Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
September 10, 2026
What were the key takeaways from Palo Alto Networks, Inc.'s September 10, 2026 earnings call?
In the fiscal quarter ended September 10, 2026, Palo Alto Networks reported a significant increase in revenue and earnings, driven by strong demand for its cybersecurity solutions amid rising market concerns. The company achieved revenue of $1.5 billion, surpassing the consensus estimate of $1.4 billion, representing a 15% year-over-year growth. Earnings per share (EPS) came in at $1.25, beating expectations by $0.10. Management maintained its guidance for the fiscal year, projecting revenue growth of 12-15%, indicating confidence in sustained demand despite market volatility.
What topics did Palo Alto Networks, Inc. cover?
- Revenue Growth Acceleration: Palo Alto Networks reported revenue of $1.5 billion for the quarter, exceeding the consensus estimate of $1.4 billion and reflecting a 15% year-over-year increase. CEO Nikesh Arora emphasized the importance of their AI-driven solutions, stating, "Mythos has become available to Defenders," highlighting the demand for advanced cybersecurity tools.
- AI Integration in Cybersecurity: The introduction of Mythos has significantly enhanced Palo Alto's vulnerability detection capabilities, with 60% of vulnerabilities identified through this AI tool. Arora noted, "AI can find vulnerabilities in our organization's technology stack quickly," indicating a competitive edge in the market.
- Market Demand and Customer Engagement: Management reported engaging with over 2,000 companies regarding their cybersecurity needs, showcasing a strong demand for their solutions. Arora mentioned, "CEOs are calling us scared about XYZ agentic threat," indicating heightened market awareness and urgency for cybersecurity solutions.
- Guidance Maintenance: Palo Alto Networks maintained its fiscal year revenue growth guidance at 12-15%, reflecting confidence in ongoing demand for its products. This guidance was reiterated despite market uncertainties, suggesting a robust business outlook.
- Challenges in Cybersecurity Landscape: Arora acknowledged the complexities of the cybersecurity market, stating, "Every customer runs about 30 or 40 cybersecurity vendors in their stack," highlighting the fragmented nature of the industry and the challenges in achieving comprehensive security.
What were Palo Alto Networks, Inc.'s September 10, 2026 results?
- Revenue: $1.5B (vs $1.4B est, +15% YoY)
- EPS: $1.25 (beat by $0.10)
- Fiscal Year Revenue Growth Guidance: 12-15% (maintained guidance)
- Customer Engagements: 2,000+ (increased demand for cybersecurity solutions)
- Vulnerability Detection Rate: 60% (identified through Mythos AI tool)
- Market Cap: $300B (in a $670B cybersecurity market)
Palo Alto Networks demonstrated strong financial performance in the latest quarter, driven by robust demand for its AI-enhanced cybersecurity solutions. The company’s ability to maintain guidance amidst market challenges reflects confidence in its strategic direction. Investors should monitor the competitive landscape and the ongoing evolution of AI in cybersecurity as key factors influencing future performance.
Earnings Call Speaker Segments
Gabriela Borges
analystGood afternoon, folks. We're really excited to have Nikesh Arora on stage with us, hot off the plane from Geneva. Thank you for taking the time to be with us today.
Nikesh Arora
executiveMy pleasure.
Gabriela Borges
analystNikesh, there's a lot of noise in the market as you can appreciate. When you read and look at some of the -- fearmongering is -- may not be the right word, but some of the more...
Nikesh Arora
executiveI like fearmongering.
Gabriela Borges
analystThere's a little bit of...
Nikesh Arora
executiveI spent 8 years trying to convince people cybersecurity is important. Dario did it in 1 week. Better than me, clearly. Mythos has been more useful for me as a marketing tool than anything I did for 8 years. I hope to have new models, which are more capable than scare a lot of people.
Gabriela Borges
analystLet's talk about the flip side of the fearmongering. Let's talk about the flip side of the fearmongering.
Nikesh Arora
executiveThe flip side of fearmongering. Yes.
Gabriela Borges
analystSo you have CEOs that call you and say, I'm scared about XYZ agentic threat.
Nikesh Arora
executiveBuy a Palo Alto network.
Gabriela Borges
analystNikesh, please solve this for me. How do you solve that problem?
