CLAIM #66810 · Palo Alto Networks Inc (PANW) · 2025Q4 earnings call · Nov 19, 2025 · due Jan 31, 2030
“These offerings, each with very large TAMs, continue to gain momentum and reinforce our conviction in achieving $15 billion in next-generation security ARR by FY '30 on a stand-alone basis.”
Nikesh Arora · CEO
In context
“Nikesh Arora (CEO): Thank you, Hamza. Good afternoon. Thank you, everyone, for joining us today for our earnings call. As you can see, we had a strong finish to the fiscal year. We've just closed a landmark quarter, capping a year of disciplined execution and strategic acceleration. Our results this quarter are a direct reflection of a strategy we have been architecting for years, anticipating where the market is going and building the future of cybersecurity before it arrives. This is a moment of conviction, both for us and for our customers. We're proud to be the first dedicated cybersecurity company to surpass a $10 billion revenue run rate. While this milestone is significant, it is not the ultimate goal. Our focus has already shifted to leveraging the scale to define the next decade of cybersecurity. The very fabric of technology is being rewoven by AI, creating a vast, new and complex attack surface. In this new era, security is no longer a bolt-on. It is a foundational enabler of transformational success. The record-breaking number of platformization deals this quarter demonstrates that customers are not just buying products; they are buying into a strategic partnership. We believe that integrated best-of-breed platforms deliver superior security outcomes and our customers are validating this conviction by making larger, more strategic commitments with us than ever before. During Q4, many of the deals our teams had been working on during our fiscal year came to fruition. We saw robust activity across the board. In Q4, our bookings growth turned a corner and was the highest we've seen in 2.5 years. This growth is driven by deals across our platforms and also as a result of strong renewals and upsells across our existing portfolio. The robust booking growth was coupled with strong next-generation security ARR and revenue performance. This, coupled with prudent financial management, allowed us to exceed our full year guidance metrics across the board. RPO grew 24% year-over-year in Q4, an acceleration versus the prior year. It is early days, but we see the quality of revenue, ARR and retention is consistently higher across our platform customers. This bodes well for our long-term targets of Palo Alto Networks' platform business. Next-Generation Security ARR grew 32% and net new ARR for the quarter was also up double digits year-on-year. We had strong contributions across our portfolio particularly SASE, XSIAM and software firewalls. Our investment in software firewalls and SASE are bearing fruit. As our customers end up in a hybrid compute environment across multiple clouds, we expect to continue to see strength in our software firewall business. These offerings, each with very large TAMs, continue to gain momentum and reinforce our conviction in achieving $15 billion in next-generation security ARR by FY '30 on a stand-alone basis. This top line growth, coupled with scale effects and our prudent financial management has allowed us once again to expand our operating margin. Additionally, continued deft management of our deferred payments plan portfolio has allowed us to deliver 38% plus free cash flow margins for the third consecutive year. Not just that, we now believe that structurally, we have visibility to go even higher on our free cash flow margins, more from Dipak on this later. Demand for cybersecurity remains strong. Our customers are looking to us to help them secure their cloud and AI transformation journeys. We continue to see GenAI conversations as it becomes imperative for our customers to deploy productivity tools, coding tools or revamp their customer systems to enable natural language conversations. All these use cases for AI need to be protected, no pun intended. Our timely acquisition of Protect AI, which we completed this quarter coupled with our native abilities around our AI firewalls are driving conversations across many platform customers and prospects around securing the AI infrastructure. Adoption of GenAI is happening faster than any previous technology trend. Recent internal study amongst our customers showed GenAI traffic is up over 890% in 2024. Following this, data security incidents related to GenAI more than doubled since last year. With this rapid adoption of AI comes a new and complex attack surface. That's why in early Q4, we introduced Prisma AIRS, the industry's most comprehensive AI security platform. AIRS is a unified platform that empowers organizations to deploy AI bravely by providing end-to-end security across every AI application, agent model and data set. It closes critical blind spots and secures AI deployments everywhere, ensuring confidence and compliance, but securing the AI you build is only half of the equation. The other equally critical side is securing how employees use third-party AI. Our AI access solutions provide the deep visibility and granular control needed for safe adoption of those services. We are unique in providing a strategy for