A Dark Vector Cognition product

Item 1. Business

74K characters. Original on sec.gov · Markdown

Item 1. Business

General

Palo Alto Networks, Inc. is a global artificial intelligence (“AI”) cybersecurity provider and our vision is a world where each day is safer and more secure than the one before. We were incorporated in 2005 and are headquartered in Santa Clara, California.

Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. Our platforms and services help secure enterprise users, networks, clouds, endpoints, AI apps and agents, and identities by delivering comprehensive cybersecurity backed by AI and automation, and provide real-time visibility and monitoring across cloud infrastructure, applications and AI workloads. A key element of our strategy is to help our customers simplify their security architectures through consolidating disparate point products. We execute on this strategy by developing our capabilities and packaging our offerings into platforms, which are able to cover many of our customers’ needs in the markets in which we operate. Our platformization strategy combines various products and services into a tightly integrated architecture for more secure, faster, and cost-effective outcomes.

Network & AI Security

Our Network & AI Security platform is designed to deliver complete zero trust solutions to our customers. The platform includes:

  • Secure Access Service Edge (“SASE”). Prisma® Access, when combined with Prisma SD-WAN, provides a comprehensive AI-powered SASE solution that secures users, branches, data, AI apps and agents from the most evasive threats in the new AI landscape. Our Prisma Browser™ further extends zero-trust security and data protection to the browser, where the majority of work is done today, providing users with the freedom to work securely using our secure browser from any device.

  • Next-Generation Firewalls. Our ML-Powered Next-Generation Firewalls (“NGFWs”) secure on-premises environments including campus locations and data centers. Our software NGFWs secure virtual and cloud networks.

  • Cloud-Delivered Security Services (“CDSS”). Our network security platform integrates a suite of Precision AI powered security capabilities that complements our SASE and NGFW solutions. These include Advanced Threat Prevention, Advanced WildFire®, Advanced URL Filtering, Advanced DNS Security, Device Security, Quantum Security, Next-Gen Trust Protection (“NGTS”), GlobalProtect®, Prisma Access Agent, Enterprise Data Loss Prevention (“Enterprise DLP”), Software as a Service (“SaaS”) Security, and AI Access Security™. Through these add-on services, our customers are able to secure their content, applications, users, devices, and connection across their entire organization.

  • Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents. Prisma AIRS™ brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security™, AI Model Security, and AI Posture Management in a unified platform. These capabilities provide visibility into AI assets and activity, assess risks before deployment, and enforce security controls during live AI interactions and agent actions.

  • Strata Cloud Manager (“SCM”). SCM is our AI-powered unified network security management and operations solution. It enables customers to manage and monitor their NGFW and SASE environments through a single, streamlined interface. SCM helps customers centrally manage configurations and security policies, assess security posture and network health, and streamline troubleshooting and remediation. It includes Strata Copilot, which offers a natural language interface for actionable insights and guided remediation, and integrates Autonomous Digital Experience Monitoring (“ADEM”) to help customers monitor and improve end-user performance across the enterprise.

Cortex

Our AI-powered Cortex® platform transforms end-to-end security operations and observability with unified data, AI, and automation for more secure, faster, and cost effective outcomes.

  • Security Operations. We deliver the next generation of security operations capabilities that unifies standalone Security Information and Event Management (“SIEM”) tools, endpoint security, security automation, cloud detection and response (“CDR”), as well as attack surface management (“ASM”) capabilities on our Cortex platform. These include Cortex XSIAM®, for AI-powered security operations replacing traditional SIEM tools; Cortex XDR®, for the prevention, detection, and response to complex cybersecurity attacks; Cortex XSOAR®, for security orchestration, automation, and response (“SOAR”); Cortex Xpanse®, for ASM; and Koi Agentic Endpoint Security. Additionally, Cortex XSIAM integrates with the Chronosphere Telemetry Pipeline to ingest and optimize massive data volumes, promoting cost-effective scaling of autonomous operations.

- 4 -

  • Cloud Security. We deliver comprehensive security across the cloud application development lifecycle through Cortex Cloud®, delivered as a scalable SaaS offering. As a comprehensive Cloud Native Application Protection Platform (“CNAPP”) combined with CDR, Cortex Cloud secures multi- and hybrid-cloud environments for applications, data, generative AI (“GenAI”) ecosystem, and the cloud native technology stack across the full development lifecycle, from code to cloud to security operations. As part of the Cortex Cloud platform, customers can expand from Cortex Cloud to our security operations offerings available on a single user experience and unified agent. We also offer our VM-Series and CN-Series virtual firewalls for inline network security on multi- and hybrid-cloud environments.

  • Observability. Chronosphere, our next-generation observability platform, delivers real-time visibility and monitoring across cloud-native infrastructure, applications, and AI workloads. Purpose-built to handle the massive data volumes of the AI era, Chronosphere enables organizations to maintain system resilience and uptime with high cost-efficiency and reliability. Our observability platform provides comprehensive visibility into complex digital environments and automated troubleshooting of issues. It allows customers to transition from passive monitoring to proactive management of their entire digital estate. Our telemetry pipeline acts as an intelligent control layer that filters, transforms, and routes data. This helps reduce data volumes, enabling customers to cost-effectively scale their security and observability posture.

Idira

Idira™, our next-generation identity security platform, is designed to secure human, agentic, and machine identities across the enterprise with intelligent privilege controls and continuous threat prevention. By unifying identity access management, privilege access management, and identity governance and administration, organizations can continuously discover and protect against identity risk throughout the end-to-end identity lifecycle. The platform includes:

  • Workforce Identity Security. Our solutions apply identity assurance and modern access controls for the entire workforce, including through adaptive multi-factor authentication (“MFA”), single sign-on (“SSO”), secure browsing, web session protection, workforce password management, and automated identity lifecycle management. Our approach enforces least privilege by elevating access only when required.

  • Information Technology (“IT”) and Developer Identity Security (Modern Privilege Access Management). Our solutions secure high-risk access for IT administrators, third-party vendors, developers, and cloud operations teams across hybrid and multi-cloud environments, delivering just-in-time privileged access, session isolation, credential protection, and zero standing privileges, while providing native, secure access to cloud services, workloads, and development and operations pipelines. Organizations can eliminate excessive permissions, automate access to dynamic cloud resources, and maintain developer velocity while strengthening identity controls across infrastructure and application environments.

  • Machine Identity Security. Our solutions secure the growing volume of non-human identities—such as workloads, applications, containers, service accounts, certificates, and keys, including through centralized discovery and management of secrets, certificate lifecycle automation, workload identity issuance, public key infrastructure-as-a-service, Kubernetes certificate management, and secure code signing.

  • Identity Governance and Administration (“IGA”). IGA enables visibility into entitlements, automated joiner–mover–leaver processes, access certification, and ongoing identity compliance. AI-supported policy automation helps organizations govern access at scale and enforce a zero-trust model across all identities.

