팔로알토 네트워크스(PANW) 2026 회계연도 4분기 실적 발표 콜: NGS ARR 91억 달러 달성
팔로알토 네트웍스는 수주 가속화와 역대 최고 잔여 이행 의무(RPO)를 바탕으로 2026 회계연도를 마감했다. 4분기 매출은 전년 대비 34% 증가한 34억 1,000만 달러, 연간 매출은 24% 증가한 115억 달러를 기록했다. RPO는 34% 늘어난 212억 달러로 집계되었으며, 차세대 보안(NGS) ARR은 63% 증가한 91억 달러를 달성했다. 경영진은 2027 회계연도에 매출 141억~142억 달러, NGS ARR 110억 7,500만~111억 7,500만 달러를 전망하고 있다. 한편, SaaS 제품 전환에 따른 클라우드 호스팅 비용 증가와 하드웨어 부문의 원자재 가격 상승이 총이익률에 압박을 가할 가능성이 언급됐다.
팔로알토 네트웍스(NASDAQ: PANW)는 수주 가속화, 역대 최고 잔여 이행 의무(RPO), 보안 플랫폼 전반의 강력한 성장에 힘입어 2026 회계연도를 마감했다. 경영진은 이러한 모멘텀이 플랫폼 통합, AI 관련 보안 수요, 그리고 사이버아크와 크로노스피어로부터 얻은 초기 매출 시너지 효과 덕분이라고 밝혔다.
핵심 요약
- 4분기 매출은 전년 동기 대비 34% 증가한 34억 1,000만 달러를 기록했으며, 연간 매출은 24% 증가한 115억 달러를 기록했다.
- 잔여 이행 의무(RPO)는 34% 증가한 212억 달러로 역대 최고치를 기록했다. 단기 잔여 이행 의무(Current RPO) 역시 34% 증가한 93억 달러를 기록했다.
- 차세대 보안(NGS) ARR(연간 반복 매출)은 63% 증가한 91억 달러를 기록했다. 팔로알토 네트웍스는 4분기 동안 10억 달러에 가까운 순신규 NGS ARR을 추가했다.
- 회사는 4분기에 약 220건의 순신규 플랫폼화를 완료했다. 플랫폼 도입 고객의 순매출 유지율(NRR)은 120%를 초과했다.
- 프리즘아 AIRS(Prisma AIRS)는 정식 출시 후 4분기 만에 ARR 1억 달러를 돌파했으며, XSIAM은 ARR 7억 달러를 넘어서며 70% 성장했다.
- 2027 회계연도에 대해 경영진은 매출 141억~142억 달러, NGS ARR 110억 7,500만~111억 7,500만 달러를 전망하고 있다.
핵심 재무 실적
| 지표 | 2026 회계연도 4분기 / 2026 회계연도 실적 | 전년 동기 대비 변동 | 비고 |
|---|---|---|---|
| 4분기 매출 | 34억 1,000만 달러 | +34% | 전 지역 및 플랫폼에 걸쳐 광범위한 성장을 나타냄 |
| 2026 회계연도 매출 | 115억 달러 | +24% | 인수한 사업의 기여분 포함 |
| RPO | 212억 달러 | +34% | 처음으로 200억 달러 돌파 |
| 단기 RPO | 93억 달러 | +34% | 계약 기간은 전년 대비 안정적으로 유지됨 |
| NGS ARR | 91억 달러 | +63% | 4분기에 10억 달러에 가까운 순신규 ARR 추가 |
| 4분기 총이익률 | 74.8% | -100 bps | 클라우드 및 SaaS 매출 비중 확대에 따른 압박 |
| 2026 회계연도 총이익률 | 75.8% | -60 bps | SaaS 제공 서비스가 아직 총이익률 성숙도에 도달하지 않음 |
| 4분기 Non-GAAP 영업이익률 | 29.6% | — | 영업 레버리지 및 인수 시너지 반영 |
| 2026 회계연도 Non-GAAP 영업이익률 | 29.2% | +40 bps | 인수한 사업의 자체 이익률이 낮았음에도 불구하고 확대됨 |
| 4분기 Non-GAAP EPS | $1.02 | — | 경영진 가이던스 상단을 $0.04 웃돎 |
| 4분기 조정 잉여현금흐름 | 12억 9,000만 달러 | +35% | — |
| 2026 회계연도 조정 잉여현금흐름 | 44억 1,000만 달러 | — | 마진율은 38.4%로 40 bps 상승함 |
| 현금 및 단기투자자산 | 79억 달러 | — | 회계연도 말 잔액 |
사업 및 운영 실적
플랫폼화 및 주요 계약
팔로알토 네트웍스는 4분기에 약 220건의 순신규 플랫폼화를 추가했는데, 이는 2년 전 회사가 해당 지표를 추적하기 시작했을 때 기록한 실적의 2배가 넘는 수치다. 경영진은 2030 회계연도까지 4,000건 이상의 플랫폼화를 달성한다는 목표를 유지했으며, 이는 NGS ARR 200억 달러 목표를 뒷받침한다.
4분기 주요 계약으로는 글로벌 통신사와의 1억 2,600만 달러 규모 네트워크 보안 계약, IT 서비스 제공업체와의 7,200만 달러 규모 거래, 글로벌 결제 플랫폼과의 5,300만 달러 규모 플랫폼화 계약이 포함된다. 이 결제 고객은 프리즘아 AIRS에도 7자리 수 달러 후반에 달하는 금액을 집행하기로 약정했다.
네트워크 및 AI 보안
2026 회계연도 네트워크 및 AI 보안 매출은 17% 증가한 83억 5,000만 달러를 기록했다. 4분기 소프트웨어 방화벽 ARR은 29% 증가했으며, 5세대(Gen 5) 하드웨어 어플라이언스에 대한 수요도 견조하게 유지되었다.
연간 SASE 수주는 40% 증가했다. 팔로알토 네트웍스는 연간 계약 가치 기준 약 4억 5,000만 달러에 달하는 약 100개 계정에서 기존 서비스 제공업체를 대체했다. 경영진은 이러한 성과가 공통 플랫폼상에서 SASE, SD-WAN, 하드웨어 방화벽 및 소프트웨어 방화벽을 통합한 덕분이라고 설명했다.
프리즘아 AIRS는 정식 출시 첫해에 ARR 1억 달러 이상과 약 800곳의 고객사를 확보했다. 회사는 또한 코이(Koi) 인수 통합 이후 자사의 에이전틱 엔드포인트 전략 고객사가 100곳 이상이라고 발표했으며, 이는 연초 통합 완료 이후 2.5배 증가한 수치다.
코텍스 및 옵저버빌리티
2026 회계연도 코텍스(Cortex) 매출은 25% 증가한 19억 2,000만 달러를 기록했다. XSIAM은 70% 증가한 7억 달러 이상의 ARR로 한 해를 마감했으며, 1,000곳 이상의 고객사를 확보했다. 경영진은 XSIAM을 사용하는 고객의 평균 대응 시간(MTTR)이 10분 미만으로 단축되었다고 밝혔다.
옵저버빌리티 ARR은 5억 달러를 돌파했으며, 2분기 크로노스피어 인수 완료 이후 2배 이상 증가했다. 이번 분기에는 AI 추론 제공업체와의 2,000만 달러 규모 계약이 포함되었다. 경영진은 4분기 순신규 ARR에 대형 LLM 고객이 타사에서 크로노스피어로 전환하면서 발생한 억 달러 규모의 혜택이 포함되었다고 언급했다.
회사는 메트릭, 로그, 트레이스 기능에 실제 사용자 모니터링을 추가하기 위해 엠브레이스(Embrace)를 인수했다. 또한 콘솔(Console) 인수 절차를 완료했으며, 콘솔 팀은 코텍스 조직에 합류하여 IT 및 보안 운영을 위한 AI 퍼스트 제품 개발에 집중할 예정이다.