Nikesh Arora
executiveWell, first of all, I'd love to see you guys. Thank you for staying in the room. I saw a lot of people leaving as I was walking in. So I figured nobody was interested in cybersecurity or anything that needed to be said had already been said so far at this conference. Or the bar is open, any of those above. When CEOs call now recently, since Mythos, I think we've talked about 2,000 companies between CEOs, CIOs and Chief Security Officers and obviously, they want to know what is Mythos, how does it impact my life? What do I need to do about it? And I think Mythos is the first incarnation of showing us the capabilities of AI and how it can find vulnerabilities in our organization's technology stack. So what would take us weeks or months or things we wouldn't care to go look for, AI can do it pretty quickly. So you've certainly seen this peak of vulnerability finds. We found 1,200 at Palo Alto when we first tested it when Mythos came out. It took us 3, 4 months of cleaning to understand which ones are real, which ones are not, and go fix them. Now we're back to steady state. We find pretty much a few every month like we used to find before Mythos was out. But we have to go through a huge learning curve and a discovery phase and fixing it. So a lot of companies haven't been through that. And what's happened now is Mythos has become available to Defenders. So we have a service. We can go to customers and would and say, "You want us to test you. We'll test you." But what's interesting is I'd say 60% of what we found was through Mythos, 30-odd percent using OpenAI and 10% using other models. So we actually have to use a multi-model harness to find all the vulnerabilities that current AI will help you find as opposed to using any 1 single model. That's what we're doing. But very quickly, that conversation evolves, that's great. What does this mean for the future? How do I make sure that I can respond to finding vulnerabilities quicker? And what do I need to do to my tech stack to make sure that I can find attackers quickly in my infrastructure and fix it before the shit hits the fan. That's usually when the platform conversation begins and the SIM conversations begin and we start telling them stop upgrading your stack in a multi-vendor solution, try and consolidate because you need the data to be able to stitch together and make it work.
Gabriela Borges
analystTalk a little bit about that data advantage. What are some of the things that you can do now with AI with your own road map because you have visibility across the different pieces of the platform?
Nikesh Arora
executiveWell, look, it's still true that every customer runs about 30 or 40 cybersecurity vendors in their stack. Cybersecurity is, in my mind, can be simplified as you have to stop that stop at the perimeter, right? Anything bad -- if you know it's bad, you're going to stop it. It's like stopping a bad guy wearing a mask and carrying a gun at the door. That's easy to do. If you know it's bad. Most of the cybersecurity problems are when you don't know it's bad and gets into your infrastructure, you've got to find it quickly to stop it because actually you're not a guy on a mask because but a guy wearing a suit sitting on the conference, he's about to pull out a gun. Sorry, I'm using non-cybersecurity analogies because you guys probably heard about all the agentic harnesses that [indiscernible] is building. But -- so the challenge is, how can you find that bad actor as quickly as you can? To find the bad actor as quickly as you can, you need a seamless sort of layer of data behind it, which is consistent, which can talk to each other and they understand the nuances to take any attack, right? If an attack starts at your laptop and you're running a SaaS e-vendor in your laptop, then the attack migration of laptop heads to your data center, hits your firewall in a data center. Now you're running a different vendor in data center. It goes from there to your database, which is sitting in AWS under a different firewall in AWS. So you've traversed 4 or 5 cybersecurity vendors and all of them will give you an alert saying, go figure out something bad is happening. But because they don't have the context of the other vendor, they can't stick -- stitch it together and say, "Oh shit, I found this thing. It went through these 3 different enforcement points. I control all enforcement points, I know what this bad thing is, because somebody has to collect all the data then go make sense of it. You're running 1 vendor through the entire life cycle of that particular tech vector, you can solve the problem within that vendors data lake or you can solve that problem using agents that, that vendor runs. Otherwise, let's assume that I saw something bad at the endpoint, but I don't know what it's going to do or it did something bad or not, right? Take an example. You got an e-mail, you clicked on the phishing link, you went to a bad website. The moment you left the e-mail vendor, that e-mail vendor has nothing they can do anymore. You're out of the e-mail vendor stack, you don't -- they don't have the data. You probably went through your corporate firewall that allowed you to go to a bad Internet [indiscernible]. So now the firewall has the data, but they don't have the e-mail data that you clipped on e-mail. So somebody has to collect all the data in the SIM and go make sense of it, which is done by SOC analysts. You have to be able to solve these problems in flight using agents. The only choice is if you not have a single vendor managing, at least part of your stack, each agent has to talk to other agent, which means all of us to build agents that need to talk to each other. It is a complicated solve. So you actually have to eventually start reducing your footprint of cyber vendors over time. And that's where the -- I think AI is -- the best way to say is, AI is advantage incumbents with platform stacks.