  • AI Agents Security. Our solution discovers AI agents, assigns identity attributes, and restricts their access to task-specific resources. It helps monitor and record agent activity for audit purposes, allows organizations to suspend or revoke access if behavior deviates from expected norms, and governs the lifecycle of the agent and the actions taken to support compliance.

Threat Intelligence and Advisory Services

  • Unit 42® brings together world-renowned expertise across threat research, incident response, and security consulting to deliver intelligence-driven, response-ready outcomes that help customers reduce cyber risk. Our elite consultants serve as trusted advisors to our customers by assessing and testing their security controls against sophisticated threats, including Frontier AI, transforming their security strategy with a threat-informed approach, and responding to security incidents on behalf of our clients. Additionally, Unit 42 offers managed detection and response (“MDR”) and managed threat hunting services. In April 2026, we launched a new suite of Unit 42 Frontier AI Defense services to help customers proactively discover and neutralize threats introduced by next-generation AI models.

- 5 -

Products and Services

NETWORK & AI SECURITY

Secure Access Service Edge

  • Prisma Access. Prisma Access is a cloud-delivered security offering that helps organizations deliver consistent AI-driven security to remote networks and mobile users. With more than 100 locations around the world, Prisma Access offers global coverage, consistently inspecting all traffic across all ports and providing bidirectional networking to enable branch-to-branch and branch-to-headquarter traffic. Prisma Access consolidates point products into a single cloud-delivered solution, transforming network security and allowing organizations to enable secure hybrid work. Prisma Access protects all application traffic with complete, best-in-class security while also delivering a seamless user experience with industry-leading service-level agreements (“SLAs”). With native SASE integration, our Prisma Access Browser extends zero-trust security to any device—managed or unmanaged—in minutes. Prisma Access delivers seamless user experience with a combination of application acceleration—up to 5x faster than direct-to-internet—and Autonomous Digital Experience Management.

  • Prisma SD-WAN. Our Prisma SD-WAN solution is a next-generation SD-WAN solution that makes the secure cloud-delivered branch possible. Prisma SD-WAN enables organizations to replace traditional wide area network (“WAN”) architectures with affordable broadband and internet transport types that promote improved bandwidth availability, redundancy, and performance. Prisma SD-WAN leverages real-time application performance SLAs and visibility to control and intelligently steer application traffic to deliver a powerful user experience. Prisma SD-WAN also provides the flexibility of deploying with an on-premises controller to help businesses meet their industry-specific security compliance requirements and manage deployments with application-defined policies. Our Prisma SD-WAN simplifies network and security operations using AI and automation.

Next-Generation Firewalls. Our hardware and software ML-Powered NGFWs use AI—including machine learning and deep learning—to stop zero-day threats in real time, and detect and secure the entire enterprise including Internet of Things (“IoT”). All of our hardware and software firewalls incorporate the PAN-OS® operating system and include the same rich set of features, ensuring consistent operation across our entire product line. This includes SD-WAN capabilities to intelligently steer traffic to data centers, branches, and the cloud, natively integrated into our NGFWs. Enterprise data, applications, users, and devices become integral components of an organization’s security policy. Our hardware and software are designed for different performance requirements throughout an organization—with the ability to secure everything from small businesses and branch offices, to large-scale data centers and service providers. Our firewalls come in hardware form factors, containerized form factors, called CN-Series, as well as virtual form factors, called VM-Series, available on all major cloud hosting service providers. We also offer Cloud NGFW, a managed NGFW offering, to secure customers’ applications on Amazon Web Services (“AWS”) and Microsoft Azure (“Azure”).

Cloud-Delivered Security Services

  • Advanced Threat Prevention. This cloud-delivered security service provides intrusion detection and prevention capabilities and blocks vulnerability exploits, viruses, spyware, buffer overflows, denial-of-service attacks, and port scans from compromising and damaging enterprise information resources. In addition, we offer inline deep learning to deliver real-time detection and prevention of unknown, evasive, and targeted command-and-control (“C2”) communications over HTTP, unknown-TCP, unknown-UDP, and encrypted over SSL. Advanced Threat Prevention is the industry’s only offering to protect the enterprise from unknown command and control in real-time with the power of Precision AITM.

  • Advanced WildFire. This cloud-delivered security service provides protection against targeted malware and advanced persistent threats and provides a near real-time analysis engine for detecting previously unseen malware while resisting attacker evasion techniques. Advanced WildFire combines dynamic and static analysis, recursive analysis, and a custom-built analysis environment with network traffic profiling and fileless attack detection to discover even the most sophisticated and evasive threats. Preventions are delivered in seconds to our network security platform.

  • Advanced URL Filtering. This cloud-delivered security service offers the industry’s first Inline Deep Learning powered web protection engine. We deliver real-time detection and prevention of unknown, evasive, and targeted web-based threats, such as phishing. In addition, the service includes a cloud-based URL filtering database which consists of millions of URLs across many categories and is designed to analyze web traffic and prevent web-based threats, such as phishing, malware, and C2.

  • Advanced DNS Security. This cloud-delivered security service uses machine learning to proactively block malicious domains and stop attacks in progress. The service allows our network security platform access to Domain Name System (“DNS”) signatures that are generated using advanced predictive analysis, machine learning, and malicious domain data from a growing threat intelligence sharing community of which we are a part. We offer comprehensive DNS attack coverage and include industry-first protections against multiple emerging DNS-based network attacks, including real-time analysis of DNS response to prevent DNS hijacking.

- 6 -

  • Device Security. This cloud-delivered security service uses machine learning to accurately identify and classify various IoT, connected medical, operational technology (“OT”), and unmanaged IT devices, including never-been-seen-before devices, critical devices, and unmanaged legacy systems. The service uses machine learning to baseline normal behavior, identify anomalous activity, assess and prioritize risk, provide virtual patching, and provide policy and remediation recommendations.

  • SaaS Security API. SaaS Security API is a multi-mode, cloud access security broker (“CASB”) that helps govern sanctioned SaaS application usage across all users and helps prevent breaches and non-compliance. Specifically, the service enables the discovery and classification of data stored in supported SaaS applications, protects sensitive data from accidental exposure, identifies and protects against known and unknown malware, and performs user activity monitoring to identify potential misuse or data exfiltration. The solution can be combined with SaaS Security Inline for a complete integrated CASB.

  • SaaS Security Inline. SaaS Security Inline adds an inline service to automatically gain visibility and control over thousands of known and newly sanctioned, unsanctioned and tolerated SaaS applications in use within organizations today. The service provides enterprise data protection and compliance across all SaaS applications and prevents cloud threats in real time. The solution can be combined with SaaS Security API as a complete integrated CASB.

  • GlobalProtect. GlobalProtect provides protection for users of both traditional laptop and mobile devices. It expands the boundaries of the end-users’ physical network, effectively establishing a logical perimeter that encompasses remote laptop and mobile device users irrespective of their location. Regardless of the operating system, laptops, tablets, and phones will stay connected to the corporate network when they are on a network of any kind and as a result, are protected as if they never left the corporate campus.

