Arena: Market Conditions Before Palo Alto Networks
Network security teams at large enterprises · 2007 · United States first, then global
Changing technical requirementsHigh setup and upkeep costsSpecialist requirements
Enterprise firewalls decided what to allow by port and protocol, inspecting the start of a session and then letting it through PAN23. By 2007 a growing share of applications, webmail among them, ran over the same web ports 80 and 443, often encrypted, so a firewall could not tell one from another and intrusion prevention boxes were blind to SSL PAN22. Security teams added separate devices for web filtering and intrusion prevention, each bought and managed on its own, which Gartner later said raised operating costs without improving security PAN8 PAN2. The choice was to allow a whole port or block it, and the small-business all-in-one boxes did not meet large enterprises' needs PAN2 PAN8.
What shaped the outcome
Step 1 of 5 · 2005–11 · Network security (next-generation firewalls and subscriptions)
Zuk rebuilt the firewall to recognize applications instead of ports
Nir Zuk helped build stateful inspection at Check Point, the technique most firewalls used, then built one of the first intrusion prevention systems at OneSecure, which NetScreen bought in 2002 PAN3. When Juniper bought NetScreen in 2004 he proposed a new firewall; Juniper wanted to fold the products into its own, and he left PAN1 PAN3. In 2005 he started Palo Alto Networks with 25 NetScreen engineers and $9.4 million from Greylock and Sequoia, convinced that firewalls rested on decade-old designs PAN3 PAN5. The PA-4000, launched in 2007, identified applications inside web traffic, telling Yahoo Mail from corporate e-mail PAN22. By 2009 App-ID recognized more than 900 applications regardless of port or encryption, User-ID tied rules to named users, and one pass over each packet ran intrusion prevention, antivirus and URL filtering PAN32. Network World's 2008 test found the box kept about 80% of its rated speed with every feature on, at a price of $49,000, more than comparable devices PAN7.
Zuk's two earlier products showed him where the incumbents' design stopped: stateful inspection decided at the first packet, and intrusion prevention ran as a second box PAN23. Building classification into the core let one device allow a business application and block a risky one on the same port, which a port-based firewall could only approximate with helper appliances. Gartner's 2009 definition of the next-generation firewall described the same gap without naming vendors PAN8. Juniper's patent suits, settled for $175 million in 2014, show how much the design owed to the team's NetScreen past PAN2 PAN17.
Rivals Check Point, Cisco and Juniper sold stateful-inspection firewalls and added intrusion prevention and filtering as separate engines or boxes; Gartner's Greg Young said in 2007 that such products were 'not truly integrated' and passed traffic back and forth PAN22.
Founder Domain ExpertiseNovel Architecture
Step 2 of 5 · 2007–11 · Network security (next-generation firewalls and subscriptions)
Calling it a firewall and letting buyers try it on their own traffic opened enterprise doors
Some in sales wanted to sell the product as an 'application visibility and control' tool beside the existing firewall. Lee Klarich, then running product, argued it would be 'relegated to being a firewall helper' and never displace the firewall, and the company named it a next-generation firewall PAN1. The box did not have to replace anything to be tried: it could sit out-of-band on a switch or optical tap, inline beside the incumbent firewall, or in its place PAN22. Sales asked for a week in tap mode to 'show you what you're missing', and Zuk recalled that a proof of concept became a sale 90% of the time or more PAN1. Jody Brazil of FireMon recalls that customers first used it to filter applications such as Facebook or as an advanced intrusion prevention system, in addition to their existing firewalls PAN16.
The trial showed a security team the applications on its own network before it changed anything, so the decision rested on evidence the buyer gathered. Keeping the firewall label kept the larger prize in reach. Check Point first said the company was wrong, and two years later said customers needed a next-generation firewall and that Check Point had invented it PAN1. Gartner advised enterprises to move to next-generation firewalls at their next refresh PAN32, which put the company's own label on the buying checklist.
Rivals Check Point was the firewall most buyers already ran, with a strong management console PAN9; it answered the new label first by denial and then by claiming it PAN1. Doing nothing meant keeping port rules that allowed or blocked whole ports PAN8.
Category DesignDrop-In Adoption
Step 3 of 5 · 2008–12 · Network security (next-generation firewalls and subscriptions)
Resellers sold one device in place of the firewall and its helper boxes
Gartner saw the company enter enterprises through URL-filtering purchases, where its per-box price compared well PAN9; the 2012 filing described landing as a replacement for the firewall or any of its 'helpers' and replacing the core firewall over time PAN2. Zuk pitched consolidation: 'The approach of adding a new device every time you have a problem just doesn't work anymore' PAN5. In a 2011 white paper the company published customers that had consolidated: a financial firm replaced 12 Cisco ASA firewalls, two Sourcefire intrusion prevention systems and eleven web proxies, reporting about $1.9 million of capital savings, and a manufacturer replaced Cisco firewalls, TippingPoint intrusion prevention and Microsoft ISA Server PAN35. A 2015 customer chose Palo Alto Networks over Check Point after a proof of concept because Check Point's console was 'kludgey' PAN40. Substantially all revenue came through distributors and resellers that bought at a discount and resold; the company had 9,000 customers in more than 100 countries by July 2012, and revenue rose from $48.8 million in fiscal 2010 to $255.1 million in fiscal 2012 PAN2.