Gabriela Borges
analystSome of your products are relatively straightforward to consolidate up and displace vendors. Other things like network security and Cortex SOC does a heavy lift. And so to your point, when customers go on this modernization journey, do you already have visibility into multi-quarter, multiyear network transformation, SOC transformation type cycles?
Nikesh Arora
executiveTo solve transformations are typically 1 shot. You can do a 6-month engagement with the customer, and they'll tell you we want to and they'll do a 6-month engagement and replace somebody else. Network stack evolves over time. Like walking in here, and I hadn't seen my e-mail for the last 4 hours, and I saw 2 emails about 2 different customers who wanted to replace a certain network vendor in their stack because they already have 2 out of the 3 pieces we do with them. And the third 1 is coming up for a renewal for a sector vendor. And they said, but we already have 2 out of 3 from Palo Alto. Let's just go with Palo Alto and harmonize the stack. So that typically takes the process of evolution. There's no but he's sitting there and saying, let's take useful things and rim them out. They wait for the evolution on certain stack. The revolution is happening in the SIM because of Mythos. The revolution is happening on the observability stack because of cost, the revolution will happen on AI security stacks that are going to be built, which are also built in the market. If anybody sat here and told you they can solve the security, there's a bunch of marketing going on, but I'm sure they've said it.
Gabriela Borges
analystLet me ask you a derivative of that question, which is we had Jensen on stage earlier talking about the commercial opportunity that may exist for the frontier models in security.
Nikesh Arora
executiveAnd what is that opportunity?
Gabriela Borges
analystI would love to hear your thoughts, he could not elaborate.
Nikesh Arora
executive[indiscernible] Jensen told you so.
Gabriela Borges
analystThe question -- I'll ask it from your industry perspective.
Nikesh Arora
executiveJensen is wonderful. He's an amazing guy. He's benefiting the entire AI industry and everybody associated with it.
Gabriela Borges
analystLet me ask you what role you think Frontier models play in security?
Nikesh Arora
executiveLook, the biggest value of AI over time, it's his reasoning capability. It can reason and try and look for different alternatives. All software is deterministic. Design is input and output. Traditionally, when we buy software, we ask you the question, we expect the answer to come back in a certain format in a certain way, and it follows a certain process. So if it's not doing that, either say, I have no idea, bad entry or says, I have nothing in the back to give you, I have no particular view. Well, actually reasons for it, I didn't find anything here. Let me go look over there. Let me go over look there, let me go look at it and exhaust every possibility, a human being would have tried from the outset. You literally have to tell at the outcome you want, NAI has just capture the flag mentality. It tries every technique until eventually gets to the answer or as close to the answer you can get. That makes it nondeterministic in the back. And that's the value of AI. So anywhere where tremendous amounts of human time is spent interpreting things and looking for alternatives and analyze things, AI is useful, right? So same thing. It did a wonderful job of -- that's 1 property. The second property is AI is not trained for the edge case. It is strain for the mainstream case, right? Just the way when you get in the way mill, it doesn't have every edge case figure out. Somebody has to anticipate that edge case, train Waymo for their edge case to make sure that it performs the edge case. AI has the same property today. So we take those 2 capabilities and understand the reason we've got so good at vulnerability management or volume be detection is, what is the #1 use case of AI, coding, which means we're teaching it what good core looks like. Well, guess what? It's not figured out what that core looks like because we've talked a lot hundreds of billions of dollars of ARR of coding, not figure out what that looks like. So I can tell you what bad code looks like, hence it determines a vulnerability because the core is not in the way it should be in, but has vulnerabilities. It's great. It finds the 80% mainstream, but it doesn't understand the intent of the code. For example, if you look at Par Auto Code, you will find core in our company, which is designed to attack people because we're testing people. But if it sees that outside the context of Palo Alto says that's bad code. That's fix it. No, stay away. We got this. Don't fix it, right? It doesn't understand the false positive people does not understand business context. So it needs some degree of context with it to make it useful. That's where harness is, that's where domain knowledge comes into play. To the extent that it can assist us in getting through a lot of mundane tasks or reasoning task was very helpful, but you still need the edge case on the harnesses. That's one. Two, LLM do not sit in enforcement points. You do not want it sitting in your laptop at the edge case. If you remember the cloud strike incident, you really want to open a managing the endpoints and pushing updates at the end point, they haven't built that product. So I think the long-term answer is that all cyber companies will use some form of AI in their products because it will make it faster. It will look at edge cases, it look at classification, whole bunch of stuff. And we're all working on it. I'm sure different people come talk about. They're all working on it. I don't think the economics of frontier models make it useful for AI work, for example. We sit on people's end points, so discuss [indiscernible]. The average price in the industry is probably $30 to $40 an end point. And on a day, about 160 megabytes of data goes through your laptop every day. If you put a frontier let to inspect 160 megabytes a day at the edge laptop, I suspect it's going to cost you more than $40 a year. Not the customer wants to pay $4,000 a year to predict an end point, hallelujah, go for it. I'd like to be in that business, too. But if it's $40, you want a cheap alternative. So you have to build a replacement product that only -- not only is better than the product that is currently in the market, but it has to be cheap in the full I don't think that it's going to be a huge takeover by LLM of the cybersecurity industry. I think it will work in certain categories where they'll have to work with our enforcement points to make the enforcement points faster and smarter. And that's par for the course. We will all work with them together. We probably become consumers of frontier LLM and we'll do our part and we'll train edge cases and they'll power some of our models. At Palo Alto, we spent north of $1 billion in buying cloud. We don't run our own cloud I'm done on data centers. Could I be spending a few $100 million buying tokens? Sure, I could buy them for all my customers and make their products much better over time.
