Palo Alto Networks ft Nir Zuk & Nikesh Arora - The Grudge That Transformed Cybersecurity
47m 3s
The transcription discusses Near Zook's background, starting from his time at Checkpoint to founding Palo Alto Networks. It details the development of the next-generation firewall at Palo Alto Networks, focusing on its unique features and market strategy. The challenges faced by the company in disrupting the cybersecurity industry and scaling rapidly are highlighted, including competition reactions and the need for organizational changes to achieve rapid growth. Near's strategic decisions, such as focusing on customer feedback and staying true to the firewall concept, are emphasized as key factors in Palo Alto Networks' success in becoming a global leader in cybersecurity.
Transcription
7595 Words, 43783 Characters
[MUSIC PLAYING]
Everybody thought we were crazy.
Nobody would use the cloud for cybersecurity.
Nobody would send cybersecurity related data
to be inspected in the cloud and so on.
And when I hear something like that, I say,
of course, I'm going to do it, you know?
Because it's the right thing.
And if everybody believes it's not, it shouldn't be done
or it cannot be done or nobody would want it.
Then, you know, it's a good reason to do it.
Welcome to Crucible Moments.
A podcast about the decisions and inflection points
that defined some of the most consequential companies
of our time.
I'm your host, Rulof Boerza.
In the 1990s, as businesses rushed online,
a new cybersecurity industry emerged
to protect the networks powering the internet boom.
Among the industry's early builders
was an Israeli engineer who helped shape
several of those companies, until he
grew frustrated with their overly cautious cultures
that stifled innovation.
So, he decided to strike out on his own.
Along with a small team of experts,
nearer Zook built something that would change the industry,
the next generation firewall.
Unlike traditional firewalls, it didn't just block threats.
It unified multiple layers of protection
into one intelligent platform.
By blending on-premise security
with early cloud-based capabilities,
Zook's vision redefined what modern cybersecurity could be
and set the standard the industry still follows today.
In this episode, we'll explore the crucible moments
that turned PalaAlton Networks from a bold startup
into a global leader in cybersecurity,
from bringing their disruptive product to market
to scaling into a public company
and ultimately outpacing the industry
again in the cloud era.
This is the story of PalaAlton Networks
and the people who refused to play by the old rules.
I'm nearer Zook, founder and shift technology officer
at PalaAlton Networks.
I was born in Israel in 1971,
and as a teenager in the mid-80s,
one of my hobbies was to develop viruses,
some of the early computer viruses in the world,
which landed me a job with Israeli intelligence
as part of my military service.
And there, at Unit 8200,
is where I met two of the three founders of Checkpoint.
I joined them at Building Checkpoint Software in late '94.
At Checkpoint, near-worked on some of the first firewall technologies,
network security systems that could monitor and control traffic
between private networks and the outside world.
The biggest challenge I faced at Checkpoint
was that very early on,
Checkpoint has decided, number one,
that they're just going to be a firewall VPN company,
meaning they don't want to do other things
that customers require as part of their cybersecurity strategy.
And second, that they want to optimize
for very high operating margins.
Checkpoint has always run close to 60% net operating margins,
which is very high, but it also means
that there's no money to invest,
specifically in research and development.
So for me, as someone that likes to build technology,
likes to build products, like to take things forward,
it was a challenge not being able to invest in R&D
and not being able to build things
beyond basic firewall VPN.
Near-transferred to Checkpoint's California team,
hoping it would offer an opportunity
to work outside of the company's VPN-only strategy.
But when the team was shut down in 1999,
near decided to leave Checkpoint all together
and forge his own path in the cybersecurity space.
He wasn't shy about the fact that his former employer
was now his biggest competition.
- I had a custom California license plate made.
The license plate was CHKP KLR,
which reads Checkpoint killer.
So I was driving around the Bay Area with that car.
I had met with him and walked him out to his car
and it spotted the plates.
It was an example of a chip on the shoulder
that Nier had developed in his time at Checkpoint.
My name is Jim Gets, partner, it's a quick appletal.
- Sitting out to compete with Checkpoint,
Nier founded his first company, OneSecure,
which was quickly acquired by NetScreen,
which was then sold to Juniper in 2004.
The first day, literally the first day
after the acquisition closed in April 2004,
my new boss, the CTO and founder of Juniper told me
that they were not interested in the products
and they wanted to rebuild them into their own products,
which I thought was a disaster.
So I left, many other people left
and I left to start Palo Alto Networks.
I called a really good friend of mine called Ashim Chandna,
who is a VC at Greylock and told him I was going to start
something and immediately brought Jim Gets
as well into the picture.