이디라 신원 보안
사이버아크 인수로 형성된 신원 보안 플랫폼인 이디라(Idira)는 2026 회계연도에 전년 대비 21% 증가한 12억 6,000만 달러의 프로포마(Pro Forma) 매출을 올렸다. 공동 시장 진출(GTM) 활동을 통해 팔로알토 네트웍스의 기존 고객층에서 400개 이상의 공동 리드와 200개 이상의 순신규 고객사를 확보했다. 총 계약 가치가 500만 달러 이상인 4분기 계약 건수는 전년 동기 대비 50% 증가했다.
경영진은 사이버아크 인수 통합 시너지 효과가 계획보다 3~6개월 앞서 진행되고 있다고 밝혔다. 회사는 또한 Modern PAM을 출시했으며 기존의 전통적인 특권 권한 관리(PAM) 고객을 대상으로 업그레이드를 추진할 계획이다.
지역별 성장
4분기 매출은 미주 지역에서 33%, EMEA(유럽·중동·아프리카)에서 39%, JPAC(일본 및 아시아 태평양)에서 34% 증가했다.
경영진 가이던스
| 지표 | 2027 회계연도 1분기 가이던스 | 2027 회계연도 가이던스 |
|---|---|---|
| NGS ARR | 95억 4,000만~95억 6,000만 달러, +63% | 110억 7,500만~111억 7,500만 달러, +22%~+23% |
| RPO | 208억~209억 달러, +34%~+35% | 252억~254억 달러, +19%~+20% |
| 매출 | 33억~33억 1,000만 달러, +33%~+34% | 141억~142억 달러, +23%~+24% |
| Non-GAAP EPS | $0.96~$0.98 | $4.16~$4.19 |
| Non-GAAP 영업이익률 | — | 29.5% |
| 조정 잉여현금흐름 마진율 | — | 38% |
| 희석주식수 | 8억 3,700만~8억 4,400만 주 | 8억 4,400만~8억 4,700만 주 |
2027 회계연도에 대해 경영진은 네트워크 및 AI 보안 매출이 10%대 초반의 성장률을 기록할 것으로 예상하고 있다. 코텍스 매출은 약 30% 증가하고, 이디라 매출은 약 15억 달러를 기록하여 프로포마 기준 10%대 후반에서 20%의 성장을 보일 것으로 전망된다.
경영진은 2027 회계연도 순신규 NGS ARR의 60%~61%가 하반기에 발생할 것으로 예상한다. 1분기는 대형 LLM 고객의 크로노스피어 전환이 이번 분기에도 계속됨에 따라 평소보다 계절적으로 매출이 클 것으로 예상되지만, 4분기보다는 기여도가 낮을 것이다.
콘솔과 엠브레이스는 2027 회계연도 가이던스에 미치는 영향이 미미할 것으로 예상된다. 회사는 또한 2028 회계연도 조정 잉여현금흐름 마진율 목표치 40%를 재확인했다.
리스크 및 관전 포인트
- 성장세가 빠른 클라우드 및 SaaS 제품으로의 전환은 이러한 서비스가 아직 이익률 성숙도에 이르지 못함에 따라 호스팅 비용을 증가시키고 총이익률에 압박을 가하고 있다.
- 하드웨어 사업에서는 원자재 비용, 특히 메모리와 스토리지 가격이 계속 높은 수준을 유지할 것으로 예상된다. 하드웨어는 회사 전체 매출의 약 10%를 차지한다.
- 2027 회계연도 순신규 NGS ARR 비교는 2026 회계연도에 기록된 억 달러 규모의 크로노스피어 마이그레이션 혜택의 영향을 받을 것이다.
- 기업들이 평가를 진행하고 계약 만료일을 맞추며 사이버 보안 현대화와 기타 AI 이니셔티브 간의 균형을 맞춤에 따라, 고객의 플랫폼화 프로젝트에는 일반적으로 1년에서 3년이 소요된다.
- 경영진은 2027 회계연도에 영업 레버리지와 인수 시너지가 상승된 매출원가를 충분히 상쇄할 것으로 기대하고 있어, 지속적인 통합 이행이 중요한 요인이 되고 있다.
애널리스트 Q&A 하이라이트
AI 보안 및 플랫폼 수요: 경영진은 향상된 성능의 사이버 특화 및 오픈소스 AI 모델이 취약점 관리, 실시간 방어, 보안 플랫폼 통합에 대한 CEO들과의 논의를 가속화하고 있다고 밝혔다. 하지만 고객의 테스트 및 도입 주기는 즉각적이기보다는 여전히 신중하게 진행되고 있다.
M&A 전략: 니케시 아로라(Nikesh Arora) CEO는 인수합병이 그 자체로서의 전략이라기보다 제품 전략의 결과물이라고 규정했다. 팔로알토 네트웍스는 외부 기술이 내부 개발 방식보다 시장 변화에 더 빠르게 대응할 수 있을 때 기업을 인수할 수 있다고 덧붙였다.
사이버아크 매출 시너지: 경영진은 이디라가 팔로알토 네트웍스의 기존 고객층에 대한 교차 판매, Modern PAM으로의 업그레이드, 비인간(nonhuman) 신원 및 자율 에이전트 보안에 대한 새로운 수요 증가로부터 수혜를 입을 것으로 기대한다.
옵저버빌리티 확장: 크로노스피어는 초기에 AI 네이티브 고객에 초점을 맞추고 있다. 경영진은 엠브레이스 및 신세틱 모니터링을 통해 기능이 확장됨에 따라 향후 6개월 동안 더 넓은 기업 시장에서 경쟁력이 강화될 것으로 예상하고 있다.
장기적 자동화: 팔로알토 네트웍스는 사이버 탐지, 예방 및 복구에서 사람의 개입을 줄이는 것을 목표로 한다. 경영진의 장기적인 목표는 AI 에이전트가 고객 승인을 확인하면서 제품 교체, 설정 및 정책 수립을 처리하도록 하는 것이다.
실적 발표 컨퍼런스 콜 전문
전체 실적 발표 컨퍼런스 콜 녹취록
경영진 발표
Hamza Fodderwala
Good day, everyone, and welcome to Palo Alto Networks' Fiscal Fourth Quarter 2026 Earnings Conference Call. I am Hamza Fodderwala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, September 1, 2026 at 1:30 p.m. Pacific Time.
With me on today's call to discuss our fiscal fourth quarter results are Nikesh Arora, our Chairman and Chief Executive Officer; and Dipak Golechha, our Chief Financial Officer. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q4 '26 supplemental financial information and Q4 '26 earnings presentation.
During the course of today's call, we will be making forward-looking statements and projections regarding the company's business operations and financial performance as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation.
This presentation also contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis.
I will now turn the call over to Nikesh.
Nikesh Arora
Thank you, Hamza. Good day, everyone, and thank you for being with us to discuss our progress. As you can see, our execution fueled a record finish to the fiscal year. We exceeded our guidance across every financial metric in Q4, with bookings momentum accelerating for the second straight quarter. This performance is a direct result of record-breaking platformization adoption and the growing urgency among customers to fortify their defenses as AI fundamentally redefines the security landscape.
We achieved record RPO, surpassing the $20 billion threshold for the first time to close the year at $21.2 billion, representing a growth rate of 34%. NGS ARR reached $9.1 billion, up 63%, enabling us to report one of our most substantial Next-Generation Security outperformances to date. Most notably, we added nearly $1 billion in net new NGS ARR this quarter alone.
