Item 1. Business
60K characters. Original on sec.gov · Markdown
Item 1. Business
General
Palo Alto Networks, Inc. is a global cybersecurity provider with a vision of a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.
We empower enterprises, organizations, service providers, and government entities to protect themselves against today’s most sophisticated cyber threats. Our cybersecurity platforms and services help secure enterprise users, networks, clouds, and endpoints by delivering comprehensive cybersecurity backed by artificial intelligence (“AI”) and automation. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture and makes security faster, less complex, and more cost-effective. We focus on delivering value in four sectors of the cybersecurity industry:
Network Security:
- Our network security platform, designed to deliver complete zero trust solutions to our customers, includes our hardware and software ML-Powered Next-Generation Firewalls, AI Runtime Security, as well as a cloud-delivered Secure Access Service Edge (“SASE”). Prisma® Access, our Security Services Edge (“SSE”) solution, when combined with Prisma SD-WAN, provides a comprehensive single-vendor SASE offering that is used to secure remote workforces and securely enable the cloud-delivered branch. Our network security platform also includes our cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, GlobalProtect®, Enterprise Data Loss Prevention (“Enterprise DLP”), AI for IT Operations (“AIOps”), SaaS Security, and AI Access Security. Through these add-on security services, our customers are able to secure their content, applications, users, and devices across their entire organization. Strata Cloud Manager, our network security management solution, can centrally manage our network security platform irrespective of form factor, location, or scale. Strata Cloud Manager includes the Strata Copilot which provides a natural language interface to simplify and accelerate platform management.
Cloud Security:
- We deliver scalable and comprehensive security across the cloud application development lifecycle through our Code to CloudTM platform, Prisma Cloud. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”), Prisma Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the entire cloud native technology stack across the full development lifecycle, from code to cloud. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.
Security Operations:
- We deliver the next generation of security operations capabilities that combine security analytics, endpoint security, automation, and attack surface management (“ASM”) solutions through our Cortex® platform. These include Cortex XSIAM®, our AI-driven security operations platform, Cortex XDR® for the prevention, detection, and response to complex cybersecurity attacks, Cortex XSOAR® for security orchestration, automation, and response (“SOAR”), and Cortex Xpanse® for ASM. These products are delivered as software as a service (“SaaS”) or software subscriptions.
Threat Intelligence and Advisory Services (Unit 42):
- Unit 42® brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization to help customers manage cyber risk. Our consultants serve as trusted advisors to our customers by assessing and testing their security controls against the right threats, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response and managed threat hunting services.
- 4 -
Product, Subscription, and Support
Our customer offerings are available in the form of the product, subscription, and support offerings described below:
PRODUCTS
Hardware and software firewalls. Our ML-Powered Next Generation Firewalls embed machine learning in the core of the firewall and employ inline deep learning in the cloud, empowering our customers to stop zero-day threats in real time, see and secure their entire enterprise including Internet of Things (“IoT”), and reduce errors with automatic policy recommendations. All of our hardware and software firewalls incorporate our PAN-OS® operating system and come with the same rich set of features, ensuring consistent operation across our entire product line. The content, applications, users, and devices—the elements that run a business—become integral components of an enterprise’s security policy via our Content-ID™, App-ID™, User-ID™, and Device-ID technologies. In addition to these components, key features include site-to-site virtual private network (“VPN”), remote access Secure Sockets Layer (“SSL”) VPN, and Quality-of-Service. Our appliances and software are designed for different performance requirements throughout an organization and are classified based on throughput, ranging from our PA-410, which is designed for small organizations and branch offices, to our top-of-the-line PA-7500 Series, which is designed for large-scale data centers and service providers. Our firewalls come in a hardware form factor, a containerized form factor, called CN-Series, as well as a virtual form factor, called VM-Series, that is available for virtualization and cloud environments from companies such as Broadcom Inc., Microsoft Corporation (“Microsoft”), Amazon.com, Inc. (“Amazon”), and Alphabet Inc. (“Alphabet”), and in Kernel-based Virtual Machine /OpenStack environments. We also offer Cloud NGFW, a managed next-generation firewall (“NGFW”) offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).
