Go back

Palo Alto Networks ft Nir Zuk & Nikesh Arora - The Grudge That Transformed Cybersecurity

47m 3s

Palo Alto Networks ft Nir Zuk & Nikesh Arora - The Grudge That Transformed Cybersecurity

The transcription discusses Near Zook's background, starting from his time at Checkpoint to founding Palo Alto Networks. It details the development of the next-generation firewall at Palo Alto Networks, focusing on its unique features and market strategy. The challenges faced by the company in disrupting the cybersecurity industry and scaling rapidly are highlighted, including competition reactions and the need for organizational changes to achieve rapid growth. Near's strategic decisions, such as focusing on customer feedback and staying true to the firewall concept, are emphasized as key factors in Palo Alto Networks' success in becoming a global leader in cybersecurity.

Transcription

7595 Words, 43783 Characters

[MUSIC PLAYING] Everybody thought we were crazy. Nobody would use the cloud for cybersecurity. Nobody would send cybersecurity related data to be inspected in the cloud and so on. And when I hear something like that, I say, of course, I'm going to do it, you know? Because it's the right thing. And if everybody believes it's not, it shouldn't be done or it cannot be done or nobody would want it. Then, you know, it's a good reason to do it. Welcome to Crucible Moments. A podcast about the decisions and inflection points that defined some of the most consequential companies of our time. I'm your host, Rulof Boerza. In the 1990s, as businesses rushed online, a new cybersecurity industry emerged to protect the networks powering the internet boom. Among the industry's early builders was an Israeli engineer who helped shape several of those companies, until he grew frustrated with their overly cautious cultures that stifled innovation. So, he decided to strike out on his own. Along with a small team of experts, nearer Zook built something that would change the industry, the next generation firewall. Unlike traditional firewalls, it didn't just block threats. It unified multiple layers of protection into one intelligent platform. By blending on-premise security with early cloud-based capabilities, Zook's vision redefined what modern cybersecurity could be and set the standard the industry still follows today. In this episode, we'll explore the crucible moments that turned PalaAlton Networks from a bold startup into a global leader in cybersecurity, from bringing their disruptive product to market to scaling into a public company and ultimately outpacing the industry again in the cloud era. This is the story of PalaAlton Networks and the people who refused to play by the old rules. I'm nearer Zook, founder and shift technology officer at PalaAlton Networks. I was born in Israel in 1971, and as a teenager in the mid-80s, one of my hobbies was to develop viruses, some of the early computer viruses in the world, which landed me a job with Israeli intelligence as part of my military service. And there, at Unit 8200, is where I met two of the three founders of Checkpoint. I joined them at Building Checkpoint Software in late '94. At Checkpoint, near-worked on some of the first firewall technologies, network security systems that could monitor and control traffic between private networks and the outside world. The biggest challenge I faced at Checkpoint was that very early on, Checkpoint has decided, number one, that they're just going to be a firewall VPN company, meaning they don't want to do other things that customers require as part of their cybersecurity strategy. And second, that they want to optimize for very high operating margins. Checkpoint has always run close to 60% net operating margins, which is very high, but it also means that there's no money to invest, specifically in research and development. So for me, as someone that likes to build technology, likes to build products, like to take things forward, it was a challenge not being able to invest in R&D and not being able to build things beyond basic firewall VPN. Near-transferred to Checkpoint's California team, hoping it would offer an opportunity to work outside of the company's VPN-only strategy. But when the team was shut down in 1999, near decided to leave Checkpoint all together and forge his own path in the cybersecurity space. He wasn't shy about the fact that his former employer was now his biggest competition. - I had a custom California license plate made. The license plate was CHKP KLR, which reads Checkpoint killer. So I was driving around the Bay Area with that car. I had met with him and walked him out to his car and it spotted the plates. It was an example of a chip on the shoulder that Nier had developed in his time at Checkpoint. My name is Jim Gets, partner, it's a quick appletal. - Sitting out to compete with Checkpoint, Nier founded his first company, OneSecure, which was quickly acquired by NetScreen, which was then sold to Juniper in 2004. The first day, literally the first day after the acquisition closed in April 2004, my new boss, the CTO and founder of Juniper told me that they were not interested in the products and they wanted to rebuild them into their own products, which I thought was a disaster. So I left, many other people left and I left