Palo Alto Networks
Combined average of Moat (AI Resilience), Growth, and Valuation scores.
Moat Score
Palo Alto Networks operates at the network perimeter — its NGFW sits in the literal packet flow of enterprise data traffic — and is executing the most ambitious platform consolidation in cybersecurity history, bundling firewall, SASE, cloud security, identity (CyberArk), and AI SecOps into a single platformized offering.
PANW's durable competitive position rests on Transaction Embedding (NGFW in the network path), Regulatory Lock-in, and Platform Bundling at enterprise scale:
- NGFW — Embedded in the Network Path: Palo Alto's Next-Generation Firewalls sit in the physical and virtual data path of enterprise networks — every packet flowing between the internet and internal systems passes through PANW's inspection. This is the deepest form of infrastructure embedding: the firewall is not optional, it processes millions of transactions per second, and replacing it means re-architecting the network during a security freeze. The company cites 70,000+ customers and Q4 RPO of $21.2B; the NGFW installed base remains the most reliable revenue base in enterprise security.
- Platformization — Replacing 8 Vendors with One: PANW's strategic play is vendor consolidation: enterprises running 30–50 point-solution cybersecurity vendors are being pushed to consolidate onto PANW's platform (NGFW + Prisma Cloud + Cortex AI + SASE + CyberArk identity). Q4 printed $9.10B of NGS ARR, +63% YoY, with nearly $1B of net new NGS ARR in the quarter — the platform transition is still the growth engine. Organic vs inorganic mix is still not disclosed; FY27 NGS ARR guided +22–23% is the CyberArk lap now in the numbers rather than a reason to mark the moat down.
- Unit 42 + AI SecOps — Intelligence Flywheel: Unit 42, PANW's threat intelligence and incident response division, generates proprietary threat data from real-world breach investigations that feeds PANW's detection models. Cortex XSIAM (AI security operations) uses this telemetry to automate SOC workflows, with Prisma AI scaling past 100 customers and a recent Prisma AIRS integration into Anthropic Claude environments. The more enterprise customers run Cortex XSIAM, the better the detection models become — creating a data flywheel similar to CrowdStrike's Threat Graph but at the network layer rather than the endpoint layer.
Moat Verdict
PANW is a strong net beneficiary of AI — Q4's $9.10B NGS ARR and the $20B FY30 NGS ARR target are the company saying AI-generated attacks stay a demand tailwind for Cortex, Prisma, and Unit 42. The Q4 print does not change moat statuses: transaction embedding, bundling, proprietary data, and regulatory lock-in stay strong. Console is an application-layer add, not a new moat. The primary AI risk is still Microsoft's M365-native security stack in the mid-market. Customer count in the Q4 release is 70,000+.
70.8 resilient · 73.8 vulnerable · 80/20 = 71.4 · = 71
Open a moat to read its note.
Security engineers and SOC analysts deeply learn PANW's Panorama management, Cortex XSOAR playbooks, and Prisma Cloud policies. The transition to Cortex XSIAM represents a deliberate interface deepening strategy that compounds switching costs as AI automation integrates with security workflows.
Enterprises configure years of security policy in PAN-OS — application IDs, user IDs, zone rules, decryption profiles, and threat prevention policies. Cortex XSOAR playbooks and XSIAM detection rules take 12–18 months to rebuild. That is real switching cost, but it is customer-owned configuration rather than Palo Alto-owned logic competitors cannot replicate. Same bar as CrowdStrike detection rules and Snowflake SQL (intact).
Unit 42 publishes threat intelligence reports built from real-world incident response engagements. This public intel feeds PANW's detection capabilities while maintaining a proprietary advantage from the underlying raw data that remains within PANW's systems.
PANW-certified engineers (PCNSE, PCCSE), Unit 42 threat hunters, and AI SecOps specialists are in scarce supply. The PANW talent ecosystem creates a virtuous cycle: customers hire PANW-certified staff who maintain the platform, deepening the dependency.
NGFW + Prisma Cloud + Cortex AI + SASE (Prisma Access) + CyberArk identity + Wildfire + Unit 42 intelligence — all from one vendor in a platformized bundle. Q4 NGS ARR $9.10B (+63%) with nearly $1B of net new ARR in the quarter is the print under that bundle. Console extends Cortex into agentic workflows; it does not add a new pillar.