SD-WAN. Our SD-WAN is integrated with PAN-OS so that our end-customers can get the security features of our PAN-OS ML-Powered Next-Generation Firewall together with SD-WAN functionality. The SD-WAN overlay supports dynamic, intelligent path selection based on the applications, services, and conditions of the links that each application or service is allowed to use, allowing applications to be prioritized based on criteria such as whether the application is mission-critical, latency-sensitive, or meets certain health criteria.
Panorama. Panorama is our centralized security management solution for global control of our network security platform. Panorama can be deployed as a virtual appliance or a physical appliance. Panorama is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Many of our existing deployments continue using Panorama as the security management solution, while new deployments benefit from using Strata Cloud Manager instead for managing network security estate—including our Next-Generation Firewalls and SASE—with a cloud-based, unified management interface.
SUBSCRIPTIONS
We offer a number of subscriptions as part of our network security platform. Of these subscription offerings, cloud-delivered security services, such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, IoT/OT Security, SaaS Security Inline, GlobalProtect, Enterprise DLP, AIOps, and AI Runtime Security are sold as options to our hardware and software firewalls, whereas SaaS Security API, AI Access Security, Prisma Access, Prisma SD-WAN, Strata Cloud Manager, Prisma Cloud, Cortex XSIAM, Cortex XDR, Cortex XSOAR, and Cortex Xpanse are sold on a per-user, per-endpoint, or capacity-based basis—and they can be activated by customers with or without our firewalls. Our subscription offerings include:
Cloud-delivered security services:
-
Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. It includes mechanisms—such as protocol decoder-based analysis, protocol anomaly-based protection, stateful pattern matching, statistical anomaly detection, heuristic-based analysis, custom vulnerability and spyware “phone home” signatures, and workflows—to manage popular open-source signature formats to extend our coverage. In addition, it offers inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the first offering to protect the enterprise from unknown command and control in real-time.
-
Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. In addition, Advanced WildFire defeats highly evasive modern malware at scale with a new infrastructure and patented analysis techniques, including intelligent runtime memory analysis, dependency emulation, malware family fingerprinting, and more. Once identified, whether in the cloud or inline, preventive measures are automatically generated and delivered in seconds or less to our network security platform.
- 5 -
-
Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. It delivers real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing, malware, and C2. While many vendors use machine learning to categorize web content or prevent malware downloads, Advanced URL Filtering is the industry’s first inline web protection engine capable of detecting never-before-seen web-based threats and preventing them in real-time. In addition, it includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.
-
Advanced DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. Unlike other solutions, it does not require endpoint routing configurations to be maintained and therefore cannot be bypassed. It allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. Expanded categorization of DNS traffic and comprehensive analytics allow deep insights into threats, empowering security personnel with the context to optimize their security posture. It offers comprehensive DNS attack coverage and includes industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking.
-
IoT/OT Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT and operational technology (“OT”) devices, including never-been-seen-before devices, mission-critical OT devices, and unmanaged legacy systems. It uses machine learning to baseline normal behavior, identify anomalous activity, assess risk, and provide policy recommendations to allow trusted behavior with a new Device-ID policy construct on our network security platform. Other subscriptions have also been enhanced with IoT context to prevent threats on various devices, including IoT and OT devices.
-
SaaS Security API. SaaS Security API (formerly Prisma SaaS) is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. It delivers complete visibility and granular enforcement across all user, folder, and file activity within sanctioned SaaS applications, and can be combined with SaaS Security Inline for a complete integrated CASB.
-
SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and new sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. It provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time with best-in-class security. The solution is easy to deploy being natively integrated on network security platform, eliminating the architectural complexity of traditional CASB products, while offering low total cost of ownership. It can be combined with SaaS Security API as a complete integrated CASB.
-
GlobalProtect. This subscription provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. When a remote user logs into the device, GlobalProtect automatically determines the closest gateway available to the roaming device and establishes a secure connection. Regardless of the operating systems, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and, as a result, are protected as if they never left the corporate campus. GlobalProtect ensures that the same secure application enablement policies that protect users at the corporate site are enforced for all users, independent of their location.