to start Palo Alto Networks. I called a really good friend of mine called Ashim Chandna, who is a VC at Greylock and told him I was going to start something and immediately brought Jim Gets as well into the picture. I knew from the beginning they agreed from the beginning that we're going to build something that's going to change the cybersecurity industry and the three of us sat down and tried to figure out what it is. - I remember when the company started, part of the design goal was, you know, beat NetScreen, who was an incumbent renderer at the time on performance, beat Checkpoint Software, another primary incumbent on Manageability and then beat Fortinet and Cisco in their all-in-one architecture. I'm Ashim Chandna, I'm a partner at Greylock. So Kurvan Builder System where you had, you know, you beat Checkpoint Software and Manageability, NetScreen on Performance and, you know, Cisco and Fortinet in terms of the all-in-one capability. And then the question was really, how do you insert into that? Greylock and Sequoia were a very rigor in making sure that I have the right plan to be able to conquer the market. So that was, I guess, nine months project where we went through different insertion plans, different ways of getting into the market with whatever it is that I'm going to end up building. - He had several ideas, but none were refined. There was energy from near as you can expect to do a frontal attack on the firewall market. And both Ashim and I felt like a market entry tactic that may not be frontal in nature, but would embrace a more subtle approach to the market was important, and so much of the investigative work was around product definition and market entry tactics. - The team continued to brainstorm around this early crucible moment. What do you build that will set you apart in a space crowded with competitors? And how do you take that product to market? - The original plan was to be based on an ASIC, a custom silicone that we were going to build, that's going to make everything really cheap and really fast. And we scrapped that as not being enough. And then after one or two more iterations, we figured out that one of the features in the product, which was around being able to secure not just web browsing in email, which were the only protocols or only applications that enterprises were using at the time, but rather also secure other applications, which were considered consumer applications at the time. Like ICQ and net meeting, if you remember, and Skype and Facebook was emerging at the time. And so on, the assumption was that these were going to become also enterprise applications. So the decision was to take something that was relatively smaller in terms of being able to secure all these applications and making it the cornerstone of 40 days that Palo Alto Networks was going to do in the early days, build network security that can secure everything, not just web browsing and email, and making that the go-to market, the insertion plan, what we sell to customers. At the time, there were dozens of appliances doing various functions that were not being done in the firewall. And Nier's ambition was to create a single-pass architecture that would allow us to integrate that into a single system. Customers really had what was called appliance fatigue. They had many appliances for different discrete functions around security. And so part of the vision around the company was to collapse all these functions into a single architecture and into a single system, but yet provide customers with scalability and manageability and performance. In addition to a single, fully integrated platform that could serve all areas of an enterprise's security needs, the team decided to take a gamble on the way the platform was deployed. When I joined Sequoia in Greylock in 2005, the cybersecurity market was 100% on-premise, meaning everything you would buy, whether it's network security or endpoint security or data security and identity and access management and so on, was on-premise, which means that projects were expensive. They took very long, took three years to implement whatever it is that you bought. But the time you finish implementing it, you have to go back and re-implement it because technology has changed. We used to equate it to painting the Golden Gate Bridge, where when they finish painting the bridge, they have to go back and start painting it again because the paint is already corroded. One of the things that we decided to do at Palo Alto Networks is to do more and more in the cloud. Well, there was no cloud at that time, so we did it in our own data centers, but delivered as SaaS. So the idea was to take some cybersecurity functions and rather than trying to deliver them on-premise within the hardware that we were building. And later the software, we would deliver those as cloud-delivered security services from our data centers. Everybody thought we were crazy. Nobody would use the cloud for cybersecurity. Nobody would send cybersecurity-related data to be inspected in the cloud and so on. And when I hear something like that, I say, of course, I'm going to do it, you know, because it's the right thing. And if everybody believes it shouldn't be done or it cannot be done or nobody would want it, then, you know, it's a good reason