The buyer's real alternative was the stack it already ran: a port-based firewall plus web filters and intrusion prevention boxes, which Gartner said raised operating costs without improving security PAN8. Pricing one device against that stack let a box that cost more than comparable firewalls PAN7 win on total cost, and every helper due for refresh was a way in. Resellers that already serviced enterprise firewalls ran the trials and carried the sale to customers a young company could not reach alone. Andrew Plato of Anitian argued in 2012 that rivals had similar features and that Palo Alto Networks won on marketing and its interface; the switching reasons he and his readers listed, application policy inside the firewall and one box for several, are the consolidation case itself PAN39.
Rivals Cisco firewalls were bought mainly as add-ons to Cisco networks PAN9, and the white paper's customers replaced Cisco ASA firewalls together with their helper boxes PAN35. Check Point sold extra functions as Software Blades, which Gartner found lacked differentiation, and price was the main reason Gartner clients gave for replacing it PAN9.
Competitive AlternativesChannel Partners
Step 4 of 5 · 2007–22 · Network security (next-generation firewalls and subscriptions)
Check Point protected its margins and added features instead of rebuilding
Zuk said Check Point decided early to stay a 'firewall VPN company' with 'no money to invest' in R&D PAN1; it kept net margins above 43% and more than $1 billion of cash PAN18. It bought NFR for intrusion prevention in 2006 but shipped its first full next-generation product only in 2011 PAN23. At Palo Alto Networks' 2012 IPO, Gil Shwed put Check Point's share of security spending at 13% against 2.6%, called the newcomer 'a niche player' and gave it 'little chance' of success PAN33. Palo Alto Networks' R&D budget passed Check Point's in 2014 and was about three times larger by 2020 PAN23. Its revenue passed Check Point's in 2017, $1.76 billion in the year to July 2017 against $1.74 billion for 2016 PAN37 PAN38. By late 2022 it held about 24% of firewall sales to Check Point's 9%, while Check Point kept a 45% operating margin and spent about $1.3 billion a year on buybacks PAN34.
Matan Zinger's 94040 newsletter reads Check Point's delay as an innovator's dilemma PAN23, and Shwed's own interviews show the incumbent's side of it: a high-margin installed base made the newcomer look like a niche in 2012, and in 2022 Check Point still chose margin and buybacks over matching its rival's spending PAN33 PAN34. Juniper, which had turned Zuk down in 2004, sold its answer by 2012 as AppSecure, an add-on subscription for gateways already in the field PAN1 PAN36. The product gap closed in 2011, but the margin choice persisted, and the entrant used the years to build the reseller base and subscription revenue that paid for later R&D and acquisitions. Fortinet, which built for price and smaller sites, did not stall and was worth about $129 billion in 2026 PAN29; the inertia belongs to the enterprise incumbents, not to every rival.
Rivals Check Point (the incumbent most buyers weighed), Juniper and Cisco; Fortinet as the low-cost rival that did not stall PAN9 PAN29.
Incumbent system inertia
Step 5 of 5 · 2018–26 · Cloud security and security operations (Prisma and Cortex)
Arora bought cloud and security-operations leaders, sold them to the firewall base, then paid customers to consolidate
Growth slowed from 51% in 2014 to 28% in 2017 after early endpoint bets such as Cyvera PAN4 PAN27; Mark McLaughlin later said the company was 'late to the cloud' PAN1. Nikesh Arora became CEO in June 2018 and chose to try to become 'the first evergreen cybersecurity company' over 'the steady path' of network security PAN1. In fiscal 2019 the company bought RedLock, Demisto, PureSec and Twistlock and grouped products into Prisma for cloud and Cortex for security operations PAN19. Arora bought companies that had 'beat us in the market with less resources', avoided overlapping firewall or endpoint firms, tripled the specialist sales teams to 1,500 and ran operating margins in the high teens and low twenties for two or three years PAN1 PAN25. In February 2024, still 'fighting best-of-breed deals', he offered customers a two- or three-year consolidation plan: 'We'll go start implementing today, you pay us when they're done', worth on average about six months of free product PAN20. The company warned of 12 to 18 months of slower billings, and its shares had their worst day since the IPO PAN20 PAN13. By February 2025 it counted more than 1,150 platformizations among its top 5,000 customers PAN30, and fiscal 2026 revenue rose 24% to $11.5 billion, helped by the CyberArk purchase PAN31 PAN14.
Buying category leaders shortened the time to credible cloud and security-operations products, and the firewall base and its resellers gave each purchase an audience on day one; next-generation security ARR reached $5.6 billion in fiscal 2025 PAN12. Rak Garg and Francis Odum of Bain Capital Ventures note that firewalls, once more than 90% of revenue, were still above 60% in 2023 and that existing firewall customers became the targets for Cortex and Prisma PAN4. Platformization carried the same logic into accounts that already ran rivals' tools. One obstacle to consolidation was cost: an adviser said customers did not 'want to double pay' while old contracts ran PAN10, so the company absorbed the overlap and competed against the customer's whole stack rather than each specialist. The price was margin in the first years under Arora and billings in 2024, and Jim Goetz warned that most public-company acquisitions fail PAN1.
Demisto shows how a purchase became a product: Palo Alto Networks acquired it in March 2019, then launched Cortex XSOAR in February 2020 as an evolution of Demisto's security orchestration and automation platform PANMA-1.
Rivals Specialist vendors in each category, including 19 SIEM vendors that XSIAM displaced PAN20; Check Point, whose chief said in 2023 it would grab share through product development while it kept its margins PAN34.
M&A StrategyMulti-ProductResource allocation