-
Enterprise DLP. This cloud-delivered security service provides consistent, reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users. Native integration with our products makes it simple to deploy, and advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside. It helps minimize the risk of a data breach both on-premises and in the cloud—such as in Office/Microsoft 365™, Salesforce®, and Box—and assists in meeting stringent data privacy and compliance regulations, including the E.U. General Data Protection Regulation, the California Consumer Privacy Act, the Payment Card Industry Data Security Standard , HIPAA (Health Insurance Portability and Accountability Act) requirements, and others.
-
AI Access Security. GenAI applications can inadvertently expose sensitive company data, such as intellectual property, trade secrets, source code, financial records and customer information, leading to significant business and compliance risks. In addition, public GenAI tools can be exploited to spread malware and compromise cybersecurity defenses. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies and visualize insights across multiple GenAI-specific attributes. It prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.
- 6 -
- AIOps: AIOps is available in both free and licensed premium versions. AIOps redefines network operational experience by empowering security teams to proactively strengthen security posture and resolve network disruptions. AIOps provides continuous best practice recommendations powered by machine learning based on industry standards, security policy context, and advanced telemetry data collected from our network security customers to improve security posture. It also intelligently predicts health, performance, and capacity problems up to seven days in advance and provides actionable insights to resolve the predicted disruptions.
Secure Access Service Edge:
-
Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent security to remote networks and mobile users. Located in more than 100 locations around the world, Prisma Access consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point-products into a single converged cloud-delivered offering, transforming network security and allowing organizations to enable secure hybrid workforces. Prisma Access protects all application traffic with complete, best-in-class security while ensuring an exceptional user experience with industry-leading service-level agreements (“SLA”s). With native SASE integration, Prisma Access Browser extends Zero Trust to any device—managed or unmanaged—in minutes. Prisma Access delivers exceptional user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management. With these capabilities, Prisma Access delivers an optimized digital experience and application performance to end users.
-
Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional Multiprotocol Label Switching based WAN architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy and performance at a reduced cost. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver an exceptional user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using machine learning and automation.
AI Runtime Security:
- AI applications and large language model (“LLM”) models challenge traditional security. Increasingly sophisticated attacks on AI ecosystems require protection from AI applications, models and datasets. AI Runtime Security continuously monitors AI applications, models and datasets for potential threats and anomalies. It quickly adjusts to evolving attack techniques and detects suspicious activities in real time. It shields customers’ AI application ecosystem from AI-specific and conventional network attacks by leveraging real-time, AI-powered security.
Strata Cloud Manager:
- Strata Cloud Manager enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE environment—from the cloud, via one unified management interface. In addition to getting complete visibility, with Strata Cloud Manager, customers can predict and prevent network health issues, strengthen security, and configure and manage their entire network security estate. Strata Copilot, a part of Strata Cloud Manager, helps security teams quickly and easily find, understand and address threats leveraging the power and simplicity of natural language.
Cloud Security:
- Prisma Cloud. Prisma Cloud is a comprehensive CNAPP, securing both cloud-native and lift-and-shift applications across multi- and hybrid-cloud environments. With broad security and compliance coverage and a flexible agentless, as well as agent-based, architecture, Prisma Cloud protects cloud-native applications across their lifecycle from code to cloud. The platform helps developers prevent risks as they code and build the application, secures the software supply chain and the continuous integration and continuous development (“CI/CD”) pipeline, and provides complete visibility and real-time protection for applications running in the cloud.
With its code-to-cloud security capabilities, Prisma Cloud creates a complete security picture by tracing back thousands of cloud risks and vulnerabilities that occur in the application runtime to their origin in the code-and-build phase of the application. Prisma Cloud does this by consolidating multiple code and cloud security technologies such as Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Discovery and Exposure Management into a single unified platform. The platform enables organizations to “shift security left” and fix issues at the source (in code) before they proliferate as a large number of risks in the cloud. The contextualized visibility to alerts, attack paths, and vulnerabilities delivered by Prisma Cloud facilitates collaboration between security and development teams to drive down risks and deliver better security outcomes. The context helps security teams block attacks in the cloud runtime and developers fix risks in source code.
