This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Palo Alto Networks, Inc.
2/17/2026
Good day, everyone, and welcome to Palo Alto Network's Fiscal Second Quarter 2026 Earnings Conference Call. I am Hamza Farawala, Senior Vice President of Investor Relations and Strategic Finance. Please note that this call is being recorded today, Tuesday, February 17, 2026, at 1.30 p.m. Pacific Time. With me on today's call to discuss our Fiscal Second Quarter results are Nikesh Arora, our Chairman and Chief Executive Officer, and Deepak Galecha, our chief financial officer. Following our prepared remarks, Lee Claridge, our chief product and technology officer and board member, will join us for the question and answer portion. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for quarterly results to find the Q226 supplemental information and Q226 earnings presentation. During the course of today's call, we'll be making forward-looking statements and projections regarding the company's business operations and financial performance, as well as the company's recent acquisitions. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in the presentation today. This presentation contains non-GAAP financial measures and key metrics relating to the company's past and expected future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial measures and reconciliations are in the press release and the appendix of our investor presentation. Unless specifically noted otherwise, all results and comparisons are on a fiscal year-over-year basis. I will now turn the call over to Nikesh.
Thank you, Hamza. Good afternoon. Thank you, everyone, for joining us today for our earnings call. We delivered a strong Q2 fueled by robust demand for cybersecurity and continued execution against our privatization strategy. This led to strong organic results in Q2, with NGS ARR up 28% and revenue growth of 15%, excluding the impact of recently closed protocol. We saw broad-based strength across our parks, from SASE, software firewalls, and XIM, to our emerging leadership in AI security with Prisma Airs. We paired this growth with improving profitability, achieving a 30% plus operating margin for the third consecutive quarter. We're excited to head into the second half of the year, having closed both the CyberArk and Kronos for acquisitions, and I want to extend a warm welcome to both teams. Both companies continue to deliver record numbers in their most recent quarters, and we look forward to building on their momentum as we hit the ground running on our integration plans. These investments are a direct response to the inflections we see taking shape in the market. And while it's still early, initial feedback from our customers has been very encouraging. We believe we're now entering the next phase of AI adoption. Large enterprises are moving beyond experimentation and beginning to integrate foundational models into real workflows. As AI becomes embedded in day-to-day work, the central question that organizations face is shifting from capability to control. That shift has meaningful implications for security. As AI becomes more pervasive across the enterprise, it expands the attack surface area. More agents, more infrastructure, more machine-to-machine activity, and new classes of risks that simply did not exist before. In that environment, security cannot sit on the sidelines. Despite the current sentiment about AI and software, we firmly believe that security is an enabling layer that allows innovation to move forward safely and at scale. And as AI agents become autonomous employees, the old security playbook is not just slow, it's obsolete. Security must operate in real time at the critical control points where decisions are made, across network, endpoint, cloud, browser, and identity. This is where Palo Alto Networks operates. And as BAI becomes more embedded across the enterprise, those control points are converging. The fragmented defense of disparate products is no longer a viable strategy. The risk is simply too high when adversaries are moving at machine speed. Our latest Unit 42 research confirms this. End-to-end attacks are now four times faster than a year ago. And in nearly a quarter of the cases, attackers were able to break in and exfiltrate data in under an hour. The good news is that 90% of those breaches were preventable. caused by basic gaps in visibility and controls across multiple attack vectors. This is why we committed to our platformization strategy a few years ago. A platformized approach built on a real-time data-driven model that gets smarter with scale is the only way to secure the modern enterprise, and our results continue to prove that out. In Q2, we delivered approximately 110 net new platformizations, a quarterly record outside of our seasonally strong Q4. This brings our total platformization count to approximately 1,550, up 35%. The success of this strategy is also reflected in our best-in-class net retention rate amongst platformized customers, which stands at 119% with low single-digit churn. This proves that once customers adopt our platform, they not only stay but continue to invest more with us over time. This momentum isn't accidental. It's the result of a