to do it. With an ambitious plan for the novel security platform in place, the team said about bringing on talent, including an experienced head of engineering. Eating with me was interesting. Obviously, you knew the security very well. And very sharp, very analytical. And I felt that he was trying to do too much. I was basically too confident, Rajiv Bhattra, as a co-founder of Palo Alto Networks. But then we had the second meeting and we basically started talking about the kind of company we wanted to create. And our vision about the company was very, very similar. He was telling all the things I knew, but went wrong in previous companies. And what went right. And our vision was very, very aligned. And that got me excited. We decided that it's important for us to be proud of everything we do. Of everybody will tell you they want to be proud of everything they do. In reality, in the cybersecurity market, because it is so difficult for customers to check whether something actually works or not, more than 95% of the vendors in the industry are selling snake oil. They're selling products that look pretty, but don't really do anything. So it was very important for us that whatever it is that we do, we can be proud of actually does something, actually secures customers. It is much more expensive to do it, to develop it. Yet we believe that if we do the right things for the customer and we don't cut corners, and we make sure that we actually secure them, despite not having to, we would be successful. We really listen to customers. From when I joined when I shipped the first version of the product, we actually hired a salesperson whose entire job was a set of meetings for me. We had nothing to sell. And their entire job was a set of customer meetings for me. So I could go tell them what we were doing so I could get their feedback. Hi, Oli Clarish, Chief Product Officer, Pelt Networks. I talked to close to 100 companies in the first year when we didn't have a product. It was to get that feedback of, is there anything that we're missing so that we would have the conviction, such that we launched the product, we didn't get yanked and pulled in all these different directions. The only controversial thing or the thing we had to debate in the early days of Palo Alto Networks is how do we call the product? The debate was whether we call whatever it is that we built a firewall or next generation firewall or whether we hide the fact that it's a firewall and we call it multi-cyber security function gateway or whatever, you know, some other name that doesn't have firewall in it. And the reason for that is that when you call it a firewall, you make it very hard for you as a young company to sell the product. Because if you call it a next generation firewall or anything that has the firewall name in it and you go to customers and you try to sell it, the first thing they say is we already have a firewall. And then even if you are able to show them the value and you tell them, no, it's okay. It's a next generation firewall, you don't have to replace your firewall, you can deploy it behind your firewall and then one day if you want, you can replace it or you don't have to, which was the way we sold it. In some cases you hear, no, we already have a firewall, it's a political issue, the firewall belongs to another department, we cannot put something that's called a firewall, behind that firewall go away. It was hard, like telling your customers, you're a startup and you have a firewall. Customers are like, I'm not deploying a version 1.0 firewall in my network, like if it fails, my network goes down and then I get fired. And so the temptation was to say it was not a firewall, that it was a application visibility and control tool or it was one time they wanted me to create a data sheet for and call it an XGen IPS. I would show up at customer meetings being told by the salesperson, whatever you do, don't tell them it's a firewall. And so the first words out I'm out and every meeting like that was, "Hi, my name's Lee Claretch and I represent health networks and we have an amazing firewall for you." And the sales teams were kicking me under the table. I was paranoid that if we allowed ourselves to be positioned as anything other than an XGen firewall, which included the firewall piece, then we would never be able to capture it again. We would get relegated to being a firewall helper as opposed to being a firewall. The decision eventually was, yeah, we're going to call it a firewall, the next generation firewall. And the reason is that this is what we want to be. We want to be a firewall. We want to be the firewall of the organization. And even if in the beginning we have to work harder in order to sell it, it would pay off later. I used to joke with the sales teams. They said, "You have to use the F word." They have to use the F word. I said, "Yes, firewall. We have to be true to what we built." I am 100% convinced that if we had been relegated to something other than a firewall in the early days, even if the customer didn't deploy us that way, we would have never been able to get that position back. In 2007, Palau Alternate Works launched its next generation firewall, a product that could stop sophisticated cybersecurity threats at the application level, using