MAAT INDEX

CLAIM #66761 · Palo Alto Networks Inc (PANW) · 2025Q2 earnings call · May 20, 2025 · due Jul 31, 2025

These results allow us to raise our operating margin and EPS guidance for the year.

Nikesh Arora · CEO

PENDING
graded after results covering Jul 31, 2025 are reported

In context

Nikesh Arora (CEO): And thank you for joining us today for our earnings call. I'm excited about our Q2 results. Our teams did a phenomenal job of executing at scale. We've made considerable progress in platformization, allowing us to outperform both our top and bottom line expectations for this quarter. We delivered on our high RPU expectations towards the top of the range. This gave us strength in our NGS ARR and also allowed us to outperform our revenue expectations. In Q2, growth was pretty broad across the entire portfolio, with strength across all three geographies and platforms. In particular, we saw strong performance from large deals internationally and also strong contribution from SaaS, software firewalls, and XIM. On the profitability front, we delivered operating margins ahead of our internal target despite some one-time events. Our efficiency initiatives continue to bear fruit, including some promising early contributions from AI. These results allow us to raise our operating margin and EPS guidance for the year. We're also very happy with our free cash flow performance and continue to be confident in managing our free cash flow guidance over the next few years as outlined. More from Dipak on this later. From our vantage point, the outlook for cybersecurity seems to have been robust in Q2, and is likely to stay so over the rest of this year. Despite the settling in process of the new administration, we see signs that we are going to be able to see reasonable growth through the rest of the year. As the conversation around AI continues to get omnipresent, and companies race to evaluate, experiment, and deploy AI, they're discovering that some of the legacy architectures come in the way of their aspirations. Interestingly, this is resulting in a resurgence of cloud transformation projects and consequently demand for network security and network transformation. While cybersecurity's derivative effect is clear, the longer-term trend towards AI is going to continue to underpin technology transformation, and hence, continue to drive demand for security. The transformations are all geared to embedding AI capabilities across infrastructure. Additionally, many of them involve changing strategies towards data and a growing understanding that data security will be more and more important in the future. We see that from the heightened interest in data security posture management where our acquisition of DIG seems to be proving prescient. To fully harness the power of AI, customers must unshackle their data from disparate legacy systems and providers and open up broader access and lean into the cloud. Cloud infrastructure is much more dynamic than on-prem IT, creating risk. As cloud data volumes grow and customers utilize new services from the cloud service providers, such as modern data repositories, and doubling down in ensuring they're protecting their cloud environments from development to runtime. Understanding who's accessing what data in the cloud and putting controls around these new services. In other words, the cloud is becoming an integral part of the enterprise, and the same level of security must be delivered. A constantly changing attack backdrop is also compounding this inflection we've seen. There are tangible signs that bad actors use AI to accelerate attacks. Google recently found that adversaries can use generative AI to more rapidly create attacks including custom payloads, iterate on malicious scripts, and use evasion techniques. Additionally, bad actors using generative AI do reconnaissance of target organizations, including their infrastructure and hosting providers, which are often exploited in attacks. We have a new technological revolution that requires us to secure AI. As customers leverage the cloud, transform on-prem infrastructure, and respond to the escalating threat environment driven by AI, they're transforming how they manage security operations. Legacy offerings cannot unify SecOps across cloud and on-prem, across multiple vendors, and also take advantage of AI. AI is key for providing automation to help stitch together overwhelming volumes of data and generate the near real-time analysis of remediation needed to keep pace. As I said, security is a data problem. The data has to be all in one place for AI to have context and stop threats in their tracks. Our industry has to change the paradigm by shifting from fragmentation to platformization to enable the best security outcomes. In a recent study we did with IBM, platformized organizations take 72 days less to detect and 84 days less to contain a security incident. Our teams are busy helping customers as they accelerate cloud adoption and transformation across their environments. They need integrated security products and platforms for AI to be most effective in staying ahead of the active cybersecurity