I remember my first Analyst Day in 2019. Shortly after I arrived, we set a high bar to reach $1 billion in Next-Generation Security revenue by fiscal 2022, just as we were initiating our pivot from a single product firewall vendor and a unified security platform. That transformation journey has reached a pivotal inflection point, and the scale of our current success is a testament to that vision.
We delivered broad-based strength across our platforms in Q4, with Network Security, our largest business, reporting exceptional results across SASE, software and hardware firewalls. XSIAM maintained its strong momentum, while Prisma AIRS achieved a significant milestone, surpassing $100 million in ARR within 4 quarters of general availability. This represents the fastest scaling product in the history of Palo Alto Networks.
Fiscal 2026 marked a pivotal inflection point in our transformation journey. We closed the two largest acquisitions in our history with CyberArk and Chronosphere, both of which are exceeding our initial expectation. Both businesses are gaining significant traction within our platformized architecture and are scaling at an accelerated pace compared to their previous standalone performance. These achievements are a testament to the execution and deep collaboration the thousands of new colleagues who joined us this past year. We look forward to continuing to [ share ] momentum into FY '27.
Q4 was the very first quarter in which we witnessed the profound implications of cyber capable models. As I've said before, AI is a long-term tailwind for cybersecurity. While these models are becoming increasingly proficient at uncumbering vulnerabilities, detection is merely the opening act. Truly validating, interpreting context and resolving these issues requires broad cybersecurity platforms working alongside frontier AI. This synergy is essential to stress test environments, manage agentic actions and trigger machine speed remediation during an active threat.
Defending at that speed necessitates a unified data architecture where AI processes every signal, collapsing response times from days to just minutes. Platformization is the only viable strategy for real-time defense, fighting AI with AI. And that philosophy continues to gain significant resonance with our customers in Q4.
During the fourth quarter, we achieved approximately 220 net new platformizations, surpassing our prior record and representing more than twice the volume from when we initiated this metric 2 years ago. The performance validates that our philosophy of real-time defense [ to ] unified architecture continues to gain significant resonance. Beyond initial adoption, standardizing our platform yields superior retention and expansion, with NRR or net revenue retention exceeding 120% for our platformized cohort in Q4.
As we look forward, we remain on track towards our long-term objective of over 4,000 platformizations by fiscal 2030, which serves as a bedrock for reaching our $20 billion Next-Generation Security ARR target. Our largest Q4 wins show platformization in action. During the fourth quarter, we secured a $126 million agreement with a global telecoms leader. This organization moved to standardize on our network security platforms, bolstering their next-generation firewall footprint while displacing legacy proxy providers with Prisma Access for SASE.
We also closed a $72 million transaction a premier IT service provider. This client has fully embraced platformization across network security, Cortex and Idira, making 8-figure investments in each, serving as a powerful validation of our cross-sell momentum in Q4. A further highlight was a $53 million platformization deal with a leading global payments platform. Beyond standardizing their network defense on our architecture, they committed high 7 figures to Prisma AIRS as they accelerate their enterprise AI initiatives.
Fiscal 2026 has emerged as a landmark period in the rapid evolution of AI, marked by 3 distinct inflections over the last 6 months. Each of these shifts fundamentally redefines how AI interacts with the enterprise, and by extension, how it impacts the cybersecurity landscape. For us to effectively lead and protect our customers, maintaining our position of the vanguard of these structural changes is paramount.
The first inspection was the arrival of OpenClaw. Earlier this year, OpenClaw served as the catalyst for the transition from standard LLMs to agentic action, fundamentally altering the dynamic between human operators and AI systems. Just a year ago, AI was largely defined by individual human prompting, a synchronous multiturn dialogue, a task was completed to the [ person ] of the loop. Virtually overnight, we witnessed the emergence of fully autonomous agents. These are persistent entities that operate for extended durations, executing complex workflows without direct supervision.
For a single employee that wants to manage 1 task at a time, the same individual can now orchestrate thousands of autonomous agents. The implications for the enterprise are profound. Each of these agents generates continuous traffic, interacting with models, creating internal data and communicating with other tools and agents around the clock. This creates a massive volume of telemetry that must be observed while every agent requires its own set of credentials. We're now securing a whole new cast of machine identities with autonomous permissions. The surge in traffic, data and identity complexity represents a significant long-term tailwind across every one of our platforms.
The second was the Mythos moment, which prove that deep domain training enables AI to achieve unprecedented proficiency. In our sector, this is manifested as the weaponization of AI to identify and exploit vulnerability to scale. This shift has exposed to deep technical debt within the enterprise or legacy flaws and persistent risk configurations that once took months for a human to uncover are now exploited in minutes.
In an AI-driven threat environment, there is no longer anywhere to hide. For our customers, the Mythos moment reframes the security challenge from visibility to velocity. Organizations must now identify exposures before they are weaponized and respond at machine speed. This is why real-time defense has shifted from a future road map item to a present day requirement.
To address this, we expanded our Frontier AI Defense Service last month, introducing a multimodal harness that enables enterprises to stress test their environments. This service leverages the most sophisticated cyber capable models available, and we are proud to be the first certified commercial partner for [ Mythos 5 ].
The third involves an emerging inflection point that we expect will dominate the cybersecurity dialogue in the coming quarters. For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of [ open weight ] and open source architectures. Enterprises are increasingly prioritizing sovereign control over their AI, leading to the deployment of specialized models deeply integrated with proprietary data. We expect a major acceleration as organizations utilize internal telemetry to fine-tune models for bespoke enterprise use cases.
While frontier models will continue to set the high watermark for intelligence, the broader market is heading towards a rapid fragmentation and proliferation. Crucially, each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platformized protection is expanding dramatically. Three pivotal moments, each with a unique impact, yet all leading to a single conclusion. As the relationship between humans and AI evolves and deployments multiply, the necessity for unified real-time defense has never been greater.
It is early days, but we are beginning to see the signs of how these trends are impacting our business, starting with our largest business, Network Security. AI represents a significant long-term tailwind that is expanding our total addressable market in Network Security while reinforcing that platformization is the only viable strategy for the modern enterprise. As the global AI build-out continues, every new data center becomes critical infrastructure that requires robust fortification through hardware and software firewalls, whether delivered natively by cloud providers or via a unified security platform. The ecosystem driving this infrastructure expansion had reached a pivotal inflection point, and now we're seeing a new vanguard of buyers emerge spanning sovereigns, neoclouds and frontier labs, all racing to deploy massive computational capacity that must be secured. We achieved strong early traction with this cohort in FY '26, including multiple 7-figure bookings in the fourth quarter.
In total, our firewall execution drove accelerated bookings for the fiscal year, fueled by robust demand for latest Gen 5 hardware and the continued momentum of our software offerings as customers scale their cloud and AI workloads. As this infrastructure matures and autonomous agents are deployed, we expect a dramatic proliferation of agentic traffic across every network and cloud environment.
The impact on our SASE platform is already evident, where agentic traffic has surged 9x over the last 9 months. Defending at this scale requires machine speed inspection or competence, a core competence we have refined for 2 decades, enabling us to block more than 30 billion attacks in a single day. Ultimately, AI is underscoring the urgent need for unified platforms that deliver real-time defense.
In FY '26, our platform advantage drove exceptional results in our SASE business, where bookings grew 40% with broad strength across [ access ] SD-WAN and secure browser. We successfully displaced legacy incumbents in nearly 100 accounts representing over $400 million in total contract value, nearly double the volume of displacement from a year ago. While we have rapidly ascended to the #2 position in this market, we're playing to win and remain on a clear trajectory to become the SASE leader in the next 5 to 7 years.
One of the early chapters of the shift with the future necessity securing both human and machine identities through unified architecture capable of providing defense at machine speed. Organizations are transitioning AI initiatives from experimentation to full-scale production significantly, widening the defensive perimeter with each new deployment. Prisma AIRS has continuously adapted alongside these adoption cycles, evolving to mitigate the unique risk emerging from every phase of the AI journey.