I knew from the beginning they agreed from the beginning
that we're going to build something
that's going to change the cybersecurity industry
and the three of us sat down and tried to figure out what it is.
- I remember when the company started,
part of the design goal was, you know, beat NetScreen,
who was an incumbent renderer at the time on performance,
beat Checkpoint Software, another primary incumbent
on Manageability and then beat Fortinet and Cisco
in their all-in-one architecture.
I'm Ashim Chandna, I'm a partner at Greylock.
So Kurvan Builder System where you had, you know,
you beat Checkpoint Software and Manageability,
NetScreen on Performance and, you know, Cisco and Fortinet
in terms of the all-in-one capability.
And then the question was really, how do you insert into that?
Greylock and Sequoia were a very rigor in making sure
that I have the right plan to be able to conquer the market.
So that was, I guess, nine months project
where we went through different insertion plans,
different ways of getting into the market
with whatever it is that I'm going to end up building.
- He had several ideas, but none were refined.
There was energy from near as you can expect
to do a frontal attack on the firewall market.
And both Ashim and I felt like a market entry tactic
that may not be frontal in nature,
but would embrace a more subtle approach to the market
was important, and so much of the investigative work
was around product definition and market entry tactics.
- The team continued to brainstorm
around this early crucible moment.
What do you build that will set you apart
in a space crowded with competitors?
And how do you take that product to market?
- The original plan was to be based on an ASIC,
a custom silicone that we were going to build,
that's going to make everything really cheap and really fast.
And we scrapped that as not being enough.
And then after one or two more iterations,
we figured out that one of the features in the product,
which was around being able to secure not just web browsing
in email, which were the only protocols
or only applications that enterprises were using at the time,
but rather also secure other applications,
which were considered consumer applications at the time.
Like ICQ and net meeting, if you remember,
and Skype and Facebook was emerging at the time.
And so on, the assumption was that these were going to become
also enterprise applications.
So the decision was to take something that was relatively
smaller in terms of being able to secure all these applications
and making it the cornerstone of 40 days
that Palo Alto Networks was going to do in the early days,
build network security that can secure everything,
not just web browsing and email,
and making that the go-to market, the insertion plan,
what we sell to customers.
At the time, there were dozens of appliances
doing various functions that were not being done
in the firewall.
And Nier's ambition was to create a single-pass architecture
that would allow us to integrate that into a single system.
Customers really had what was called appliance fatigue.
They had many appliances for different discrete functions
around security.
And so part of the vision around the company
was to collapse all these functions
into a single architecture and into a single system,
but yet provide customers with scalability and manageability
and performance.
In addition to a single, fully integrated platform
that could serve all areas of an enterprise's security
needs, the team decided to take a gamble
on the way the platform was deployed.
When I joined Sequoia in Greylock in 2005,
the cybersecurity market was 100% on-premise,
meaning everything you would buy, whether it's network security
or endpoint security or data security and identity
and access management and so on, was on-premise, which
means that projects were expensive.
They took very long, took three years to implement whatever
it is that you bought.
But the time you finish implementing it,
you have to go back and re-implement it
because technology has changed.
We used to equate it to painting the Golden Gate Bridge,
where when they finish painting the bridge,
they have to go back and start painting it again
because the paint is already corroded.
One of the things that we decided to do at Palo Alto
Networks is to do more and more in the cloud.
Well, there was no cloud at that time,
so we did it in our own data centers,
but delivered as SaaS.
So the idea was to take some cybersecurity functions
and rather than trying to deliver them on-premise
within the hardware that we were building.
And later the software, we would deliver those
as cloud-delivered security services from our data centers.
Everybody thought we were crazy.
Nobody would use the cloud for cybersecurity.
Nobody would send cybersecurity-related data
to be inspected in the cloud and so on.
And when I hear something like that,
I say, of course, I'm going to do it, you know,
because it's the right thing.
And if everybody believes it shouldn't be done or it cannot
be done or nobody would want it, then, you know,
it's a good reason to do it.
With an ambitious plan for the novel security platform
in place, the team said about bringing on talent,
including an experienced head of engineering.
Eating with me was interesting.
Obviously, you knew the security very well.
And very sharp, very analytical.
And I felt that he was trying to do too much.
I was basically too confident, Rajiv Bhattra,
as a co-founder of Palo Alto Networks.
But then we had the second meeting
and we basically started talking about the kind of company
we wanted to create.
And our vision about the company was very, very similar.
He was telling all the things I knew,
but went wrong in previous companies.
And what went right.
And our vision was very, very aligned.
And that got me excited.