A comprehensive library of compliance frameworks included in Prisma Cloud vastly simplifies the task of maintaining compliance. Seamless integration with security orchestration tools ensures rapid remediation of vulnerabilities and security issues.
- 7 -
Further, the Code to Cloud Platform is positioned to secure AI-powered applications for enterprises. In March 2024, we announced limited general availability of data security posture management (“DSPM”) capabilities and in May 2024, we released the early preview of AI security posture management (“AI-SPM”) capabilities to our customers. These features were made available to all customers in our August 2024 software release. Prisma Cloud customers can activate them within the platform to discover, classify, protect, and govern AI-powered applications. DSPM and AI-SPM together provide visibility into the entire GenAI ecosystem, identify LLM vulnerabilities, prioritize misconfiguration risks, reduce the risk of data exposure, and surface compliance violations. The native integration of Prisma Cloud with Cortex XSIAM is further expanded with the recent addition of cloud detection and response (“CDR”) capabilities, providing a broader context to protect, detect, and respond to advanced cloud threats. It also brings together cloud security and security operations teams, fostering strong collaboration.
With a flexible, integrated platform that enables customers to license and activate cloud security capabilities that match their need, Prisma Cloud helps secure organizations at every stage in their cloud adoption journey. The platform enables security teams to consolidate multiple products that address individual risks with an integrated solution that also delivers best-in-class capabilities. Prisma Cloud’s code-to-cloud CNAPP delivers comprehensive protection for applications and their code, infrastructure (workloads, network, and storage), data, APIs, and associated identities.
Security Operations:
-
Cortex XSIAM. This cloud-based AI-driven security operations platform for the modern SOC harnesses the power of AI to radically improve security outcomes and transform security operations. Cortex XSIAM customers can consolidate multiple products into a single unified platform that delivers security information and event management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence management (“TIM”), identity threat detection and response, and CDR. CDR is the latest addition to Cortex XSIAM and XDR that addresses the growing need for security teams to respond to cloud threats with purpose-built SOC tools that seamlessly integrate with their security programs. Cortex XSIAM integrates these capabilities into a single, converged platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation. Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.
-
Cortex XDR. This cloud-based subscription enables organizations to collect telemetry from endpoint, network, identity and cloud data sources and apply advanced analytics and machine learning, to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics for network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes.
-
Cortex XSOAR. Available as a stand-alone cloud-based subscription, an on-premises appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and TIM to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.
-
Cortex Xpanse. Available as a stand-alone cloud-based subscription and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.
- 8 -
SUPPORT
Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and certain cloud offerings, which includes ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of spare appliances and other accessories.
Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed and confidence.
Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.
RESEARCH AND DEVELOPMENT
Our research and development efforts are focused on developing new hardware and software and on enhancing and improving our existing product and subscription offerings. We believe that hardware and software are both critical to expanding our leadership in the enterprise security industry. Our engineering team has deep networking security, cloud security, endpoint security, security operations, and incident response expertise as well as expertise in AI and machine learning capabilities that are applied across these areas. Our scale and position in multiple areas of the security market enable us to leverage core competencies across hardware, software, and SaaS and also share expertise and research around threats, which allows us to respond to the rapidly changing threat landscape. We supplement our own research and development efforts with technologies and products that we license from third parties. We test our products thoroughly to certify and ensure interoperability with third-party hardware and software products.
We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2024, we introduced several new offerings, including: Prisma Cloud Darwin release with newly integrated Code to Cloud intelligence capabilities, PAN-OS 11.2 Quasar, Cortex XSIAM 2.0, new Cortex XSIAM features, Prisma SASE 3.0, and Precision AITM. Additionally, we acquired productive investments that fit well within our long-term strategy. For example, in December 2023, we acquired Dig Security Solutions Ltd. ("Dig"), which we expect will enhance our Prisma Cloud capabilities with a DSPM solution; and we acquired Talon Cyber Security Ltd. (“Talon”), which will support Prisma SASE’s approach to provide secure access to business applications for unmanaged and personal devices with an enterprise browser.
We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.
- 9 -
INTELLECTUAL PROPERTY
We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights. We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect and control the use of our proprietary technology and intellectual property rights. We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research and development. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We have registered various trademarks for our company and our products in the United States (“U.S.”) and other jurisdictions internationally. We intend to continue pursuing additional protections for our proprietary technology and intellectual property to the extent we believe it would be beneficial and cost-effective.