  • Prisma Access Agent. Prisma Access Agent provides secure, remote access to corporate resources for employees working from any location or device. The agent establishes an encrypted tunnel to Prisma Access or our NGFW, ensuring consistent security, data protection, and threat prevention for a distributed workforce accessing any application.

  • Enterprise DLP. This cloud-delivered security service provides consistent and reliable protection of sensitive data, such as personally identifiable information and intellectual property, for all traffic types, applications, and users. Native integration with our products makes the service simple to deploy, while advanced machine learning minimizes management complexity. Enterprise DLP allows organizations to consistently discover, classify, monitor, and protect sensitive data, wherever it may reside.

  • AI Access Security. AI Access Security classifies and prioritizes GenAI applications to assess risk, detect anomalies, and visualize insights across multiple GenAI-specific attributes. The service prevents sensitive data loss and defends against malicious responses, ensuring safe and effective AI adoption.

AI Security: Prisma AIRS. Prisma AIRS™ is our comprehensive AI security platform designed to help organizations discover, assess, and protect AI agents, applications, models, and data across the AI lifecycle. It supports key enterprise use cases, including securing AI-assisted software development, protecting custom AI applications from development through runtime, and governing autonomous AI agents as they access enterprise data, tools, and systems. Prisma AIRS brings together AI Gateway, Agent Security, AI Red Teaming, AI Runtime Security, AI Model Security, and AI Posture Management in a unified platform. Together, these capabilities provide visibility into AI assets and activity, identify risks before deployment, and apply security controls to live AI interactions and agent actions.

  • AI Gateway. Serves as the centralized AI security control plane through which all enterprise AI traffic flows—including LLM calls, tool invocations, agent interactions, and prompt data. AI Gateway enables organizations to govern AI agents, secure AI coding tools, and safely enable enterprise AI apps from a single control plane. The gateway provides real-time visibility into usage, tracks token consumption and cost, and inspects every interaction to prevent data leakage, prompt injection, and unsafe outputs. Before agents or coding tools access enterprise data or systems, the gateway enforces identity-aware controls and authorizes actions against defined permissions.

  • Agent Security. Provides lifecycle security and governance for enterprise AI agents, from development through production. It establishes a central registry to inventory and verify every agent across endpoints, browsers, SaaS tools, and internal systems, mapping autonomous actions directly to human sponsors, specific agents, and business tasks. By assessing operational risk based on permissions, connected data, and integrated tools, Agent Security enforces identity-aware authorization and task-specific boundaries. These capabilities help organizations reduce shadow agent blind spots, protect sensitive data, prevent tool misuse and unauthorized actions, and maintain audit trails as agents automate business processes.

  • AI Red Teaming. Continuously validates the security of custom autonomous agents, applications, and models through automated adversarial testing at enterprise scale. By profiling each deployment’s unique business context, workflows, and connected tools, AI Red Teaming autonomously executes over 50 advanced attack techniques—including jailbreaks, prompt injections, and goal manipulation—to test against the intended behavior of AI apps and agents. Enriched by threat intelligence from Unit 42 and the huntr research community, it delivers actionable remediation mapped to industry frameworks (OWASP, NIST, MITRE ATLAS) so teams can secure enterprise AI apps and deploy autonomous systems with confidence.

  • AI Runtime Security. Provides continuous, real-time protection for live AI autonomous agents, applications and models operating in production. It actively intercepts mid-conversation threats, such as prompt injections, indirect

- 7 -

injections, malicious URLs, retrieval manipulation, and tool abuse while enforcing enterprise-grade Data Loss Prevention (“DLP”) across prompts and outputs. By stopping exploits as they unfold and preventing unauthorized data exfiltration, AI Runtime Security ensures business continuity, protects high-value enterprise data, and keeps operational agents acting safely within policy boundaries to secure enterprise AI apps and AI-assisted coding.

  • AI Model Security. Protects the foundation of the AI ecosystem by extending continuous scanning to underlying model architectures, weights, operators, agent artifacts, code dependencies, and skills. AI Model Security inspects components in-place to identify hidden malware, poisoned assets, unsafe permissions, and indirect injection paths before they reach production. It ensures engineering teams can adopt AI coding safely, prevent secret leakage, and build trusted software without introducing supply chain risk.

  • AI Posture Management. Provides continuous, real-time risk assessment across cloud, SaaS, and endpoint environments to help eliminate "Shadow AI" blind spots. It discovers deployed chatbots and agents, maps data flows, and enforces policy rules aligned with frameworks like the E.U. AI Act and OWASP Top 10 for LLMs. By surfacing misconfigurations and untracked AI usage across the enterprise, AISPM enables security teams to manage risk exposure, uphold corporate governance, and use GenAI safely.

Strata Cloud Manager (“SCM”). SCM enables our customers to easily manage their Palo Alto Networks’ Network Security infrastructure—including NGFWs and SASE deployments—from the cloud, via one unified management interface. As an AI-powered, unified cloud management solution, SCM enables organizations to enhance their network security posture and streamline operations. It utilizes AI to swiftly identify potential vulnerabilities, provide real-time recommendations for remediation, proactively address support needs, and improve overall digital experiences, leading to reduced operational overhead and improved speed, accuracy, and scale of support. By analyzing telemetry, historical data, and its diverse knowledge base, SCM can instantly answer questions, pinpoint solutions to known problems, and automate data collection to speed up assisted support for new challenges. Built into this robust solution are Strata Copilot™, offering a natural language interface for intuitive insights and guided actions, and ADEM, designed for proactive infrastructure health, simplified troubleshooting, and consistent end-user performance across the network.

Panorama. Panorama**®** is used for centralized policy management, device management, software licensing and updates, centralized logging and reporting, and log storage. Many of our existing deployments continue to use Panorama as the security management solution. New deployments benefit from using SCM for managing network security estate—including our NGFWs and SASE—with a cloud-based, unified management interface.

CORTEX

  • Cortex XSIAM. Our cloud-based AI-powered security operations platform harnesses the power of AI to significantly improve security outcomes and transform security operations. Cortex XSIAM customers are able to consolidate multiple products into a single unified platform that delivers security information and event management, extended detection and response (“XDR”), SOAR, network traffic analysis, ASM, threat intelligence management (“TIM”), identity threat detection and response, and CDR. Cortex XSIAM integrates these capabilities into a single platform built for security operations, enabling organizations to simplify operations, stop threats at scale, and accelerate incident remediation. Cortex XSIAM automates data integration, analysis, and triage to respond to most alerts, enabling analysts to focus on only the incidents that require human intervention.