landscape. Herein, we're pleased with our progress in driving our platformization strategy and the adoption and endorsement of platformization broadly across the industry. As I mentioned a few quarters ago, I wish we had made this move earlier. We're seeing some interesting behavior that reinforces our conviction that the future state of cybersecurity will have to be AI-enabled platforms that can markedly improve the speed of response. We delivered approximately 75 new platformizations in Q2, up from approximately 45 in the year-ago period. We now have a total of over 1,150 platformizations within our top 5,000 customers. As you might expect, many of our platformizations start with network security and are from customers that have platformized in one area. However, our number of two-platform customers grew over 50% in Q2, and we're seeing a number of three-platform customers up three times year over year. Also, the number of customers platformized in Cortex is up more than three times, reflecting strong excitement. We're excited to see the number of parts we have had success driving strategy so far, and our Q2 performance keeps us on track to achieve our stated target of 2,500 to 3,500 platformizations by fiscal year 2030. Investors have always asked me what platformization deals look like. I want to provide a few examples based on deals we signed this quarter. A bank in Asia signed a transaction worth over $65 million in Q2 platformizing with us for the first time in Cortex, with a significant XIM deployment. They have been leveraging XDR and other Cortex capabilities several years ago also a network security customer and a QRadar customer. They had many point products in their SOC and were not getting the outcomes they needed. With limitations in the time to discover and remediate security incidents resulting in compliance issues. In platformizing on Cortex, our LGS AR with this customer increased by five times over $12 million. Here we are. We look forward to driving a successful deployment here, which can be an avenue to platformizing a network or cloud security in the future for this customer. A US municipality signed a transaction over $60 million which included renewal of its network security estate and expansion across our portfolio. The customer leverages all three of our four form factors within network security and is already platformized there. The deal also included Cortex and Prisma Cloud, which positions us well for future platformization in these areas. GSA are here. Increased over 40% in the last twelve months. Over $11 million. European automated automotive manufacturers signed a $25 million transaction in Q2 that already platformized with us in network security and cloud security. That includes several capabilities as they renewed their firewalls, and support footprints, including IoT, virtual firewall, and SASE. This is a complex customer, and we also secured business with them in Cortex, with XTR, XO, and Expanse, as well as Prisma Cloud. In doing so, we're now well-positioned in the future to consolidate the SOC opportunity with XIM. For this customer, the NGSA IR grew 50% to $9 million. More broadly than these anecdotes, the growth in our large deals tells a story. We had 74 accounts that had transactions over $500 in Q2, up 25% year over year, and 32 accounts added transactions over $10 million, up over 50%. Now moving on to an update about our first security platform network secure NetSec. Our Q2 net segment was driven by strong software demand. We continue to lead the market in network security, which is approximately 80% of our bookings. Our Zero Trust platform combines three best-of-breed form factors built on a consistent architecture. This is fast becoming a requirement as applications proliferate across data centers, hyperscalers, and SaaS. Meanwhile, users are increasingly distributed across headquarters, remote locations at home, and other places. And also there are now soon to be nonhuman users in the form of AI agents, where interactions with applications must be secured. Disjointed network security offerings require significant resources to be applied to integration, creating the possibility of gaps in security policies given the disparity of control panes and more importantly, unless we can harmonize the data across the network, it'll be challenging for customers to adopt AI-enabled security capability in the future. We have to believe that in the future, all solutions will need to integrate harmonize data, and use that to train AI agents to solve security. Looking deeper into firewall as a platform, our bookings accelerated and grew by 21%. Within this, we continue to see stable demand in the appliance market. That stability, coupled with us continuing to take market share, allowed us to grow our appliance bookings in the mid-single digits. There's a refresh cycle coming from many players in the industry, and we believe we are well-positioned to benefit from it. Software and SaaS make up approximately two-thirds of our firewall and platform bookings and grew one and a half times faster than the rate of the total firewall as a platform