While our initial focus addressed the chatbot-centric era of generative AI, our vision has expanded towards proving a comprehensive architecture of agentic security. This unified approach begins with securing machine identities and credentials, incorporates deep observability of agentic footprints and extends to the endpoint where we analyze behavioral intent. By funneling this traffic to our AI gateway, we ensure that security policies are enforced real-time across every interaction.
Prisma AIRS achieved a remarkable milestone in Q4, surpassing $100 million in ARR within just 4 quarters of general availability, marking the most rapid scale out of any product in our history. Our momentum is reflected in a growing base of our 800 customers for this product, with the majority of our largest transactions now featuring multi-module adoption in Q4.
We're also seeing significant early validation of our agentic endpoint strategy following the Koi acquisition. We believe the endpoint is reaching a critical inflection point as AI development tools migrate to the desktop environment. This shift as an expanded surface area where agents autonomously manage files and access sensitive credentials. Legacy security tools often remain blind to the underlying intent and reasoning behind these machine speed actions. In this landscape, visibility without action is insufficient.
Our platformized approach delivers end-to-end transparency from the initial prompt to the final execution, enabling in-line prevention and machine speed. This capability is becoming a fundamental requirement for the enterprise. We've already secured over 100 logos, representing a 2.5x increase since finalizing the Koi integration earlier this year.
Ultimately, the synergy of detection and prevention is most effective when unified as a single platform, with XSIAM serving as a central nervous system for this critical telemetry. Earlier this year, our Unit 42 researchers demonstrated the staggering speed of modern threats by simulating a comprehensive AI-driven attack in under 30 minutes. Contrast that with the industry standard defense report response of 4 days, and it's clear that legacy approaches are no longer sustainable.
Customers standardizing XSIAM are transforming their operations, reducing their mean time to respond to less than 10 minutes, massively from the days of weeks acquired previously as we continue our relentless push towards true realtime defense. In the fourth quarter, XSIAM maintained its exceptional momentum, concluding the year with over $700 million in ARR, up 70%, while surpassing the 1,000th customer milestone in the platform.
The power of our architecture lies in the fact that live telemetry is already resident within XSIAM, allowing us to seamlessly unlock new value through our unified data lake. Expanding deployment does not require the friction of new product integration. It simply involves [ curing ] existing data in new ways. As of Q4, the majority of customers have embraced this platform advantage, utilizing multiple modules, including exposure management and cloud security.
Turning to observability. We continue to see the world's premier AI native and cloud-first organization standard in our technology. The entire entities pioneering the AI frontier generate telemetry to scale that traditional tools cannot withstand. Chronosphere has engineered specifically for these massive data volumes, capturing every training run in [ Agent Blue ]. This quarter, we signed a $20 million deal with a hyper-growth AI inference provider that processes tens of trillions of tokens a day. This is no longer -- there is no stronger validation of our platform than when the architects of the AI ecosystem trusts us to monitor their own infrastructure.
Since finalizing the Chronosphere acquisition in Q2, our observable ARR has more than doubled, eclipsing the $500 million mark. This performance has significantly outperformed our initial targets and represents the most rapid post acquisition scaling in our history. Our cross-sell strategy is delivering tangible results, with XSIAM contributing to 50% of net new cross-rate logos this quarter through multiple 7-figure agreements.
We are further enriching the stack with the acquisition of Embrace, integrating real user monitoring to complement our core metrics, logs and traces. This expansion enables us to provide a comprehensive end-to-end observability platform that spans from the core infrastructure to the final user experience. Collectively, XSIAM and observability now represent over $1 billion in ARR, a remarkable achievement for data-intensive platforms that were not part of our portfolio just a few years ago.
A [ consort ] of our success throughout my tenure at Palo Alto Networks has been our ability to identify premier technology and world-class talent and seamlessly integrate them into our culture. While the complexity of our integration effort naturally increased scale of this year's acquisitions, result has been extraordinary. In Q4, the success was most evident in our performance with CyberArk, or now called Idira.
Just 2 quarters after finalizing our largest acquisition date, we are accelerating growth while capturing synergies ahead of schedule, a rare feat that demonstrates the power of our integration engine. These results are a testament to the deep collaboration with our new colleagues. From a go-to-market perspective, our joint efforts yielded over 400 shared leads, driving more than 200 net new logos from our installed base. We are also seeing a significant move towards larger commitments, with $5 million-plus TCV deals up 50% year-over-year in the fourth quarter.
Yet the most significant challenge and opportunity remains the rise of agentic AI. By definition, an agent possesses agency, necessitating a machine identity with the precise context and permissions required to execute its workflow. As enterprises deploy thousands of these autonomous entities, many remain outside of formal governance often lacking property scope permissions. This summer served as a wake-up call as rogue agents compromised environments at several frontier AI labs.
In 1 notable instance, an agent escaped its sandbox and exploited system vulnerabilities because its access has never been properly restricted. At its core, this represents a fundament identity crisis for the enterprise. This is a strategic imperative behind our Idira platform. Idira extends sophisticated identity security and privilege controls to our agents, ensuring every machine action is authorized, scoped and fully auditable.
As we integrate these agentic controls of our AI gateway into Prisma AIRS, we're empowering organizations to enforce security policies and maintain defense in real time. Fiscal 2026 was a transformative year for Palo Alto Networks and the broader industry. We remain convinced that the AI tailwinds catalyzing cybersecurity demand will only intensify as we look towards the future.
First, the global AI infrastructure build-out is drawing trillions in investment. We anticipate more capital expenditure in the next 5 years than the preceding 2 decades. This massive expansion is fueled by demand that continues to outstrip supply. For AI to deliver on its promise, both traffic and data volume must scale and has to do every bit requires inspection, and every byte requires observability.
This surge in critical infrastructure is a permanent tailwind for cybersecurity, a trend already manifesting in the accelerated momentum of our network security and observability businesses this year. Second is a strategic imperative transition towards real-time defense. With cyber attacks now operating at machine speed, fragmented legacy tools are no longer viable. There's approximately $1 trillion of global cybersecurity debt that must be modernized to defend against automated threats. Because AI operates instantaneously, this modernization must occur on unified platforms. Platformization is the only solution for real time defense, ensuring the telemetry policy are harmonized across every control point. We're still in the early chapters of the structural change.
Third, AI has inaugurated a fundamentally new market for cybersecurity. The rise of autonomous agents will dramatically expand the network surface area that requires fortification. Robust governance and security guardrails for AI have shifted from optional features to essential enterprise requirements. While this market is evolving rapidly, we believe the future belongs to architectures providing end-to-end controls, a vision we are delivering through Prisma AIRS.
Lastly, I do want to mention, in breaking news, we closed our acquisition of Console today. Console brings an AI-first approach to product development in the IT and security operations space. [ Andre ] and his team are going to work as part of our Cortex effort to identify our capabilities and drive us faster into the AI era. I want to welcome both the Embrace and Console teams, acquisitions we closed this quarter, to Palo Alto Networks.
As we move into fiscal 2027 with significant momentum, we understand that our continued leadership must be earned through disciplined execution every quarter. I want to express my gratitude to our employees for their performance during this milestone year and to our customers for their enduring partnership.
With that, let me hand over to Dipak.
Dipak Golechha
Thank you, Nikesh, and good afternoon, everyone. We delivered a strong close to a record year, driven by the broad-based strength across our platforms and the early success of our integration efforts. Our teams executed with discipline, and we exceeded guidance across every metric. Before walking through the details, please note that I'll be speaking to our results both on a reported and a pro forma basis to provide a normalized growth comparison where applicable. All growth percentages will be on a year-over-year basis unless stated otherwise.