deliberate flywheel motion we've built. When we committed to our platformization strategy years ago, we're betting on a shift that has now become an industry standard. This approach allows us to not only solve today's problems, but also provides the foundation to address new ones as they emerge. It starts by providing multiple clear landing paths. In network security, customers can begin with SASE, hardware or software firewalls, and now AI security with Prisma Airs. In the SOC, they can land on our Cortex platform via XDR, cloud security, or directly onto XIM. From any starting point, customers experience the superior outcomes of an integrated platform, which leads them to develop more deeply across our ecosystem. In a market changing this quickly, we believe our responsibility is to anticipate the next inflection and ensure our platform is ready. That philosophy guides our strategic investments, and it is us giving us the confidence to continue. A secure browser, for example, was one such early investment that is now accelerating our SASE business with over 9 million licenses sold to date. Similarly, in AI security, Prisma Airs launched just a few quarters ago and is already rapidly scaling with over 100 customers ending in Q2. This is the discipline we now plan to apply to two large established markets poised for inflection, identity and observability. If AI becomes a new interface for how work gets done, identity security will be required to create the permissions and boundaries that teams can trust. As AI introduces unprecedented scale, observability is essential for building resilient systems that can operate reliably. By bringing our platformization discipline to these new pillars, we believe we can deliver even greater value to our customers and solidify our role as a trusted partner to navigate the complex security and data challenges of the AI era. Let me share a few examples of how this strategy is translating into deeper, more strategic customer relationships. First, a global automotive leader selected us for a major security transformation. Their goal was to modernize their security architecture and dramatically improve efficacy. This resulted in an over $50 million deal, including $30 million for SASE and $20 million for XIM to run their global stock. Similarly, a global technology supplier selected us for a transformation initiative for over $40 million, choosing XIM to modernize their security operations globally while expanding their investment in SASE. Finally, a transaction with a leading IT service provider perfectly illustrates our flywheel. Building on existing investments, they committed for a $20 million expansion centered on XIM and have now platformized across network security and security operations. These aren't just transactions. They're architectural decisions. When the stakes are highest, these wins validate that industry leaders are choosing the superior outcomes delivered by Palo Alto Networks. With that, let's dive deeper into the individual performance of our platforms, starting with our largest segment. Our network security business delivered a standout quarter, demonstrating the power of a platform designed to be customers wherever they are in their hybrid journey. In Q2, our SASE business continued to grow from stint to stint, surpassing the 1.5 billion ARR milestone while growing approximately 40% year-on-year, solidifying our position as the fastest-growing SASE provider at scale. What's particularly telling is the shift we are seeing in the market. Many early adopters of SASE who made choices four or five years ago during the pandemic are now finding that those early solutions are not comprehensive enough for today's threats and complexity. As a result, they're reconsidering their first-generation point products in favor of a platform approach that provides a single, unified architecture to secure their entire hybrid environment, from the data center to the cloud and their remote workforce. A key driver of these wins is also our secure browser. This stems from a strategic bet we made over two years ago with the acquisition of Talon. Our thesis was that the browser is the most critical unmanaged edge where users, data, and now AI agents intersect. The results show our customers agree, as a Q2 Prisma browser has been adopted by over 1,500 customers, 10% of which are in the global 2,000, with an additional 2 million licenses seats sold in Q2. This success has clearly not gone unnoticed. It's encouraging to see others in the industry waking up to the idea that they must secure the browser layer. validating the importance of this increasingly critical control point. While many of these approaches simply extend existing architectures into the browser, we continue to believe the browser itself should function as a native security platform, architected for real-time control rather than retrofitted through extensions. We also continue to see strong momentum in our software firewall business. Last quarter, we called it our hidden gem. That was validated once again in Q2. Our ARR growth was approximately 25% driven by the need to secure increasingly dynamic multi-cloud environments, a need that grows as AI workloads scale. This is