We decided that it's important for us
to be proud of everything we do.
Of everybody will tell you they want to be proud of everything
they do.
In reality, in the cybersecurity market,
because it is so difficult for customers
to check whether something actually works or not,
more than 95% of the vendors in the industry
are selling snake oil.
They're selling products that look pretty,
but don't really do anything.
So it was very important for us that whatever it is that we do,
we can be proud of actually does something,
actually secures customers.
It is much more expensive to do it, to develop it.
Yet we believe that if we do the right things for the customer
and we don't cut corners,
and we make sure that we actually secure them,
despite not having to, we would be successful.
We really listen to customers.
From when I joined when I shipped the first version
of the product, we actually hired a salesperson
whose entire job was a set of meetings for me.
We had nothing to sell.
And their entire job was a set of customer meetings for me.
So I could go tell them what we were doing
so I could get their feedback.
Hi, Oli Clarish, Chief Product Officer, Pelt Networks.
I talked to close to 100 companies in the first year
when we didn't have a product.
It was to get that feedback of,
is there anything that we're missing
so that we would have the conviction,
such that we launched the product,
we didn't get yanked and pulled
in all these different directions.
The only controversial thing
or the thing we had to debate in the early days
of Palo Alto Networks is how do we call the product?
The debate was whether we call whatever it is
that we built a firewall or next generation firewall
or whether we hide the fact that it's a firewall
and we call it multi-cyber security function gateway
or whatever, you know, some other name
that doesn't have firewall in it.
And the reason for that is that when you call it a firewall,
you make it very hard for you as a young company
to sell the product.
Because if you call it a next generation firewall
or anything that has the firewall name in it
and you go to customers and you try to sell it,
the first thing they say is we already have a firewall.
And then even if you are able to show them the value
and you tell them, no, it's okay.
It's a next generation firewall,
you don't have to replace your firewall,
you can deploy it behind your firewall
and then one day if you want, you can replace it
or you don't have to, which was the way we sold it.
In some cases you hear, no, we already have a firewall,
it's a political issue, the firewall belongs
to another department, we cannot put something
that's called a firewall, behind that firewall go away.
It was hard, like telling your customers,
you're a startup and you have a firewall.
Customers are like, I'm not deploying a version
1.0 firewall in my network, like if it fails,
my network goes down and then I get fired.
And so the temptation was to say it was not a firewall,
that it was a application visibility and control tool
or it was one time they wanted me to create a data sheet
for and call it an XGen IPS.
I would show up at customer meetings
being told by the salesperson, whatever you do,
don't tell them it's a firewall.
And so the first words out I'm out
and every meeting like that was, "Hi, my name's Lee Claretch
and I represent health networks
and we have an amazing firewall for you."
And the sales teams were kicking me under the table.
I was paranoid that if we allowed ourselves
to be positioned as anything other than an XGen firewall,
which included the firewall piece,
then we would never be able to capture it again.
We would get relegated to being a firewall helper
as opposed to being a firewall.
The decision eventually was, yeah,
we're going to call it a firewall,
the next generation firewall.
And the reason is that this is what we want to be.
We want to be a firewall.
We want to be the firewall of the organization.
And even if in the beginning we have to work harder
in order to sell it, it would pay off later.
I used to joke with the sales teams.
They said, "You have to use the F word."
They have to use the F word.
I said, "Yes, firewall.
We have to be true to what we built."
I am 100% convinced that if we had been relegated
to something other than a firewall in the early days,
even if the customer didn't deploy us that way,
we would have never been able to get that position back.
In 2007, Palau Alternate Works launched
its next generation firewall,
a product that could stop sophisticated cybersecurity
threats at the application level,
using built-in intrusion prevention,
malware detection, and other advanced defense systems.
With this groundbreaking solution,
Nireni's team burst into the cybersecurity arena.
- When we were selling against checkpoint,
against juniper, against Cisco, against Fortnite,
it was pretty easy actually.
What we told customers is, hey,
today you are blind to anything that comes in,
not via web browsing and email.
Put our box on the network for a week.
We had a mold in the box where you didn't even have to put it
in the network, you just tapped into the network
through a switch or through an optical network tap.
Give us a week and let us show you what you're missing.
And in most cases, customers said, fine,
'cause it was so easy to deploy.
We put the box there, we show them
that their existing products are completely blind
to anything that's not basically web browsing and email.
They go back to their vendors, they ask for a fix,
the vendors have no fix, and then they bought our product.
So it was pretty easy.
We knew from the beginning that if we get a POC,
a proof of concept with a customer,
our chances of selling the product were in the '90s,
so 90% or more.