Starting with the top line, Q4 RPO exceeded $20 billion for the first time, ending the year at $21.2 billion, up 34%. Our bookings growth accelerated for the second consecutive quarter on a pro forma basis, driven by the success of our platformization strategy. Current RPO reached $9.3 billion, also up 34% as contract durations remained steady year-over-year. We also delivered a record result in NGS ARR, which reached $9.1 billion in Q4, up 63%. As Nikesh highlighted, most notable was that nearly $1 billion of net new NGS ARR in Q4, which almost doubled year-on-year and is a milestone that only a select category of technology companies have ever achieved.
I still recall my first quarter as CFO in Q3 of fiscal '21, when we surpassed $970 million in total NGS ARR. We've now added approximately that amount in a single quarter. That's a testament to the multiple growth drivers in our business. five years ago, SASE was still in its infancy, and XSIAM had not yet launched. Today, those will either surpass or approaching $1 billion ARR businesses.
To provide more visibility into our growth drivers, we're introducing new revenue disclosure by platform, as I previewed last quarter. Those 3 platforms are Network and AI Security, Cortex and Idira. We provided historical periods as well as product composition to these platforms in the appendix of our earnings presentation published on our website.
Before diving into our revenue by platform, please note that Network and AI Security includes the certificate life cycle management business we acquired with CyberArk, which has since been rebranded to Next-Generation Trust Security or NGTS. NGTS contributed approximately $85 million to Network and AI Security revenue in fiscal year '26. Additionally, the revenue by platform I will discuss excludes certain items like professional services, which are reported in the category titled Other, as shown in the earnings presentation appendix.
Let's start with Network and AI Security. Our revenue here grew 17% for the full fiscal '26, reaching $8.35 billion in revenue. We continue to deliver above market and double-digit growth in network security, which speaks to our strong competitive position and the large market opportunity still ahead of us in our largest platform. As an example, we continue to gain share in SASE, with bookings and ARR growing well ahead of the overall market. Our software firewall business accelerated once again, reaching 29% ARR growth in Q4. And Prisma AIRS surpassed $100 million in ARR within its first year of general availability. Finally, we had another strong quarter in our hardware firewall business, driven by the adoption of our latest Gen 5 appliances.
Turning to Cortex, which includes our security operations and observability platform. Revenue grew 25% in fiscal year 2026 to $1.92 billion in revenue. As noted earlier, XSIAM continues to be a key driver of Cortex, with ARR growing 70% in Q4. On the observability side, our ARR surpassed $500 million and more than doubled since we closed the acquisition of Chronosphere in Q2. Keep in mind, and as we noted last quarter, our Q4 net new ARR includes a 9-figure benefit from a large LLM customer migrating to Chronosphere from an incumbent vendor.
Lastly, we have Idira, which consists of our identity security platform from the CyberArk acquisition closed in early fiscal Q3. As noted earlier, Idira excludes revenue from the certificate life cycle management acquired from CyberArk. On a pro forma basis, Idira revenue reached $1.26 billion in fiscal year '26 and grew 21%. Our bookings grew faster than revenue in Q4, which is a testament to our early integration success and go-to-market collaboration.
In total, our revenue grew 34% to $3.41 billion in the fourth quarter. And for the full fiscal year, revenue reached $11.5 billion, up 24% year-over-year. From a geographic perspective, we delivered robust growth across all of our regions. The Americas was up 33% year-over-year, EMEA was up 39% year-over-year and JPAC was up 34% year-over-year.
Moving down the P&L. Total gross margin in Q4 was 74.8%, down 100 basis points year-over-year. For the full fiscal year, gross margin was 75.8%, down 60 basis points year-over-year. This decline reflects a mix shift towards our faster-growing SaaS offerings, which continue to scale with our platforms and have yet to reach their gross margin maturity. Looking ahead, the growing majority of revenue is cloud and SaaS, and we anticipate that mix shift will drive our cloud hosting costs faster than total revenue in fiscal year '27.
Turning to the supply chain. We expect rising commodity costs to persist in our hardware business, particularly as it relates to memory and storage. As a reminder, while we're pleased with the strength that we're seeing in our hardware demand, revenue from hardware represents approximately 10% of the total company. We continue to manage our component cost exposure through our strategic supplier relationships and selective pricing actions across our portfolio of hardware products. Ultimately, our primary focus remains on optimizing the business for total operating income and margin, and this focus was reflected in our Q4 results and our full year results.
Q4 non-GAAP operating margin came in at 29.6%. And for the full fiscal year, we achieved operating margin of 29.2%, an increase of 40 basis points year-over-year. This annual expansion is particularly notable, as it includes a partial year of our largest acquisitions, which operated in much lower operating margins at stand-alone entities.
We're making excellent progress on this front. Regarding CyberArk synergies, our integration synergy targets remain 3 to 6 months ahead of plan. Looking ahead to fiscal year '27, we anticipate Higher cost of goods sold will be more than offset by continued operating leverage as we scale efficiently and deliver on M&A synergies.
Our focus on operating leverage drove Q4 non-GAAP EPS of $1.02, exceeding the high end of our guided range by $0.04. Adjusted free cash flow for the fourth quarter reached 1.9 -- sorry, reached $1.29 billion, growing 35% year-over-year. For the full fiscal year '26, adjusted free cash flow was $4.41 billion, delivering a margin of 38.4%, an increase of 40 basis points year-over-year. As a result of our strong free cash flow generation, we ended fiscal '26 with a robust balance sheet, including $7.9 billion in cash, cash equivalents and short-term investments.
Stepping back, over the past 3 years, we've proven our ability to deliver durable and profitable growth. Our execution has driven over 500 basis points operating margin expansion. We've achieved this whilst capturing market share across new categories, driven by our industry-leading R&D investment.
Our operating leverage has also translated directly to cash flow. Adjusted free cash flow margin has been 38% or better in each of the last 4 years. And we sustained the strong cash flow generation even while absorbing the impacts of large M&A and as our customers moved increasingly from multiyear to annual billing. This track record of scaling profitably is the bedrock of our financial model. It provides us with the ability to neutralize potential cost headwinds while simultaneously fueling our innovation engine, our ultimate competitive advantage and the catalyst for our customers' platformization journeys.
Looking ahead, we continue to have increasing visibility into our free cash flow. This has been driven by a combination of steady operating margin expansion as well as a smooth transition to deferred or annual billing in our core business. To provide some context, annual billings increased significantly from 6% of bookings in fiscal '20 to 27% in fiscal '25. Now we're seeing a steady rise with the percentage of annual billings having increased by low single digits year-over-year in fiscal '26 to about 30% of total bookings. With this structural transition now largely stabilized, we have highly predictable compounding cash engine going forward. This cash flow visibility, paired with our continued focus on margin expansion and durable double-digit bookings growth, reinforces our confidence in achieving our 40% free cash flow margin target in fiscal '28.
Before we turn to guidance, I also want to step back and frame the growth opportunity ahead. As I mentioned earlier, our industry-leading R&D investment over the years has fueled our innovation engine and expanded our market opportunity into new categories. That ongoing commitment has earned us leadership recognition in nearly every major category that we operate in. What began predominantly as a stand-alone firewall business is now a platform with multiple billion dollar ARR businesses and several more approaching that milestone.
We continue to remain underpenetrated against a total addressable market of $340 billion by 2030. We believe that AI will only expand our opportunity whilst reinforcing the need for platformization and real-time cyber defense. This puts us on track to achieve our target of $20 billion in NGS ARR by fiscal year 2030.