complemented by our strongest hardware performance in several quarters, with revenue up nearly 10%, driven in part by early adoption of our latest Gen 5 firewalls. Finally, we remain focused on where the market is going, and that includes preparing our customers for the post-condom era. The set is already here. Adversaries are using a harvest now, decrypt later strategy, stealing encrypted data today to break in the future. We've seen this become a C-level priority in our early customer conversations. And the broad interest in this topic was confirmed by nearly 5,000 attendees at our Quantum Summit last month. This is a critical part of our customer long-term roadmap, and we believe we are uniquely positioned to guide them through this coming architectural uplift and shift. Now moving to Cortex. Customers continue to partner with us on their AI SOC modernization. In Q2, XIM surpassed the half-billion-dollar ARR milestone. We welcomed almost 150 new customers, bringing our total base to over 600, paying an average of nearly $1 million in ARR. But the key story here remains not just the growth, it's the outcomes. Over 60% of our deployed customers are now achieving mean-time remediation of less than 10 minutes, a profound shift from the days or weeks they measured before. The success of Exime is a great example of our ability to identify a market inflection early, invest aggressively, and execute to scale. We made a bet on the AI-driven SOC well before it became an industry-wide team, and it is also showing its scale in just three and a half years after GA. The same focus on what's next led us to develop Agentix. The simplest way to think about it is we're enabling our customers to build a workforce of autonomous AI agents. But the key differentiator, and what makes this a real breakthrough, is where these agents can operate. Unlike traditional security tools confined to their own ecosystem, our agents can securely extend into first and third-party infrastructure. This means an agent can not only detect an issue in XIAM, but then can go out in order to remediate it directly in a cloud console, an identity provider, or a firewall at machine speed. This capability, already enabled by 200 XIAM customers, is the key to delivering true enterprise-wide automation. This is a powerful example of how we use AI to create better security outcomes. But that's only one part of our AI security strategy. Over the last couple of years, we have expanded our AI security capabilities aligned to what our customers need as they deploy AI at scale. We're bringing those capabilities together as part of a universal AI security platform, one designed to protect AI deployments across models, agents, and the environments in which they operate. It starts with Prisma Airs to secure AI models and AI-powered applications across their lifecycle, from model scanning and red teaming to runtime defense. We launched this platform just a few quarters ago, and its adoption has been remarkably strong. From Q1 to Q2, we more than tripled our customer count to over 100. While bookings also doubled during the same period, with the nine-figure pipeline already materializing, it's clear the market has been waiting for a comprehensive platform to secure AI. At the same point, we're also seeing a new class of autonomous AI agents emerge, software that can perform tasks and interact with local systems on its own. This naturally extends security requirements to the endpoint. This is why I'm excited to announce our intent to acquire Koi, a pioneer in securing the next major inflection point in security, the agentic endpoint. Koi will enhance our endpoint capabilities within XTR 2.0, while also becoming an integrated part of our universal AI security platform, extending security and governance to autonomous agents at the device layer. We are witnessing a dramatic shift in how software lives on the endpoint. Traditional security tools are often blind to the new AI layer of software, the massive rise of MCP servers, browser extensions, plugins, and ephemeral code that bypasses standard security controls. This represents a significant unmanaged attack surface. We identified this new threat vector early, and Palo Alto Networks has been a customer of Koi since summer of 2025. On my recent trip to Israel in December, Lee Klarich and I met with the Koi team and were immediately impressed by their foresight into the next generation of endpoint threats. Since then, we've seen this risk pattern intensify, including security concerns that have been recently popularized by the widespread adoption of open call. We believe this is the latest example of what the future of an AI attack surface will look like, and that Core will help our XTR platform remain well positioned to provide the most innovative security solutions to our customers. After closing, Core will also be able to provide unique extensions to Prisma Ares and Prisma Browser to ensure that our customers have visibility to any AI software and browser that are only present on the endpoint, resulting in the most comprehensive visibility to the AI attack surface. Over time, this will help ensure that the endpoint becomes more agentic. Our customers will remain fully