Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary

September 4, 2025

NASDAQ US Information Technology Software conference_presentation 48 min

What were the key takeaways from Palo Alto Networks, Inc.'s September 4, 2025 earnings call?

In the earnings call held on September 4, 2025, Palo Alto Networks, Inc. (PANW) reported a revenue of $10.5 billion for the fiscal year, marking a 15% increase year-over-year. The company also achieved an earnings per share (EPS) of $4.25, exceeding analyst expectations by $0.30. Management maintained its guidance for the next fiscal year, projecting revenue growth to reach $12 billion, driven by increased demand for cybersecurity solutions amid rising AI integration. The stock may react positively to these results, particularly given the raised expectations for future growth.

What topics did Palo Alto Networks, Inc. cover?

  • AI Integration and Cybersecurity Demand: Nikesh Arora highlighted the ongoing 'frantic AI spending frenzy' and its implications for cybersecurity, stating, 'As long as we can call it cybersecurity AI, it's fine with us too.' This signals a strong alignment of Palo Alto's offerings with the growing AI trend, which is expected to drive future demand.
  • Acquisition of CyberArk: The acquisition of CyberArk was described as a transformative move, with Arora stating, 'We believe CyberArk allows us to have a product that satisfies the user identity use case.' This acquisition is expected to enhance Palo Alto's identity management capabilities significantly.
  • Revenue Growth Projections: Management projected revenue growth to $12 billion for the next fiscal year, with Arora asserting, 'We can take this business to that $15 billion range in the next 5 years.' This ambitious target reflects confidence in the company's growth trajectory.
  • Platformization Strategy: Palo Alto's strategy to increase platform customers was emphasized, with Arora noting, 'Our NRR for our platform customers is 120%.' This suggests a strong retention and expansion potential within existing accounts.
  • Challenges in AI Security Market: Arora acknowledged the slow maturation of AI security, stating, 'There is a lack of maturation and frankly, critical mass of productionized AI environments.' This indicates potential headwinds in fully capitalizing on AI security opportunities in the near term.

What were Palo Alto Networks, Inc.'s September 4, 2025 results?

  • Revenue: $10.5B (vs $9.1B est, +15% YoY)
  • EPS: $4.25 (beat by $0.30)
  • Next Fiscal Year Revenue Guidance: $12B (maintained guidance)
  • Net Revenue Retention (NRR): 120% (for platform customers)
  • CyberArk Acquisition Value: $25B (transformational acquisition)
  • Next Generation Security Business Target: $15B (target for 2030)

Palo Alto Networks is positioned for strong growth, particularly with its strategic focus on AI integration and the recent acquisition of CyberArk. Investors should monitor the execution of its platformization strategy and the evolving landscape of AI security, as these will be critical to sustaining momentum and addressing analyst concerns.

Earnings Call Speaker Segments

Fatima Boolani

analyst
#1

All right. Ladies and gentlemen, I think we're ready to get going for our halftime show here, day 2 of Citi's.

Nikesh Arora

executive
#2

Give her some -- pay attention to Fatima.

Fatima Boolani

analyst
#3

I should use my outdoor voice, right, not my indoor voice. There we go.

Nikesh Arora

executive
#4

I'm your mom voice.

Fatima Boolani

analyst
#5

My mom voice, there you go, my disciplinary invoice. I have a 4-month old at home. So I have a lot of practice and a 2-year old. Good afternoon, everybody. Thank you so much for being here at day 2 of Citi's Global TMT Conference. I am excited for our halftime show today with our starting keynote with the CEO of Palo Alto Networks, Nikesh Arora, thank you so much for being here.

Nikesh Arora

executive
#6

Thank you for having me, Fatima.

Fatima Boolani

analyst
#7

Well, we have lots to talk about, so I will dispense with the formalities. For those of you who don't know me, I'm Fatima Boolani. I jointly head up our software research franchise, and I'm very excited to delve into all matters of cyber and beyond.

Nikesh Arora

executive
#8

Let's go.

Fatima Boolani

analyst
#9

Excellent. All right. I think a good place to start would be at the stratospheric level, very big picture, a state of the union, if you will, of the industry at large. Nikesh, I'm hoping you can opine on the budgetary climate, the budgetary competition. And actually, most importantly, talent acquisition, both from a sales and a technology perspective. And you know where I'm going with this because of the underpinnings of the AI wave, which we'll, of course, talk about. But I think that's a great place to start from the perspective.

Nikesh Arora

executive
#10

All right. Well, good afternoon, everybody. I hope you're enjoying your meal. Look, every time we get worried about cyber spending, a new thing happens in technology and suddenly, we all get very excited. I think 24 months ago, we were not excited about tech spending and then this AI wave came about, and we can -- all of you are excited when you see another tech company planning to spend tens of billions of dollars to build AI clusters. So I think from a spending perspective, the environment continues to be the same. I do think that AI spending has a bit of a free pass right now that every CEO wants their companies to experiment on AI, figure out how AI is going to impact their lives. And as long as we can call it cybersecurity AI, it's fine with us, too. But no, in all fairness, I think the AI wave is creating a bit of frantic behavior that everybody is trying to figure out. So I don't think, generally, broadly speaking, the hammer is coming down on IT budgets, let alone cybersecurity budgets. And cybersecurity budgets kind of like more often than not, end up being part operating, part transformation. The operating budgets are impact -- are intact. I think it's fair to say that you'll always find a CIO and a procurement team, which wants to not have cybersecurity ongoing budgets go up. They like them flat. They like them growing a little bit, not a lot. And there's obviously net new budget for new ideas. And in that environment, because we are positioned ourselves as a consolidation play, we're fine with flat budgets because we expect to take share from other people and maintain our growth. So that's kind of where we feel from a spending environment perspective.