  • Cortex XDR. This cloud-based service enables organizations to collect telemetry from endpoint, network, identity, and cloud data sources and apply advanced analytics and machine learning to quickly find and stop targeted attacks, insider abuse, and compromised endpoints. Cortex XDR has two product tiers: XDR Prevent and XDR Pro. XDR Prevent delivers enterprise-class endpoint security focused on preventing attacks. XDR Pro extends endpoint detection and response (“EDR”) to include cross-data analytics for network, cloud, and identity data. Going beyond EDR, Cortex XDR detects the most complex threats using analytics across key data sources and reveals the root cause, which can significantly reduce investigation time as compared to siloed tools and manual processes. Additionally, the recent acquisition of Koi Security Ltd. (“Koi”) introduces Agentic Endpoint Security capabilities to protect vibe coding agents and autonomous endpoint tools.

  • Cortex XSOAR. Available as a stand-alone, cloud-based service, an on-premises virtual appliance, or delivered natively through Cortex XSIAM, Cortex XSOAR is a comprehensive SOAR offering that unifies playbook automation, case management, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. With Cortex XSOAR, security teams can standardize processes, automate repeatable tasks, and manage incidents across their security product stack to improve response time and analyst productivity. Cortex XSOAR learns from the real-life analyst interactions and past investigations to help SOC teams with analyst assignment suggestions, playbook enhancements, and best next steps for investigations. Many of our customers see significantly faster SOC response times and a significant reduction in the number of SOC alerts which require human intervention.

- 8 -

  • Cortex Xpanse. Available as a stand-alone, cloud-based service and a cloud-based subscription module within Cortex XSIAM, Cortex Xpanse provides ASM, which is the ability for an organization to identify what an attacker would see among all of its sanctioned and unsanctioned Internet-facing assets. In addition, Cortex Xpanse detects risky or out-of-policy communications between Internet-connected assets that can be exploited for data breaches or ransomware attacks. Cortex Xpanse continuously identifies Internet assets, risky services, or misconfigurations in third parties to help secure a supply chain or identify risks for mergers and acquisitions due diligence. Finally, compliance teams use Cortex Xpanse to improve their audit processes and stay in compliance by assessing their access controls against regulatory frameworks.

  • Cortex Cloud. Available as a stand-alone, cloud-based service or an add-on to Cortex XDR or to Cortex XSIAM. Cortex Cloud, the next generation of Prisma Cloud, merges CNAPP with CDR for real-time cloud security. The solution allows you to harness the power of AI and automation to prioritize cloud risks with runtime context, enable remediation at scale, and stop attacks as they happen. Cortex Cloud consolidates multiple code and cloud security technologies, such as Cloud Detection and Response, Software Composition Analysis, Infrastructure as Code security, CI/CD security, secrets scanning, Cloud Security Posture Management, Cloud Identity and Entitlements Management, API security, Vulnerability Management, Cloud Workload Protection, Web Application and API Security, Cloud Network Security, and Cloud Attack Surface Management into a single unified offering. As part of the Cortex platform, customers can transform end-to-end security operations, from code to cloud to SOC, by adopting Cortex Cloud together with Cortex XSIAM. Existing customers can continue leveraging Prisma Cloud as they upgrade to Cortex Cloud for significantly better, faster, and more effective multi-cloud protection.

  • Chronosphere Platform. Our observability platform enables Site Reliability Engineering (“SRE”) teams to efficiently identify and resolve customer-facing issues faster, while managing cloud-native complexity. It provides control over observability costs and access to a purpose-built, highly scalable observability SaaS platform for cloud-native environments. By reducing data volumes, the platform is designed to optimize costs and accelerate troubleshooting. Additionally, the platform supports all telemetry types, including metrics, events, logs, and traces from various delivering application performance monitoring (“APM”) capabilities integrated with open-source telemetry.

  • Chronosphere Telemetry Pipeline. Designed to address growing log data volumes, the pipeline allows observability and security teams to collect data from a wide range of sources; transform, enrich, and reduce logs in transit; and route data to any destinations. Our telemetry pipeline is built on open standards and is engineered to operate efficiently and require fewer infrastructure resources than other leading pipelines.

IDIRA

  • Privileged Access Management (“PAM”). Available as a core cloud-native platform module or software, Idira PAM establishes a modern framework for securing high-risk administrative access across multi-cloud, on-premises, and hybrid infrastructures. The solution enforces a strict Zero Standing Privilege (“ZSP”) model by utilizing Just-in-Time (“JIT”) dynamic privilege elevation, ensuring that administrative pathways exist exclusively for the duration of an authorized task and are terminated immediately upon completion. The system automates credential rotation, securely manages SSH keys, and delivers real-time session isolation and live monitoring alongside comprehensive forensic recordings to detect and respond to lateral or vertical threat movement. By continually discovering hidden access paths and unmanaged accounts, Idira PAM helps customers reduce the privilege gaps associated with administrative environments.

  • Identity and Access Management (“IAM”). Our cloud-based service enables organizations to deliver secure application and infrastructure connectivity for a decentralized workforce. Idira IAM unifies core identity services—including SSO, phishing-resistant MFA, and automated lifecycle management—into a single high-availability identity hub. The platform features an extensive integration catalog with thousands of pre-configured application connections utilizing industry-standard protocols, such as SAML, OpenID Connect, and SCIM. Operating at scale, it enforces policy-driven contextual authentication parameters based on device posture, network environment, and real-time threat intelligence, which are engineered to help organizations mitigate credential-based attacks and unauthorized access.

  • Endpoint Privilege Manager. This cloud-based endpoint protection module secures enterprise laptops, workstations, and servers by enforcing strict least-privilege policies directly at the operating system layer. Idira Endpoint Privilege Manager minimizes the local attack surface by stripping standard corporate users of excessive local administrative credentials, which serve as a primary vector for credential harvesting and local exploit execution. In addition to dynamic privilege management, the solution delivers robust application control capabilities, allowing security teams to define execution rules that stop untrusted, malicious, or unapproved software from running on critical endpoints. By connecting local enforcement metrics with central identity governance workflows, it ensures continuous compliance and real-time security posture enforcement across distributed infrastructure.

- 9 -

  • Identity Governance. Designed to automate and streamline compliance auditing across the enterprise identity landscape, this cloud-based solution unifies visibility and lifecycle tracking for human and machine accounts. Idira Identity Governance simplifies IGA by replacing fragmented, manual certification workflows with AI-driven continuous visibility and automated access evaluations. The platform aggregates user access rights, role definitions, and historical entitlements to proactively flag policy deviations, toxic access combinations, and orphaned accounts. By automating entitlement reviews, lifecycle onboarding, and offboarding flows, the solution is designed to help organizations reduce operational overhead while supporting ongoing audit readiness across complex multi-cloud and hybrid environments.

  • Workforce Password Management. This cloud-delivered solution extends security capabilities to corporate applications, SaaS tools, and web portals that lack native support for federated SSO protocols. Idira Workforce Password Management allows security teams to bring unmanaged password-based applications under centralized administrative oversight. The solution enforces enterprise password policies, automates complex credential generation and rotation, and securely stores data within encrypted enterprise vaults. By integrating directly into the user’s browser workflow, it enables frictionless passwordless entry experiences for the workforce while providing IT leadership with complete visibility into application usage, credential strength, and shared account vulnerabilities.