New position Palo Alto Networks
has the clearly superior alternative
to the industry incumbents.
His credibility built from years of experience
at those firms helped fuel word of mouth
among enterprise IT teams frustrated with legacy firewalls.
Palo Alto Networks grew rapidly, generating $5 million
in its first year alone.
The company began attracting larger clients,
including a $10 million deal with Citibank,
a clear sign it was disrupting the cybersecurity industry.
As Palo Alto Networks' next-generation firewall gained traction,
rivals took notice, opening the company up
to potential vulnerabilities.
When you change the market, the biggest worry you have
is that one of your competitors will wake up too early
and deliver the same.
As interesting in terms of how competitors reacted to us,
I remember Juniper actually tried to preempt us
coming out of stealth mode and to say
that they had done what we did, which, of course,
they hadn't technically, so it didn't matter too much,
but it was interesting to see them trying to position it that way.
Checkpoint initially, who we viewed as our biggest competitor,
their initial response was to say that we didn't know
what we were talking about, who were wrong.
About two years later, they changed from we're wrong
to actually turns out you need an action firewall
and checkpoint invented it in retrospect.
By 2010, 2011 time frame, the market space was largely,
everyone was saying they had an action firewall.
Near and his team faced a crucible moment.
They realized that if they wanted to beat out competitors
and become the true industry leader,
they would need to scale and scale fast.
We felt the pressure to scale the company fast
from the early days.
We knew that there is a market out there
that we have a disruptive product
that we have to get to as many customers as possible.
We were doing a few hundreds of millions of dollars a year in sales
and we needed to go to a few billion.
And that always requires a change.
Every time you multiply yourselves,
then things have to change.
They have to change in the way you market your products.
You have to change the way you sell the product,
you approach the market and so on.
You have to change the way you support the product,
you have to change many different things in the organization.
The company's first change was to seek out new leadership.
When you grow really, really, really fast,
very quickly you get to a point that
whatever it is that you hired is running the biggest thing
that they've ever did.
Sometimes they're able to grow with it
and sometimes they're not.
If you're a founder and you find yourself in a company that's doing
a few million dollars in ARR or tens of millions of dollars in ARR
or hundreds of millions, good for you,
and you need to scale it to the next level, 10x.
So from few millions to few tens of millions,
from few tens of millions to hundreds of millions,
from hundreds of millions to billions,
if you've never done it yourself, which you probably haven't,
don't be a hero, don't try to do it yourself.
Your chances are relatively low.
Bring someone that's done it before and let them do it for you.
So we were looking for basically the person who can take the next level
who already had an experience.
Being in the public market, the scale we need to do
and how to basically make it happen.
And we were looking for a great leader at that point
to me that was very, very crucial.
And actually, an unusual situation in that I was offered to CEO job twice
the first time in 2008 and for personal reasons, family reasons.
I was then able to take it at that time.
So I declined knowing that I professionally regret that,
probably for the rest of my life.
And then low and behold, got the opportunity again in 2011,
things had changed at home and I was able to say, yes, that time
and ended up being the best professional decision I ever made.
Mark McLaughlin, I had the privilege of being the CEO and chairman
of Poulton Networks from 2011 until 2018 and on the board until 2022.
The companies doing very well, clearly selling well,
established the next gen firewall is an important thing in the market.
And so let's go scale it.
The expectation was when I joined, I mean, literally,
not the expectation was pretty, pretty explicit in those.
OK, you're here.
We're going to go public in six months.
Poulton Networks' leadership and board believe the best way to scale
and to cement its category dominance was through an IPO.
Going public would send a powerful signal
and give the company additional resources to grow.
But upon his arrival, Mark pushed back on the idea of an imminent IPO.
He wanted the team to think critically about the company's direction
and ensure it was on strong footing before making this leap.
What's the vision for Poulton Networks?
It's very easy for a company to scale itself to death.
And there's lots in that statement of example,
as you go down, which would be, we have one product.
The product is great.
Everybody loves it.
And you're just late on the next one or the next one.
And you just kind of, you just peter off, right?
The next one is higher, higher, higher as fast as you can.
Because we're growing so fast.
And you dilute or destroy the culture of the company simply
by just layering then because you relax your filters right on
who's going to join the company or just have too many people.
There's a lot of ways to scale yourself down very quickly.
But folks today, if you're fortunate enough
to be in a hyper-growth company in Poulton Networks,
a hyper-growth company, not growth, not super-growth.
In a hyper-growth company, it's like trying to stand on a marble.
It's very, very difficult to maintain balance
or even get it ever.