With that long-term framework in mind, let's turn to our Q1 and our fiscal year '27 guidance. Note that our recently closed acquisitions of Console and Embrace are immaterial to our fiscal year '27 guidance. For the first -- for the fiscal first quarter 2027, we expect -- for Q1, we expect NGS ARR of $9.54 billion to $9.56 billion or 63% growth. We expect RPO of $20.8 billion to $20.9 billion or 34% to 35% growth, and we expect revenue of $3.3 billion to $3.31 billion or 33% to 34% growth, fully diluted share count of 837 million to 844 million shares and diluted non-GAAP EPS to be in the range of $0.96 to $0.98 per share.
For the fiscal year 2027, we expect NGS ARR of $11.075 billion to $11.175 billion or 22% to 23% growth. We expect RPO of $25.2 billion to $25.4 billion or 19% to 20% growth, and we expect revenue of $14.1 billion to $14.2 billion or 23% to 24% growth. We're guiding operating margin of 29.5% and diluted non-GAAP EPS to be in the range of $4.16 to $4.19 per share, fully diluted share count of 844 million to 847 million shares and adjusted free cash flow margin of 38%.
We've included our typical modeling points in the appendix of our presentation for your review, but I would like to point out a few things. First, as previously mentioned, our fiscal year '26 net new NGS ARR included a 9-figure benefit from a large LLM customer migrating to Chronosphere from an incumbent provider. Our outlook assumes the tail end of this migration will last through Q1 of fiscal '27 and that the net new ARR contribution from this migration will be less than what was added in Q4. This will impact the seasonality of the net new NGS ARR for fiscal '27, making Q1 larger than normal. We expect 60% to 61% of the net new NGS ARR to fall in the second half for fiscal year '27.
Second, while we do not intend to give revenue guidance by platform, we are providing initial modeling points to help you establish the revenue growth trajectory for each of the platforms within the context of our total company guidance. For fiscal year '27, we expect Network and AI Security revenue growth of low double digits year-over-year. We expect Cortex revenue up approximately 30% year-over-year, and we expect Idira revenue of approximately $1.5 billion, representing pro forma growth of high teens to 20% year-over-year.
With that, I will turn it back to Hamza for Q&A.
Hamza Fodderwala
Okay. Thank you, Dipak. [Operator Instructions] First question will be Rob Owens from Piper Sandler, followed by Brian Essex from JPMorgan.
질의응답
Robbie Owens
Great. Thank you, Hamza. Nikesh, your prepared remarks spoke to a lot of the tailwinds that you guys are seeing across cyber right now. And I think that was evidenced in your booking strength, and you mentioned the second straight quarter of acceleration. But this has been uneven throughout the environment. And obviously, scaled players and players with breadth of coverage really has mattered here.
So to that end, as you look at the new fiscal year, how are you thinking about M&A? How are you thinking about something else that could be transformational to Palo Alto, just given that the market is shifting so quickly? And while you have had an ability to take advantage of it, given what you've done in the past, what are you contemplating moving forward?
Nikesh Arora
Rob, thank you for your question. I'll just send you the names of the company so it makes it easier. I don't have to answer that -- you appreciate that, right? As I always maintain that M&A is not a strategy. M&A is a consequence of stuff that we do from a product development perspective.
To give you a sense, if you -- I talked about the 3 major pivots we've seen in AI already in the last 7 months. You've seen people go from LLMs to agents to now open weight models. And every one of these technological shifts on the customer side obviously requires a slightly different security architecture. How do you protect these agents? How do you ensure that [ open weight ] models are protected, they just don't go rogue?
And obviously, we have a point of view internally, and we're building towards that from a product development perspective. But sometimes you can get caught flat-footed because you're going down 1 path, and suddenly the market shifts elsewhere. This is where I -- we have the privilege of looking at the entire cyber security landscape and seeing 40 or 50 companies that have been funded in this category. And then you suddenly realize that some other company had the strategy right, and that's when you step in and make an acquisition.
So the acquisition happens because they've got a technology trend right and we'd rather embrace it quickly and get on that so our customers can have that capability much faster. Because, honestly, as you can see, after Mythos, what has happened is customers are willing to experiment with a lot of AI implementations. But before they deploy, they want to ensure a robust security harness around it. The most sort of common questions we get are what do I do about the vulnerability that Mythos is going to find in my environment? How do I solve it today and how do I follow it for the long term? Or what happens if we deploy agents and our agents go rogue, how do we make sure our agent doesn't go running to Hugging Face.
Hamza Fodderwala
All right. Thank you, Rob.
Nikesh Arora
I'll keep your request, and I'll send you the company's name as soon as I buy it.
Hamza Fodderwala
All right. Thanks for the question, Rob. Next, we have Brian Essex from JPMorgan, followed by Saket Kalia from Barclays.
Brian Essex
Nikesh, look, it's great to see the acceleration in CyberArk performance. And only 200 net new logos from the Palo Alto installed base. Would love to get a sense of what those conversations are like? How big are those deals relative to the rest of the CyberArk platform?
And you still have a substantial amount of your installed base. I think a lot of people focus on the cost synergies, they forget about the revenue synergies. How much penetration do you think you can get into your installed base with the CyberArk platform?
Nikesh Arora
Look, I'm really excited about CyberArk. I think if you look at both ends and you rightfully articulated, we have been able to really hit the ground running. On the cost synergy side, you've seen that our margin is reverting back to what our stand-alone margin was in just about 2 quarters. And we think we'll be at a stable point coming into the next quarter.
So to be able to transform a large company like CyberArk in 9 months and get their margins up by 1,000 basis points or more is already good work on the cost side. But like you said, we didn't buy it because we had cost synergy. We bought it because we felt there's a need in the market for identity security, and this was an inflection point.
I think the Phase 1 from our perspective was don't break it, accelerate their momentum. And you've seen we've been able to do that. We just hired new leader last quarter, [ Sunny Sing ]. He's right now at our sales conference in Asia, rallying the troops in CyberArk. The team has taken really well to joining Palo Alto. I think there's been phenomenal collaboration between the 2 teams. I'm excited. We just launched a new product called Modern PAM. So CyberArk was in traditional PAM, Modern PAM is an expansion category for PAM, something they hadn't spent a lot of time on before. The product team at CyberArk has been -- or Idira now, I should say, has been amazing at being able to embrace it. That product is generally available now. We expect to try and upgrade all of the existing traditional PAM customers to that.
So there's a lot of activities we have going on in both on the upsell and expansion side as well as a net new sell side. So as long as we can run at a faster growth rate than CyberArk ran individually, independently and expand the margin by [ 110 ] basis points, I think that's a phenomenal acquisition for us, not to mention that they have a pole position in being able to help with nonhuman identities and agents going forward because that is a whole new field where there is no established leader.
Hamza Fodderwala
Thank you, Brian. Next, we have Saket Kalia from Barclays, followed by Fatima Boolani from Citi.
Saket Kalia
Great finish to the year. Nikesh, maybe for you, you said that Mythos isn't a moment, but it's rather at the beginning. And so maybe the question here is, how are you seeing buying behavior change as the AI threat becomes the new normal? And what I mean by that is, do you see more of a willingness to platformize? Do you see more pipeline growth than you would expect? Do you see more appreciation for value, less sensitivity in pricing? I guess I'm just curious if you can translate this new beginning with some of the deal dynamics that you saw in the quarter -- over the last couple of quarters?
Nikesh Arora
Please make sure the suite show up at Hamza's house a week before. Otherwise, you won't get your first spot to ask questions in the future. In terms of the momentum, look, I did say Mythos is the beginning because what is happening is, I've strived for 8 years to go and get CEOs' interest in cybersecurity. I couldn't, but [ Doro ] did a phenomenal job by having Mythos. Because every CEO and I want to talk about what does this mean to us? How do we get access to it, how do we test ourselves from a vulnerability perspective.