Fatima Boolani

analyst
#11

As a $10 billion player in the cybersecurity market, you were the largest...

Nikesh Arora

executive
#12

$120 billion more than $10 billion, or use that.

Fatima Boolani

analyst
#13

The $120 billion in ballpark and cap asset with $10 billion in revenue, largest pure-play cybersecurity vendor in the market in the space, you naturally have a seat at every single large important organization in the world across verticals. So as -- probably not a fly on the wall, but with a lot of talking points sitting at these tables with these very large companies, what have you determined are and have been becoming the most common patterns and pain points and discussion threads on how some of your largest customers are tackling cyber hygiene against and in preparation for operationalizing an AI strategy. And I want to go back to something you said, there is a frantic AI spending frenzy right now. Everyone is throwing spaghetti on the wall as to how AI is going to improve their business and work for their business. So your seat at that table, what implications does that have from a cyber hygiene perspective?

Nikesh Arora

executive
#14

All right. So I think let me break that down into 2 parts. Let's first talk about where we see AI and what I see -- how I see the AI landscape evolving because that actually dictates how we prepare for that environment from a cybersecurity perspective. I think if you look at the global AI reality or traffic, 80% to 85% of the traffic is in consumer right now, right? People are building the next version of ChatGPT, the next version of Gemini, Grok, Llama, Deep research, all these things. And the way they manifest themselves is consumers getting excited. The reason OpenAI raises it $0.5 trillion or Anthropic raised $180 billion is because there's a lot of people using these models to ask questions, whether they're search type questions, their videos they're making, asking questions on Grock, they're asking questions on Meta AI. That's where 85% of the traffic is. That's where the training is happening and that's where "the arms race" is on AI models. And that's fine. We understand that. You can see the direct application. There's large distribution, billions of users who use some version of Meta's products or Google's products. They're all becoming natural users. My Gmail is summarizing things for me now. It's like in product. I mean last -- this past quarter, we have a secure version of Gemini deployed at Palo Alto. I ran my earnings scripts with Gemini and asked it, how many times am I repeating certain, it told me stop using the word momentum so many times. So it does stuff like that. It's kind of useful.

Fatima Boolani

analyst
#15

Pick test 7, the source there .

Nikesh Arora

executive
#16

So it does a bunch of stuff like that, and that's -- you're seeing the consumer use case, that's where 80%, 85% of traffic is. That's why more GPUs will be sold and more models will be trained. So we get that. I think the second category, which is slowly emerging is let's call it the AI application category. This is where you see the cursor of the world, people doing wipe coding, you see Harvey, the legal sort of application stuff, Grammarlys of the world. There's about 1,200 applications which are using some version of a wrapper around the AI models to make some tasks, some workflow better, right? You're seeing that. And they're also kind of like the best way to sort of create an analogy is it's like the drop boxes or the box of the world where they are generic for every enterprise. They're not specific to any one enterprise. There's a lot less customizability, but they're generic enough that they apply to a standard use case for enterprise. So you're seeing some traction there. I want to say that's 5% to 7% of the volume right now, including coding in the market. And the remaining 4%, 5% is enterprises experimenting with AI to see how can I make my application useful to my customer, which I think still ways off. In that context, security only applies to the third category. If you're going to deploy your LLM in your company, you want to secure it, you want to make sure there's a firewall around it. It applies to the enterprise deployment of the Gleans of the world or the Harveys of the world, which they are slowly getting their arms around, but it's slow. It's like there are not many customers asking for a secure enterprise. That's how kind of cybersecurity plays into it. But I think the anxiety is more around AI deployment and cybersecurity. People all hear about agents saying, "Oh my God, if I have agents running around in my enterprise, who's going to manage them, who's going to control them? How are we going to give them credentials? How are we going to track them because these are nonhuman identities floating on my enterprise." So people want to hear the story. People hear the story of how am I going to protect my AI deployment with an AI firewall. So the conversations as it relates to AI are mostly about securing models, securing my deployment, securing my employees from not sending my corporate data outside and making sure agents don't take over my enterprise without some version of a guardrail or a kill switch, right? If I go to the regular discussion around cybersecurity, I think there is a growing understanding that some version of interworking consolidation commonality needs to start coming into play because the infrastructure is too disparate, too fragmented. And it's kind of interesting. It's not coming from an economic consolidation perspective. It's coming from holy****. I'm going to have to respond faster to cybersecurity events and with a fragmented architecture of 30 or 40 vendors, I can't do that fast enough, and I know these AI agents will be used against me who are going to come chase me down and try and attack it. And then a week doesn't go by where somebody doesn't get breached. In fact, as you might have seen in the last week, even some of our Salesforce data got compromised and so did that of 699 other companies. So 700 companies got breached in some way, shape or form because of an API or an agent of a third-party app that had too much access to our data and that's going to happen more and more.