  • Vendor Privileged Access. Designed to mitigate third-party supply chain liabilities, this solution secures and governs remote access for external contractors, supply partners, and service vendors without requiring corporate agents or complex virtual private network (“VPN”) infrastructure. Idira Vendor Privileged Access establishes an isolated, browser-based secure gateway that authenticates external contributors using strict multi-factor checks and contextual policies. Once inside, vendors are restricted to specific authorized applications or servers through precise JIT entitlements, rather than being granted broad network-level visibility. Security operations teams can actively monitor, shadow, and automatically terminate active third-party sessions in real time, capturing full session playbacks in order to achieve accountability and regulatory compliance.

  • Secrets Management. This machine identity solution delivers simplified, high-performance protection of non-human credentials across modern application architectures, container environments, and DevOps pipelines. Idira Secrets Management prevents data breaches by systematically removing hard-coded, static passwords, API keys, and configuration tokens from software repositories, source code, and developer environments. It centralizes machine authentication paths under a unified control plane, utilizing programmatic application programming interfaces (“APIs”) and native cloud plug-ins to manage and distribute credentials securely. By consolidating secrets management across complex hybrid structures, it helps security organizations eliminate vault sprawl and establish an optimized, secure non-human security architecture.

  • Secrets Hub. Available as a policy-driven orchestration tier, this solution extends enterprise-grade oversight across native cloud secrets stores, including AWS, Azure, Google Cloud, and HashiCorp Vault architectures. Idira Secrets Hub allows security teams to define and enforce uniform credential rotation, expiration, and access policies from a single control plane without forcing developer teams to abandon their preferred cloud-native storage environments. By consolidating disparate, siloed vaults under a singular oversight layer, the platform effectively mitigates "vault sprawl" across complex multi-cloud environments. The solution continually tracks credential lifecycles, automatically flagging policy deviations, overly permissive configurations, and unmanaged shadow vaults to streamline corporate compliance.

  • Credential Providers. Engineered to address the operational and security demands of distributed software deployment, this solution eliminates embedded credentials by providing automated, dynamic secret provisioning. Idira Application Credentials Delivery provides secure, JIT secret retrieval for applications residing in traditional data centers, public clouds, and Kubernetes container platforms. Instead of relying on static keys embedded within software configurations, authorized application components pull short-lived authentication materials dynamically at the moment of execution. This continuous injection model significantly reduces the risk of credential scraping or exposure during code breaches, enabling high-velocity software engineering pipelines to scale securely without manual credential upkeep.

  • Secure AI Agents. Designed for AI workloads and agents, this solution delivers an identity-first approach to securing the agentic workforce. Idira Secure AI Agents continuously scans SaaS, cloud, and developer environments to discover active "shadow" AI agents and automatically onboards them into a centralized agent registry. The solution routes all interactions through a gateway that applies precise guardrails, granting short-lived permissions exclusively for the duration of a specific task and automatically revoking access the moment a job is completed. If an agent suffers a prompt injection attack or exhibits anomalous behavior, the broker can deny access in real time, while maintaining a clear audit trail.

- 10 -

THREAT INTELLIGENCE AND ADVISORY SERVICES

  • Customer Support. Global customer support helps our customers achieve their security outcomes with services and support capabilities covering the customer's entire journey with Palo Alto Networks. This post-sales, global organization advances our customers’ security maturity, supporting them when, where, and how they need it. We offer Standard Support, Premium Support, and Platinum Support to our end-customers and channel partners. Our channel partners that operate a Palo Alto Networks Authorized Support Center typically deliver level-one and level-two support. We provide level-three support 24 hours a day, seven days a week through regional support centers that are located worldwide. We also offer a service offering called Focused Services that includes Customer Success Managers to provide support for end-customers with unique or complex support requirements. We offer our end-customers ongoing support for hardware, software, and cloud offerings. Support for cloud offerings includes a standard level of support with the applicable subscription, with optional premium support offerings available for customers requiring enhanced service levels including ongoing security updates, PAN-OS upgrades, bug fixes, and repairs. End-customers typically purchase these services for a one-year or longer term at the time of the initial product sale and typically renew for successive one-year or longer periods. Additionally, we provide expedited replacement for any defective hardware. We use a third-party logistics provider to manage our worldwide deployment of service-related spares.

  • Threat Intelligence, Incident Response and Security Consulting. Unit 42 brings together world-renowned threat researchers, incident responders, and security consultants to create an intelligence-driven, response-ready organization that is passionate about helping clients proactively manage cyber risk. We help security leaders assess and test their security controls, transform their security strategy with a threat-informed approach, and respond to incidents rapidly. The Unit 42 Threat Intelligence team provides threat research that enables security teams to understand adversary intent and attribution, while enhancing protections offered by our products and services to stop advanced attacks. Our security consultants serve as trusted partners with state-of-the-art cyber risk expertise and incident response capabilities, helping customers build effective security programs, uncover critical exposures to prevent incidents, and, should incidents occur, respond to them with speed and confidence. Additionally, Unit 42 experts help customers proactively discover and neutralize threats introduced by next-generation AI models with the Frontier AI Defense service.

  • Professional Services. Professional services are primarily delivered directly by Palo Alto Networks and through a global network of authorized channel partners to our end-customers and include on-location and remote, hands-on experts who plan, design, and deploy effective security solutions tailored to our end-customers’ specific requirements. These services include architecture design and planning, implementation, configuration, and firewall migrations for all our products, including Prisma and Cortex deployments. Customers can also purchase on-going technical experts to be part of customer’s security teams to aid in the implementation and operation of their Palo Alto Networks capabilities. Our education services include certifications, as well as free online technical courses and in-classroom training, which are primarily delivered through our authorized training partners.

RESEARCH AND DEVELOPMENT

Our research and development efforts are strategically centered on expanding our leadership within the enterprise security industry through AI-powered innovation. We focus on enhancing our integrated platforms and developing new software and hardware capabilities. Our engineering teams apply deep expertise in AI and machine learning across networking security, cloud security, endpoint security, security operations, and identity security to address the rapidly evolving threat landscape. This approach enables us to leverage core competencies across hardware and software for agile responsiveness and to ensure interoperability with third-party technologies. We supplement our own research with technologies and products licensed from third parties.

We believe that innovation and timely development of new features and products is essential to meeting the needs of our end-customers and improving our competitive position. During fiscal 2026, we introduced several upgrades and new offerings, including: PAN-OS 12.1 Orion, Prisma AIRS 2.0, NGTS, and Prisma AIRS 3.0.

We plan to continue to significantly invest in our research and development efforts as we evolve and extend the capabilities of our portfolio.