The reality is, if you want to go public,
yeah, your product technology and that stuff really matters.
But if you don't have just as much emphasis
on how you're going to build and possibly innovate
and scale and go to market machine,
you're going to get creamed in the public markets.
Public markets, every quarter, they don't ask you
if you launched a product, they ask you if you met your numbers.
Mark joined, and the first thing was to slow that down
to make sure that we were going to be ready,
not to go public like that was the end state,
but that was going to be the start of the rest of the company
of being a public company and what it takes
to be a successful public company.
We better get our stuff together and be ready for that.
I think Mark wanted time to recruit a world-class team
and build out the culture and make sure
that we had the right talent in Europe and in Asia.
But also, key areas that had been, I think,
under-invested early on, whether it be support
or sales enablement, finance.
And Mark, rightfully pushed back on the board
and suggested that we were financially ready to go public,
but we were criminally understaffed
and needed to hire a handful of leaders.
And I think quickly the board recognized that Mark was correct.
And we all got comfortable with giving him that time.
Mark convinced leadership to slow the sprint to an IPO.
Meanwhile, he went about expanding sales, support,
and finance teams while carefully preserving and building
on the company culture near and Rajiv
had worked so hard to cultivate.
What Mark really did was came to a company
where the basic product market fit had been established.
And the product had begun to kind of grow in the market.
But he really kind of went out and recruited a world-class
executive team, worked closely with the founders,
and built an executive team at the company
that could really take advantage of the business
opportunity that had been created and help materialize that.
In July 2012, with a firm roadmap for expansion
and the proper systems and leadership in place,
Palau Alternate Works went public at a market cap
over $4 billion.
One of the largest tech IPOs of the year.
The IPO gave us the money to set up the tents
and buy the food at base camp.
Yeah, that's where we are.
A lot of people never make it to base camp, right?
But that's where we are, and we've got the resources
to actually start to climb the mountain now.
That was probably the most important thing on my mind to go,
OK, let's get people thinking about 10 years from today.
In the years that followed under Marx leadership,
revenue sold tinfold from a run rate of just over $200 million
in 2012 to $3 billion in 2018.
The team grew just as dramatically from around 700 employees
to over 5,000.
And along the way, the company definitively cornered
the firewall market.
Palau Alternate Works grew its business at a rapid pace
and it day arrived when Palau Alternate
passed checkpoint and revenue size.
When that day came, near changes license plate
to CHKP, space KLD killed.
The CHKP killer became CHKP KLD.
In 2013 or '14, we became the largest network security vendor
in the world by surpassing checkpoint and Cisco
and 49, Juniper, disappeared by that time.
It was yet another milestone.
Certainly something that we always wanted to be.
Always wanted to be the biggest one.
It was also the queue for us that it's time
to move beyond network security
and start implementing the bigger master plan
to consolidate, not just the network security market,
but the entire cybersecurity market
into a single platform.
By 2018, Palau Alternate Works was the incumbent network security
company, but near-ambitioned stretch
towards capturing every corner of the cybersecurity industry
and his first target was end-point security.
It was very clear that what I was set to do in 2005,
which is turn the network security market
into a, you buy one thing and everything else is delivered
on top of it, has worked and we've changed the market
and network security is done.
They're only going to be a few large vendors.
And we wanted to start seeing that happening
in the larger cybersecurity market,
which includes other things.
For example, end-point security.
We want an end-point security to be part of a bigger thing.
Part of you buy a network and end-point security together,
which makes a lot of sense.
But it was a struggle.
It was very difficult to do that.
It was not growing as fast as we wanted it to.
We were still mostly a network security company.
While Palau Alternate Works was focused
on building our capabilities for end-point security,
a new era of technology was emerging, the cloud.
With its rise came a wave of cloud-first cybersecurity
companies, ones that threatened to leave
Palau Alternate Works behind.
The company really began in the on-premise era
and the company began where a cloud had not still happened.
So the company really grew in the on-prem firewall market,
on-prem network security market.
And then cloud began to grow.
And so at some point, the company was at risk of basically
being in a market that was an important market,
the on-prem security market, but missing the new growth
market, which could become a primary market.
It was very clear by this point, very, very obvious.
The cloud was going to have a huge impact.
How do we go from being an action firewall company?
Like that is our DNA.
That is what we do.
That is 95 plus percent of our business
to being something more.
And I remember looking and saying, OK,
well, there must be some other company that
has done this before.
What's the blueprint?
Let's go look at other companies that
have gone from being the best at one thing
to the best at multiple things.
And in cybersecurity, it didn't exist.
There was no blueprints.