Unit 42 incident data, Cortex XDR telemetry from 15,000+ customers and Wildfire sandboxing improve Palo Alto's models, but it is not a dataset rivals cannot match — Microsoft processes 78 trillion security signals a day (2024 Digital Defense Report), and CrowdStrike runs the same kind of flywheel. Re-rated from strong to intact for consistency with CrowdStrike.
FedRAMP High, IL4/IL5, CMMC and HIPAA/PCI validation make Palo Alto procurable for government and regulated buyers, and the SEC's four-day incident-reporting rule raises demand for a SOC platform — but any SOC platform satisfies it, and CrowdStrike, Microsoft and Fortinet hold the same authorisations. Standard certifications are table stakes in this market — they bar small entrants, not the peers this name competes with — so they rate intact; strong is reserved for a barrier few competitors in the market can clear. Re-rated from strong to intact.
Unit 42's threat intelligence network improves with scale: more enterprise deployments → more telemetry → better threat models → better protection for all customers. The AutoFocus threat intelligence sharing platform creates a secondary network effect across the PANW customer base.
PANW's NGFW processes every network packet in the enterprise — it is literally embedded in the transaction layer of corporate data flow. Q4 RPO $21.2B is contracted time in that path. This is the most durable form of embedding in cybersecurity: you cannot pause traffic inspection, cannot have downtime during a migration, and cannot run two competitive NGFWs simultaneously. Rip-and-replace requires a security freeze.
Cortex XSIAM serves as the security system of record for incident investigations, threat hunting queries, and compliance reporting. For regulated industries with audit trail requirements, XSIAM's event history cannot simply be deleted and rebuilt — it is the forensic record that regulators require.
Software at near-zero marginal cost: scale shows up as network effects, data or bundling, which are rated there. No separate unit-cost lead to credit.
Buyers are enterprises choosing on switching cost, integration and performance, which the other pillars rate. The name carries reputation, not a price premium it could hold on brand alone.
Combined average of Moat (AI Resilience), Growth, and Valuation scores.
Moat Score
Palo Alto Networks operates at the network perimeter — its NGFW sits in the literal packet flow of enterprise data traffic — and is executing the most ambitious platform consolidation in cybersecurity history, bundling firewall, SASE, cloud security, identity (CyberArk), and AI SecOps into a single platformized offering.
Growth Score
Q4 FY2026 (ended July 31, reported Sep 1) printed revenue $3.41B (+34% YoY) and non-GAAP EPS $1.02, beating ~$3.35B / $0.98. NGS ARR $9.10B (+63%) beat the raised $8.90–$8.95B guide; RPO $21.2B (+34%). FY26 revenue was $11.48B with adjusted FCF $4.41B (38.4% margin). FY27 guide is revenue $14.10–$14.20B (+23–24%), NGS ARR $11.075–$11.175B (+22–23%), RPO $25.2–$25.4B, non-GAAP operating margin 29.5%, EPS $4.16–$4.19, adj. FCF margin 38%. Q1 NGS ARR is still guided +63% to $9.54–$9.56B; the 22–23% full-year NGS ARR rate is the CyberArk lap. GAAP Q4 net loss of $282M is convert/capped-call fair value ($524M) plus deal/SBC, not the operating print. Console (AI-native agentic workflows) closed into Cortex; it is optionality, not a new growth driver until it prints. Close $362.09 on Sep 1.
Valuation Score
PANW closed Sep 1 at $362.09 (session −5.2% on a duration day, before the print) vs ~$363 on the Aug 18 card. At ~$295B market cap the stock is ~21× FY27 sales ($14.15B midpoint) and ~87× FY27 non-GAAP EPS ($4.175 midpoint), a small cheapening versus the prior ~22× / ~88× on ~$13.8B Street. The Q4 test passed; the multiple now has to underwrite a 22–23% NGS ARR year, not a 60% one. Ladder held at $250 / $340 / $440. Price sits a few percent above base.
The Platformization Moat
PANW's durable competitive position rests on Transaction Embedding (NGFW in the network path), Regulatory Lock-in, and Platform Bundling at enterprise scale:
- NGFW — Embedded in the Network Path: Palo Alto's Next-Generation Firewalls sit in the physical and virtual data path of enterprise networks — every packet flowing between the internet and internal systems passes through PANW's inspection. This is the deepest form of infrastructure embedding: the firewall is not optional, it processes millions of transactions per second, and replacing it means re-architecting the network during a security freeze. The company cites 70,000+ customers and Q4 RPO of $21.2B; the NGFW installed base remains the most reliable revenue base in enterprise security.