built-in intrusion prevention, malware detection, and other advanced defense systems. With this groundbreaking solution, Nireni's team burst into the cybersecurity arena. - When we were selling against checkpoint, against juniper, against Cisco, against Fortnite, it was pretty easy actually. What we told customers is, hey, today you are blind to anything that comes in, not via web browsing and email. Put our box on the network for a week. We had a mold in the box where you didn't even have to put it in the network, you just tapped into the network through a switch or through an optical network tap. Give us a week and let us show you what you're missing. And in most cases, customers said, fine, 'cause it was so easy to deploy. We put the box there, we show them that their existing products are completely blind to anything that's not basically web browsing and email. They go back to their vendors, they ask for a fix, the vendors have no fix, and then they bought our product. So it was pretty easy. We knew from the beginning that if we get a POC, a proof of concept with a customer, our chances of selling the product were in the '90s, so 90% or more. New position Palo Alto Networks has the clearly superior alternative to the industry incumbents. His credibility built from years of experience at those firms helped fuel word of mouth among enterprise IT teams frustrated with legacy firewalls. Palo Alto Networks grew rapidly, generating $5 million in its first year alone. The company began attracting larger clients, including a $10 million deal with Citibank, a clear sign it was disrupting the cybersecurity industry. As Palo Alto Networks' next-generation firewall gained traction, rivals took notice, opening the company up to potential vulnerabilities. When you change the market, the biggest worry you have is that one of your competitors will wake up too early and deliver the same. As interesting in terms of how competitors reacted to us, I remember Juniper actually tried to preempt us coming out of stealth mode and to say that they had done what we did, which, of course, they hadn't technically, so it didn't matter too much, but it was interesting to see them trying to position it that way. Checkpoint initially, who we viewed as our biggest competitor, their initial response was to say that we didn't know what we were talking about, who were wrong. About two years later, they changed from we're wrong to actually turns out you need an action firewall and checkpoint invented it in retrospect. By 2010, 2011 time frame, the market space was largely, everyone was saying they had an action firewall. Near and his team faced a crucible moment. They realized that if they wanted to beat out competitors and become the true industry leader, they would need to scale and scale fast. We felt the pressure to scale the company fast from the early days. We knew that there is a market out there that we have a disruptive product that we have to get to as many customers as possible. We were doing a few hundreds of millions of dollars a year in sales and we needed to go to a few billion. And that always requires a change. Every time you multiply yourselves, then things have to change. They have to change in the way you market your products. You have to change the way you sell the product, you approach the market and so on. You have to change the way you support the product, you have to change many different things in the organization. The company's first change was to seek out new leadership. When you grow really, really, really fast, very quickly you get to a point that whatever it is that you hired is running the biggest thing that they've ever did. Sometimes they're able to grow with it and sometimes they're not. If you're a founder and you find yourself in a company that's doing a few million dollars in ARR or tens of millions of dollars in ARR or hundreds of millions, good for you, and you need to scale it to the next level, 10x. So from few millions to few tens of millions, from few tens of millions to hundreds of millions, from hundreds of millions to billions, if you've never done it yourself, which you probably haven't, don't be a hero, don't try to do it yourself. Your chances are relatively low. Bring someone that's done it before and let them do it for you. So we were looking for basically the person who can take the next level who already had an experience. Being in the public market, the scale we need to do and how to basically make it happen. And we were looking for a great leader at that point to me that was very, very crucial. And actually, an unusual situation in that I was offered to CEO job twice the first time in 2008 and for personal reasons, family reasons. I was then able to take it at that time. So I declined knowing that I professionally regret that, probably for the rest of my life. And then low and behold, got the opportunity again in 2011, things had changed at home and I was able to say, yes, that time and ended up being the best professional decision I ever made. Mark McLaughlin, I had the privilege of being the CEO and chairman of Poulton Networks from 2011 until 2018 and on the board until 2022. The companies doing very well, clearly selling well, established the next gen firewall is an important thing in the market. And