NASDAQ

Palo Alto Networks Inc

PANW

14 stories

$343B Market cap · 2026-10-09

@convequity

Convequity on X

Software multiples have fallen further since our January report. As of 7 Oct 2026, 238 companies in our all-software watchlist have EV/Sales (NTM) data on Koyfin. The median is 3.1x, down from 3.7x in January. The average is 5.4x, down from 6.2x. The 25th percentile is 1.8x, down from 1.9x. The 75th percentile is 5.5x, down from 6.1x. 191 of the 238 (80%) trade below our 6.7x private equity floor. 113 trade below 3x. The Bessemer Cloud Index shows the same pattern. Its median is 4.7x, down from 5.1x in January. 46 of its 68 companies (68%) trade below 6.7x. The cheapest are $CXM at 0.9x, $SPT at 1.1x, $MNDY at 1.7x and $WIX at 1.8x. In our watchlist, only 21 companies trade above 10x. The most expensive are $PLTR at 44.5x, $CRWD at 42.4x, $NET at 38.6x, $PANW at 24.2x, $DDOG at 19.5x and $SNOW at 16.3x. Growth still earns a higher multiple. The 44 names expected to grow revenue 20%+ a year over 3 years have a median of 5.2x. The 85 names expected to grow under 10% have a median of 2.6x. Even for the faster growers, the 5.2x median is below the floor. The market is paying up for very few names. We think that is right. Many software companies have slowing growth, high costs and no clear AI strategy. We would not buy the sector, or a cloud index, on valuation alone. In software, we focus on the few companies rebuilding their products around AI, and our SaaS Survival Scorecard tests key SaaS names against the pressure from AI agents.
@convequity 3 clicks

Convequity on X

We agree with Ampersand: an agent is vaporware without deep access to the customer's systems of record. But the result is headless SaaS, where the agent becomes the interface, and headless SaaS does not keep today's economics. Convequity's SaaS Survival Scorecard splits a vendor into three layers, the interface, the workflow and the data, and scores how many of the three it keeps once agents arrive. 1. Deep integration into the system of record is the headless path: the user works through Claude, ChatGPT or another third-party agent, and the vendor keeps workflow and data underneath. Our scorecard calls this Route 2: roughly half the SaaS value is replaced, and the vendor is survivable but diminished unless outcome pricing rescues it. It is the most likely near-term route, and a starting point rather than a stable endpoint. 2. Model companies will expand into the workflow layer to keep growing, and a vendor whose workflows mainly connect other SaaS APIs is highly absorbable. A vendor left with only its data layer is plumbing: it still earns on agent traffic, but it gives up a lot of the value. A vendor that keeps hard-to-replace workflows retains more of it. 3. More agents does not mean more SaaS revenue in every domain. Back-office cost centers like HR, accounting and IT service management have a natural ceiling, because making the work cheaper does not create more of it. Agents cannot create demand for an extra tax filing. Revenue-generating functions like sales and marketing can grow with agents, because extra work there produces extra revenue. 4. Keeping all three layers is rare. $PLTR is the full Route 3 case in our scoring so far, because its ontology works as a quasi system of record and it has model-layer leverage. $PANW approaches Route 3 only within security operations, where sensors and inline enforcement are hard for an agent to absorb. Nearly every other vendor will give up the interface. Ampersand's integration layer and our scorecard describe the same future: the agent is the interface, and the vendor keeps workflow and data. We differ on the economics: a vendor keeps more revenue where the work is unbounded and it holds its workflows, and less where the work is bounded or it is left with only its data.
@convequity

Convequity on X

Whether AI can run security operations on its own comes down to one question: when an automated action is wrong, who is accountable for finding out what happened and fixing it? Our note borrows two levels from self-driving cars. At L2 the driver answers for mistakes. At L4 the car drives itself, so accountability shifts to the company behind the system. 1. At L2, a third-party AI agent mostly assists. It connects to a security platform over MCP, the protocol that lets an outside AI model pull data from a vendor's platform. It suggests next steps and drafts investigations, while the human and the security platform still hold the wheel. 2. At L4 or L5, the system acts with no human in the loop in the security operations centre. It quarantines a machine, kills a process, revokes access or blocks traffic. Any of those can be wrong. When one is, the customer needs a clear accountable party that will investigate and fix the problem. In our view $PANW can be that party. It is already inside the customer's systems, keeps audit trails, and its own products take those hard-to-reverse actions. AI model labs are poorly placed for that role. On our reading, their terms usually limit what they answer for, so when an outside agent acts wrongly, the customer is left to investigate and fix the problem alone. Outside agents compete most easily for the analyst's workspace, which is L2 work. That makes $PANW better placed than model labs to sell autonomy.
@convequity