Despite our efforts to protect our proprietary technology and intellectual property rights, our rights may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors, third-parties and non-practicing entities, may also claim that our cybersecurity platforms and services infringe their intellectual property rights. From time to time, third parties have in the past and may in the future assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could prevent us from offering certain products or features, require us to develop alternate, non-infringing technology, which could require significant time and during which we could be unable to continue to offer our affected products or solutions, require us to obtain a license, which may not be available on reasonable terms or at all, or force us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risks Related to Intellectual Property and Technology Licensing” in Part I, Item 1A “Risk Factors” in this Form 10-K.
GOVERNMENT REGULATION
We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.
COMPETITION
We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:
-
large companies that incorporate security features in their products, such as Cisco Systems, Inc. (“Cisco”), Microsoft, Alphabet, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;
-
independent security vendors, such as Check Point Software Technologies Ltd. (“Check Point”), Fortinet, Inc. (“Fortinet”), CrowdStrike Holdings, Inc. (“CrowdStrike”), Zscaler, Inc. (“Zscaler”), and Wiz, Inc. (“Wiz”), that offer a mix of security products;
-
startups and point-product vendors that offer independent or emerging solutions across various areas of security; and
-
public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).
As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.
- 10 -
The principal competitive factors in our market include:
-
product features, reliability, performance, and effectiveness;
-
product line breadth, diversity, and applicability;
-
product extensibility and ability to integrate with other technology infrastructures;
-
price and total cost of ownership;
-
adherence to industry standards and certifications;
-
strength of sales and marketing efforts; and
-
brand awareness and reputation.
We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, many of our competitors have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.
SALES, MARKETING, SERVICES, AND SUPPORT
Customers. Our end-customers are predominantly medium to large enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security functions across a variety of deployment scenarios. Typical deployment scenarios include the enterprise network, the enterprise data center, cloud locations, and branch or remote locations. No single end-customer accounted for more than 10% of our total revenue in fiscal 2024, 2023, or 2022.
Distribution. We primarily sell our products and subscription and support offerings to end-customers through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell our products and subscription and support offerings to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 45 calendar days of the date we issue an invoice for such sales. For fiscal 2024, 59.0% of our total revenue was derived from sales to four distributors.
We also sell our VM-Series virtual firewalls directly to end-customers through Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, and Alphabet’s Google Cloud Marketplace under a usage-based licensing model.
Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, which include resellers, global and regional systems integrators, service providers, and cloud providers. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.
Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.
Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors and channel partners that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals. As of July 31, 2024, we had more than 6,500 channel partners.
Global Customer Success. Our Global Customer Success organization is responsible for delivering professional, educational, and support services directly to our channel partners and end-customers. We leverage the capabilities of our channel partners and train them in the delivery of professional, educational, and support services to enable these services to be locally delivered. We believe that a broad range of support services is essential to the successful customer deployment and ongoing support of our products, and we have hired support engineers with proven experience to provide those services.
- 11 -
Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Cloud Threat Report and the Unit 42 Network Threat Trends Research Report, which are based on data from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.
Our products and services have been recognized as leading in 24 categories by third-party industry analysts firms that perform independent assessments of these categories. This recognition by third parties is an important measure of validation for our customers.
Backlog. Orders for subscription and support offerings for multiple years are generally billed upfront upon fulfillment and are included in deferred revenue. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. We expect backlog related to subscription and support offerings will change from period to period for various reasons, including the timing and duration of customer orders and varying billing cycles of those orders. Products are billed upon hardware shipment or delivery of software license. The majority of our product revenue comes from orders that are received and shipped in the same quarter. However, insufficient supply and inventory may delay our hardware product shipments. As such, we do not believe that our product backlog at any particular time is necessarily indicative of our future operating results.
Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have begun to see seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.
MANUFACTURING
We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts represent our estimates of future demand for our products based upon historical trends and analysis from our sales and product management functions as adjusted for overall market conditions.
The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.