business. We have been on a multiyear journey to reinvent our security subscriptions, which we use consistently across all three form factors. Each of these advanced subscriptions are cloud-delivered, and at least significantly differentiate with what's in the market. Delivering these incremental innovations into our platform, like advanced subscriptions in the network security, makes our customers' adoption seamless. This is core to our strategy of staying ahead of our customer security needs with future-proof innovation. There's also a win-win for Palo Alto Networks, Inc. and the customer. Next, let's dive deeper into SaaS in a software firewall business. As customers transform their networks to keep pace with delivering first-class security capabilities for remote users and branch offices, we continue to see demand for SASE. Many SaaS projects are large and comprehensive, which is well suited to our rich offering. SASE continues to be our fastest-growing form factor in network security and a strong contributor to our growth. We grew SaaS customers by over 20%, we grew bookings well north of 50% and increased deals over $1 million in value by two and a half times. We now have over 5,600 SASE customers and over 23 million individual seats. Across our SaaS base as well as our GP customers that have been chosen to help protect the base of over 100 million users. Meanwhile, the drivers of our SaaS momentum are broadening. Bookings of newer modules of the SASE platform such as Autonomous Digital Experience Management or ADEM, Cloud Access Security Broker or CASB, Prisma access browser, which you just saw an ad for, NAI Access grew nearly fourfold this year. Customers are happy with their initial SaaS deployments, so adding these to derive a more modern security environment and streamline their vendor landscape. I'm particularly excited about the momentum we're seeing with Prisma Access Browser. Roughly one-third of the new Prisma Access seats we sold in the quarter work for our secure browser. We signed a transaction in Q2 for over $10 million with one customer. With a total of over $30 million in Prisma Access Browser bookings in Q2, and growing seats by 95% quarter over quarter. We also continued to innovate in SaaS, releasing the mobile version of our integrated secure browser. This browser, integrated with Prisma Access, offers mobile phone and tablet users the same robust security and access to private applications. We added capabilities to AI access, ensuring organizations can apply controls to how their users interact with AI-based applications. We can now provide real-time visibility into over 1,800 applications, up from 500 six months ago. AI access comes with out-of-the-box policies to manage functions such as uploads, downloads, and sharing capabilities. In a short period of time, this quarter, we crossed 300 customers who use the AI access capability. We can also provide comprehensive data protection to secure sensitive data secrets and intellectual property. Now turning to software firewalls. This has been a strong area of growth. We saw 50% bookings growth in our software firewall business with AI and public cloud adoption continuing to be the strongest driver. Approximately 70% of our VM deployments are now in the public cloud. We continue to see customers adopt our software firewalls alongside our hardware appliances. As a testament to this, about two-thirds of our software firewall customers are also hardware customers, showing the hybrid nature of the solution and the need for platformization. We also continue to innovate in this business. Early in Q2, we released our API-based AI runtime security capability, adding the ability of our product directly to secure applications without being in the traffic path. Later in Q2, we leveraged this capability to secure AI agents many of our customers look forward toward the value propositions of agents but need to secure them as they would need to secure any other user or application. This capability helped drive our first seven-figure software firewall transaction for AI in the quarter, and we have a healthy eight-figure pipeline for AI firewalls for the future. Now moving on to Cortex. This morning, we had an exciting announcement. We took our industry-leading Prisma Cloud platform and evolved it with more capability, merged it with our CDR capability, and our Cortex platform, to announce the introduction of Cortex Cloud. Cortex Cloud is now the industry's first end-to-end cloud security platform which deeply integrates into the SOC. As we have been delivering cloud security over time, we've learned that customers are keen to ensure that they can trace the cloud security capability all the way into runtime and production and do real-time security against that. We're also delivering a powerful data security DSP experience and real-time security capability with our cloud agent. Again, this is now natively connected to the Cortex platform. This is where cloud security is going. We have anticipated the market change in cloud security, as one reason for our momentum and leadership in the space. Recall that in our early days, we