There was no companies that had done this before.
There was no guidebook for this.
But we had to sort of trailblaze this expansion
into being a multi-platform company.
There was all these new cloud security things
had nothing to do with network security and action firewalls.
How do we go be the absolute best at those?
Palau Alto Network's wrist falling behind
in the emerging cloud security category.
They faced crossroads.
How should they adapt to seize the opportunity?
One of the first things that became clear
was that the company's strategy of building technology
in-house was unsustainable.
I always say in the leg of the journeys,
for Palau Alto Networks, and here I'll pick up in 2010,
right up to call 2018, we built everything ourselves.
We didn't buy anything, right?
But that wasn't an arrogance move.
Like we're the best at everything.
It was a move that was structural in nature,
which is if you don't build it yourself,
these capabilities at the network level,
you can't have the seamlessness
of what we're promising is next-gen firewall.
And that worked very, very well.
Okay, worked technically well,
and it translated into business success as well.
Okay, fast forward to 2017, 2018.
And with the cloud being a major structural change
on how people are actually gonna do compute, right?
The problem with that of the mindset is,
we make everything ourselves.
So it all works together, really didn't work then,
from a cloud perspective.
This is on me, I mean, is the CEO of the buck stops
with the CEO, right?
I think we're late to the cloud,
and by 2017, it's definitely 2018, realized it.
And part of the catch-up of like,
okay, hey, let's, we can be the best at this.
But we have to think like,
as if we were born in the cloud, right?
Like, not do at least try to insert ourselves.
Here's our firewall, it runs in the cloud, right?
Like if you were born in the cloud,
how would you do a firewall, right?
As Bella alternate to us,
grappled with strategy around cloud security,
leadership received startling news.
In a shocking move, Mark took Lee Clarice and I to lunch,
and told us that he wants to retire.
I said, hey, it's, it's time for me to actually
spend some time at home.
And a lot of people say that, but in my case, it's like,
no, really, you know, right?
I went home to home school.
I went home to home school, my youngest child, right?
So with that in mind, very thoughtful discussions
with the board are like, okay, this is going to happen.
So now we're gonna, you know, figure out who's next, right?
Being a shock for us, okay, he took us 24 hours,
we recovered, what do we need to do?
Let's go higher and you see, oh.
That's kind of the black sheep candidate.
They had a whole roster of people
who had done cybersecurity,
were sitting CEOs of cybersecurity companies
and had a long history in cybersecurity.
Now it's one of the people who had no idea
about cybersecurity.
I thought there were two different words.
Cyber and security.
My name is Nikesh Arora, I'm chairman
and CEO of Bollalton Networks.
Nikesh was a controversial hire.
I mean, Nikesh is an extraordinary talent.
Creative, a outside in thinker, gifted as a leader.
He is arguably one of the best recruiters
on the planet and capable of motivating
all aspects of an organization,
but he didn't have cybersecurity experience
and lacked enterprise experience.
And so we were taking two levels of risk,
but it also became clear from the reference work that we did
that he was an extraordinary leader
and he was going to be an exceptional CEO.
The references from Google, from Eric Schmidt,
from the board were just overwhelming.
And although many of the board members
were uncomfortable with his lack of expertise in cyber
and enterprise, we decided we needed to take the risk.
- I approached, I'd say, the first three to six months
with a very strong mindset on learning
and not disrupting too much around me.
Part of my job was to not look stupid
and that required me to go spend in our every morning
give or take with Lee Claretch understanding
how our product universe is structured
and I would near somewhere towards the end of the day
or vice versa saying, hey, how does the world operate?
- If you're trying to build something new
and there is already a team out there,
a good team out there, a team that fits your culture
that has been building it for the last several years.
And they already have market traction.
Then the right thing to do is probably to go
and buy that company instead of trying to do it yourself.
Nikesh spearheaded an aggressive acquisition strategy
acquiring three companies in his first year on the job.
He'd go on to acquire 12 in his first three years.
- The challenge we ran into was
we didn't quite understand Cloud Security really well,
we didn't know how to talk Cloud Security,
we didn't know how to sell Cloud Security
because we didn't have a product in the category.
So part of our opportunity was to see
how do we bring companies into our fold
who understand Cloud Security,
that's why we made an acquisition of the space.
We use those leaders to actually bootstrap our leadership team
in that point in time,
build a whole go-to-market motion and capability around them.
We actually pioneered the notion of speedboats
where we said, every one of these things are speedboats
because we have a large destroyer or perhaps
whichever is the more benign version of a naval vessel.
But the idea of the speedboard was that we have to make sure
that we don't constrain them without them run faster.