HUMAN CAPITAL
We believe our ongoing success depends on our employees. Development and investment in our people is central to who we are, and will continue to be so. With a global workforce of 15,289 as of July 31, 2024, our People Strategy is a critical element of our overall company strategy. Our People Strategy is a comprehensive approach to source, hire, onboard, develop, listen, and engage employees. Our approach is grounded on core tenets: respect each employee as a unique individual, demonstrate fairness and equity, facilitate personalization whenever possible, and nurture a culture where employees have access to industry-leading professional development programs and are empowered to do the best work of their careers. Our values of disruption, execution, collaboration, inclusion, and integrity were co-created with employees and serve as the foundation of our culture.
Source & Hire. At Palo Alto Networks, sourcing talent with the necessary skills and capabilities to contribute to our culture is central to our talent acquisition strategy, known as “The Way We Hire.” We prioritize internal mobility to foster career growth within Palo Alto Networks, enabling employees to advance through traditional career paths or explore roles across different business functions, at times leading to promotions.
We utilize structured interviewing practices, thorough job analyses, and success profiles to identify high-quality candidates and staff critical roles. Our Global Hiring Committee, introduced in fiscal 2023, plays a key role in maintaining our hiring standards, which help drive objectivity. This group of cross-functional senior leaders reviews every finalist candidate to ensure they meet our criteria and fit well with our company.
Interviewer training is a critical component of our strategy. In fiscal 2024, we began to implement a structured three-tier program to improve interviewer skills, save time across the hiring process, and enhance hiring quality. Interviewers receive learning courses focused on effective feedback and practical assessments; hiring managers are provided with in-depth, in-person training, and hiring champions receive a scenario-based training program.
- 12 -
To attract a diverse range of expertise and perspectives, and reach underrepresented talent, we promote job descriptions across diverse hiring channels, conduct interviews with a diverse slate of panelists, and encourage employee referrals. Our hiring managers also receive unconscious bias training, and our interviewing process emphasizes values and capabilities that support our culture.
Onboard & Develop. Each member of our workforce is unique, and their integration into Palo Alto Networks and career journey involve individual needs, interests, and goals. In response, our development programs are grounded on personalization, flexibility, and choice. From onboarding to professional development, FLEXLearn, our comprehensive platform offers multiple paths to assess, develop, and grow.
Before an employee’s start date, they are provided access to foundational tools to help them prepare to join Palo Alto Networks. We view pre-boarding as fundamental to introducing new employees to our culture, building trust, and facilitating rapid productivity. Welcome Day is a combination of in-person, virtual learning platforms and communication channels that provide new employees with inspirational, often personalized, onboarding experiences that carry on through the first year of employment. We have specialized learning tracks for interns and new graduates that have been recognized as best in class externally to support early-in-career individuals in acclimating to our culture as they progress on their career journey. As part of our merger and acquisition strategy, we have established a robust integration program that works to enable individuals joining our teams to feel part of our culture.
Following onboarding, there are a variety of ways that employees can assess their interests and skills, build a development plan specific to those insights, and continue to grow using FLEXLearn. The platform contains curated content and programs, such as assessment instruments, thousands of courses, workshops, and mentoring and coaching services. Leaders and executives also have access to tools that allow them to identify their strengths and areas for development, and personalized learning tracks that help them deliver maximum personal and team performance. Employees have agency to direct their growth at their pace and choosing. Development information about core business elements, required company-wide compliance training and information about activities on topics ranging from inclusion to well-being and collaboration, are also deployed through FLEXLearn. On average, employees had completed 33 hours of development through the FLEXLearn platform during fiscal 2024.
Listen & Engage. We aim to foster engagement and strive to meet our unique employees where they are, and in ways that help them feel connected to our mission and values. Through our multifaceted approach, we collect, understand, and act on employee feedback. We share and gather information through corporate and functional “All Hands” meetings, digital displays across our sites, our intranet, regular email communications, an active Slack platform, and regular two-way dialogue—such as the small, in-person monthly listening sessions our CEO hosts. We also conduct ad-hoc pulse surveys and offer a peer-to-peer recognition platform.