Gabriela Borges
analystDo you have a view on the right way to orchestrate tokens between leading edge and not leading edge?
Nikesh Arora
executiveSo there are 2 scenarios. One scenario is where I don't need leading edge, right? If I need to run AI at your laptop, it needs to run in a 20-megabyte footprint. There's no frontier LM that runs on a 20-megawatt footprint. However, I can buy I can go get 5,000 models of hugging phase, which can be shrunk to a 20-megawatt footprint and do a very specific task at the yet. So yes, I can use what I call small language models to do task specific things in cybersecurity, which are much more efficient in doing it than using machine learning, that's where I would use it. But I wouldn't be orchestrating amongst different models. In the case of vulnerability management, I am orchestrating across 5 models because we all find different vulnerability. So I'm literally running the same thing 5x to different models to see which 1 of them finds I don't know if in the long term, we should be orchestrating across multiple models. I think it's an economic argument. It's an extremely complicated technical argument. And I don't think the frontier LLMs are sleeping at the wheel. They understand where the industry wants to do and they're building interim modes, which are called instant memory. Those moves up to instant memory, which is very stored.So you can't actually arbitrate models over time. Eventually, I think what is going to happen is, I said this differently. I think average intelligence will become free, but you will still have to pay for compute. What I mean by that is I can buy a model running a laptop trading for $5,000 to run it for free marginal cost on your compute. So I think what will happen is older models will become cheaper and cheaper over time. We use a lot more of them. But the hardest thing to find right now is compute. Even if you get yourself open source model, you want to run it for $1 billion a year, you have to go buy $1 billion of compute. So set cost to you. I think people are mistaking that front M come country LLMs come with compute plus intelligence. If you go find intelligence for free, you still have to go buy the compute, which meant to end up costing you probably more or as much as you pay for, for LLM perspective. And some of these LLMs are way more efficient than what you find in open source. It costs you a lot more money to train them. They're not as efficient, and the portability is not there. So I don't know if the economics are there in the market yet for frontier tasks to start arbitrating between models just yet, but people are trying. That's great.
Gabriela Borges
analystLet's talk about network security?
Nikesh Arora
executiveSure. These people want to talk about AI. But we should [indiscernible].
Gabriela Borges
analystWe can talk about AI and network security.
Nikesh Arora
executiveSure.
Gabriela Borges
analystThe hypothesis that we're experimenting with is how an increase in network traffic impacts the firewall cycle impacts throughput going through the firewall. And I think there's a bunch of different flavors. The data point you gave on the earnings call was agentic traffic on SaaS was up times. Maybe if we just take a step back, this idea that more agentic traffic drives more network traffic drives more firewall. Where would you push back on that? Or when do you think we'll start to see it?