Fatima Boolani

analyst
#17

Nikesh, what I'm hearing from you is -- and by the way, I think this is one of the most fervent debates in the investor community right now, specifically with the software investor community on who gets paid on AI. I mean, certainly, there is a case to be made on the application software side where maybe there's not that much inspiration on that side right now. But certainly, a ton of debate that's formenting on who is actually going to get paid on AI. And what I'm hearing from you is that there is a lack of maturation and frankly, critical mass of productionized AI environments for you to step in to wrap guardrails around that, right? So with that precursor and that preamble in mind, you said something interesting, and I think I'm going to pull on that thread, you always say interesting things. So -- is there necessarily a prerequisite of an IT infrastructure and IT architectural evolution for you to then step in to provide the safeguards from an AI perspective, kind of like how we saw in COVID where the SASE transformations begot network transformations, which happened because of COVID, which created this impetus because all of us ended up working from home, right? So a long-winded way to ask you, is there a chicken and egg situation where we have to wait for the underlying infrastructure at most large organizations to evolve and modernize before AI security can be a juggernaut on its own?

Nikesh Arora

executive
#18

You said a lot of things. Let me break it into 2 or 3 parts. One part is I think a lot of us have the impact of AI on software wrong, right? And we can talk about that if you want to or we can talk about security. There's going to be a whole revolution need over there, and it's not simple copilots that sit next to your products. I think products will fundamentally need to be reinvented. And what I mean by that is most software for enterprises designed in the end result in a series of dashboards, which then humans are supposed to look at and say, what's my problem? How do I solve the problem? What do I do with it? If you have the data structured right and you're able to create the dashboard, you should be able to now with some version of AI, figure out the anomalies, the next step is you should be able to fix it. So I think you'll see a lot more software get reengineered where it will be more do this task for me, either at the prompt of a user or by itself, and that requires a full transformation of the software stack in a way to make it AI ready and make it work. So picking our book, we're working hard in every one of our products to see how can we turn from a dashboard and discovery product into a fix it product, so our customers actually get the benefit of the outcomes we can create as opposed to the analytics only. So I think that's going to happen across every space. And it's going to happen to most SaaS software that we use, and that needs to happen. It's not going to be copilot in the long term. So let's put that aside. I think your question around when does the AI security wave hit, I think there is already an awareness and realization that if I don't get my infrastructure modernized, I will not be ready for AI-based attacks. So I don't need -- we don't need AI to productionize for people to start feeling the pain that "Oh my God, if I don't get my s*** together, now they are beginning to understand everything in IT is a data problem. Even security is a data problem. How do I transform myself? How do I get myself into a happy data space and solve the security cloud." In terms of AI security itself becoming a thing, the day you tell me that look at this cool AI app Home Depot has and look at this cool AI app JPMorgan has and look at this cool AI app Goldman Sachs have, trust me, they're going to have buy a lot of security.

Fatima Boolani

analyst
#19

Look at this cool AI app Citigroup has.

Nikesh Arora

executive
#20

That's right. Right. right. Yes, that one, too.

Fatima Boolani

analyst
#21

I think you've had very strong and prescient views on the impact of AI. That's very apparent. You've also made very bold and early bets with prompt AI, which was a deal you did earlier this summer.

Nikesh Arora

executive
#22

Protect. That's a different company, they have prompt, but same difference. It's like Citi, Goldman, Palo Alto, Cisco.

Fatima Boolani

analyst
#23

There you go. Tomato tomato. What does Palo Alto's portfolio look like from an AI security perspective? And is the ultimate vision to own the entire AI value/supply chain from a protection standpoint?

Nikesh Arora

executive
#24

So there are 2 schools of thought. One school of thought says that everything will have to transform with AI. So it's going to be sort of -- it going to be across the entire enterprise. It won't be a separate thing, in which case, your SaaS app will have AI in it, your E-mail will have AI in it. So you can't take it out and say, AI, you sit over here, everybody else is here. Everything that you do in an enterprise will have AI. Today, if my Gmail is summarizing using Gemini, I need to make sure that Gemini is secure when it runs in Gmail. I don't have to wait for say, Gemini you sit here. So I think there's going to be AI features built into every product that we have that will check if AI is not doing something different. So that's going to happen. Everybody has to enhance our products to take advantage of the AI use case. For example, we have a firewall that works on the data center, it works at the edge. Now our software firewalls has AI traffic inspection capability. It's not a new product. It's sitting in the product in the software firewall called AI firewall. Or if I write code using Cursor versus humans, do I have different product that checks the code that Cursor writes? Or do I have the same product that checks the code humans write and apply that product towards Cursor, more likely the latter than the form, right? So every product that we do will have to make sure that it anticipates and inspects for the AI use case. In addition to that, the net new part will be every enterprise is going to build an AI stack. I'm going to have my LLM, I'm going to have my vector DB. I'm going to have some sort of prompt engineering or inference engine. And at last count, we discovered to our amusement and...

Fatima Boolani

analyst
#25

Dismay.

