Palo Alto Networks completed its $25 billion acquisition of CyberArk in February, the largest deal in the company's history, with CyberArk shareholders receiving $45.00 in cash and 2.2005 Palo Alto shares per ordinary share. The company has since rebranded the business as Idira, and added Chronosphere, Protect AI, and KOI Security along the way.
The strategic rationale is stated plainly in the company's own materials: the acquisition allows it to secure every identity across the enterprise, human, machine, and agentic.
That last word is the whole thesis, and it is worth taking seriously before assessing whether the price was right.
Why the identity argument holds up
Enterprise security spent two decades organized around a network perimeter, then around endpoints. The claim now is that identity is the perimeter, and the agentic AI shift makes that more than a slogan.
Consider what an autonomous agent actually is from a security standpoint. It authenticates to systems, holds credentials, accesses databases, calls APIs, and takes actions with consequences, all without a human approving each step. That is the definition of a privileged account, which is precisely what CyberArk's core product was built to manage.
Machine identities already outnumber human ones in most large enterprises, often substantially. Agents multiply that ratio again, and they differ from traditional service accounts in an important way: they are created and destroyed dynamically, their permissions are harder to scope in advance, and their behavior is less predictable, because the whole point is that they decide what to do.
So an enterprise deploying agents at scale faces a credential management problem it has no existing tooling for. Buying the leading privileged access management company to address it is a coherent response, not a narrative retrofit.
The numbers that support the case
Third quarter results showed revenue up 31% year over year to $3 billion, including $388 million from the recent acquisitions.
The stronger figure is remaining performance obligations, which rose 36% year over year to $18.4 billion. RPO growing faster than revenue means contracted future business is accumulating faster than it is being recognized, which is generally the most reliable forward indicator a software company produces, because it reflects signed commitments rather than pipeline optimism.
Next-generation security ARR reached $8.1 billion, up 60%, with 65% coming from platformized customers. And Prisma AIRS, the AI security product, grew to more than 300 customers, roughly ten times the prior year, though from a small base.
The numbers that complicate it
The same quarter produced a net loss of $177 million, or 22 cents per share, against net income of $262 million a year earlier.
That swing is the accounting cost of $25 billion in acquisitions: intangible amortization, deal expenses, and stock compensation. Much of it is non-cash, and companies rightly direct attention to adjusted figures. It is still worth noting that the reported bottom line went from profit to loss while revenue grew 31%.
Dilution is the less-discussed cost. Issuing 2.2005 shares per CyberArk share for a $25 billion target means existing shareholders own a meaningfully smaller portion of a larger company. The acquisition has to generate enough incremental value to overcome that, not merely add revenue.
And the valuation leaves little room. The stock trades around 20 times sales against roughly 5.3 times for the Nasdaq Composite after a 62% run this year. That multiple embeds successful integration of the largest deal the company has ever done, in a market where security acquisitions have a long history of underdelivering.
The metric worth interrogating
"Platformization" appears throughout the company's reporting, with a target of more than 4,000 platformizations by fiscal 2030 and $20 billion in next-generation security ARR.
It is a company-defined term. There is no accounting standard for what counts as a platformization, and the threshold sits with management. That does not make it misleading, and companies reasonably create metrics for strategies that standard reporting does not capture. It does mean the number cannot be compared across vendors or audited against a common definition, and that a metric which is both central to the narrative and defined by the narrator deserves more scrutiny than a GAAP line item.
The verifiable version of the same question is whether customers buying multiple modules actually retain and expand at higher rates than single-product customers, which eventually shows up in net revenue retention and gross margin rather than in a count.
The structural bet underneath
Every platform consolidation strategy in security is a wager on one proposition: that CISOs prefer fewer vendors to better tools.
That debate has swung repeatedly. Best-of-breed wins when threats evolve quickly and specialists ship faster. Platforms win when complexity and integration overhead become the dominant cost, and when security teams are stretched too thin to manage twenty consoles. The current cycle favors platforms, and vendor sprawl is a genuine operational burden that consolidation genuinely relieves.
The tension specific to this moment is that the argument for buying the platform, that AI is accelerating the threat landscape, is also the argument against it. If attack techniques are evolving faster than before, the premium on vendor speed rises, and speed is the thing large integrated companies historically trade away for breadth. A company absorbing four acquisitions at once is allocating substantial engineering attention to integration rather than to novel threats.
Both things can be true: consolidation reduces the complexity that causes most breaches, and integration periods are when platforms move slowest. Which effect dominates over the next few years is the actual investment question, and it will not be answered by the deal logic.
Analysts have speculated about a defensive response, including a possible combination of other identity and network security vendors to create a second platform of comparable scale. Whether or not that specific pairing happens, the direction is clear: the industry is consolidating toward a small number of full-stack vendors, and best-of-breed startups increasingly need to be acquirable rather than independent.
What to watch
Three things separate the thesis from the execution.
Whether RPO continues outgrowing revenue, since that gap is the cleanest evidence that demand is real rather than reported.
Whether net revenue retention improves as customers adopt more modules, which is the honest test of whether platformization creates value or merely relabels cross-selling.
And whether identity products grow faster inside Palo Alto than CyberArk was growing independently. A $25 billion acquisition justified by distribution synergy should produce acceleration. If the acquired business grows at its previous rate, the company bought revenue rather than leverage, at a price that assumed otherwise.