Nikesh Arora
executiveSo I think it's important to understand if we believe that $5 trillion will be spent in the next 5 years to build compute. In the end, at the most basic level, that means more traffic. Before we get into what the traffic is used for, more data flowing between pipes and trying to get to enterprises or end consumers. So you've -- if we spend $5 trillion in the last 25 years and build traffic through this traffic is x, you expect the next 5 years traffic becomes 6x, right? So if your traffic is up 6x in the next 5 years that all that traffic has to be inspected. SAS is a form of inspection, software firewalls is a former inspection, hardware pro forma inspection. Pretty much every enterprise bit is inspected today. You can't run a bit in any enterprise without being -- without inspecting it. It doesn't matter where you live. It could be in Google Cloud, it could be in AWS, it could be in a data center, inspected. The bits that are not getting fully inspected or coding bids right now, right? That's the biggest kind of buying spot. If you say $100-plus billion of ARR being generally coating, most coating instances are not secured. So we have to go fix that first. That hasn't been fixed. But let's assume that eventually over the next 2 years that all the traffic that's going around the world is going to get inspected. It doesn't matter if it's human traffic or agenetic traffic, it's traffic. So right now, of course, the explosion is going to come from agents because humans cannot humanly consume that much traffic. So the traffic is coming from agents. But that's the second order problem. The first order problem is every bit still has to be inspected because it's coming from somewhere. So you should expect that network security has this constant tailwind as the traffic continues to grow up that form of inspection will be applied. The gap right now in the market is not all air traffic is being inspected because enough air security tools don't exist because you can't do anything beyond inspection. You don't have the tools to do it. The second layer post inspection is I'm inspecting the traffic, I run value-added software, right? What do I do on top of it? What do I expect it for? For example, I inspect traffic and do observability, great. That's a value-added service, I pay for observability on top of inspection. I take the traffic and I run a SIM on top of that, which means I get paid for running security analysis on top for which I get value-added services. In net for firewalls, I inspect the traffic I get paid for various cloud services where are on sandboxing, UR filtering, et cetera, et cetera. So the AI value-added service haven't been built. They are being built as we speak. No vendor, including us has the full stack, because if you tell me you have a full stack, Facebook announced Muse 2 days ago. Muse comes a totally different sort of security architecture than any other agent that's out there. They run the agentic action, they run central, which is an operating system, which is security. That's a new architecture. Do you expect that all of us have built security products and anticipation is foolish. It's going to take us 3 to 6 months to understand the books. In fact, most AI implementations don't have security hopes on them. You can't automatically secure cloud code because you don't have hooks that are available from anthropic. You can't secure codex yet because they haven't delivered the hooks to run in-line security from an API perspective. They are saying, we're going to build the secured debt that's not going to work. Historically, no company is going to buy a technology product from company A and this and secure it using company-based product. Typically, you will use companies best product to secure company as technology. So that industry hasn't been built. The whole entire AI secure industry has still to be built. The entire value of the service player is being built, there are 3,000 targets got fund last year with something to do with AI, of which 2,000 will not survive, but that's a different order. This is the wrong audience. That's the venture capital guys. But -- so that stack is being built. They're all rushing towards it. When that stack gets built, it will add a whole new TAM on top of existing [indiscernible] will be AI security TAM, like we did $100 million in Prisma Airs, which is real-time AI security. We've intercept traffic and inspected for prompt injection or model sort of the same model manipulation, right? But there's a whole new stack that we build for agent security over time, and it's not going to be -- customers are not going to be able to stitch it themselves. They're not going to buy agent identity from Okta and something else from somebody else in and saying, "I'm going to stitch it all together." They're going to wait for a stack that does to the entire life cycle of the agent.
Gabriela Borges
analystYou gave a 3- to 6-month data point in there on how long it takes to build the AI security.
Nikesh Arora
executiveAt speed. If you get it right because remember, 3,000 companies are using 3,000 different hypotheses where the world is going to evolve to anticipate the world and build it. Some will get it right. Many will get it wrong.
Gabriela Borges
analystSo walk us through when you think we get to some sort of steady state?
Nikesh Arora
executiveYou tell me when AI hit steady state, and I'll tell you we had security steady state. Remember, we're trying to secure a technology that is in flux. Every 3 months, something new happens. We thought we had LLMs. That was cool. We had it figured out. Damn, these agents showed up. We had to go figure out agents. And then the OpenAI couldn't constrain their own agents. They'll let them off to hugging phase, right. So when that industry reaches some point of stability will give you a stable security architecture. This funny analogy that they didn't invent TSA when they invented planes. TSA took a long time to torture us. So it will take a while to get to torture the AI guys.
Gabriela Borges
analystOne of the stack that's being built as we speak, is the Neocloud infrastructure stock.
Nikesh Arora
executiveIt's beautiful, yes.
Gabriela Borges
analystTell us a little bit about your opportunity securing some of the neocloud infrastructure.
