SQUAWK/NEWS
Account
Theme
Account
Menu
Live News LIVE ARTICLE H impact

Palo Alto Networks Reports Q4 2026 Results: Full Earnings Call Transcript

Palo Alto Networks (NASDAQ: PANW ) reported fourth-quarter financial results on Tuesday. The transcript from the company's fourth-quarter earnings call has been provided below. This transcript is brought to you APIs. For real-time access to our entire catalog, please visit for a consultation. Access the full call at Summary Palo Alto Networks reported record financial performance for Q4 2026, exceeding guidance across all metrics with bookings momentum accelerating and RPO surpassing $21.2 billion, up 34% year-over-year. The company highlighted strategic acquisitions of CyberArk and Chronosware, which are performing above expectations and integrating well into the platform architecture. Future outlook includes continued focus on AI and cybersecurity innovations, with guidance for FY27 projecting revenue growth of 23% to 24% and NGS ARR growth of 22% to 23%. Operational highlights include significant wins in platformization, with major deals in telecom and IT sectors, and Prisma AIRS reaching $100 million in ARR within a year. Management emphasized the importance of platformization and AI-driven security solutions, predicting a shift towards real-time defense and increased demand fo

PANW

Palo Alto Networks (NASDAQ: PANW ) reported fourth-quarter financial results on Tuesday. The transcript from the company's fourth-quarter earnings call has been provided below. This transcript is brought to you APIs. For real-time access to our entire catalog, please visit for a consultation.

2 billion, up 34% year-over-year. The company highlighted strategic acquisitions of CyberArk and Chronosware, which are performing above expectations and integrating well into the platform architecture. Future outlook includes continued focus on AI and cybersecurity innovations, with guidance for FY27 projecting revenue growth of 23% to 24% and NGS ARR growth of 22% to 23%. Operational highlights include significant wins in platformization, with major deals in telecom and IT sectors, and Prisma AIRS reaching $100 million in ARR within a year.

Management emphasized the importance of platformization and AI-driven security solutions, predicting a shift towards real-time defense and increased demand for unified security platforms. Full Transcript Hamza Farwalla, SVP Investor Relations and Strategic Finance And welcome to Palo Alto Networks' fiscal fourth quarter 2026 earnings conference call. I am Hamza Farwalla, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, September 1, 2026 at 1:30 pm Pacific Time.

With me on today's call to discuss our fiscal fourth quarter results are Nikesh Arora, our Chairman and Chief Executive Officer, and Deepak Galecha, our Chief Financial Officer. com. 26 earnings presentation. During the course of today's call, we will be making forward-looking statements and projections regarding the Company's business operations and financial performance as well as the Company's recent acquisitions.

These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in today's presentation. This presentation also contains non-GAAP financial measures and key metrics relating to the Company's past and expected future performance.

Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. I will now turn the call over to Nikesh.

Nikesh Arora, Chairman and CEO Thank you, Hamza. Good day, everyone, and thank you for being with us to discuss our progress. As you can see, our execution fueled a record finish to the fiscal year. We exceeded our guidance across every financial metric in Q4, with bookings momentum accelerating for the second straight quarter.

This performance is a direct result of record-breaking platformization adoption and the growing urgency among customers to fortify their defenses as AI fundamentally redefines the security landscape. 1 billion, up 63%, enabling us to report one of our most substantial next-generation security ARR performances to date. Most notably, we added nearly $1 billion in net new NGS ARR this quarter alone. I remember my first analyst day in 2019 shortly after I arrived; we set a high bar to reach $1 billion in next-generation security revenue by fiscal 2022, just as we were initiating our pivot from a single-product firewall vendor to a unified security platform.

That transformation journey has reached a pivotal inflection point, and the scale of our current success is a testament to that vision. We delivered broad-based strength across our platforms in Q4, with network security—our largest business—reporting exceptional results across SASE, software, and hardware firewalls. XSIAM maintained its strong momentum, while Prismaers achieved a significant milestone, surpassing $100 million in ARR within four quarters of general availability. This represents the fastest-scaling product in the history of Palo Alto Networks.

Fiscal 2026 marked a pivotal inflection point in our transformation journey. We closed the two largest acquisitions in our history, with CyberArk and Chronosware, both of which are exceeding our initial expectations. Both businesses are gaining significant traction within our platformized architecture and are scaling at an accelerated pace compared to their previous standalone performance. These achievements are a testament to the execution and deep collaboration of the thousands of new colleagues who joined us this past year.

We look forward to continuing the shared momentum into FY27. Q4 was the very first quarter in which we witnessed the profound implications of cyber-capable models. As I've said before, AI is a long-term tailwind for cybersecurity. While these models are becoming increasingly proficient at uncovering vulnerabilities, detection is merely the opening act.