so let's go scale it. The expectation was when I joined, I mean, literally, not the expectation was pretty, pretty explicit in those. OK, you're here. We're going to go public in six months. Poulton Networks' leadership and board believe the best way to scale and to cement its category dominance was through an IPO. Going public would send a powerful signal and give the company additional resources to grow. But upon his arrival, Mark pushed back on the idea of an imminent IPO. He wanted the team to think critically about the company's direction and ensure it was on strong footing before making this leap. What's the vision for Poulton Networks? It's very easy for a company to scale itself to death. And there's lots in that statement of example, as you go down, which would be, we have one product. The product is great. Everybody loves it. And you're just late on the next one or the next one. And you just kind of, you just peter off, right? The next one is higher, higher, higher as fast as you can. Because we're growing so fast. And you dilute or destroy the culture of the company simply by just layering then because you relax your filters right on who's going to join the company or just have too many people. There's a lot of ways to scale yourself down very quickly. But folks today, if you're fortunate enough to be in a hyper-growth company in Poulton Networks, a hyper-growth company, not growth, not super-growth. In a hyper-growth company, it's like trying to stand on a marble. It's very, very difficult to maintain balance or even get it ever. The reality is, if you want to go public, yeah, your product technology and that stuff really matters. But if you don't have just as much emphasis on how you're going to build and possibly innovate and scale and go to market machine, you're going to get creamed in the public markets. Public markets, every quarter, they don't ask you if you launched a product, they ask you if you met your numbers. Mark joined, and the first thing was to slow that down to make sure that we were going to be ready, not to go public like that was the end state, but that was going to be the start of the rest of the company of being a public company and what it takes to be a successful public company. We better get our stuff together and be ready for that. I think Mark wanted time to recruit a world-class team and build out the culture and make sure that we had the right talent in Europe and in Asia. But also, key areas that had been, I think, under-invested early on, whether it be support or sales enablement, finance. And Mark, rightfully pushed back on the board and suggested that we were financially ready to go public, but we were criminally understaffed and needed to hire a handful of leaders. And I think quickly the board recognized that Mark was correct. And we all got comfortable with giving him that time. Mark convinced leadership to slow the sprint to an IPO. Meanwhile, he went about expanding sales, support, and finance teams while carefully preserving and building on the company culture near and Rajiv had worked so hard to cultivate. What Mark really did was came to a company where the basic product market fit had been established. And the product had begun to kind of grow in the market. But he really kind of went out and recruited a world-class executive team, worked closely with the founders, and built an executive team at the company that could really take advantage of the business opportunity that had been created and help materialize that. In July 2012, with a firm roadmap for expansion and the proper systems and leadership in place, Palau Alternate Works went public at a market cap over $4 billion. One of the largest tech IPOs of the year. The IPO gave us the money to set up the tents and buy the food at base camp. Yeah, that's where we are. A lot of people never make it to base camp, right? But that's where we are, and we've got the resources to actually start to climb the mountain now. That was probably the most important thing on my mind to go, OK, let's get people thinking about 10 years from today. In the years that followed under Marx leadership, revenue sold tinfold from a run rate of just over $200 million in 2012 to $3 billion in 2018. The team grew just as dramatically from around 700 employees to over 5,000. And along the way, the company definitively cornered the firewall market. Palau Alternate Works grew its business at a rapid pace and it day arrived when Palau Alternate passed checkpoint and revenue size. When that day came, near changes license plate to CHKP, space KLD killed. The CHKP killer became CHKP KLD. In 2013 or '14, we became the largest network security vendor in the world by surpassing checkpoint and Cisco and 49, Juniper, disappeared by that time. It was yet another milestone. Certainly something that we always wanted to be. Always wanted to be the biggest one. It was also the queue for us that it's time to move beyond network security and start implementing the bigger master plan to consolidate, not just the network security market, but the entire cybersecurity market into a single platform. By 2018, Palau Alternate Works was the incumbent network security company, but near-ambitioned stretch towards capturing every corner of the cybersecurity industry and his first