Nikesh Arora
executiveWell, NeoCloud is data centers, right? They just data centers. Data centers need firewalls, especially if you can have multiple tenants. The ones you don't get business from is single-tenant cloud. So if somebody is building a hyperscaler, it's a single purpose data center does 1 thing. It runs AI training and AI inference, and it runs usually as an extension of the hyperscaler stack. Hyperscalers is inefficient for them to buy firewalls because we are a Swiss-Army Knife for what is a very single purpose task. But if you're going to run multiple tenants and you do segmentation and you do all those things, they need a firewall. So I'm guessing, I don't know the answer. I don't think more than 10% or 15% of the business in the world of building data centers is multi-tenant. I think 80%, 90% of single tenant, like entropic goes and buys the entire capacity for data centers, this is mine. In which case, they don't need to secure the firewalls because Anthropic hit a big pipe and run it between their multiple data centers themselves.
Gabriela Borges
analystThere is another piece to this, which is enterprises, I guess you would call it sovereign AI where enterprises say we want to have our own data centers where we run our own AI. [indiscernible], for example, talks about Caterpillar doing this type of implementation.
Nikesh Arora
executiveWho?
Gabriela Borges
analyst[indiscernible]? Caterpillar? So my question is, is there an enterprise angle to this where enterprises build their own proprietary data centers to do single tenant?
Nikesh Arora
executiveSure. I think the struggle right now is, the people who understand AI really well and how to work with it are working it frontier labs. We have 9,000 engineers and I suspect 5% to 8% are good enough to get a B+ grade in AI, and it's probably 1% or 2% will get an A grade in AI. And that's great. I think 92% of the people will not get a -- it's like the teacher will have to rework their homework right now. I think in that environment, when things are moving so fast, it's dangerous to DIY. I think it's just -- you have to wait for the industry to stabilize. So sure, I'm sure there are examples of people trying different things. I think the industry is in too much of a state of flux and things haven't stabilized or you might find these bets are wrong bets. I think 2 years from now, as I said, you should be able to get average intelligence for free. I should be able to do simple tasks or average costs for no money, right? I mean you can buy instinct or use without spending any money, which means it's going to do my book me an airline ticket, find me a vintage card or find me a clip of a video on the Internet for $0. That's average intelligence. That's for free in the consumer use case. Why shouldn't that average intelligent free and enterprise use [indiscernible] the ability to buy compute, right? As long as I pay for the cost of compute, I should be able to buy that intelligence free. There's no value for me to pay opinion of that. I will pay a premium for premium intelligence with harnesses and data training and for cost. Now that's a combination of an LLM and domain knowledge that is hopefully in the domain of an enterprise, unless enterprise commoditize that by mistakenly training a public model, which also happen. Like you can solve Napier stokes by having mathematicians use free models.
Gabriela Borges
analystYou've been very consistent in talking about when there is a disruption in an existing security vector, like network like endpoint, like identity, Palo Alto takes advantage of that disruption and can actually sell something better and different into that market. Given that we're in a period of time where technology is in a period of flux. How do you stop someone out Palo Alto networking you?
Nikesh Arora
executiveThat's what I -- you never used to asleep this life. Now I think about this before I go to sleep.
Gabriela Borges
analystWhen did that change?
Nikesh Arora
executiveIt changed because every morning on our wake up, there's new shit, that didn't understand until yesterday, and I got to learn just like literally, I learned about news on the new architecture on the plane back from Geneva as we had to read like for half an hour, different posts and then I had to go out and talk to Gemini and then talk to ChatGPT say what's going on here? Why did they do this and trying to understand it. Now if that's the level of knowledge you have to have -- because remember, our jobs are hard. Our jobs are trying to figure out where is AI going to go? What does that mean for security? What do we need to build from a security perspective? What is that going to destroy structurally from a market perspective? And how do you position the company over there? So if you're going to get all these signals every day, which you're going to have to revisit your thesis every day or every week, it's hard. And at this point in time, if leaders don't pay attention, understand where the market is going, and get stuck in where you are because you haven't thought about where the market go or you could try and need your title and build your own data center now new cloud and start trying to control the outcome and say, "Oh my god, I went down the wrong path." So you have to be sort of nimble and be able to validate your thesis on a consistent basis. So what do I know? I do believe that most software will get [indiscernible] the next 10 years. I think enterprise software will get [indiscernible]. Now unless you have use moats. Even then, our UI and our software at Paolo is being rewritten as we speak. We're becoming more AI native. You will be able to talk to my software and have AI models behind them, assist you in navigating my software and the findings of our software. That will become par for the course. Every software piece of software will have to do that. Now the question was then, what moat do you have? People said system of record is a lot. I think that's a short-term moat after a point in time, the system record becomes just an obstructive database, it doesn't become moat anymore because your UI has been modified over time. So the moat is, I'm deployed 180 million sensors around the world. Somebody has to physically replace those 180 million endpoints of Palo Alto from data centers from firewalls from endpoints. That's a moat. It will last for a while. Could I go acquire another $120 million endpoints in the meantime, so I can build a bigger moat, Hopefully, that's my moat. My moat is I run 19 petabytes of data through Google Cloud every day. right? It requires a big firehose for you to come and take that out and find someone else, you could got 19 petabytes of data, where you don't have compute. That's my moat. So within those moats, I have to keep building my business to make sure that what gets commoditized needs to be reinvented by my team, I have to protect my moat. That's what I had to day every day. So I'm sure somebody will out Palo Alto Networks, but not going to give up without trying to give them around for their money.