Nikesh Arora

executive
#26

Dismay that within Palo Alto, we have 37 models being used. We didn't know that until we build an AI discovery product saying, go discover the models we have, holy****. 37 is a lot. If you'd ask me, I'd say 2, maybe 3. And I think that story will play itself out in every enterprise that enterprises don't know, a developer can go to Hugging Face and download an LLM and deploy it on their laptop and be doing an experiment and use your corporate data in that LLM. And you have no idea if the LLM was made in unfriendly countries, which is -- has a back door to the country with your data in it. So if I'm a chip designer, I say, you know what, my boss said, don't use a public LLM, but I can always go look at an open source LLM from Hugging Face, download in my laptop, run my chip design against it. You just don't know that it has an open connection here in the back. You just cut copy paste your chip design and do some database in some other country that you wanted to go to. So at some point in time, when you start building your AI stack, you will have to ring-fence it with security. You have to make sure that has guardrails. And that's where I feel the AI security opportunity is in addition to transforming everything you do and ensuring that you're inspecting the AI use case.

Fatima Boolani

analyst
#27

Now imagine the very incipient and embryonic stage we are at with every single day, we have these mammoth innovations coming out of the foundational model companies and you alluded to Anthropic and they're around. So clearly a lot of value creation happening there. But how does that...

Nikesh Arora

executive
#28

A lot of spending happening.

Fatima Boolani

analyst
#29

And spending up happening. How does -- as an allocator of research and development capital around AI, AI security and all of sort of the niches that you talked about, how does that complicate or empower your R&D strategy where you might be chasing innovation that might prove to be a flash in the pan in 6 months or becomes commoditized very, very quickly because we're having these very shallow cycles, right? So how are you thinking about that? And ultimately, from a dollars and cents perspective, driving yield and leverage from your R&D investments because you're obviously trying to skate to where the puck is going with respect to AI.

Nikesh Arora

executive
#30

Yes. It's a good question. So let's break it down. The good news is we're not in the model business. And the best news is the people building the models are putting the tens of billions of dollars required to train them and letting us pay by the drink, which is great, which means somebody else has the capital-intensive model, we have the subscription model. So if I don't use it, I don't end up spending a lot of money. But a good thing. We like that because that allows us to experiment and not have to go deploy $1 billion to build a stack that allows us to train our LLM. So let's leave it there. That's one part. I think there are 2 big transformations every enterprise will have to make. One is data, the other is talent. On the data front, most companies are not collecting AI-friendly data. And let me explain what I mean by AI-friendly data. If you take the example of a self-driving car, GM was not collecting mapping data on every street that GM drove. Like a GM car drove, they were not taking pictures of everything around the street and saying, what is a tree, what is the plant? Where is the plant? Where is the tree? They had something like [ scale.ai ] that was labeling $10 billion worth of data for every car company for 5 or 7 years before they actually got an AI-friendly data environment to be able to build self-driving cars because you had to know the true case and the false case from a data perspective. You need the same thing in every AI application you build. If you want to use customer support, you need to know what a good solution looks like versus the wrong solution. You need to collect the data in such a way. So one every company will have to go through some version of a data transformation or data collection strategy. That is nonregrettable. You can invest money in that, and you will get a return when you get the data right. You can do it now, you can do it tomorrow, you can do it in 6 months. My data is no used to [ Jay Chaudhry ]. His data is no used to me. He's got his own products. I got my own. I have to do my own data collection, my own true case and wrong case. So that is a nonregrettable problem. We can solve the problem. Two, 75% of our employees are not AI ready. They think traditional first, right? And I'll compare and contrast. So you're writing a software application today working at Palo Alto, Salesforce, Workday, you write it a certain way. If you're working at Cursor, you write a different way. Cursor doesn't have traditional UI. It has a UI, which is an AI UI. It's a prompt, you ask if you talk to it. And the good case, the bad case all built into that interaction. In our case, we get a dashboard. And sometimes the dashboard will say, here's the conclusion, because you solve with some, I don't know. So there are AI-ready talent that are out there, which we need to make sure that everybody in our company is AI ready, which is, I think, the hardest problem. Getting 4,000, 5,000 people who are in decision-making situations to start understanding the new technology and start getting them ready is a big challenge. Outside of that, I think the third place is you got to watch out is don't start building internal AI productivity apps. There will be third-party apps like SaaS was, let them do it for you when they're ready, use them. So we don't want to spend money in building applications. We think the market is going to build. We are focused on the data transformation, the product development, mental transformation and the people transformation.

Fatima Boolani

analyst
#31

And what about the M&A process? Because you haven't been shy about being acquisitive in, again, very bleeding-edge areas? I mean you were...

Nikesh Arora

executive
#32

Like CyberArk?

Fatima Boolani

analyst
#33

We'll get to that. Don't worry. You've definitely taken a very strong stance on acquiring bleeding-edge assets to drive velocity around category creation and category absorption, right? So how does, again, the rate and pace of innovation in the broader AI industrial complex influence the way you think about M&A from here? Again, to emphasize the fact that the obsolescence factor and risk factor is so much higher.

Nikesh Arora

executive
#34

Yes. If you subscribe to what I said that the harder problem in AI to be useful in the enterprise is a data problem and a people problem. I don't know if a third-party start-up in the enterprise software space can in 12 to 24 months, come up with such an amazing product that I feel that I must have it because they will need to build the product with access to my data. And by the way, anyone's data, not just mine, right? So if you want to build a better Salesforce or better Workday or better, whatever have you, you need access to data, you need to be able to come in and plug it in and understand all the use cases. So I think the anxiety is misplaced that all this stuff is going to go away very soon. I think it's going to stick around for a long time. We have to build real value as a start-up ecosystem to be able to actually be useful. A lot of the start-ups you see in the AI space are solving a very small point problem. The risk is you just perpetrate the same fragmentation you had in the industry, which we're trying to get out of back again because you have this paranoia, this AI is going to fix it for me. There are some cases like data security where you might have some techniques which are never available before, but that's more innovative as opposed to just an AI rewrap or rewrite of -- yes. I think the opportunities will still have to be in systems that manage, process, understand large amounts of data from an AI perspective, less so people who are doing workflow sitting on top of my data.