But they're wise. They sit down and say, listen, I get it that this is the new normal. People will be able to find vulnerabilities much faster, how do I solve this problem in the long term. That's really where the conversation starts about. The only way to solve this problem in the long term is if something escapes, boss to your perimeter, you got to find it quickly and shut it down. That talks about modernizing their cyber estate. That talks about platformization. That talks about having an AI-driven SOC.
So that's why we've been able to have so many conversations around the modernization of infrastructure. And every conversation is not about fragmenting their estate and buying yet more smaller vendors. It's more about finding a consolidated way of sort of standardizing our platform, evaluating a platform. I think this is a big tailwind for the larger players in the sector. I don't think this is a moment where -- you will see, obviously, startups with some unique products, niche products which they are able to bring to market faster, which customers will use in the interim. But I think this is definitely a long term, I'd say, duration changing trajectory change to our growth rate.
Because you think about it, open source models are now already able to compete with the capabilities of Mythos. And this thing is going to get better, not worse. If that happens, and this capability becomes commonplace, we have a short window by when to get all the cybersecurity technical debt which hasn't been paid over many years up to the mark. And I suspect there will be some major breaches over the coming years because customers have not been able to get their transformation act in place. And that's generally going to be a tailwind for all of us in this space.
Hamza Fodderwala
Thank you, Saket. Next, we have Fatima Boolani from Citi, followed by Matt Hedberg from RBC.
Fatima Boolani
Nikesh, you brought up this concept of technical debt. So I wanted to zoom out and ask you a question in the context of something you announced earlier this week or a couple of weeks ago, Frontier AI Critical Defense. So one thing we haven't necessarily heard you talk about is this notion of operational technology and the use case here potentially gaining critical mass and especially in the context of your own platformization strategy.
So now that we know what the models are capable of in terms of insane vulnerability chaining against a part of your technical environment that has historically been underinvested in, again, with a lot of technical debt, what are some of the gating factors here still for you to be able to accelerate wallet capture? And then relatedly, how does that cooperation versus competition continuum with some of the frontier lab partners that you have get expressed in this market opportunity with OT that seems like it would be ripe for more capture?
Nikesh Arora
A lot of questions in there. Look, first and foremost, I think 9 months ago, we were all guilty and convicted of near death as cybersecurity and software because frontier AI was going to eat all of our lunch and breakfast and dinner. Clearly, in the last 6 to 9 months has become apparent that that's not happening. We're all going to be enjoying this feast together.
And we've seen both OpenAI and Anthropic and Google come to the table in terms of partnerships. We have early access to these models. We're able to test them. We able to test their cybersecurity capabilities. As I said in my prepared remarks, we are -- we were the first or are the first commercial partner allowed to use Mythos as part of our testing harness. We already use OpenAI 5.6 as part of our testing harness. We are able to bring multiple models to customers.
Because the customers are quickly disincented from this notion of finding more vulnerabilities. They all know what do I do about them. The last thing they want is more security problems, they have enough already. So the conversation is quickly shifting from what do I do about this. And in that conversation is where the need for platforms, as I mentioned earlier, comes up.
In terms of OT specifically, I think the challenge is even more pronounced because OT is hard to patch. Even if you found a vulnerability in an OT instance or deployment, imagine patching an oil rig out in the ocean or imagine patching a bunch of technology which does not have more access cannot be remotely patched, you'd have to go there and fix it. The good news is -- Lee is not here this week, so I'm going to do Lee right now. So we have actually built a capability where we can build signatures for OT vulnerabilities and open source vulnerabilities and deploy them in under 4 hours. So we can find an open source vulnerability and OT vulnerability, deploy the fix in 4 hours and propagate that to our software and hardware firewalls so that will stop the bad actors in their tracks, which is a far cry from the current standard of 55 days, take 55 days to patch open source vulnerabilities or routine vulnerabilities in the world. This will allow our customers to have the ability to block the bad actors for any network-related OT or open source vulnerability in under 4 hours.
So it's a good thing you asked me what the gating factor was. The gating factors really the customers taking the time to understand what major changes do they need to make, doing POCs, assessing what the environment looks like, thinking about who they want to deploy, then eventually getting down deployment. This is not something customers are -- they take their time to go to the deployment. That's why I think it's a long-term tailwind, and you will start seeing that in constant sort of overperformance in the industry on a quarterly basis. But it's not going to be coding agent style ARRs that we're seeing in the AI space, which have [ Envios ] software.
Fatima Boolani
Good answer, but not good cyber leased.
Nikesh Arora
Well, that's easy to fix.
Hamza Fodderwala
Okay. Thank you, Fatima, for the questions. Next, we have Matt Hedberg from RBC, followed by Michael Turrin from Wells Fargo.
Matthew Hedberg
Nikesh, you guys have a long-standing vision of being the #1 vendor in a category. I mean, you don't enter a market unless you think you can be the share leader. And so I guess, putting Lee's hat on again, you've had a lot of success, obviously, in observability. With stand-alone Chronosphere, you added a brace synthetic or you develop synthetics. Where are you from a functionality perspective now versus some of the sort of the historic market leaders there? And how much of this is share shift versus just like this market just getting bigger with AI, and we think we can take a lion's share of it?
Nikesh Arora
Well, look, the premise of Chronosphere has been that it was designed for the AI era. It is a net new technology. The premise of Chronosphere is that because of the large volumes of data that are being sort of spit out in the observability space, it is designed as a architecture that allowed you to have a lower total cost of ownership. So Chronosphere is on average, 30% or 40% cheaper than any of the leading incumbent observability solutions out there.
From a parity of capability perspective, we started off being very good from an AI-native perspective from tracing logs and metrics. So a majority of Chronosphere's customers are AI-native customers, including a very large frontier AI lab. With the absorption of Embrace and the development of [ synthetics ], that will put us at par with some of the leading players on a cross sort of capability perspective, which allows us to go after the enterprise space. So that will allow all the Palo Alto sellers to start selling. For now, we're restricting Chronosphere just to AI-native sales because it's where it's more suited. But I expect the next 6 months, we'll get to a point where Chronosphere will be a competitive product in its category vis-a-vis other enterprise players.
And then we have both an AI-first capability and as well as a cost advantage. So that should allow us, over time, as the space normalizes to have a multibillion-dollar ARR business. Very excited is we bought it when its $85 million ARR. It's already crossed the $0.5 billion ARR. We can clearly see line of sight for that to keep getting bigger over the next few quarters. And then hopefully, address the enterprise market with it as well. Because remember, for us to reach our aspirations of a bigger business, we need to have multiple multibillion-dollar ARR businesses. Observability is such a TAM, [ XSIAM ] is such a TAM. And obviously, our Network Security business and Identity business are similar TAMs.
Hamza Fodderwala
Thank you, Matt. Next, we have Michael Turrin from Wells Fargo, followed by Gray Powell from BTIG.
Michael Turrin
Great close to the year. Maybe just on the initial fiscal '27 guide, I'm curious how you approached that exercise given the inflection point taking shape across cyber? You mentioned three major AI inflections you've seen, 4 of them were still early in the overall 2027 cybersecurity budget discussion. So maybe just walk us through what you're assuming as a baseline and any key drivers of upside you see on the horizon we should focus on as well?
Nikesh Arora
Michael, we take the guidance very thoughtfully. And we look at where you are from a consensus perspective. We make sure we look at the underlying business plans of our businesses, evaluate if we are able -- going to be able to meet, beat or exceed your consensus. We're delighted to see that we expect with that execution and the tailwinds, we are going to be able to exceed your consensus. And that's how we guide.
Michael Turrin
It's very clear. We look forward to it.
Nikesh Arora
Dipak?