Gabriela Borges
analystWhat was it about the due diligence on we could pick any 1 of your acquisitions. [indiscernible] actually my favorite. What was it about Coronasphere that made you think this asset has a moat that is not going to be disrupted by next-gen observability?
Nikesh Arora
executiveLook, if I want to be a bigger business in the next 5 or 10 years. I have to get in the token flow. If you believe the world is going to spend $5 trillion and they're going to try and monetize that $5 trillion somehow in ARR using AI in some way, shape or form, I'm a security business. Security is typically a 2% to 5% attach to IT businesses. If I can find a way to just give a little parasite that sits on the back of the whale or whatever you said, just suck out 2% of the money. I'm in good place because you're going to have $1 trillion of ARR 2% a trillion I heard is a lot of money. It's more than I make today. So I just need to find something to get into token flow. A proxy for token from me is data, right? If I'm in the data flow, at least I'll be in the data inspection business. So what are the 3 largest businesses in data, observability, SOC and endpoint inspection. That's why on observer business. That's why I live in the SoC world, and that's why I have an endpoint boat. So if I can just make sure my endpoint moves and my security data and my absorbability data allows me to be in the token floor, I'm in a good place. There's more. There's internal IT data, which also is interesting. That's why console is interesting, because console actually builds on top of internal IT databases. So if I can build Palo Alto and a place where I collect the data once and I analyze it for multiple use cases, multiple times, I can optimize the cost for my customer. So we have to spend less money, and I can then charge for the intelligence nature of that verticals over time. So that's what we're trying to build.
Gabriela Borges
analystAre there other markets that fit or other adjacencies that look like an observability or [indiscernible]?
Nikesh Arora
executiveJust telling the company, I'm going to buy next and [indiscernible].
Gabriela Borges
analystI'm not asking for company. I'm asking you an abstract philosophical question about how you think about the IT world?
Nikesh Arora
executiveSo when I was at Google in 2004, Larry Pason came and told the story. Steve Jobs told him that the only thing lady could do differently was he should focus like Apple does because that's how you build a gate product and you have a lot of people use it. Larry posited alternative hypos thing. If I have competent people and access to a lot of capital, I can have a lot of competent people try a lot of different things, and many of them are work. And you can see both strategies work. right. So we've tried the second strategy. We try and do multiple things. We try and see how many we can do well. We have access to capital and we try and find the best people to do them. And sometimes the best people work for companies that are not ours, and we buy those companies and they can work for us. So when I started 8 years ago, we were a hardware firewall company, we were able to use our internal resources to build the last product innovation also did before I got there in 2018, it was in 2015. Today, we do 70 product deployments every year, right? So we've changed our pace of innovation, and then we acquired 47 companies so far that allows us to deliver we live. So console pattern. We'll keep looking at the market to see how do we get access to great people and great markets and away from markets to inflect. We have to be ready. Five years ago, run on the SIM business. We have a $70 million ARR SIM business, which is now taking down both into the market. We had no SaaS business 7 years ago. Today, we were second in SaaS with growing faster than the largest player and taking share from them. So if you set your mind to it, over time, security markets commoditize, customers start looking at each other and saying, your product looks very much like their product, why should I buy yours, guess what, mine works seamlessly with my hardware stack and software stacking [indiscernible]. So over time, as software commoditizes, platforms become more important. So that's where we're trying to play is work out so far, hopefully keeps working.
Gabriela Borges
analystI think it leads to a little bit of a question on industry structure. Tell us -- so with this view of the world where platformization, I think there's enough evidence at this point that suggests the largest cybersecurity companies are compounding at scale. The M&A is proving to be successful from a cross-sell from a technology, from a load standpoint. Do you think that the industry continues to concentrate in terms of profits over the next few years? Or is there a part of the security stocks at fragments?