protected. Now, this focus on visibility is critical, but to actual precision, you first need to see with clarity. This is why a new level of observability is so essential, which brings me to Chronosphere. In the age of AI, Chronosphere offers a unique value proposition. deliver observability on a massive scale, proven in production today by many of the world's leading born-of-the-cloud and AI-native companies. During Q2 and after we closed the Chronosphere acquisition, we signed a multi-year, nine-figure expansion deal with a leading AI model provider, a testament to Chronosphere's ability to scale in the largest and most complex environments. The momentum is clear in the numbers, with the company generating approximately 200 million in ARR as of Q2, well above our expectations. The end-turn observability platform is also getting traction with over 80% of new logos last year, landing with multiple products such as metrics, logs, and traces. By combining Chronosphere's deep visibility with the automated action of agentics, we are enabling our customers to build the self-healing autonomous enterprises of the future. So we have prevention, we have visibility, and we have automation. But every action, whether by a human or AI agent, is governed by an identity, which brings me to our next newest major pillar. We're delighted to have closed the acquisition of CyberArk early in Q3 and are ready to execute on what I believe is a massive opportunity in identity security. As many of you noticed earlier this month, CyberArk is coming off an exceptional December quarter. The record net new ARR and 30% of subscription ARR growth at scale. We've been rigorously building and refining integration plans and we're moving fast to put these plans into execution. This includes aligning our go-to-market engines. We're already well... underway on detailed account planning and aligned sales incentives to ensure our teams are collaborating from day one. From a product perspective, the innovation roadmap here is massive. We aren't just looking at legacy IAM, which in our view is basic hygiene. We're building a next-generation identity security platform that protects across humans, machines, and AI agents. We also look forward to delivering machine identity and certificate lifecycle management to our 65,000-plus firewall customers. Longer term, we remain excited about the opportunity to address the growing needs of identity to secure AI agents. We bought CyberArk because when AI agents start logging in at machine speed, logging in becomes the primary attack factor. We believe we are now the only company that can verify the who and secure the what simultaneously. Given the momentum in the business currently and our innovation roadmap, we believe we are well positioned to become the largest identity security player of the time. In summary, we continue to execute against our platformization strategy in Q2, with momentum building across multiple areas of business. Our core innovation engine remains strong, with great traction in new products like AI and agentics, and are ready to put our integration plans into action with CyberArk and Chronosphere. Before I hand over to Deepak, I want to take a few minutes to reflect on the recent advancements in AI. We're seeing significant innovation in new agentic platforms targeting the enterprise, and while it's still early, it is causing some companies to reassess how their applications are built, how workflows are automated, and what decisions are made. Long-standing assumptions about systems directed are being revisited, and perhaps even more so, the analytics layer built on top of them. In many enterprise applications, data reflects structured business processes within defined workflows. Security data is different. In our case, It is real-time threat activity generated at the control point where our platforms operate and continuously refine through more than 30 billion attacks blocked daily and 15 petabytes of telemetry processed in our AI software. That distinction matters. When we say precision AI, it is not AI layered onto a feature set. It is AI trained on a proprietary data set and embedded directly at those critical control points. As AI begins interacting autonomously across applications and infrastructure, Fragmented security introduces delay at precisely the wrong moment. Security must operate as a coordinated system, unified, consistent, and real-time. Because our platform sits at these control points, we see these shifts as they happen. The data generated across network, cloud, identity endpoint, and browser continually informs our models, creating a feedback loop that compounds the scale. But scale is not enough. Sustaining leadership requires a willingness to adapt and challenge our own assumptions. Technology cycles change. Architectures evolve. For the past seven and a half years, we have consistently aimed to invest ahead of inflection points in technology, even when the path is not fully defined. Maintaining this discipline is vital to ensuring that we remain the digital guardian for our consumers, however the technology stack could evolve. With that, I will hand over the call to Deepak to review the quote of his answer in detail.