both sides of the landscape, each with integrated DLP controls to protect our customers' sensitive data. This complete vision is resonating, and we have a strong combined pipeline for AI security offerings. The chart you see here tells a powerful story. It's not just a graph of numbers going up. It's a visual representation of our customers' growing conviction in our strategy. The question is why is this happening? It is because we made a promise to our customers that when they partner with us, they are investing in platforms that are constantly evolving, and we are going to stay ahead of the threat landscape. Time and again, you've seen the future first. We saw it with the tectonic shift to the next-generation firewall, which we pioneered 17 years ago. You saw it with the move to the cloud and with the rise of SASE, we're now the clear leader. We saw the inevitable shift from reactive SIEM to proactive powered SOX as well as in XSIAM, a platform that is now our fastest-growing offering ever. We saw the market's ultimate shift towards the world we define as platformization, integrated platforms that deliver superior security outcomes; a framework our peers once again are now rushing to imitate. We continue to evolve our platforms and this quarter was no exception. In our network security platform, we announced PAN-OS 12.1 Orion, which includes new appliances designed to provide an easy path to quantum readiness and multicloud security. We are anticipating threats of tomorrow, so our customers don't have to. This commitment to future-proofing their investments while we're seeing robust interest in integrated subscriptions like CASB and DLP, building on the launch of Cortex Cloud in Q3, we delivered powerful new capabilities like Application Security Posture Management, or ASPM helping to redefine application security for the demands of the AI era. Needly built into our Cortex Cloud platform, ASPM provides a single source of truth correlating data from our native scanners and third-party tools to secure the entire AI developer life cycle. This allows our customers to break down the silos between their teams and focus on remediating the critical vulnerabilities that truly matter. And our XSIAM platform continues to expand beyond a score wartime mission with new peacetime modules like exposure management that proactively identifies and fixes security gaps before attack can ever happen. That confidence translates directly into the platformization traction you see here. These platformizations are driving superior financial outcomes for us and better security outcomes for our customers. In Q4, our net retention rate amongst platform customers was an impressive 120% to nearly 0 churn. This is the ultimate proof of the value we deliver and the deep strategic partnerships we are building. As we aim to more than double the number of platformization in the next 5 years, we believe our foundation for sustainable growth becomes stronger. This underpins our confidence in achieving $15 billion of NGS ARR on a stand-alone basis by FY '30. The clear validation of our strategy is in the landmark deals we're signing. These are not product sales. These are deep partnerships with the world's leading organizations to transform the security posture. We had one of our strongest large deals quarters ever. Customers who were $5 million and $10 million in ARR were up approximately 50% year-over-year and $20 million plus ARR customers are up nearly 80% year-over-year. These types of large multi-platform deals hardly existed a few years ago and showcase our customers' growing commitment to us. Let's look at a few examples. A leading global consulting firm signed a deal for $100 million in Q4 for cloud security and SASE, including a purchase of our new AI access security product. The customer lacked identity entitlement controls over AI and cloud environments and also required comprehensive secure access offerings that could scale globally across its employees, contractors, and clients. Our deep relationship with the company C-suite were also critical to landing a deal of this size. With this deal, this customer is now fully platformized and provides us an ARR of $50 million. Next, a leading European bank signed a $60-plus million deal. This customer is going through a significant digital transformation and adopted XSIAM with multiple goals in mind: to address an expanding attack surface while simplifying their security stack and keeping costs under control. Platformization was a competitive edge as part of this deal, and we have become a true security partner as now they have 3 platforms with us. Finally, a leading U.S. insurance company purchased $33 million across network security, SASE, SecOps, and Cloud Security. This customer needed to improve their security posture, level up their SOX analysts, and drive further automation to reach their goals of a 15-minute mean time to contain. This involves using AI and machine learning to assist analyst teams while also reducing their false positives. In addition to their existing Palo Alto network spend, this customer is now platformized on network security, cloud, and security operations. There's a common theme developing across these platform deals. While customers are consolidating and simplifying their