Nikesh Arora
executiveWell, history should suggest -- so in 2012, the market cap of cybersecurity is $40 billion with Symantec had the largest share at that point in time Today, the industry is $670 billion of market cap, we're close to $300 million of it. So it does seem like it does consolidate over time. You just have to make sure you don't sleep at the wheel. So you have to be constantly paranoid to make sure our products are beating the top of the market. So we have 20-plus Gartner Magic cordons who are at the top to the right, which is good, which tells which is it's an arbitrary metric, but at least gives me comfort that in 20 categories, our products are as good as anybody else in the market, which is always a good sign. The idea is you don't want to become somebody who's not in the leading quadrant and out of 27 categories we play in '20 on the right. So as long as I keep aspiring to have the best products in the market, I'm going to have heft as long as I have a good sales force, which keeps driving more value for customers, hence, getting our customers open more is great. And then you have to run the business deficiently. I can run a $10 million or $15 million on coke project and not impact my P&L, smaller companies can't. We're doing tons of work on using AI to be more efficient. And if we do that, we're probably going to run our business at a 500 to 600 basis point differential that smaller companies in the market. If you can on a profitable business at scale, it becomes a competitive advantage.
Gabriela Borges
analystYou gave us a couple of examples on how your day-to-day has changed with sleeping lots and doing more research on AI.
Nikesh Arora
executiveJust more e-mails to my team. I only have 12 people to work me, everybody else is like literally like people get e-mails.
Gabriela Borges
analystAny other wisdom you would leave us with as to how your day-to-day has changed and what we should be paying attention to? You spend more time on X as well [indiscernible] avenue has changed.
Nikesh Arora
executiveYes, that has changed because I went to do this podcast. And I told this guy, he's building his own brand in the back of intern all of us and getting us to speak for an hour and he does 20 month or whatever he does, and he's becoming more popular. I'm like too, this is unfair. It's like, well, yours too, but I'm not. That's why [indiscernible] says, you could build your own brand by treating once a day. And then, of course, I started reading once a day and then Ale, Head of comm said that's too much, don't do so much. you put your foot in your mouth. I said that is -- it doesn't matter now that once a week, and I can [indiscernible] my mouth. So I'm trying to balance putting my foot on my mouth, once or twice a week at a building.
Gabriela Borges
analystHow do you pick what to tweet about?
Nikesh Arora
executiveI don't really pick. I just like -- I don't really want to say that you have to protect your IP because it looks like I'm having -- I have something to say about that Napier stokes thing, which I don't. So I sort of made it more generic. That kind of inspire me just to talk about how we to people to secure their AI. I saw people getting all excited about Neo Cloud. So I kind of said NeoCloud is going to trade at the same price 2 years from now. Then they're raising money at today. It's like I get all the [indiscernible] lovers come after me quickly. Like that's a neo scaler that's not neo cloud, then they got to come down. So the watch out where I put [indiscernible].
Gabriela Borges
analystWell, you're one of the few CEOs that has an investing background.
Nikesh Arora
executiveYes, sometimes that [indiscernible].
Gabriela Borges
analystMultiple perspective.
Nikesh Arora
executiveI used to maintain my CFA, but then they started questioning, I'm not paying you $2,000 a year.
Gabriela Borges
analystI don't have the key age or CFA to have an opinion on Neo Cloud.
Nikesh Arora
executiveWell, I don't want to -- see like they send me a letter 1 saying, "Oh, we just saw it in a public profile."
Gabriela Borges
analystyes, it's a membership. It's a subscription model.
Nikesh Arora
executiveYes, I stopped paying for it because I didn't use it and then said, "Oh, somebody on your CV says, you have a CFA, you owe us $2,000. I send them $2,000. And now I can say I'm CFA. And then say you have to do training to do professional services, conduct or something like it, shit I don't want to [indiscernible]. So I stop paying like, I still do not write CFA in my CV anywhere. So I'm gone, I'm good. I think the artist -- I could say former CFA, I think. I wonder how that would go legally, but I could say former CFA.
Gabriela Borges
analystI don't know if that would give you more or less credibility with the Navios people.
Nikesh Arora
executiveNo, they're very passionate. I think look, [indiscernible], like eventually long-term data centers have an 18% IRR. So in the meantime, you can take funding CapEx with equity is a bad economic decision, but you guys can tell me that. I don't think so. But for now it's working.
Gabriela Borges
analystI think that's all the time we have. Please join me in thanking a wonderful Nikesh [indiscernible].
Nikesh Arora
executiveThank you guys. [indiscernible].
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 255,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 255,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.