you're going to be a $100 billion market cap company. That's absolutely come to a fruition. And I think it's worth mentioning, you were a $20 billion market cap company 7 years ago. So I wouldn't be a tiger mom if I didn't ask you, where is the next $100 billion of market cap going to come from? And what things absolutely have to go right to have that outcome?
Look, you guys do the math. I don't think we need to change our financial profile from an operating margin, free cash flow margin perspective. I'm talking just organically for us without the CyberArk piece. I don't think we need to change anything in our operating profile financially to achieve our $15 billion ARR target in 2030. So '25, 5 years from now, we are at $5.6 billion today on the next-generation security, you get to $15 billion.
You guys have better multipliers than I am. You can figure out what that does. If you keep the multiple the same. I don't know what the math is. If you depress our multiple a little bit what the math says, I don't think -- there's no math you can do, which gets you less than $100 billion going from $5.6 billion to $15 billion, just what organically we can do.
Then the question is what can we do with CyberArk? Can we do with CyberArk, what we did to Palo Alto? And of course, they don't have the option to go into multiple swim lanes. They can be the identity platform in the future. Even 5 years from now, we can make CyberArk identity platform of the future as part of Palo Alto and take their $20-plus billion market cap and double or triple it, that's gravy on top of the $100 million.
Well, we'll be watching from the sidelines.
Or $50 billion.
I like it. Make it $300 billion.
No. No. I'm not [ Moss ], I'm not investing in data centers in the United States.
All right. Fantastic. I think that's a great place to put a pin in. Thank you so much for an awesome conversation. Thanks.
Thanks, Fatima. Nice to see. Thank you everyone.
Financial data from Palo Alto Networks
Revenue
Revenue is the sum of all sales generated by a company, e.g. for its products or services.
Revenue (TTM) metric explainedDirect Costs
Direct costs are the costs incurred directly in connection with the manufacture of the product or service.
Gross Profit
Gross Profit indicates how much of the revenue remains in the company after deducting direct production costs. If the percentage share of sales is calculated, this is referred to as the gross margin.
Gross Profit metric explainedSelling and Administrative Expenses
Selling, general and administrative expenses (SG&A) include all expenses for marketing and sales as well as the general administration of the company.
Research and Development Expense
Research and development costs (R&D) provide information on how much the company invests in the research and development of its products. The costs are particularly interesting as a percentage of revenue and in comparison to direct competitors.
EBITDA
EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) is the company's earnings before interest, taxes, depreciation and amortization. The EBITDA margin is calculated as a percentage of sales.
Depreciation and Amortization
Depreciation represents reductions in the value of the company's assets (e.g. due to wear and tear on machinery).
EBIT (Operating Income)
EBIT (Earnings Before Interest and Taxes) is the company's profit before interest and taxes, also known as the operating income. The EBIT Margin is calculated as a percentage of sales at
.
Net Profit
Net Profit represents the profit or loss after deduction of all costs.
Net Profit metric explainedStocksGuide Free
| Jul '26 |
+/-
%
|
||
| Revenue | 11,480 11,480 |
24%
24%
100%
|
|
| - Direct Costs | 3,401 3,401 |
39%
39%
30%
|
|
| Gross Profit | 8,079 8,079 |
19%
19%
70%
|
|
| - Selling and Administrative Expenses | 4,855 4,855 |
33%
33%
42%
|
|
| - Research and Development Expense | 2,551 2,551 |
29%
29%
22%
|
|
| EBITDA | 1,550 1,550 |
2%
2%
14%
|
|
| - Depreciation and Amortization | 855 855 |
149%
149%
7%
|
|
| EBIT (Operating Income) EBIT | 695 695 |
44%
44%
6%
|
|
| Net Profit | 307 307 |
73%
73%
3%
|
|
In millions USD.
Don't miss a Thing! We will send you all news about Palo Alto Networks directly to your mailbox free of charge.
If you wish, we will send you an e-mail every morning with news on stocks of your portfolios.
Palo Alto Networks Stock News
Company Profile
Palo Alto Networks, Inc. engages in the provision of network security solutions to enterprises, service providers, and government entities. It operates through the following geographical segments: Americas; Europe, the Middle East, and Africa; and Asia Pacific and Japan. The company was founded by Nir Zuk, Rajiv Batra and Yu Ming Mao in March 01, 2005 and is headquartered in Santa Clara, CA.
StocksGuide Free
| Head office | United States |
| CEO | Mr. Arora |
| Employees | 17,027 |
| Founded | 2005 |
| Website | www.paloaltonetworks.com |