target was end-point security. It was very clear that what I was set to do in 2005, which is turn the network security market into a, you buy one thing and everything else is delivered on top of it, has worked and we've changed the market and network security is done. They're only going to be a few large vendors. And we wanted to start seeing that happening in the larger cybersecurity market, which includes other things. For example, end-point security. We want an end-point security to be part of a bigger thing. Part of you buy a network and end-point security together, which makes a lot of sense. But it was a struggle. It was very difficult to do that. It was not growing as fast as we wanted it to. We were still mostly a network security company. While Palau Alternate Works was focused on building our capabilities for end-point security, a new era of technology was emerging, the cloud. With its rise came a wave of cloud-first cybersecurity companies, ones that threatened to leave Palau Alternate Works behind. The company really began in the on-premise era and the company began where a cloud had not still happened. So the company really grew in the on-prem firewall market, on-prem network security market. And then cloud began to grow. And so at some point, the company was at risk of basically being in a market that was an important market, the on-prem security market, but missing the new growth market, which could become a primary market. It was very clear by this point, very, very obvious. The cloud was going to have a huge impact. How do we go from being an action firewall company? Like that is our DNA. That is what we do. That is 95 plus percent of our business to being something more. And I remember looking and saying, OK, well, there must be some other company that has done this before. What's the blueprint? Let's go look at other companies that have gone from being the best at one thing to the best at multiple things. And in cybersecurity, it didn't exist. There was no blueprints. There was no companies that had done this before. There was no guidebook for this. But we had to sort of trailblaze this expansion into being a multi-platform company. There was all these new cloud security things had nothing to do with network security and action firewalls. How do we go be the absolute best at those? Palau Alto Network's wrist falling behind in the emerging cloud security category. They faced crossroads. How should they adapt to seize the opportunity? One of the first things that became clear was that the company's strategy of building technology in-house was unsustainable. I always say in the leg of the journeys, for Palau Alto Networks, and here I'll pick up in 2010, right up to call 2018, we built everything ourselves. We didn't buy anything, right? But that wasn't an arrogance move. Like we're the best at everything. It was a move that was structural in nature, which is if you don't build it yourself, these capabilities at the network level, you can't have the seamlessness of what we're promising is next-gen firewall. And that worked very, very well. Okay, worked technically well, and it translated into business success as well. Okay, fast forward to 2017, 2018. And with the cloud being a major structural change on how people are actually gonna do compute, right? The problem with that of the mindset is, we make everything ourselves. So it all works together, really didn't work then, from a cloud perspective. This is on me, I mean, is the CEO of the buck stops with the CEO, right? I think we're late to the cloud, and by 2017, it's definitely 2018, realized it. And part of the catch-up of like, okay, hey, let's, we can be the best at this. But we have to think like, as if we were born in the cloud, right? Like, not do at least try to insert ourselves. Here's our firewall, it runs in the cloud, right? Like if you were born in the cloud, how would you do a firewall, right? As Bella alternate to us, grappled with strategy around cloud security, leadership received startling news. In a shocking move, Mark took Lee Clarice and I to lunch, and told us that he wants to retire. I said, hey, it's, it's time for me to actually spend some time at home. And a lot of people say that, but in my case, it's like, no, really, you know, right? I went home to home school. I went home to home school, my youngest child, right? So with that in mind, very thoughtful discussions with the board are like, okay, this is going to happen. So now we're gonna, you know, figure out who's next, right? Being a shock for us, okay, he took us 24 hours, we recovered, what do we need to do? Let's go higher and you see, oh. That's kind of the black sheep candidate. They had a whole roster of people who had done cybersecurity, were sitting CEOs of cybersecurity companies and had a long history in cybersecurity. Now it's one of the people who had no idea about cybersecurity. I thought there were two different words. Cyber and security. My name is Nikesh Arora, I'm chairman and CEO of Bollalton Networks. Nikesh was a controversial hire. I mean, Nikesh is an extraordinary talent. Creative, a outside in thinker, gifted as a leader. He is arguably one of the best recruiters on the planet and capable of motivating all aspects of an organization, but he didn't have cybersecurity