We let them build entire motion around them
as opposed to bifurcate that motion.
Functionally and suddenly have far more people
telling salespeople how to sell Cloud.
So we actually built a whole cohesive team around that capability
and that allowed us to gain muscle over time
to understand these new swim lanes
and be able to be at scale.
This strategy, however, came with risk.
I would say the vast majority of public market acquisitions fail.
Well, it's one of the challenges
with a public company quarterly reporting.
When you acquire these young companies,
they're often not generating, meaning for revenue.
There's an op-ex hit.
And so all of that was absorbed into the existing operating
plan that we had offered to the street.
So we did not frame a new set of guidelines for financials
based on these acquisitions.
And so we had absorbed the op-ex of each of these acquisitions
and the dilution of the equity within our existing envelope
that we had in terms of guidance for the street.
And that was at times viewed as a risky strategy.
But the execution on the go-to-market front
was so extraordinary that we were able to absorb it.
And that became Nikesh's go-to mode
rather than resetting expectations with the street.
I've also been around the tech industry
to watch that majority of M&A transactions
fail because of the execution issues post M&A.
And some of the key learnings from the failures
are a company throws away in a category,
doesn't make it, goes and acquires somebody
and the same people who were toiling away in the category
and failed end up managing the new acquisition.
So we don't do that apologize.
Rule number one, the acquired company
or the partner that we've acquired actually
beat us in the market with less resources,
more focus and better execution.
So maybe those people should be part of a lot of driving
that strategy, not people who've been trying and failed.
That's the first thing we do is an acquisition
is you make the new leaders responsible for our strategy
and put them in our leadership team to drive the new area.
Do when the acquisitions happen,
a lot less time is spent on aligning the product strategy
before you make the acquisition.
You try and adjust it afterwards.
So pretty much for the most of our acquisitions
will be spent a lot of time.
I'd say the religion spirit is less
about understanding your financials, which we do, of course.
There's a team that does that really well.
Our aligning corporate structures, our aligning organizations,
we spend an inordinate amount of time debating
on product strategy and what the product strategy needs
to be for the next two to three years
because it's a lot easier to work with people who are fully
aligned from product strategy,
prospecting we've done that before the acquisition
that afterwards.
So we always joke once we buy the house,
we get to choose what color we painted,
but we spend a lot of time consulting
with the people who are living it
to make sure that we both agree.
So that's kind of unique to our approach.
It's a lining product strategy prior to acquisition.
So our combination of both organic product development
where we accelerate and add resources
and acquisition drove that up.
Each acquisition was a strategic play
to absorb the talent and expertise driving those companies,
even at the expense of the company's bottom line.
Not all those products are fully ready and we're not being sold.
So you end up putting the cost in your balance sheet,
but you're not fully getting the benefits of the revenue
because you're still in development phase.
And we did take our operating margins down
as the company's first two or three years
and we were operating the high deans and low 20s
for the first two years because we were investing
in building capability in multiple categories
which we didn't exist in before.
The strategy proved correct.
Under Nikesh's leadership, Palau Alternator X
has acquired over 25 companies
and released products such as Prisma Cloud
and Cortex Cloud, comprehensive cloud native application
protection platforms designed to secure applications
and data across multi-cloud environments.
These innovations gave Palau Alternator X
a strategic edge that transformed the company
into a comprehensive cybersecurity platform
and a leader in the cloud.
2018 in hindsight ended up being a crucible moment
for Palau Alternator X
because we could have gone down the steady part
of continuing to excel in network security
and possibly ended up as a large network security company.
And at that point in time,
we competed with two or three of the biggest players
in network security who are still around
or the option for us was to see if we can expand
to being a much larger player in cybersecurity
with the ambition of being the first ever green cybersecurity
company.
And I think we chose the path that set us on track
to be, I hope, which is the first at scale
ever green cybersecurity company in the world.
And have we not taken that fork in the road?
We'd be fine.
We wouldn't be done poorly.
That kind of those companies have done well.
They've succeeded in their space
but they have not been able to move into other swim lanes
and be successful on other swim ways
but that was not their standard ambition.
So that's sometimes to say,
if you don't declare an ambition, it's hard to get to it
because you actually don't know how you're headed there.
So it was a crucible moment for us.
And in hindsight, it was a bet we made and it worked out.
As of October 2025, Palau Alternatrix's market cap
is nearly $150 billion.
And it employs 16,000 people globally.
As cybersecurity moves into the AI era,
the company continues to stay nimble
in an ever changing industry.
Cybersecurity industry is the most innovative industry
in the world because the bad guys are always trying
to innovate on how to attack our customers,
which means we cannot rest on our laurels.