Truly validating, interpreting context, and resolving these issues requires broad cybersecurity platforms working alongside frontier AI. This synergy is essential to stress test environments, manage agentic actions, and trigger machine-speed remediation during an active threat. Defending at that speed necessitates a unified data architecture where AI processes every signal, collapsing response times from days to just minutes. Platformization is the only viable strategy for real-time defense—fighting AI with AI—and that philosophy continued to gain significant resonance with our customers in Q4.

During the fourth quarter, we achieved approximately 220 net new platformizations, surpassing our prior record and representing more than twice the volume from when we initiated this metric two years ago. The performance validates that our philosophy of real-time defense through unified architecture continues to gain significant resonance beyond initial adoption. Standardizing on our platform yields superior retention and expansion, with NRR, or net revenue retention, exceeding 120% for our platformized cohort in Q4.

As we look forward, we remain on track towards our long-term objective of over 4,000 platformizations by fiscal 2030, which serves as a bedrock for reaching our $20 billion next-generation security ARR target. Our largest Q4 wins show platformization in action. During the fourth quarter, we secured a $126 million agreement with a global telecoms leader. This organization moved to standardize on our network security platforms, bolstering their next-generation firewall footprint while displacing legacy proxy providers with Prisma Access for SASE.

We also closed a $72 million transaction with a premier IT service provider. This client has fully embraced platformization across Network Security, Cortex, and Idera, making eight-figure investments in each, serving as a powerful validation of our cross-sell momentum in Q4. A further highlight was a $53 million platformization deal with a leading global payments platform. Beyond standardizing their network defense and architecture, they committed high seven figures to Prisma as they accelerate their enterprise AI initiatives.

Fiscal 2026 has emerged as a landmark period in the rapid evolution of AI, marked by three distinct inflections over the last six months. Each of these shifts fundamentally redefines how AI interacts with the enterprise and, by extension, how it impacts the cybersecurity landscape. For us to effectively lead and protect our customers, maintaining our position at the vanguard of these structural changes is paramount. The first inflection was the arrival of OpenCloud earlier this year.

OpenCloud served as the catalyst for the transition from standard LLMs to agentic action, fundamentally altering the dynamic between human operators and AI systems. Just a year ago, AI was largely defined by an individual human prompting a synchronous, multi-turn dialogue—the task was completed with a person in the loop. Virtually overnight, we witnessed the emergence of fully autonomous agents. These are persistent entities that operate for extended durations, executing complex workflows without direct supervision.

Where a single employee once managed one task at a time, that same individual can now orchestrate thousands of autonomous agents. The implications for the enterprise are profound. Each of these agents generates continuous traffic, interacting with models, querying internal data, and communicating with other tools and agents around the clock. This creates a massive volume of telemetry that must be observed.

While every agent requires its own set of credentials, we're now securing a whole new class of machine identities with autonomous permissions. The surge in traffic, data, and identity complexity represents a significant long-term tailwind across every one of our platforms. The second was a MITOS moment, which proved that deep domain training enables AI to achieve unprecedented proficiency in our sector. This has manifested as the weaponization of AI to identify and exploit vulnerabilities at scale.

This shift has exposed the deep technical debt within the enterprise, where legacy flaws and persistent misconfigurations that once took months for a human to uncover are now exploited in minutes. In an AI-driven threat environment, there is no longer anywhere to hide for our customers. The MITOS moment reframed the security challenge from visibility to velocity. Organizations must now identify exposures before they are weaponized and respond at machine speed.

This is why real-time defense has shifted from a future roadmap item to a present-day requirement. To address this, we expanded our Frontier AI Defense service last month, introducing a multimodal harness that enables enterprises to stress test their environments. This service leverages the most sophisticated cyber-capable models available, and we are proud to be the first certified commercial partner for MITOS 5. The third involves an emerging inflection point that we expect will dominate the cybersecurity dialogue in the coming quarters.

For the past 90 days, the market has moved beyond a handful of frontier models towards a diversified ecosystem of open-weight and open-source architectures. Enterprises are increasingly prioritizing sovereign control over Over their AI, leading to the deployment of specialized models deeply integrated with proprietary data. We expect a major acceleration as organizations utilize internal telemetry to fine-tune models for bespoke enterprise use cases. While frontier models will continue to set the high watermark for intelligence, the broader market is heading towards rapid fragmentation and proliferation.

Crucially, each new deployment adds more infrastructure to fortify and more sensitive data to protect. The surface area requiring platforms' protection is expanding dramatically. Three pivotal moments, each with a unique impact, yet all leading to a single conclusion. As the relationship between humans and AI evolves and deployments multiply, the necessity for unified real-time defense has never been greater.