entered the cloud security market in 2018 with two acquisitions and continued to build up these capabilities, pioneering the category and leading with our initial cloud posture capabilities. Soon after, it became apparent that too many security issues were reaching production, and organizations could not keep up with remediating them once applications were deployed. We led the trend to shift left, connecting this to the cloud posture to address security that should be in place before deployment. Attackers took note as customer deployment of mission-critical applications and sensitive data accelerated into the cloud. Our own Unit 42 research shows that 80% of security exposures are found in cloud attack surfaces, with a 66% increase in threats targeting cloud environments. With these evolutions of the attack backdrop, we believe cloud security operations must be an integrated part of the organization's security strategy. Existing Prisma Cloud customers will have a seamless upgrade to Cortex Cloud to benefit from AI-powered prioritization, automated remediation, and a new simplified powerful user experience. Additionally, they can also adopt Cortex's best-in-class CDR capability to gain real-time cloud security capability. So the unification of enterprise to cloud can further drive the adoption of XIM in the customer's cloud environment. Cortex Cloud natively integrates with cloud data, context, and workflows within Cortex XIM, significantly reducing the mean time to respond to modern threats with a single unified SecOps solution. More importantly, because we are natively integrating cloud solutions into the SOC, XIM has now transformed into both a cloud and enterprise SIEM. We're excited about the prospects for us to maintain or accelerate our strong momentum. As I mentioned, we are making this announcement in the back of strong momentum in our cloud security and security business. I want to give you some highlights. We drove bookings growth of approximately 50% in both Cortex and Prisma Cloud in Q2, with healthy momentum in customer growth of approximately 20%. Fueling this customer growth, we again signed hundreds of new XDR customers in Q2, which become opportunities for transformation on the broader Cortex platform in the future. Our XDR momentum continues to be fueled by the efficacy of our product. This quarter, we achieved further external recognition, achieving leadership results in the most recent MITRE ATT&CK evaluations. XIM, our AI-driven SecOps platform surpassed the $1 billion cumulative bookings milestone in Q2. While we know we have a winning product with XIM, we're also starting to see external validation of our leadership with Frost and Sullivan and OMDA recognizing us as leaders in the same category. Contributing to our Cortex strength in Q2 was over $100 million in QRadar-related bookings. Our pipeline on QRadar is equally strong, leaving us optimistic about our IBM partnership as a driver of Cortex. On the cloud side, we saw the adoption of our capabilities continue to broaden. With DSP integrated with Prisma Cloud, we see early adoption to be one of the strongest among any of our new cloud security capabilities. We're excited to see the success continue with DSP as part of the Cortex Cloud product we announced this morning. We're also seeing particular success among some of the largest companies in strategic industries. For example, several SaaS companies signed significant cloud security deals with us in Q2. In this industry, XIM is the top ten SaaS companies outside of the cybersecurity market, leveraging their cloud security capabilities to secure the customer's environment. As you can see, we saw strong momentum across the business in Q2. We're seeing customer imperatives around AI driving accelerated cloud adoption and infrastructure investment, which is supporting strong cybersecurity demand. This healthy spending backdrop along with strong execution from our team and platformization helped drive the healthy top line trend we saw in Q2 across RPO, GSARR, and revenue. We remain optimistic about sustaining this momentum as our sales teams leverage our ecosystem and continue to become more adept at aligning our many capabilities into a unique platformization journey for each customer. We remain confident in our long-term NGS ARR forecast. Supporting this is a steady innovation stream and momentum across our portfolio. Leading early mover into new market categories like enterprise browser, secure AI by design, the AI-powered SOC, are making it easy for our customers to adopt key new innovations with our platform approach. Lastly, we're driving profitable growth, balancing operating margin improvements with strong cash flow. We continue to make progress in driving a culture of efficiency at all levels of Palo Alto Networks. You've seen the results of this over the last few years. This focus on efficiency and some early success in AI-based initiatives gives us the confidence to continue delivering profitable growth. I will now pass on to Dipak for his remarks.

Verify independently

SEC filings for PANW · Claim quote is verbatim from the 2025Q2 earnings call.