We can't live in a world where we're not constantly trying
to out-in-oate the bad actors.
Today, we talk about how to secure with AI,
how to deploy browsers on the world,
how to build a common data lake for security
and be innovative in the future.
So I think we are getting the seat of the table now
with our customers to define and help them
think through the future cybersecurity architecture.
The way I approach Palau Alternatrix today
is really thinking about it and always trying to sort of maintain
an evergreen philosophy in terms of how we approach product
technology, but even go to market and everything else
the company does.
You can't assume that what got us to our success five years
ago is what's going to make a successful day.
Or what we're doing today is going
to make a successful three or four years from now.
And so that evergreen philosophy and always
being willing to disrupt ourselves before someone else does
is a lot of what I think about every day
when I think about the future of health networks.
If I look at Palau Alternatrix today, and by the way,
I recently announced that I'm going to retire
from Palau Alternatrix.
And the reason for that is that I think
that Palau Alternatrix has finally achieved
the vision that I set 20 years ago,
meaning recently we announced the 25 or so billion-dollar
acquisition of a company called CyberArc, which
is in the identity space, they're doing many different things
in identity, identity and access management,
privilege, access management, and other things.
And that, to me, completes the platform, meaning we now
provide all the major components of a cybersecurity
infrastructure, network security, endpoint security,
security operations center, automation, and control,
and cloud security, identity and access management.
We went into AI security, which is a new space,
into email security, which is a traditional space.
We went into vulnerability, assessment
and vulnerability management, a traditional space.
We have all the major components at Palau Alternatrix
that an organization would need in order
to achieve their cybersecurity goals,
which is what I set to do 20 years ago.
And now I can retire from Palau Alternatrix with Peace,
knowing that I'm leaving a company with all the products
and all the technology that it needs,
with a great management team, led by Nikesh,
and the company in a great financial state,
and the company can go and continue
to be successful, living without me.
My advice to startups that are being disrupted,
or companies that are being disrupted by either another company
doing the same thing just in a much better way, in a different way,
or you're being disrupted by a shift in market dynamics
like the cloud, like AI, and so on,
my advice to you is embrace the disruption.
If you don't embrace the disruption,
you will end up like companies that
didn't embrace the disruption.
So for example, in our case, if you end up like checkpoint,
in the case of cell phones, you end up like Nokia,
that was disrupted by Apple and later Google,
you will get killed by disruption.
So always embrace a disruption,
despite that disruption, or you embracing it,
hurting your business for the short term.
If you do it right, you will get out of it
on the other side much stronger than you would
if you hadn't embraced the disruption.
This has been Crucible Moments,
a podcast from Sequoia Capital.
Crucible Moments is produced by the Epic Stories
and Fox Creative Podcast Teams, along with Sequoia Capital.
Special thanks to Mirzouk, Ashim Chandra, Jim Gets, Rajiv Batra,
Lee Clarich, Mark McLaughlin, and Nikesh Aurora
for sharing their stories.
Podcast Summary
Key Points:
Near Zook's journey from Checkpoint to founding Palo Alto Networks.
Development of the next-generation firewall at Palo Alto Networks.
Challenges faced by Palo Alto Networks in disrupting the cybersecurity industry and scaling rapidly.
Summary:
The transcription discusses Near Zook's background, starting from his time at Checkpoint to founding Palo Alto Networks. It details the development of the next-generation firewall at Palo Alto Networks, focusing on its unique features and market strategy. The challenges faced by the company in disrupting the cybersecurity industry and scaling rapidly are highlighted, including competition reactions and the need for organizational changes to achieve rapid growth.
Near's strategic decisions, such as focusing on customer feedback and staying true to the firewall concept, are emphasized as key factors in Palo Alto Networks' success in becoming a global leader in cybersecurity.
FAQs
The founder was frustrated with the cautious cultures of previous companies and wanted to innovate freely in the cybersecurity industry.
Palo Alto Networks introduced a next-generation firewall that unified multiple layers of protection into one intelligent platform, securing more than just web browsing and email.
Palo Alto Networks saw an opportunity to innovate by delivering cybersecurity functions through cloud-based services, despite initial skepticism from the industry.
Despite initial reluctance, Palo Alto Networks decided to call their product a next-generation firewall to establish their position in the market.
Palo Alto Networks engaged with customers extensively, seeking feedback and ensuring that their products were effective in securing customers' networks.
By offering a superior alternative to legacy firewalls and attracting large clients like Citibank, Palo Alto Networks rapidly grew and generated significant revenue.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.