Fatima Boolani

analyst
#35

I know investors like to -- and certainly, I do as well, like to think about transformations with some historical precedent and analogs, right? So as you think about the evolution within the AI security space, both security for AI and AI for security, so with both those lenses. How much of what we saw in the cloud realm and cloud security realm where there was so much alphabet soup of CSPM, CWPP, CIEM, how much of that are you seeing repeated in kind of this gold rush for AI security? And you kind of said it yourself, right? We're going down the path of sprawl before we consolidate it. Again, how much -- how valid of an analog do you think that is?

Nikesh Arora

executive
#36

I think a lot of the things that we built for the cloud world will be applicable in the AI world. So you'll have to expand your product. But you still need, let's say, a new product called AI-SPM, AI security posture management. You need to understand your AI artifacts, your models, your databases, et cetera. So you need some of that. We'll need an AI firewall, which is an extension of a cloud firewall. So you can call it a cloud firewall with AI capabilities, you can go on the AI firewall. Depending if you're a start-up, you'll probably call it the AI firewall. If you're an incumbent, you call the cloud plus AI firewall, right? So yes, I think that's where all the action is. I don't think the -- there is going to be agentic AI security, which is a whole different conversation. We can take 45 minutes. I don't -- I'm not there yet on agentic AI. I think there will be nonhuman identities which will need to be managed. That's more of an identity problem, and we'll talk about that in the context of CyberArk than an agentic security problem. And I'll do a segue here because I did that with a smaller group. Look, I'm pretty sure everybody in this room is convinced that with tens of billions of dollars being spent every month in AI, something is going to come out of this thing. You can all see the impact on the consumer space. And yesterday morning, we launched an ad campaign. The entire ad campaign was built using AI. We built one last year with Keanu Reeves over 6 months. We built this in 30 days. Last time it was Keanu Reeves because we need a live person. This time, it's Benjamin Franklin, Marie Curie, Alexander Graham Bell. In order to [ consents ] about these people, they are no longer alive. We brought them all back to life using AI. They were kind of free. We didn't have to pay them $5 million, like we had to Keanu. And they did not want artistic control about what they said, interesting enough, which we had to do with Keanu. So we got it done in 30 days instead of 5 months, it cost us less than $100,000. The last one cost us millions of dollars, and we didn't have to build a set and shoot in L.A. for 30 days and nor did we have to go to the actors guild and get involved with them. This ad campaign -- so this stuff is going to happen. There will be tons of use cases in the consumer space, the enterprise space they're going to build. So we believe that. If you believe all the hype around agentic AI, and you can imagine that Dario from Anthropic is building an Agentic browser, Google is going to turn Chrome into one, Perplexity is building one. There's going to be a few more. I think Atlassian just bought a browser company this morning. We bought one 1 year ago, 1.5 years ago now. So if you can imagine a scenario that your Agentic browser is going to book your next airline ticket and get your restaurant reservation and get DoorDash delivered to your house and your grocery is done and pick your favorite activity, that Agentic browser can only do that with your credentials in your browser. It'll have to borrow your credentials to go do it, log into Uber Eats log into OpenTable, log into DoorDash. One constituency that hates that idea is CIOs. They don't want your credentials being used by any automated piece of software within the browser. So this is a tough prediction, and we'll see if I have egg in my face. But I think Agentic browsers become real, they will be banned in enterprises.

Fatima Boolani

analyst
#37

Well, speaking of credentials, we got to talk about CyberArk.

Nikesh Arora

executive
#38

We'd get there in a second, but I'm telling you -- let me finish the last sentence on that one. If Agentic consumer browsers get banned in enterprises, a whole series of secure enterprise browsers will be needed. We bought one 18 months ago, with 1 of 2 players in the market. Now we can talk about CyberArk.

Fatima Boolani

analyst
#39

We'll come back to that. So it's actually refreshing to hear you're less hyperbolic about Agentic AI. But in the context...

Nikesh Arora

executive
#40

But it's a great talking point. It gets into a lot of meetings.

Fatima Boolani

analyst
#41

It gets everyone all excited. There's so much sizzle, right? But let's get down to brass tacks. You announced your intention to acquire CyberArk this summer. By all accounts, it is your single largest, most transformational transaction in your 7 and change years at the company. Now look, I can fully appreciate that you've bucked conventional wisdom time and time again. But I think there is a lot of sort of trepidation on a number of different facets as to what this means for you? What bets are you making that CyberArk is better under the Palo Alto umbrella than independent. So just sort of help us understand what the bulls are maybe not bullish enough on and what the bears are totally getting wrong with $25 billion check to CyberArk.

Nikesh Arora

executive
#42

Bulls and bears, people in your industry who don't like it and people who like it. Got it.

Fatima Boolani

analyst
#43

There's more bears than bulls.