Thank you, Nikesh, and good afternoon, everyone. As Nikesh noted, our strong Q2 results reflect the consistent execution of our platformization strategy coupled with a robust demand environment. The increasing adoption of our platforms is most evident in our next-generation security ARR, which grew 33% to $6.33 billion. This includes a $200 million contribution from our recent acquisition of Chronosphere. On an organic basis, NGS ARR was up 28% year over year, and NetNew ARR was up 11% year over year. This performance was driven by an acceleration in SASE and software firewall ARR, alongside Continuum Momentum and XIM. A key contributor to our software firewall growth in recent quarters is Prisma AIRS. As customers increase their AI deployments, they're looking for a trusted partner to secure this critical transformation. Prisma Airs directly addresses this need, and as Nikesh mentioned, it is scaling rapidly with over 100 customers and in Q2. Our remaining performance obligation, or RPO, grew 23% to $16.0 billion. This includes approximately $150 million of RPO from our Chronosphere acquisitions. It's important to note that RPO balances for Chronosphere can fluctuate from period to period, given usage-based pricing, with ARR and revenue being more representative of business performance. Our current RPO, which represents the near-term revenue realization, was $7.1 billion, representing 18% growth. Total revenue was $2.59 billion and grew 15%. Given the close of our Chronosphere acquisition came near the end of fiscal Q2, the revenue contribution was immaterial during the quarter. Product revenue was up 22%, with 45% of the product revenue coming from software form factors over the trailing 12 months, which was up from 38% in the trailing 12 months ending Q2 25. This was driven in part by strong demand for software firewalls, as noted earlier. Our software growth was complemented by improving hardware demand, led by the adoption of our latest Gen 5 firewall appliances and SD-WAN. Total services revenue grew slightly above 13%. Within this, subscription revenue was up 14%, while support revenue grew 12%. From a geographical perspective, we saw broad-brace strength across all of our major theaters, with the Americas growing 14%, EMEA growing 17%, and J-PAC growing 17%. Moving further down the income statement, our disciplined focus on profitability and operational leverage continued to deliver strong results in Q2. Given the timing of the Chronosphere acquisition, the impact of this transaction to our P&L financials was immaterial. Our total gross margin for the quarter was 76.1%. Within this, product gross margin was 78.2%, an increase of 150 basis points year over year, driven by a higher software mix compared to last year. As noted earlier, we did see improvement in a hardware business during Q2. Therefore, on a sequential basis, the higher mix of hardware and product revenue resulted in a 180 basis point decrease to product gross margin versus Q1. The services segment delivered gross margin of 75.6%, down 100 basis points year-over-year. The year-over-year change in services gross margin reflects a positive mix shift towards our high-growth SaaS offerings, which remain in the earlier part of their scaling curve. We continue to be pleased by the growth of our SaaS offerings and remain focused on driving efficiencies here. Now, turning to the supply chain, we observed a marginal impact on product COGS this quarter from higher memory and storage pricing. But we believe we are well positioned to manage through these dynamics. First, our high and growing software mix provides a natural hedge. Second, we will leverage our scale, deep supply chain expertise, and lessons learned through COVID and prior supply chain constraints. And third, pricing actions taking effect later this fiscal year will help offset corresponding cost increases. We have proactively factored these considerations into our Q3 and full year outlook. We delivered our third consecutive quarter of 30% plus operating margins, with Q2 operating margin of 30.3%, a 190 basis point expansion versus Q2 of last year. This strong expansion reflects our ability to drive consistent scale and efficiency across all OpEx line items. Our diluted non-gap EPS reached $1.03, which once again came in above the high end of our guidance. Q2 adjusted free cash flow was $502 million. On a trailing 12-month basis, we generated $3.75 billion in adjusted non-GAAP free cash flow, representing a margin of 37.9%. Our cash and cash equivalents for the period was $7.9 billion, reflecting a $2.6 billion cash