- Platformization — Replacing 8 Vendors with One: PANW's strategic play is vendor consolidation: enterprises running 30–50 point-solution cybersecurity vendors are being pushed to consolidate onto PANW's platform (NGFW + Prisma Cloud + Cortex AI + SASE + CyberArk identity). Q4 printed $9.10B of NGS ARR, +63% YoY, with nearly $1B of net new NGS ARR in the quarter — the platform transition is still the growth engine. Organic vs inorganic mix is still not disclosed; FY27 NGS ARR guided +22–23% is the CyberArk lap now in the numbers rather than a reason to mark the moat down.
- Unit 42 + AI SecOps — Intelligence Flywheel: Unit 42, PANW's threat intelligence and incident response division, generates proprietary threat data from real-world breach investigations that feeds PANW's detection models. Cortex XSIAM (AI security operations) uses this telemetry to automate SOC workflows, with Prisma AI scaling past 100 customers and a recent Prisma AIRS integration into Anthropic Claude environments. The more enterprise customers run Cortex XSIAM, the better the detection models become — creating a data flywheel similar to CrowdStrike's Threat Graph but at the network layer rather than the endpoint layer.
Moat Verdict
PANW is a strong net beneficiary of AI — Q4's $9.10B NGS ARR and the $20B FY30 NGS ARR target are the company saying AI-generated attacks stay a demand tailwind for Cortex, Prisma, and Unit 42. The Q4 print does not change moat statuses: transaction embedding, bundling, proprietary data, and regulatory lock-in stay strong. Console is an application-layer add, not a new moat. The primary AI risk is still Microsoft's M365-native security stack in the mid-market. Customer count in the Q4 release is 70,000+.
70.8 resilient · 73.8 vulnerable · 80/20 = 71.4 · = 71
Open a moat to read its note.
Security engineers and SOC analysts deeply learn PANW's Panorama management, Cortex XSOAR playbooks, and Prisma Cloud policies. The transition to Cortex XSIAM represents a deliberate interface deepening strategy that compounds switching costs as AI automation integrates with security workflows.
Enterprises configure years of security policy in PAN-OS — application IDs, user IDs, zone rules, decryption profiles, and threat prevention policies. Cortex XSOAR playbooks and XSIAM detection rules take 12–18 months to rebuild. That is real switching cost, but it is customer-owned configuration rather than Palo Alto-owned logic competitors cannot replicate. Same bar as CrowdStrike detection rules and Snowflake SQL (intact).
Unit 42 publishes threat intelligence reports built from real-world incident response engagements. This public intel feeds PANW's detection capabilities while maintaining a proprietary advantage from the underlying raw data that remains within PANW's systems.
PANW-certified engineers (PCNSE, PCCSE), Unit 42 threat hunters, and AI SecOps specialists are in scarce supply. The PANW talent ecosystem creates a virtuous cycle: customers hire PANW-certified staff who maintain the platform, deepening the dependency.
NGFW + Prisma Cloud + Cortex AI + SASE (Prisma Access) + CyberArk identity + Wildfire + Unit 42 intelligence — all from one vendor in a platformized bundle. Q4 NGS ARR $9.10B (+63%) with nearly $1B of net new ARR in the quarter is the print under that bundle. Console extends Cortex into agentic workflows; it does not add a new pillar.
Unit 42 incident data, Cortex XDR telemetry from 15,000+ customers and Wildfire sandboxing improve Palo Alto's models, but it is not a dataset rivals cannot match — Microsoft processes 78 trillion security signals a day (2024 Digital Defense Report), and CrowdStrike runs the same kind of flywheel. Re-rated from strong to intact for consistency with CrowdStrike.
FedRAMP High, IL4/IL5, CMMC and HIPAA/PCI validation make Palo Alto procurable for government and regulated buyers, and the SEC's four-day incident-reporting rule raises demand for a SOC platform — but any SOC platform satisfies it, and CrowdStrike, Microsoft and Fortinet hold the same authorisations. Standard certifications are table stakes in this market — they bar small entrants, not the peers this name competes with — so they rate intact; strong is reserved for a barrier few competitors in the market can clear. Re-rated from strong to intact.
Unit 42's threat intelligence network improves with scale: more enterprise deployments → more telemetry → better threat models → better protection for all customers. The AutoFocus threat intelligence sharing platform creates a secondary network effect across the PANW customer base.