Nikesh Arora

executive
#44

Okay. Well, good for them. That makes it an opportunity for the bulls. That's why you make money. If everybody saw the same thing, we have a problem, right? It's good. It's good for the market. Anyway, look, 7 years ago, when we were probably sitting on a stage similar, there were more bears than -- there were no bulls when I took the job. And at that point in time, we decided we want to be a multi- swim lane cybersecurity company. The last 7 years, we have anticipated and built 4 swim lanes. And in 3 of those swim lanes, we have built $1 billion ARR businesses in under 7 years. Not a bad thing, a bad stick if you can get it. And we have stayed away from identity for the entire period of time because we've said every time we want to enter a market and be big in it if there's an inflection point. And we didn't see an inflection in identity until about 8 or 9 months ago. We've been analyzing the market and understanding it. We believe with the conversation around agents and the fact that agents will start taking over credentials and start doing things is going to create a relook at the credential and identity infrastructure in the company, one. Two, 89% of breaches still happen because of credential theft. Somebody's credentials get stolen and used to extract or exfiltrate data. Three, the way the identity industry has operated is in this world of what is called identity access management, IAM, think Okta or PAM, privileged access management which is in CyberArk. The fundamental difference is if you work in a company, which I think all of you do, many of you can get a badge. If it's only your first day of work, the badge allows you to enter the building. Once you're in the building, you can pretty much go everywhere, except perhaps a few rooms which have another badge against them, but everywhere else, you can go. That's called identity access management in the digital world. You can log in, then you can do whatever you want in your enterprise systems. Nobody tracks you, nobody keeps -- follows you, nobody has a video of what you're doing. You just do what you want. It's called IAM. That's what single sign-on IAM is called. In an IT administrator, everything you do is logged and kept track of because you have access to the crown jewels. So you probably go into your server room. There's probably a camera in your server room in your company, but you probably know the CEO's office has a camera to make sure nobody goes in there. But everything else, you can go everywhere. We think that model is broken that needs to be changed. We think every identity needs to be tracked and followed and logged in the digital sense, which means we think everybody needs to become a privileged access user, not an IAM user. Let's assume why did they start that way? They started that way because the cost of deploying these 2 models was 1 to 10. It took 10x more to deploy privileged access management and 1/10 the cost to go deploy identity access management. So you can buy an IAM seat for $8 to $10, you have to pay $100 to buy a privileged access seat. Interestingly, you have 2 different players in this space. It takes CyberArk anywhere from 6 to 9 months to deploy a customer. They have to build special connectors to every room, every server, every data room to make sure that you have the privileged access available. So they've already done the hard work. The question is, can we get them to be able to do all the work required to be an identity access user in addition to being a privileged. We think we can. So we think CyberArk allows us to have a product that satisfies the user -- employee identity use case, not a type of user use case, which is the fragmentation comes in. I walk in, you follow everything I do. If I go to a privileged area, you have more controls in privilege, otherwise, still keep track of me as an employee. The breaches happen because there's a guy in finance who has access to your SAP system, who's not a privileged user, but he can take your earnings and release them 2 weeks before. Is that a breach? It's a breach. But in the traditional sense, not a privileged user. So we think every user should be followed. We think in the next 24 months, that is what's going to happen in the market. It will happen to every agent, every nonhuman identity for which we need an identity play. Then the question is, why don't you buy a startup and do it like you did the last 24 times, why buy an incumbent? Because the value or the disruption in trying to replace the company's entire identity infrastructure is too high. CIOs will not replace their identity architecture infrastructure because they don't know what's going to break. And if you break identity, you shut down the company, right? If you broke the identity system and a trading system, identity got dislodged and your trading systems go down in your company, the CIO and CISO don't have a job. It's worse than a breach. So nobody wants touch the identity infrastructure. So you have to go in as an identity player in the market who's doing the harder job of identity, not the easier job. So long story for sure, we bought CyberArk because we think -- and by the way, unequivocally, every customer we've talked to of CyberArk is delighted we bought them. CyberArk is delighted to be part of Palo Alto. So it's a good move from a customer perspective. They have 8,000 users with 8 million endpoints. We have 100 million endpoints we cover. We think we can take their 8 million endpoints and try and expand them into our user base and into their own user base. We think we can build incremental products. We think financially, we can gravitate them to our margins on cash flow and operating margins. So all in all, it's -- I think the industrial logic is very strong. I think time will tell if we got the inflection right. And then you have to trust that in 7.5 years, we have one of the better track records in M&A in cybersecurity and software across the industry, and you have to trust management that will do our job.

Fatima Boolani

analyst
#45

I don't know if you can stick...

Nikesh Arora

executive
#46

For those who don't trust, they should sell their shares to the bulls and then they can buy them back and they become a growth stock from the bulls.

Fatima Boolani

analyst
#47

That how we make market.

Nikesh Arora

executive
#48

Yes, exactly.

Fatima Boolani

analyst
#49

I don't know if you were conspicuous in not mentioning this, but how does CyberArk advance the AI strategic road map and the agentic AI product road map and maybe you can put Lee Klarich's hat on. You don't have a side burn, so I don't know if you could fit the bill, but...