- 11 -

ACQUISITIONS

We believe that the industry in which we operate necessitates a variety of technologies, products, capabilities, and features. We evaluate opportunities to acquire complementary businesses, technologies, services, and intellectual property to complement our organic innovation and research and development efforts, advance the development of our platforms, and enable further investment in our key priority areas. Our evaluation of acquisition opportunities seeks to confirm that any potential transaction would accelerate our strategy, represent an attractive customer opportunity, address a customer need, align with our customer base and go-to-market strategy, and present a clear timeline and path for value accretion. Our acquisitions enable us to gain access to talent, technology, products, and features, and can range in size and complexity, from those that enhance or complement existing products and accelerate development of features to those that result in new offerings.

For example, in January 2026, we completed the acquisition of Chronosphere, Inc. (“Chronosphere”), a privately-held observability technology company, forming our next-generation observability platform; in February 2026, we completed the acquisition of CyberArk Software Ltd. (“CyberArk”), an identity security company, forming our next-generation identity security platform; in April 2026, we completed the acquisition of Koi, a privately-held endpoint posture management company, which adds agentic endpoint security capabilities to our security operations platform and enhances Prisma® AIRS™; in May 2026, we completed the acquisition of Portkey, Inc. (“Portkey”), a privately-held AI Gateway company, which enhances the capabilities of Prisma AIRS; in July 2026, we entered into a definitive agreement to acquire Embrace Mobile, Inc. (“Embrace”), a privately-held Real User Monitoring (“RUM”) company that we expect will add RUM capabilities to our observability platform; and in July 2026, we entered into a definitive agreement to acquire Console Systems, Inc. (“Console”), a privately-held company providing an AI-native platform that enables agentic workflows across enterprise operations, which we expect to deepen our agentic capabilities in Cortex.

For additional information related to the impact of acquisitions to our business, see Part I, Item 1A “Risk Factors” and Note 8. Acquisitions and Note 20. Subsequent Events in Part II, Item 8 of this Annual Report on Form 10-K.

INTELLECTUAL PROPERTY

We believe that our intellectual property rights are valuable and important to our business, and that our success depends, in part, on our ability to protect and use our core technology and intellectual property rights. We rely on a combination of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish, protect, and control the use of our proprietary technology and intellectual property rights. We continue to grow our global portfolio of intellectual property rights in connection with our products, services, research, and development. We file patent applications to protect our intellectual property and believe that the duration of our issued patents is sufficient when considering the expected lives of our products. We have registered various trademarks for our company and our products in the United States (“U.S.”) and other jurisdictions internationally. We intend to continue pursuing additional protections for our proprietary technology and intellectual property to the extent we believe it would be beneficial and cost-effective.

Despite our efforts to protect our proprietary technology and intellectual property rights, our rights may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents, copyrights, trademarks, domain names, and trade secrets, and frequent claims and related litigation based on allegations of patent infringement, misappropriation, or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors, third-parties, and non-practicing entities may also claim that our cybersecurity platforms and services infringe their intellectual property rights. Third parties have in the past and may in the future assert claims of infringement, misappropriation, and other violations of intellectual property rights against us or our customers, with whom our license or other agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could affect our ability to offer, or prevent us from offering, certain products and subscriptions. This could result in time during which we may be unable to continue to offer our affected products and subscriptions because of a potential need for us to develop alternate, non-infringing technology, which could require significant time and resources, or require us to obtain a license, which may not be available on reasonable terms or at all, or could require us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risks Related to Intellectual Property and Technology Licensing” in Part I, Item 1A “Risk Factors” in this Form 10-K.

GOVERNMENT REGULATION

We are subject to numerous U.S. federal, state, and foreign laws and regulations covering a wide variety of subject matters. Like other companies in the technology industry, we face scrutiny from both U.S. and foreign governments with respect to our compliance with laws and regulations. Our compliance with these laws and regulations may be onerous and could, individually or in the aggregate, increase our cost of doing business, impact our competitive position relative to our peers, and/or otherwise have an adverse impact on our business, reputation, financial condition, and operating results. For additional information about government regulation applicable to our business, see Part I, Item 1A “Risk Factors” in this Form 10-K.

- 12 -

COMPETITION

We operate in the intensely competitive enterprise security industry that is characterized by constant change and innovation. Changes in the application, threat, and technology landscape result in evolving customer requirements for the protection from threats and the safe enablement of applications. Our main competitors fall into four categories:

  • large companies that incorporate security or observability features in their products, such as Alphabet Inc., Cisco Systems, Inc., and Microsoft Corporation, or those that have acquired, or may acquire, security vendors and have the technical and financial resources to bring competitive solutions to the market;

  • independent vendors that offer a mix of security products, such as Check Point Software Technologies Ltd., CrowdStrike Holdings, Inc., Delinea Inc., Fortinet, Inc., Okta, Inc., SailPoint Technologies, Inc., and Zscaler, Inc., vendors that offer a mix of observability products, such as DataDog, Inc., Dynatrace, Inc., and Elasticsearch B.V., or vendors that may offer a mix of security and observability products;

  • startups and point-product vendors that offer independent or emerging solutions across various areas of security; and

  • public cloud vendors and startups that offer solutions for cloud security (private, public, and hybrid cloud).

As our market grows, it will attract more highly specialized vendors, as well as larger vendors that may continue to acquire or bundle their products more effectively.

The principal competitive factors in our market include:

  • product features, reliability, performance, and effectiveness;

  • product line breadth, diversity, and applicability;

  • product extensibility and ability to integrate with other technology infrastructures;

  • price and total cost of ownership;

  • adherence to industry standards and certifications;

  • strength of sales and marketing efforts; and

  • brand awareness and reputation.

We believe we generally compete favorably with our competitors on the basis of these factors as a result of the features and performance of our portfolio, the ease of integration of our security solutions with technological infrastructures, and the relatively low total cost of ownership of our products. However, some of our competitors may have substantially greater financial, technical, and other resources, greater name recognition, larger sales and marketing budgets, broader distribution, more diversified product lines, and larger and more mature intellectual property portfolios.

SALES, MARKETING, SERVICES, AND SUPPORT

Customers. Our end-customers consist of enterprises, service providers, and government entities. Our end-customers operate in a variety of industries, including education, energy, financial services, government entities, healthcare, Internet and media, manufacturing, public sector, and telecommunications. Our end-customers deploy our portfolio of solutions for a variety of security use cases across several settings. Typical deployment settings include the enterprise network, the enterprise data center, cloud locations, branch or remote locations, and on-device agents. No single end-customer accounted for more than 10% of our total revenue in fiscal 2026, 2025, or 2024.

Distribution. A substantial portion of our sales to end-customers are through our channel partners utilizing a two-tier, indirect fulfillment model whereby we sell to our distributors, which, in turn, sell to our resellers, which then sell to our end-customers. Sales are generally subject to our standard, non-exclusive distributor agreement, which provides for an initial term of one year, one-year renewal terms, termination by us with 30 to 90 days written notice prior to the renewal date, and payment to us from the channel partner within 30 to 75 days calendar days of the date we issue an invoice for such sales. For fiscal 2026, 30% of our total revenue was derived from sales to two distributors.