security stack in part to optimize costs, the larger benefit comes from the improved security outcomes. This includes faster incident response times, a better user experience, and removing the operational burden of stitching together point products. As our customers recognize the value of platformization, they're increasing their commitment to us reaffirming our strategy and vision. Now shifting to network security, which had a strong Q4. Network security continues to account for over 75% of our bookings. Although over the last 5 years, we have transformed the nature of this business. Now over 60% of our network security bookings are driven by software form factors across SASE and virtual firewalls. In addition to having an integrated platform that allows for a consistent pane of glass policy and more than 10 software subscriptions, we also continue to lead the market and gain share across the capabilities as a singular best-of-breed solution if our customers desire. As enterprises look to secure increasingly hybrid workforces and IT environments, we believe our platform is well positioned to allow our customers with any of our products to consolidate on our platform. Our growing mix towards software form factors once again drove better-than-expected growth this quarter. Our software part of the business had another strong quarter in Q4, with ARR up nearly 20% year-on-year and almost double the total contract value. As a result of the strong showing of our software firewalls and with our steady growth in hardware, slightly ahead of industry growth, we saw product revenue growth of 19% year-over-year, which is market-leading in its category at scale. Our software market share is nearly 50%, and our product is native in all major public clouds. This quarter, we signed a $60 million deal, significantly expanding our partnership with a leading U.S.-based cloud provider. All in, we generated nine figures in deals across the major cloud service providers in Q4. As I shared earlier, we're also building momentum in AI runtime security with Prisma AIRS as customers look to secure the growing AI attack surface. In Q4, this included an 8-figure deal with a global professional services company with a strong pipeline; we see an opportunity for AIRS to become a growing contributor in the next 5 years. We also continue to gain share in hardware firewalls. As mentioned earlier, this past week, we launched PAN-OS 12.1 Orion and newer appliances designed to provide an easy path to quantum-safety and multicloud security. We saw modest improvements in hardware demand in Q4, but expect this will continue to be a mid-single-digit grower in FY '26. All in all, our next-generation network security business, which includes software form factors like SASE and software firewalls, reached $3.9 billion in ARR, up approximately 35% year-on-year. We believe this makes us the largest and fastest-growing next-generation network security player at scale. Speaking of SASE, this continues to be our fastest-growing product in network security. As customers transform the networks to keep pace with delivering first-class security capabilities for remote users and branch offices, we continue to see strong growth for SASE. Many SASE projects are large and transformational, which is well suited for our comprehensive enterprise-focused expertise. This quarter, we won our largest SASE deal, a $60 million contract with a global professional services firm covering nearly 200,000 seats. This was in addition to a record number of 8-figure SASE deals. We're gaining share. For the last year, we displaced incumbent SASE vendors in over 70 accounts, exceeding $200 million in TCV. Our SASE ARR grew 35% year-over-year, more than twice as fast as the overall market. We now have over 6,300 SASE customers and account for 1/3 of the Fortune 500. Meanwhile, the drivers of our SASE growth are broadening this quarter. We once again saw particular strength in Prisma Access Browser. The browser is becoming the new operating system for the enterprise, the primary interface for AI and cloud applications. Securing it is not optional. We sold over 3 million licenses in Q4 alone, resulting in our cumulative seat count more than doubling on a sequential basis to over 6 million. Notable deals include an over $3 million transaction with a leading U.S. pharmaceutical company who purchased Prisma Access Browser for over 80,000 seats. We are beginning to see browser wars as we see the adoption of AI. Understandably, this is a requirement as we march towards agents. Interestingly, it will become impossible to allow employees access to non-secure browsers in the future. As more and more critical applications and data reside within the browser, it naturally becomes a target for cyber attacks. Prisma Access Browser's built-in controls and real-time visibility are designed to help ensure that sensitive data remains safeguarded during browsing sessions regardless of the user's location or the application they're accessing. And we believe it is strategically positioned to be the future OS in enabling secure and productive work in an AI-driven world. We expect to see browsers become an integral part of the SASE stack for all of our customers. Moving on to Cortex and Cloud, we saw broad-based strength