It is early days, but we are beginning to see the signs of how these trends are impacting our business. Starting with our largest business, Network Security, AI represents a significant long-term tailwind that is expanding our total addressable market in network security while reinforcing that platformization is the only viable strategy for the modern enterprise. As the global AI buildout continues, every new data center becomes critical infrastructure that requires robust fortification through hardware and software firewalls, whether delivered natively by cloud providers or via a unified security platform.

The ecosystem driving this infrastructure expansion has reached a pivotal inflection point, and now we're seeing a new vanguard of buyers emerge, spanning sovereigns, neo clouds, and frontier labs, all racing to deploy massive computational capacity that must be secured. We achieved strong early traction with this cohort in FY26, including multiple seven-figure bookings in the fourth quarter. In total, our firewall execution drove accelerated bookings for the fiscal year, fueled by robust demand for latest Gen 5 hardware and the continued momentum of our software offerings as customers scale their cloud and AI workloads.

As this infrastructure matures and autonomous agents are deployed, we expect a dramatic proliferation of agentic traffic across every network and cloud environment. The impact on our SASE platform is already evident, where agentic traffic has surged 9x over the last nine months. Defending at this scale requires machine-speed inspection, a core competence we have refined for two decades, enabling us to block more than 30 billion attacks in a single day. Ultimately, AI is underscoring the urgent need for unified platforms that deliver real-time defense.

In FY26, our platform advantage drove exceptional results in our SASE business, where bookings grew 40% with broad strength across access, SD-WAN, and secure browser. We successfully displaced legacy incumbents in nearly 100 accounts representing over $400 million in total contract value, nearly double the volume of displacement from a year ago. While we have rapidly ascended to the number two position in this market, we're playing to win and remain on a clear trajectory to become the SASE leader in the next five to seven years.

We're in the early chapters of the shift where the future necessitates securing both human and machine identities through unified architecture capable of providing defenses at machine speed. Organizations are transitioning AI initiatives from experimentation to full-scale production, significantly widening the defensive perimeter with each new deployment. Prisma has continuously adapted alongside these adoption cycles, evolving to mitigate the unique risks emerging from every phase of the AI journey. While our initial focus addressed the chatbot-centric era of generative AI, our vision has expanded towards providing a comprehensive architecture for agentic security.

This unified approach begins with securing machine identities and credentials, incorporates deep observability of agentic footprints, and extends to the endpoint where we analyze behavioral intent. By funneling this traffic through our AI gateway, we ensure that security policies are enforced in real time across every interaction. Prisma AIRS achieved a remarkable milestone in Q4, surpassing $100 million in ARR within just four quarters of general availability, marking the most rapid scale-out of any product in our history.

Our momentum is reflected in a growing base of over 800 customers for this product, with the majority of our largest transactions now featuring multi—module adoption in Q4. We're also seeing significant early validation of our agentic endpoint strategy following the Koi acquisition. We believe the endpoint is reaching a critical inflection point as AI development tools migrate to the desktop environment. This shift creates an expanded surface area where agents autonomously manage files and access sensitive credentials.

Legacy security tools often remain blind to the underlying intent and reasoning behind these machine-speed actions. In this landscape, visibility without action is insufficient. Our platformized approach delivers end—to—end transparency from the initial prompt to the final execution, enabling inline prevention at machine speed. This capability is becoming a fundamental requirement for the enterprise.

We've already secured over 100 logos, representing a two—and—a—half—times increase since finalizing the Koi integration earlier this year. Ultimately, the synergy of detection and prevention is most effective when unified as a single platform, with XSIAM serving as a central nervous system for this critical telemetry. Earlier this year, our Unit 42 researchers demonstrated the staggering speed of modern threats by simulating a comprehensive AI—driven attack in under 30 minutes. Contrast that with the industry—standard defense response of four days, and it's clear that legacy approaches are no longer sustainable.

Customers standardizing on XSIAM are transforming their operation, reducing their mean time to respond to less than 10 minutes, massively from the days or weeks required previously. As we continue our relentless push towards true real—time defense, in the fourth quarter XSIAM maintained its exceptional momentum, concluding the year with over $700 million in ARR, up 70%, while surpassing the thousandth—customer milestone on the platform. The power of our architecture lies in the fact that live telemetry is already resident within XSIAM, allowing us to seamlessly unlock new value through our unified data lake.

Expanding a deployment does not require the friction of new product integration; it simply involves querying existing data in new ways. As of Q4, the majority of customers have embraced this platform advantage, utilizing multiple modules including exposure management and cloud security.