consideration for the Chronosphere acquisition. Given the recent close of our CyberArk acquisition, we expect a $2.3 billion cash outlay in Q3. This results in total combined cash outlay of $4.9 billion. In connection with our acquisition of CyberArk, we guaranteed the payment obligations under CyberArk's convertible senior notes due 2030. The acquisition resulted in a make-hole fundamental change under the notes, and we will be making an offer to repurchase the notes in the coming days. We also issued 112 million shares in consideration for the CyberArk acquisition. Before I turn to guidance, I also want to extend a warm welcome to the over 4,000 talented individuals from CyberArk and Chronosphere. We're thrilled to have them on board and excited to execute on our integration plans to unlock the full value of these acquisitions. Our focus is on a frictionless onboarding experience for our new colleagues, and within just the first few days, we've provided access to collaboration tools for every individual to work as one cohesive team. We remain confident in our ability to deliver significant scale and leverage across every line of each of our financial things. From an operational standpoint, integration is being executed with the same rigor that we apply to running our core business, We've established clear governance, defined work streams across all functions, including IT, finance, IT, HR, products, and go-to-market, and implemented measures to ensure continuity for customers, partners, and employees. Our priority is maintaining business momentum while methodically bringing platforms, reporting structures, and operating rhythms together. Taken together, we believe this disciplined approach to integration reinforces our confidence in delivering sustained growth and operating leverage, enabling us to achieve our target of 40% of the cash flow margin by fiscal 2028 and our longer-term goal of $20 billion in NGS ARR by fiscal 2030. Now let me take you through the guidance. Please note that our Q3 and full year 2026 guidance is inclusive of both the CyberArk and Chronosphere acquisitions, which have been aligned to our fiscal year and our definitions of certain non-GAAP metrics. This includes NGS ARR, which reflects only the subscription portion of CyberArk's ARR and has been conformed to our standard revenue-based definition. Our Q3 and full year 2026 guidance assumes reported NGS ARR for CyberArk will be approximately 2% to 3% lower than the equivalent on the CyberArk's previous bookings-based ARR definition. Please see the appendix of our earnings presentation for more detail on the comparison of the two ARR definitions. For the fiscal third quarter 2026, we expect NGSARR to be in the range of $7.94 to $7.96 billion, an increase of 56%. This includes a $1.47 billion contribution from M&A. Remaining performance obligation of $17.85 to $17.95 billion, an increase of 32% to 33%. This includes a $1.6 billion contribution from M&A. Revenue to be in the range of $2.941 to $2.945 billion, an increase of 28% to 29%. This includes a $340 million contribution from M&A. Our fully diluted share count of 812 to 817 million shares, which accounts for the close of the CyberArt acquisition on February 11th. Diluted non-GAAP EPS to be in the range of $0.78 to $0.80. For the fiscal year 2026, we expect NGS ARR to be in the range of $8.52 to $8.62 billion, an increase of 53% to 54%. This includes a $1.52 billion contribution from M&A. Remaining performance obligation of $20.2 to $20.3 billion, an increase of 28%, which includes a $1.6 billion contribution from M&A. Revenue to be in the range of $11.28 to $11.31 billion, an increase of 22% to 23%. This includes a $760 million contribution from M&A. Operating margins to be in the range of 28.5% to 29%. Diluted non-GAAP EPS to be in the range of $3.65 to $3.70 per share. Our fully diluted share count of 768 to 773 million shares, which accounts for the close of the CyberArk acquisition. An adjusted free cash flow margin of 37%. We have included our typical modeling points in the presentation for your review, but I would like to highlight a few now. First, note that under our accounting policy, the upfront portion of term licenses and any perpetual license revenue from CyberArk will be recognized as product revenue. All of our Chronosphere revenue will be included in services. For Q3, we expect product revenue growth of 25%, and for the year, we expect product revenue growth in the low 20s. With that, I will turn it back to Hamza for Q&A.
You're reading a preview of the PANW Q2 2026 earnings call.
Free account.