Nikesh Arora

executive
#50

Look, the other part of CyberArk business, they bought a company called Venafi, which is on the nonhuman identity part, the certificate lifestyle management. I think at the end of the day, if you believe everything -- I can't believe everything Mark Bennett or Bill McDermott say, but if you believe the idea that agents are going to get more prevalent in organizations and they will be fungible between humans and agents, then everything becomes an identity of either a nonhuman kind or a human kind. The question is you still have to understand credential across both those instances and see how the identities mesh and work with each other. So I think the identity needs a platform approach. It needs an approach where every identity is managed from the beginning until the end and needs to understand that it needs to be tracking both human and nonhuman identities. So today, this is fragmented across 4 different products in the industry, 4 different categories. We think they all need to become one, and that's where the opportunity is with the Venafi acquisition, with the Zilla acquisition, identity governance that CyberArk did with their PAM product and the IAM product that they have.

Fatima Boolani

analyst
#51

Let's talk about keeping the lights on at Palo Alto. And what I mean by that is all this AI opportunity and the secular tailwinds are great, but you're running a core that is a [ staller ], right? And I think one of the pieces that gets a lot of investors hot and bothered is the firewall franchise, right? There is absolutely cyclicality in that business. I think you've not been shy about expressing that. But in terms of the whole notion of the death of the firewall being greatly exaggerated, where are we on this curve of dissolution after several years of atypical and aberrant trends? And when you think about, again, AI, what does that do to the medium- and long-term trajectory of how all of us should think about the firewall business?

Nikesh Arora

executive
#52

Look I think thinking about the firewall business in piece parts is the wrong thing to do. And I said this before, and I apologize if I'm repeating myself. The amount of digital traffic in the world continues to compound every year. AI is only going to compound it further. To deliver security, all traffic has to be inspected by a security product, whether it's traffic coming from your laptop going to your company, whether it's traffic coming from a nonhuman identity, whether it's traffic coming from hardware, all traffic has to be inspected. It gets either inspected through a hardware firewall, a software firewall or SASE. That's how traffic gets inspected. Even AI traffic will be inspected by any of these 3. If you believe that the traffic is going to continue to compound even faster with AI and all the data going in the cloud, you have to believe that inspection will continue. There's no other solution. Inspection doesn't go away. Like there will always be security scanners at the airport, unfortunately, if you're traveling. They're not going to go away. We're kind of like the same thing. We cause latency, we make it slow. It's a little irritating, but we're going to be around for a long time. So if you believe that, then the question is, where does the money come? Does it come in hardware? Does it come in software? Does it come in SASE? From a product development, quality, delivery, margin perspective, my software and SASE business are way better than my hardware business because hardware, I got to go produce it. I got to get chips from some different parts of the world. I got to go do quality control. If it doesn't work, I got to bring it back, I got to send you a new one. It's hard to upgrade software because customers decide when to upgrade the software. In software and SASE, I do the upgrades. You can't touch it. So it's a much more efficient operating model. It's a much more secure model. So the more the business moves from left to the right, the happier I am. In 7 years, we have taken our hardware -- 100% hardware business and 60% of that has been migrated to software. And our hardware business still grows at 5% to 8% on average a year. So I'm happy. I don't know why people are not happy.

Fatima Boolani

analyst
#53

I'm pretty happy.

Nikesh Arora

executive
#54

That's good. Because only you and I are happy. These guys are not.

Fatima Boolani

analyst
#55

And what I'm happy about is using that as the linchpin to build what is a $5.6 billion next-generation security business. This was, by my count, a $0.25 billion business 7 years ago when you came.

Nikesh Arora

executive
#56

It was 0 when I came.

Fatima Boolani

analyst
#57

So virtually 0. We'll round down to 0. So sub-$300 million, closer to 0. You've 20x to this business in the last 7 years, in excess of 30% growth pretty consistently. You've got goals to 2.5x this franchise in the next 5 years, right? And this is, as a reminder, completely on an organic footing. This is...

Nikesh Arora

executive
#58

Not including CyberArk.

Fatima Boolani

analyst
#59

Not including CyberArk. These are big numbers. So I want to get a better sense from you on the micro, the bottoms-up factors that are going to help you achieve these objectives of going from roughly 6 to 15 in the next 5 years?

Nikesh Arora

executive
#60

Yes. I think, look, if you go back to 2018, when we first met, we had 0 in this business. If I told you, in 10 years, it will be a $12 billion to $15 billion ARR business, you'd laugh me off the face of the -- whatever, right? So what we've come to realize is that like every enterprise business, you want to sell more to the same customer. The scale of Salesforce is such that they sell more to the same customer. You look at every platform business and software, whether it's Salesforce, Workday, ServiceNow, the idea is to build more functionality, sell it to the customer, add value, create value, and that's what drives your outcomes. Cybersecurity did not have such a [ player ]. So we -- after 5 to 6 years of product development, being #1 in 24 Magic Quadrants in Gartner, we came to the conclusion that integrating these much better from a technical perspective, giving the outcomes is what the customer needs. So we have them available in their own form factor, but also more effective integrated form factor. We started tracking the integrated customers, integrated sales, we've discovered that, a, these customers pay us a lot more than sliver customers because they have more products from us. They have the best NRR. Our NRR for our platform customers is 120%. We've never had 120% in any of our product categories because we've never been a platform business. So if I can maintain my NRR in the 15-plus percent range, 115% plus range, take my number of platforms from 1,450, which we announced last quarter, take them to 3,000 or slightly more, we can take this business to that $15 billion range in the next 5 years. And we're very focused on the platform business. It's land one product, expand that into a platform, deploy the platform, show up and ask customers to give you more consolidation.