in Cortex and Cloud as well with combined ARR up nearly 25% year-over-year in Q4. For years, the industry has been stuck in an old SIEM paradigm, collecting logs, writing rules and overwhelming analysts with alerts. We saw the writing on the wall; this model is not sustainable in the age of AI-powered attacks. It's a battle that humans alone cannot win, and our customers are seeing it too. XSIAM, our autonomous SOC platform, and our fastest-growing product ever is modernizing and disrupting the SOC market with AI, and we continue to see amazing milestones. This includes reducing customers' mean-time to respond from weeks to minutes. Today, over 60% of deployed customers cite mean-time to respond in under 10 minutes. We ended Q4 with approximately 400 customers on XSIAM, and the average ARR per customer continues to be over $1 million. Nearly 1/4 of XSIAM customers are represented in the Global 2000, creating a marquee list of referenceable customers across a number of major industries. Beyond XSIAM, Cortex XDR saw deals over $1 million grow 30% year-on-year. As we continue to build on our industry recognition, we are seeing opportunities in larger accounts. I also want to highlight the growing significance of Cortex Cloud. As the market shifts from static posture management, the urgent need for real-time runtime security, our thesis on the convergence of cloud, security, and security operations is proving correct once again. This is where we are fundamentally different from the competition. While others may offer strong cloud posture tools or a separate SIEM, we're the only ones to natively unify a best-in-class CNAPP with our AI-powered SOC platform. This allows our customers to move beyond simply reporting on misconfigurations to actively stopping cloud attacks in real time. Cortex Cloud allows our customers to not only shift left to secure applications during development but also shield right, protecting them in production. The platform is already gaining significant validation. It was recently praised for its ability to fully secure the entire lifecycle of cloud-native applications and has achieved FedRAMP high authorization, a critical credential for our public sector customers. This product set is resonating with the market. Early interest has driven a strong pipeline, spending hundreds of customers who understand the need just to stop cloud attacks in real time. Our platforms are powerful data-centric engines for organic innovation. Our core thesis is that the integrated data we capture from across network, cloud, and security operations is the ground truth needed for a whole variety of security use cases. For AI to be effective, it needs this complete contextual data, a capability unique to our platform approach. This massive data stream is what makes our XSIAM platform so effective in its primary wartime mission of stopping active threats. But as the slide illustrates, we are now leveraging the same powerful data to expand into new peacetime missions. By applying our AI to this rich data set, we are organically creating new modules and expanding into new TAMs like exposure management and email security. This represents an $18 billion opportunity for us in fiscal year 2026 and beyond. We see significant upsell opportunities from these modules as they attach to larger XSIAM deals. We're encouraged by the early customer feedback on these new capabilities. This is our data-to-market engine in action, allowing us to explore new frontiers in security and deliver continuous value to our platform customers. To close, we're exiting FY '25 with strong organic momentum as we march along our path to that $15 billion target. Our bookings and ARPU accelerated this quarter, driven by large deal traction and a sharp focus on excellence and execution. The results of our customer-centric strategy are clear. We're seeing more customers platformize with us than ever before, not just to save money, but to achieve a level of security that a fragmented approach simply cannot provide in an AI-driven world. This realization that platformization is the way forward is also the engine behind our strong Q4 results and our confident outlook. We see broad-based strength across our network security, cloud and SecOps segments, and a strong pipeline as a majority of core sellers are now equipped to sell across multiple platforms. The strong early traction with Prisma AIRS and with our relentless focus on innovation, we believe, Palo Alto Networks can be the ideal partner to help organizations achieve and secure their AI transformation goals. However, before I hand over to Dipak, let me also talk about what we see for FY '26. Looking ahead, we have multiple tailwinds driving our business in FY '26 and beyond. In network security, there is growing demand for software firewalls and SASE, which continue to grow well above the market. The higher mix of software gives us confidence in the sustainability of double-digit product revenue growth in FY '26. We have multiple newer products contributing to our growth, including Prisma AIRS and secure browsers, each with large pipelines. In Cortex, XSIAM continues to deliver rapid growth at scale. AI is transforming the SOC, and we believe we are well positioned to capitalize on this. Our migration to