We also sell our VM-Series virtual firewalls and Cloud NGFW via various cloud marketplaces. For example, our VM-Series virtual firewalls are sold on Amazon’s AWS Marketplace, Microsoft’s Azure Marketplace, Alphabet’s Google Cloud Marketplace, and Oracle Corporation’s Oracle Cloud Marketplace either directly to end-customers or as part of the respective cloud hosting service provider’s offerings under a usage-based licensing model.

Sales. Our sales organization is responsible for large-account acquisition and overall market development, which includes the management of the relationships with our channel partners, working with our channel partners in winning and supporting end-customers through a direct-touch approach, and acting as the liaison between our end-customers and our marketing and product development organizations. We pursue sales opportunities both through our direct sales force and as assisted by our channel partners, which include resellers, global and regional systems integrators, service providers, managed security service providers, and cloud hosting service providers. We expect to continue to grow our sales headcount to expand our reach in all key growth sectors.

- 13 -

Our sales organization is supported by sales engineers with responsibility for pre-sales technical support, solutions engineering for our end-customers, and technical training for our channel partners.

Channel Program. Our NextWave Channel Partner program is focused on building in-depth relationships with solutions-oriented distributors, resellers, managed security service providers, and authorized delivery and services partners that have strong security expertise. The program rewards these partners based on a number of attainment goals, as well as provides them access to marketing resources, Partner Development Funds, technical and sales training, and support. To promote optimal productivity, we operate a formal accreditation program for our channel partners’ sales and technical professionals, including those authorized to provide customer support or implementation services. As of July 31, 2026, we had more than 8,700 channel partners.

Global Customer Success. Our Global Customer Success organization delivers professional, educational, and support services to customers and partners worldwide. We extend the reach and consistency of these services through a global network of certified partners. These offerings help customers successfully deploy, adopt, operate, and realize value from our products throughout their lifecycle. We invest in technical talent with deep domain expertise, AI-enabled capabilities, and automation to enhance delivery, scale, and consistency of our customer success services.

Marketing. Our marketing is focused on building our brand reputation and the market awareness of our portfolio and driving pipeline and end-customer demand. Our marketing team consists primarily of product marketing, brand, demand generation, field marketing, digital marketing, communications, analyst relations, and marketing analytics functions. Marketing activities include pipeline development through demand generation, social media and advertising programs, managing the corporate website and partner portal, trade shows and conferences, analyst relationships, customer advocacy, and customer awareness. Every year we organize multiple signature events, such as our end-customer conference “Ignite” and focused conferences such as “Cortex Symphony” and “SASE Converge.” We also publish threat intelligence research, such as the Unit 42 Global Incident Response and State of Cloud Security Report, which are based on insights from our global threat intelligence team, Unit 42. These activities and tools benefit both our direct and indirect channels and are available at no cost to our channel partners.

Backlog. Contract amounts that are not recorded in deferred revenue or revenue are considered backlog. Orders billed prior to revenue recognition are included in deferred revenue. We expect backlog will change from period to period for various reasons, including the timing of billing and fulfillment, such as inventory shortages. As such, we do not believe that backlog at any particular time is necessarily indicative of our future operating results.

Seasonality. Our business is affected by seasonal fluctuations in customer spending patterns. We have seen seasonal patterns in our business, which we expect to become more pronounced as we continue to grow, with our strongest sequential revenue growth generally occurring in our fiscal second and fourth quarters.

MANUFACTURING

We outsource the manufacturing of our products to various manufacturing partners, which include our electronics manufacturing services provider (“EMS provider”) and original design manufacturers. This approach allows us to reduce our costs as it reduces our manufacturing overhead and inventory and also allows us to adjust more quickly to changing end-customer demand. Our EMS provider is Flextronics International, Ltd. (“Flex”), who assembles our products using design specifications, quality assurance programs, and standards that we establish, and procures components and assembles our products based on our demand forecasts. These forecasts are based upon historical trends and analysis, adjusted for overall market conditions. All of our hardware products are assembled in the U.S.

The component parts within our products are either sourced by our manufacturing partners or by us from various component suppliers. Our manufacturing and supply contracts, generally, do not guarantee a certain level of supply or fixed pricing, which increases our exposure to supply shortages or price increases.

HUMAN CAPITAL

We believe our ongoing success depends on our employees. As AI transforms the cybersecurity landscape, we continue to invest in our workforce to build AI fluency that enables our employees to innovate, adapt, and meet evolving customer needs while delivering on our mission of protecting our digital way of life.

With a global workforce of 21,921 as of July 31, 2026, our People Strategy is a critical element of our overall company strategy and is overseen by our Chief People Officer who regularly updates our board of directors and the board’s Compensation and People Committee on human capital matters.

Our People Strategy is designed to enable a workforce that is nimble, high-performing, and innovative. We take a comprehensive approach to attracting, enabling, and engaging world-class talent and fostering a culture where every employee can thrive. Our approach includes respecting each employee as a unique individual, demonstrating fairness in all we do, and advancing a culture where employees are inspired to do the most impactful work of their careers.

We also focus on building AI fluency across the organization by tailoring AI learning opportunities to specific roles and functions. For example, we offer department based hands-on training and peer-to-peer use case sharing, as well as a range of self-paced learning processes.

- 14 -

Our values of disruption, execution, collaboration, inclusion, and integrity were co-created with employees and serve as the foundation of our culture. These values are embedded in our talent acquisition, learning and enablement, engagement and performance elevation, rewards, and recognition programs.

Attract and Hire. We continue to evolve our talent strategy to meet the rapidly changing technology landscape. Recognizing the pace of innovation in an AI-driven world, our recruitment strategy prioritizes durable, "AI-readiness" capabilities, such as critical thinking, adaptability, and a capacity for continuous learning.

Our global recruiting programs focus on attracting highly skilled talent across technical and business functions who contribute to our culture, mission and continued innovation.

In fiscal 2026, we continued to strengthen our hiring operations by further embedding AI across the talent acquisition lifecycle. We deployed intelligent tools to enhance core processes, such as sourcing and structured interview tools. Each step is optimized for speed, consistency, and bias mitigation, and we maintain human oversight of hiring decisions.

Our Global Hiring Committee continues to play a key role in maintaining objectivity and our hiring standards. This group of cross-functional senior leaders reviews finalist candidates’ information with a focus on experience and capability. To build robust talent pipelines, we partner with academic institutions and other organizations to support new careers in cybersecurity, promote open roles, proactively reach out to candidates across multiple hiring channels, and source candidates with a range of experiences. We also encourage employee referrals and internal mobility.

Onboard and Enable. Each member of our workforce has a unique career journey and individual needs, interests, and goals. To that end, we strive to create an environment where everyone feels valued, respected, and supported to solve the world’s toughest cybersecurity challenges.