Fatima Boolani

analyst
#61

Platformization was a new vocabulary word. You coined about 1.5 years ago and really shook everybody up a little bit. So you got 18 months of platformization selling underneath your belt. The sales org is better, faster, stronger, more mature in articulating that vision to the customer. But I'm going to pause it to you that does that potentially come as a double-edged sword because what you are championing is a lot of your very large customers continue to incrementally consolidate their product footprint with you, but also their risk footprint with you, right? So on the one hand, how are you mitigating some of the natural maybe pushback you're getting on, well, I can't have one vendor do so much of my cybersecurity because that's systemic risk issue just from a cyber hygiene perspective? And please feel free to disagree. And then secondarily, from a financial model perspective, these are potentially multiyear, very large deals that you're doing, right, $50 million, $100 million-plus deals. Just from a financial model volatility standpoint, how do you mitigate some of the effects of, hey, you're going to have some renewal cliffs happen every 3 to 5 years where you have these big chunky customers do for $100 million plus renewal?

Nikesh Arora

executive
#62

So many questions. Let me start from the last one because that's the one I remember. We've discovered once you platformized a customer, there is no road back. because you have a software firewalls from Palo Alto, hardware firewalls from Palo Alto, SASE firewalls from Palo Alto. If you ever decide to rip us out, you'd have to replace us with 3 vendors and build the entire control pane between the 3 and make the integration happen. And like I start with a customer, it took them 3 years to replace 500 firewalls, we put them in. You have to decide at your last renewal that you don't intend to renew with me and you just start them. You can't replace a network security platform from Palo Alto in under 3 years if you are fully platformized across the board or you can't replace a SIEM platform in less than 12 to 18 months if you are fully platformized. So I don't know what a renewal cliff is. I think it's a renewal opportunity to give them more functionality and sell them more as opposed to renewal cliff. So the NRR at 120% is that's the reason it's 120%. We don't see churn. So I don't think there is a renewal risk. You did say there's a, let's call it, the consolidation risk. I was trying to find the best analogy. I guess perhaps the best analogy, which is old is I started my career at Fidelity in the technology team, and we had 23 applications, which made up what is today called CRM. And over time, 3 or 4 vendors emerged between Oracle, Microsoft, Salesforce and others who provided you a single platform did 23 functions that allowed you to consolidate those 23 applications. I'm pretty sure somebody had a conversation, "Oh my God, we're consolidating a risk," but the value of that being together is so high that you say that's the right answer. This was the wrong answer. And that same movie is played out in HR systems, same movie is played out in financial systems. Cybersecurity is the youngest industry in technology. We only came about when connectivity came about. Until your iPhones were connected to the Internet, there was no need for cybersecurity. It was all data center-driven, all terminal-driven in the office. You walked in IBM gave you a frame, mainframe, but terminals, you need security. Who needed security then? You did client server architectures, you did liberal security and did firewall inspection. Now with the sprawl of the technology infrastructure, you need security every juncture. I think it's just the stage of the industry where it is. I think 10 years from now, you will not be buying sliver products, which are small products based out of startups. I think that consolidation is happening. And I will say, look at our industry, 7 years ago, everybody played in the swim lane. Today, everybody is trying to cross swim lanes. If you take a look at the top 10 cybersecurity companies in the world, they are trying to get a product in the other swim lane, and you can ask -- I'm pretty sure you have everybody. So I think that's the trend. I don't think that's a risk the customer sees. The customer sees the value of these things being on one control pane and then they are not gonna go back.

Fatima Boolani

analyst
#63

Nikesh, my last question for you is 3 years ago, you made a prediction that you're going to be a $100 billion market cap company. That's absolutely come to a fruition. And I think it's worth mentioning, you were a $20 billion market cap company 7 years ago. So I wouldn't be a tiger mom if I didn't ask you, where is the next $100 billion of market cap going to come from? And what things absolutely have to go right to have that outcome?

Nikesh Arora

executive
#64

Look, you guys do the math. I don't think we need to change our financial profile from an operating margin, free cash flow margin perspective. I'm talking just organically for us without the CyberArk piece. I don't think we need to change anything in our operating profile financially to achieve our $15 billion ARR target in 2030. So '25, 5 years from now, we are at $5.6 billion today on the next-generation security, you get to $15 billion. You guys have better multipliers than I am. You can figure out what that does. If you keep the multiple the same. I don't know what the math is. If you depress our multiple a little bit what the math says, I don't think -- there's no math you can do, which gets you less than $100 billion going from $5.6 billion to $15 billion, just what organically we can do. Then the question is what can we do with CyberArk? Can we do with CyberArk, what we did to Palo Alto? And of course, they don't have the option to go into multiple swim lanes. They can be the identity platform in the future. Even 5 years from now, we can make CyberArk identity platform of the future as part of Palo Alto and take their $20-plus billion market cap and double or triple it, that's gravy on top of the $100 million.

Fatima Boolani

analyst
#65

Well, we'll be watching from the sidelines.

Nikesh Arora

executive
#66

Or $50 billion.

Fatima Boolani

analyst
#67

I like it. Make it $300 billion.

Nikesh Arora

executive
#68

No. No. I'm not [ Moss ], I'm not investing in data centers in the United States.

Fatima Boolani

analyst
#69

All right. Fantastic. I think that's a great place to put a pin in. Thank you so much for an awesome conversation. Thanks.

Nikesh Arora

executive
#70

Thanks, Fatima. Nice to see. Thank you everyone.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.