Convequity on X

$PANW and $DDOG both put something real inside the customer's systems that an AI lab cannot recreate by calling SaaS APIs. Palo Alto's install is still harder to replace with AI. 1. Datadog's agents mostly sit outside the traffic and watch production. A bad agent version rarely takes the business down the way a bad firewall rule can. 2. Palo Alto's firewalls and SASE cloud gateways sit inside the traffic and decide what to allow, deny, decrypt or inspect. A wrong allow or deny hits live traffic and live machines. 3. Many Datadog users start the day in a coding agent and open Datadog when something looks wrong. Many Palo Alto users start in its console and stay there through alerts, triage and response. For them, an outside AI agent is an add-on. Cybersecurity work splits two ways on AI risk. Work done before code ships ("shift-left") or from outside the traffic, such as scanning code, checking cloud settings and sorting collected alerts, gives answers that are easy to check. AI agents are already taking over more of it. Work in live traffic and on live machines ("shift-right") means judging whether an attacker is still inside and whether blocking them is safe. That is more ambiguous and mistakes cost more, so enterprises move slower and demand earned trust. Palo Alto is not risk-free. In our view its exposure is the easily checked detection and vulnerability work inside its platform, which AI agents can take over sooner. The threat is not an AI-native firewall startup.
@convequity 1 click

Convequity on X

Cybersecurity isn’t uniformly exposed to model labs. Host agents (telemetry), inline enforcement, and shift-right ops — humans, live environment, adversaries — stay relatively hard to absorb for the intermediate future. Shift-left and the checkable end (vuln scanning, validators) are already getting hit hardest by stronger codegen and coding agents. Relatively safer (host agents / inline / shift-right): $PANW, $CRWD, $FTNT, $NTSK More exposed (shift-left / scan / checkable): $TENB, $QLYS, $RPD.
@convequity 1 click

Convequity on X

Pondering how safe $PANW and other cyber incumbents really are if model labs keep expanding. Split security into two buckets. Bucket one: scanning and out-of-band work. Code and package vulns, cloud config checks via APIs, posture reports, “is this alert real?” These jobs are relatively checkable. Coding agents and Mythos-class models can do more of them over time — often with no endpoint agent or firewall in the path. That is where AppSec and vuln tools look exposed. Bucket two: live sensors and inline enforcement. See the process. See the packet. Allow or deny. Contain the machine. AI cannot do that from the outside by calling an API. Something still has to sit in the estate. That is much harder for a lab to recreate. So the interesting question is not “is cyber safe?” It is: how much of the franchise is bucket one, and how much is bucket two? PANW lives mostly in bucket two — plus deep SOC context. That looks safer than a pure scanner. Not untouchable. Just a different risk.
@convequity

Convequity on X

Exploring SaaS survival in the agentic era — $PANW vs $DDOG. Both sit on critical telemetry. Both expose MCP. On paper they look alike. They aren’t. Model labs have a real reason to build their own observability collectors. Coding agents write and ship code; to get better they need production feedback. Own the host telemetry, close the loop. That same incentive is much weaker for cybersecurity endpoint agents. Finding beacons and writing better code are different jobs. Building a Falcon- or Cortex-class sensor estate is years of trust, labeled attacks, and compliance — not a natural side quest for a model lab. Then there’s the screen. Datadog doesn’t own where developers live. They already live in Cursor / Claude Code / Copilot. So those agents pull Datadog in over MCP. The data plane stays sticky; the UI gets shared. Palo Alto usually does own where the SOC lives. The shift starts in the security console — cases, playbooks, response. In a PANW shop, Cortex is the main workplace. Claude can sit on top in a multi-vendor stack. That’s the risk but not the base case. Same idea — agents need the pipes. What’s different is who tries to own the collector, and who already owns the desk. Thoughts welcome. Full Part 3 write-up for Convequity subscribers is on its way.
@convequity 1 click

Convequity on X

Snyk is a clean postmortem for what happens when a security tool lives inside the coding agent’s loop. The product was mostly scan-and-warn. Find the issue, comment on the PR, suggest a fix. Blocking the merge usually sat in GitHub, not in Snyk. Bigger platforms smothered it. $PANW, $CRWD, and Wiz pulled AppSec into the bundle the CISO was already buying. GitHub was the main developer surface and put scanning where the code already lived. Then coding agents arrived and delivered the final blow. A lot of that scanning became something the agent could just do. Growth held up for a short while after the COVID/cloud tailwind. Then it decelerated hard. This is the same lens we use in Convequity’s SaaS Agentic Survival Evaluation Framework. The PANW, CRWD, and FTNT reviews go up on Convequity in a few days.

Tickers on this page

Companies the stories above are also about, besides PANW.