PANW's NGFW processes every network packet in the enterprise — it is literally embedded in the transaction layer of corporate data flow. Q4 RPO $21.2B is contracted time in that path. This is the most durable form of embedding in cybersecurity: you cannot pause traffic inspection, cannot have downtime during a migration, and cannot run two competitive NGFWs simultaneously. Rip-and-replace requires a security freeze.
Cortex XSIAM serves as the security system of record for incident investigations, threat hunting queries, and compliance reporting. For regulated industries with audit trail requirements, XSIAM's event history cannot simply be deleted and rebuilt — it is the forensic record that regulators require.
Software at near-zero marginal cost: scale shows up as network effects, data or bundling, which are rated there. No separate unit-cost lead to credit.
Buyers are enterprises choosing on switching cost, integration and performance, which the other pillars rate. The name carries reputation, not a price premium it could hold on brand alone.
Growth Analysis
Growth Drivers
Key Risk
FY27 NGS ARR is guided +22–23% against a 63% Q4 headline, and organic vs CyberArk is still not disclosed. If Q1 misses $9.54–$9.56B NGS ARR or FY27 revenue/$11.1B NGS ARR cuts, the ~21× FY27 sales multiple compresses toward 14–16×.
Score Derivation
81.3 base + 1.3 trajectory − 5 risk = 78
Base 81.3 (15–19% CAGR, midpoint 17%: the +23–24% FY27 guide includes a full-year CyberArk lap after the Feb 11, 2026 close, so the multi-year rate is the mid-teens organic path, not the guided year) + 1.3 trajectory (platformization accelerating; NGS ARR and CyberArk stable) + 0 margin (FY27 non-GAAP op margin 29.5%, adj. FCF margin 38%) − 5 moderate residual (organic mix still undisclosed; Microsoft mid-market stack) = 78
Price Scenarios (12–24 Months)
Valuation Multiples
| Trailing P/E (GAAP) | n/m |
| Forward P/E (FY27, non-GAAP) | ~87× |
| PEG Ratio | ~3.7× on revenue |
| Price / Sales (FY27) | ~21× |
| Price / FCF | ~55× FY27e |
The print raised the sales denominator and left the price ~unchanged versus the August card, so the multiple eased from ~22× to ~21× FY27 sales. It is still CrowdStrike-like on sales, and FY27 NGS ARR +22–23% is the number that multiple has to live with. Next trip is Q1 NGS ARR $9.54–$9.56B, not a restamp off the session close.
Approximate figures as of September 1, 2026 (Q4 FY2026 print; close $362.09).
Where We Are vs Targets
Loading live price…
Q1 misses $9.54–$9.56B NGS ARR or FY27 $11.1B NGS ARR / $14.1B revenue cuts as CyberArk lapses; the multiple compresses toward 14–16× FY27 sales.
- Organic NGS ARR (still undisclosed) is the high-20s or worse once CyberArk laps, so the 63% headline was the deal
- Q1 FY2027 misses $9.54–$9.56B NGS ARR or FY27 revenue/$11.1B NGS ARR is cut
- Microsoft Defender + Sentinel + Intune bundling takes mid-market NGFW share via M365
- Multiple compresses toward 14–16× FY27 sales — ~30% downside from $362
Q4 delivered. FY27 lands in $14.10–$14.20B and NGS ARR $11.075–$11.175B, Q1 prints the $9.54–$9.56B NGS ARR, and the multiple settles ~18–20× sales.
- Q1 NGS ARR $9.54–$9.56B (+63%) prints; FY27 NGS ARR $11.075–$11.175B is the lap, not a miss
- FY27 revenue $14.10–$14.20B, non-GAAP EPS $4.16–$4.19, adj. FCF margin ~38%
- CyberArk remains in the stack; Console stays unquantified
- Non-GAAP operating margin ~29.5% as guided
NGS ARR beats the $11.2B FY27 guide and tracks toward the $20B FY30 target; the multiple holds ~21–23× on faster-than-guided platformization.
- AI-agent attack surface keeps NGS ARR above the 22–23% FY27 guide
- CyberArk + Cortex + Console compound inside the 70,000+ customer base
- FY30 $20B NGS ARR stays on the table without another large deal
- Revenue toward $16B+ and non-GAAP EPS toward $5 by FY28 — ~22× NTM sales gets to ~$440