Cortex Cloud continues to progress. We believe we are well positioned to capitalize as the market evolves from posture management to real-time security for AI. Of course, we've heard the market, and it's clear our customers are asking for comprehensive security platforms. Over the last 7 years, I have been asked often, why are we not a player in identity? For the longest time, I believed that we were not at an inflection point. But as we saw the emergence of Agentic AI, as we saw AI getting mass adoption, we are beginning to reach conviction that the identity market will inflect in the next 12 to 24 months. If you believe that we have been able to identify inflections well at Palo Alto Networks, it is important for you to believe that we have this one right as well. Similar to our roots in the network, identity is a key enforcement point for enterprise security. Unlike most forms of security, like network firewalls, identity is also a real-time product. Because of this, we believe that the future for Identity will actually be owned by somebody who is well-prepared to take on the challenges of identity going forward as opposed to a new player. Hence, we have diverged from our original approach of going and buying first-in-market best-of-breed products to owning our categories. Instead, we believe the future in this category is going to belong to somebody who's already established a strong reputation and is a leader in identity security. So as the widespread deployment of agents makes privileged access more important, we believe security, not SSO-focused identity vendors are best positioned to address emerging needs. And that growth in PAM data and sensors will further solidify category leaders like CyberArk. Second, with 90% of our breaches involving stolen or mismanaged credentials, every user machine and AI agent should be considered a privileged user rather than just a small set of IT administrators. CyberArk's reach extends to over 8 million privileged end users and over 50% of the Fortune 500, with the right product strategy and go-to-market acceleration from Palo Alto Networks. We believe CyberArk will be able to both deepen its penetration in PAM and target a significantly larger base of global IAM users and machine identities. Thirdly, the identity industry is lacking a broader platform. Today, over 100 vendors are vying to capture customers' attention across multiple functional domains. These domains are converging as the complexity of stitching together disparate solutions and the rise in identity-related breaches push enterprises to favor better integration. We believe Palo Alto will take an accelerated CyberArk platform vision as they look to expand across multiple identity domains by combining their leadership in identity security with our industry-leading AI-powered security platforms. With our platformization approach coupled with our go-to-market, we will be able to offer the most complete integrated security solution in the market. We're building an evergreen security company that will define the industry for decades to come. After many detailed conversations, we have strategic alignment with the CyberArk team and a common culture of innovation. Following the close of the transaction, we will optimize our combined go-to-market resources and continue to lead innovation. To provide some context, we have nearly 10 times the number of core sellers, and they see an opportunity to expand CyberArk's presence into our much larger 75,000 customer base. Overall, we believe this accelerates our mission to double the value of our joint businesses over the next 5 years. We are strategically entering this category now to define the next chapter of cybersecurity for the AI era. We look forward to providing more details on our strategy once we close the transaction. Before I hand over to Dipak, I want to take a moment to speak from the heart on the important leadership announcement we made today. Our founder, our first innovator and a true titan of this industry, Nir Zuk, has decided to retire after more than 20 years. When you think about Palo Alto Networks, you think of Nir. It is impossible to overstate Nir's impact. He didn't just start a company. He started a revolution with the next-generation firewall, forever changing the security landscape. Personally, it has been a privilege to call him a partner and a friend. The relentless competitive fire that defines our culture is his legacy. It is in our DNA. His legacy isn't just in our products; it isn't in our people. So to Nir, on behalf of every single one of us, thank you. This marks a seamless and natural transition as we pass the torch to Lee Klarich, who will now serve as both Chief Product and Technology Officer and as a member of our board. For years, almost as many as Nir, Lee has been the chief architect of our product strategy, masterfully turning our vision into the industry-leading platforms we have today. Appointing him as both CP and CTO and to our Board of Directors is a reflection of the profound trust we have in his leadership. This ensures the soul of our innovation not only continues but accelerates into the future. With that, let me pass on to Dipak.”
Verify independently
SEC filings for PANW ↗ · Claim quote is verbatim from the 2025Q4 earnings call.