Dipak Golechha
Yes. No, I think, Michael, look, we do look at a lot of different inputs. If I just look at a number of the different trends, we will look at what's happening to pipeline, are we seeing traction? Do we see a trend in terms of what's going on with some of the new areas that we have? We take all of that ingest it all, look at the resource requirement, it requires territory planning, et cetera, et cetera. And that's effectively how we do it.
It's a pretty well-established world-class process. I wouldn't say much has changed from a process point of view in the last 5, 6 years that I've been here as the CFO. And I think we've been pretty transparent and there have been a number of inflection points that we've been able to kind of like capture within our forecast criteria.
Hamza Fodderwala
Thank you, Michael. Next, we have Gray Powell from BTIG, followed by Meta Marshall from Morgan Stanley.
Gray Powell
Great. Congratulations on the really strong results. So I just want to make sure that I was looking at something correctly. I think last quarter, you called out $200 million in competitive SASE displacements for the last 9 months. This quarter, that number jumped to $450 million. So I just want to make sure that those are comparable with statistics? Because if so, well, you had a really big Q4. Either way, what's -- as the way the numbers are impressive. What's driving the improved pace of displacements and just overall strength in SASE relative to peers?
Nikesh Arora
Gray, I think the number is $400 million, if I remember correctly. 450? Okay, $450 million. Good. Well, clearly, we had a good Q4. That's evident in our numbers. So yes, we did have a good Q4.
Look, the displacement is a consequence of 2 events. One, when SASE as a category came about early, it was a very Internet-driven phenomena. It was Internet access driven. But COVID changed all of that. When we hit the COVID mark, people wanted sort of access consistently both to the private access as well as in access, which is where we come from. We come from a private access space. And obviously, our product on the Internet access space is now at par or far exceeds the competitive landscape we have in front of us.
It's really the sort of integration of SASE with SD-WAN, which we were early in, we were the first player to go acquire [ CloudGenix ], integrated SASE fabric. Having our SASE fabric be consistent with our hardware and software fabric allows our customers to use Palo Alto firewalls to actually gravitate towards our SASE solution as opposed to elsewhere. And not just that, it also makes it an easier choice if they're looking to consolidate and have 1 platform because they already are using our consoles, our Strata Cloud Manager, our services for the hardware and software follow use case. And it doesn't feel like a big sort of change or to go adopt us on the SASE front as well because we already also have our agents in many cases, which do the VPN product is now a consistent agent of SASE.
So we've surrounded the SASE set of incumbents with effectively a complete platform where the choice of standardization of our platform is a simpler choice for them if they choose to just replace the SASE piece because they already have the other element loss. So sometimes is that, sometimes it's just perhaps customers want to modernize their SASE infrastructure.
Dipak Golechha
And just for clarit, Gray, it was 200 year-to-date at Q3, and it's 450 for the full year.
Gray Powell
All right. So it's a pretty big number for Q4. Thank you. That all makes a lot of sense.
Hamza Fodderwala
Okay. Next, we have Meta Marshall from Morgan Stanley. And our last question will be Brad Zelnick from Deutsche Bank.
Meta Marshall
Great. Nikesh, you were mentioning kind of this addressing of the $1 trillion of technical debt. Platforms can help enterprises pay for that in some ways. But just how do you think either about ways that you can help them in terms of professional services, investment or other things that can help from just speeding up the amount of technical debt they can address in a compressed period of time?
Nikesh Arora
So as you know, Meta, a few years ago when we launched the platformization strategy, we have had very clear models in the market where we're willing to take staggered payment or align their contracts or deploy before the existing vendor has to be replaced to drive faster platformization. So we make all that available.
Honestly, the constraint that you always run into it, the customers always have a full deck. They're already working on a series of things that they would like to get done in their enterprise. And today, with AI, there's a very large contingent of AI transformation that's out there. People want to transform customer support, they want to go do coding on an aggressive basis, they want to deploy LLMs. So this is yet another priority that must be managed in the context of that overall priority.
So it's just a balance the customer strike. That's why they don't go whole hog and so let's go replace everything tomorrow. They do sit down and say, let's have a more cohesive and intelligent transformation plan. As a transformation plan, it's going to take 5 years is too long, you got to get it done sooner.
So you typically end up in the 1 to 3 range, but it's not something that gets done in 1 quarter. And they want to sort of all walk ground. They want to get some stuff done as other vendors sort of fall off their sort of end-of-life periods or their contracts are up renewal. So all I can say is the desire to standardize or platformize on larger vendors where products are at par or better than the state of the art of the market is becoming more and more of a trend, and that's generally in our favor.
Hamza Fodderwala
Thank you, Meta. And last, but certainly not least, we have Brad Zelnick from Deutsche Bank.
Brad Zelnick
Wonderful. Thanks very much, Hamza. Nice to see everybody. Nikesh, you have strong credibility doing M&A at this point. And today's Console acquisition seems directionally consistent with moving closer to autonomous security operations. And I can ask the simple why Console, but if you fast forward 5 years and Palo Alto has succeeded beyond your wildest expectations, what's the most valuable activity that customers have completely stopped doing themselves because Palo Alto Networks is doing it for them?
Nikesh Arora
It's a great question, Brad. I think that's why I know what Hamza saves you for last. So if you believe that we're going to spend $5 trillion of CapEx in the next 5 years building data centers and AI capability, I have to believe that AI is going to be adding tremendous value to our lives in the enterprise space. Otherwise, it makes no sense to deploy $5 trillion in the ground.
So I'm an optimist and believe that we will be using a lot of AI to do a lot of agentic tasks. And if that's true, cybersecurity has to become less manual and more agentic and more done by us than the customers themselves because the bad actors will be using AI from their angle, which means we have to make sure our customers are as agentified or AI-fied as the bad actors are. Now that is not possible as you're discovery in every industry category, you cannot deploy AI effectively until we have the right data in place, the right training data, the right data, you have to break the silos and have things talk to each other.
That leads itself towards a cohesive, unified data lake of some sort, whether it's an enterprise IT data lake, observability data lake, a security data lake. If you see strategically where we have been pivoting the business over the last 2 or 3 years is we're a very data first company. Now we ingest a lot of data in XDR. We ingest 19 petabytes a day in the XSIAM product already, and we have just barely north of 1,000 customers. We have observability data which is now the data of an entire frontier LLM that is being ingested to provide them observability.
So we are becoming a data-oriented AI-first cybersecurity company. Our aspiration is to reduce the amount of human intervention in the act of detection, prevention and remediation in the cyberspace. So if you would ask me what's that North Star, that's our North Star. The question is, how do we get there? And that's where the whole company is focused on trying to get there.
So 5 years from now, if you were far exceeding our expectations of ourselves, I would be able to walk in to a company and say, you want to place x, Guess what? I have agents that can understand your deployment. My agents would replace that product. I can do that in under a week. And when I deploy my product, you will need a lot less people. And our products would actually just look for validation from you and get the task done without having you to get into the nits and grits of how to configure things, what policies to write because we've seen that across thousands of instances and we can bring that intellection knowledge to bear.
Today, we look at enterprise products, every enterprise product starts dumb for the next customer despite being deployed for 100,000 customers. I think AI gives us the opportunity of learning for the multiple deployments we do and the multiple customers we have and show up more intelligent for the next customer every time. And that's the aspiration we have.
Hamza Fodderwala
All right. That concludes the Q&A portion of the call. I'll hand it back to Nikesh for any closing remarks.
Nikesh Arora
I just want to take the opportunity to once again thank all of you guys for being here, thank our customers, our shareholders and all of our employees for what was a spectacular FY '26 for all of us at Palo Alto Networks.











코멘트 (0)
$ 버튼을 클릭하고, 종목 코드를 입력한 후 주식, ETF 또는 기타 티커를 연결합니다.