Our learning and development programs help employees build critical capabilities in cybersecurity and AI, while strengthening human-centric skills, such as problem solving, resilience, and adaptability. Learning is integrated into employees’ daily work through a blend of in-person experiences and personalized digital resources, including AI-curated onboarding roadmaps and mentor networks. We provide adaptive learning tracks for employees at every stage of their careers, including specialized paths for early-career talent and employees joining through acquisitions. To further build responsible AI fluency across the organization, we introduced ongoing campaigns, the first of which showcased practical AI use cases, and continue to leverage AI-enabled simulations to help managers strengthen coaching and leadership skills.

Listen and Engage. We aim to foster engagement and help employees feel connected to our mission and values. We use in-person and virtual channels to provide a regular flow of information to and between employees and leadership. These channels include company meetings, digital displays across our sites, our intranet, regular email communications, an active Slack platform, pulse surveys, a peer-to-peer recognition platform, and regular two-way dialogue—such as small, in-person listening sessions hosted by our chief executive officer.

Employee sentiment is also collected and measured from external sources, such as Glassdoor and Comparably. In addition, based on employee participation in an anonymous survey, the Best Practice Institute has certified Palo Alto Networks as one of the “America’s Top 100 Most Loved Workplaces” in 2025. Palo Alto Networks has been recognized by Glassdoor as one of the “Best Places to Work” and the “Best Companies in Tech & AI” in 2026 and by Comparably for “Best Company Culture” in 2025, as well as other employer of choice awards.

In addition to our formal, company-wide, semiannual performance review process, which helps employees set learning and development plans, we believe in always-on performance feedback. Further providing engagement are 12 Employee Network Groups, open to all employees, that leverage different perspectives to build, understand, and support our mission.

Compensation and Benefits. We offer employees competitive compensation and our flexible benefits plans include a variety of health, time off, wellness, and voluntary benefits. Our pay strategy, which includes base salary, cash bonus programs, and equity awards, focuses on compensation based on individual performance. Palo Alto Networks is a fair pay company and we conduct an annual assessment of our pay practices. Through our flexible benefits programs, employees are able to request reimbursement for a range of lifestyle items including fitness, caregiving, and education. Additionally, through our Giving+ program, employees can request monetary matching of their charitable donations and volunteer time.

Health, Safety and Wellbeing. Our commitment to the health, safety and wellbeing of our employees includes providing tools, resources, and benefits focused on physical, mental, and emotional wellbeing. This includes courses designed to equip employees with the knowledge to work safely, and mental health-focused resources on our employee intranet.

- 15 -

CORPORATE RESPONSIBILITY

Corporate Responsibility (“CR”) is integrated into our business strategy and supports our mission of protecting our digital way of life. Our CR approach is informed through many inputs, including our business objectives, ongoing stakeholder engagement, investor and customer interests, benchmarking of industry best practices, regulatory developments, and more. We execute meaningful CR initiatives that include advancing environmental sustainability, investing in people, and operating with integrity. Palo Alto Networks has been recognized by multiple organizations for our corporate responsibility practices, including being ranked third overall on Newsweek's list of “America's Most Responsible Companies 2026” and inclusion on TIME’s “World's Most Sustainable Companies of 2026” list.

Advance Environmental Sustainability. Palo Alto Networks remains committed to reducing the adverse environmental impacts of our operations and value chain and supporting customers' sustainability objectives. Our decarbonization pathway includes implementing operational efficiencies, procuring renewable electricity to run our managed sites, targeting greenhouse gas emissions reductions across our value chain, and making progress on our science-based targets. In fiscal 2026, we continued to strengthen the data, systems, and processes that support our environmental strategy, including expanding carbon emissions lifecycle assessments of select firewall products to better understand product-related emissions. We also enhanced our renewable electricity strategy by procuring high-quality Energy Attribute Certificates in key operating regions, where available and feasible. We report progress towards our goals in our annual Corporate Responsibility Report.

Invest in People. As a company built on trust, continuing to be a leader in responsible business practices and social impact supports our corporate strategy. In addition to our People Strategy described in the section titled “Human Capital” above, we continue to communicate our expectations regarding labor standards, business practices, and workplace health and safety conditions to our supply chain through our Global Supplier Code of Conduct. During fiscal 2026, we maintained our affiliate membership in the Responsible Business Alliance. As cyber threats become increasingly sophisticated and AI-driven, we share threat intelligence and research that helps organizations and communities better understand emerging risks, collaborate with industry partners to advance cybersecurity innovation and resilience, and invest in and support initiatives and nonprofit organizations that expand access to cybersecurity education and help develop the next generation of cybersecurity professionals. We also provide opportunities for employees to support causes they care about through volunteering and community engagement initiatives.

Operate with Integrity. We maintain enterprise-wide ethics, compliance, information security, and data privacy programs designed to promote responsible business practices throughout our operations and value chain. Integrity is one of our core values. Employees, contractors and suppliers are informed about our ethics, labor, and governance expectations, including through our Codes of Conduct, compliance training programs and ongoing communications. The Governance and Sustainability Committee of the board of directors provides primary oversight of corporate responsibility and the board of directors and applicable committees receive regular updates on corporate responsibility topics. In fiscal 2026, we achieved certification under the Global Cross-Border Privacy Rules and Privacy Recognition for Processors systems, demonstrating our commitment to internationally recognized, independently assessed privacy standards governing the responsible handling and cross-border transfer of personal data. We also further strengthened our enterprise-wide AI governance program that supports compliance, privacy, and security across both our internal operations and products.

AVAILABLE INFORMATION

Our website is located at www.paloaltonetworks.com, and our investor relations website is located at investors.paloaltonetworks.com. Our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to reports filed or furnished pursuant to Sections 13(a) and 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), are available free of charge on the Investors portion of our website as soon as reasonably practicable after we electronically file such material with, or furnish it to, the Securities and Exchange Commission (“SEC”). We also provide a link to the section of the SEC’s website at www.sec.gov that has all of our public filings, including Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, all amendments to those reports, our Proxy Statements, and other ownership-related filings.

We also use our investor relations website as a channel of distribution for important company information. For example, webcasts of our earnings calls and certain events we participate in or host with members of the investment community are on our investor relations website. Additionally, we announce investor information, including news and commentary about our business and financial performance, SEC filings, notices of investor events, and our press and earnings releases, on our investor relations website. Investors and others can receive notifications of new information posted on our investor relations website in real time by signing up for email alerts and RSS feeds.

Further corporate governance information, including our corporate governance guidelines, board committee charters, and code of conduct, is also available on our investor relations website under the heading “Governance.” The contents of our websites are not incorporated by reference into this Annual Report on Form 10-K or in any other report or document we file with the SEC, and any references to our websites are intended to be inactive textual references only. All trademarks, trade names, or service marks used or mentioned herein belong to their respective owners.

- 16 -

Previous: Cover and table of contents · Next: Item 1A. Risk Factors