We also listen to and address engagement through external sources such as Glassdoor, The Best Practice Institute, Comparably, and others. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as “Top 100 Global Most Loved Workplaces” since 2021. Palo Alto Networks has been recognized by Comparably, Human Rights Campaign, Disability:IN, and others as an employer of choice. Our CEO has also earned a 91% employee approval rating on Glassdoor, a top percentile score.
In addition to a comprehensive compensation and diverse benefits program, we believe in an always-on feedback and rewards philosophy. From recurring 1:1 sessions, quarterly performance feedback, semi-annual performance reviews to use of our Cheers for Peers peer recognition program, employees get continuous input about the value they bring to the organization.
These listening and engagement strategies have informed our holistic People Strategy. Based on employee feedback, ratings from external sources, our modest attrition rate compared to market trends, and strong participation in our development and Internal Mobility programs, we believe employees at Palo Alto Networks feel engaged.
Inclusion & Diversity. We are intentional about including diverse points of view, perspectives, experiences, backgrounds, and ideas in our decision-making processes. Our corporate inclusion and diversity (“I&D”) programs are designed to promote a workforce where employees feel safe and where they are encouraged to understand, listen, support, and elevate one another.
We have eleven employee network groups (“ENG”s)that play a vital role in building understanding and awareness. As of July 2024, 26% of our global workforce was involved in at least one ENG. We involve our ENGs in listening sessions with executive teams and they contribute to our annual I&D plans.
Our I&D philosophy is integrated in our programs to source, hire, onboard, develop, listen and engage talent. The diversity of our board of directors, with women representing 40% of our board as of July 31, 2024, is an example of our commitment to I&D.
- 13 -
ENVIRONMENTAL, SOCIAL, AND GOVERNANCE
We believe integrating environmental, social, and governance (“ESG”) practices throughout our operations builds business resilience and helps manage risk. Our ESG strategy is designed to enhance safety, security, and sustainability for our stakeholders: customers, investors, employees, suppliers and our broader communities. This includes executing a science-based environmental strategy, investing in our global workforce and communities, and operating with integrity. We work to keep our stakeholders informed and maintain their trust by publishing an annual ESG report aligned to globally-recognized ESG reporting frameworks and standards.
Environmental. Palo Alto Networks acknowledges the risk and opportunities associated with climate change and remains committed to doing our part to address the climate crisis by reaching our 1.5°C-aligned and externally verified Science-Based Targets, procuring 100% renewable electricity to run our managed sites by 2030, and working collaboratively across our value chain. Fiscal 2024 is the first full year that we powered our Santa Clara, California headquarters with 100% renewable energy through our local utility provider. Our near-term scope 1, 2, and 3 emissions reduction goals have been verified by the Science Based Targets initiative. We were also recognized by CDP (formerly Carbon Disclosure Project) as a “Climate Change A-List” company and a “Supplier Engagement Leader.” We report progress towards our goals in our annual ESG report.
Social. In addition to our People Strategy described in the section titled “Human Capital” above, we continue to communicate our expectations regarding labor standards, business practices, and workplace health and safety conditions to our supply chain through our Global Supplier Code of Conduct. During fiscal 2024, we maintained our affiliate membership in the Responsible Business Alliance. We also value our role as a trusted corporate citizen and in fiscal 2024 continued to execute our social impact programs. We made charitable grants through our donor-advised fund to support nonprofit organizations providing services in areas such as cybersecurity education and disaster relief. We maintained our work to provide cybersecurity curriculum to schools, universities, and nonprofit organizations to help individuals of all ages protect their digital way of life and to prepare people for careers in cybersecurity. Employees continued to participate in our volunteering and giving programs to positively impact their local communities.
Governance. Integrity is one of our core values. Our corporate behavior and leadership practices model ethical decision-making. All employees are informed about our governance expectations through our Codes of Conduct, compliance training programs, and ongoing communications. Our board of directors is governed by Corporate Governance Guidelines, which are amended from time to time to incorporate best practices in corporate governance. Reinforcing the importance of our ESG performance, the charter of the Governance and Sustainability Committee of the board of directors includes the primary oversight of ESG.
AVAILABLE INFORMATION
Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.
We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds. Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.
- 14 -
Previous: Cover and table of contents · Next: Item 1A. Risk Factors