experience and lacked enterprise experience. And so we were taking two levels of risk, but it also became clear from the reference work that we did that he was an extraordinary leader and he was going to be an exceptional CEO. The references from Google, from Eric Schmidt, from the board were just overwhelming. And although many of the board members were uncomfortable with his lack of expertise in cyber and enterprise, we decided we needed to take the risk. - I approached, I'd say, the first three to six months with a very strong mindset on learning and not disrupting too much around me. Part of my job was to not look stupid and that required me to go spend in our every morning give or take with Lee Claretch understanding how our product universe is structured and I would near somewhere towards the end of the day or vice versa saying, hey, how does the world operate? - If you're trying to build something new and there is already a team out there, a good team out there, a team that fits your culture that has been building it for the last several years. And they already have market traction. Then the right thing to do is probably to go and buy that company instead of trying to do it yourself. Nikesh spearheaded an aggressive acquisition strategy acquiring three companies in his first year on the job. He'd go on to acquire 12 in his first three years. - The challenge we ran into was we didn't quite understand Cloud Security really well, we didn't know how to talk Cloud Security, we didn't know how to sell Cloud Security because we didn't have a product in the category. So part of our opportunity was to see how do we bring companies into our fold who understand Cloud Security, that's why we made an acquisition of the space. We use those leaders to actually bootstrap our leadership team in that point in time, build a whole go-to-market motion and capability around them. We actually pioneered the notion of speedboats where we said, every one of these things are speedboats because we have a large destroyer or perhaps whichever is the more benign version of a naval vessel. But the idea of the speedboard was that we have to make sure that we don't constrain them without them run faster. We let them build entire motion around them as opposed to bifurcate that motion. Functionally and suddenly have far more people telling salespeople how to sell Cloud. So we actually built a whole cohesive team around that capability and that allowed us to gain muscle over time to understand these new swim lanes and be able to be at scale. This strategy, however, came with risk. I would say the vast majority of public market acquisitions fail. Well, it's one of the challenges with a public company quarterly reporting. When you acquire these young companies, they're often not generating, meaning for revenue. There's an op-ex hit. And so all of that was absorbed into the existing operating plan that we had offered to the street. So we did not frame a new set of guidelines for financials based on these acquisitions. And so we had absorbed the op-ex of each of these acquisitions and the dilution of the equity within our existing envelope that we had in terms of guidance for the street. And that was at times viewed as a risky strategy. But the execution on the go-to-market front was so extraordinary that we were able to absorb it. And that became Nikesh's go-to mode rather than resetting expectations with the street. I've also been around the tech industry to watch that majority of M&A transactions fail because of the execution issues post M&A. And some of the key learnings from the failures are a company throws away in a category, doesn't make it, goes and acquires somebody and the same people who were toiling away in the category and failed end up managing the new acquisition. So we don't do that apologize. Rule number one, the acquired company or the partner that we've acquired actually beat us in the market with less resources, more focus and better execution. So maybe those people should be part of a lot of driving that strategy, not people who've been trying and failed. That's the first thing we do is an acquisition is you make the new leaders responsible for our strategy and put them in our leadership team to drive the new area. Do when the acquisitions happen, a lot less time is spent on aligning the product strategy before you make the acquisition. You try and adjust it afterwards. So pretty much for the most of our acquisitions will be spent a lot of time. I'd say the religion spirit is less about understanding your financials, which we do, of course. There's a team that does that really well. Our aligning corporate structures, our aligning organizations, we spend an inordinate amount of time debating on product strategy and what the product strategy needs to be for the next two to three years because it's a lot easier to work with people who are fully aligned from product strategy, prospecting we've done that before the acquisition that afterwards. So we always joke once we buy the house, we get to choose what color we painted, but we spend a lot of time consulting with the people who are living it to make sure that we both agree. So that's kind of unique to our approach. It's a lining product strategy prior to acquisition. So our combination of both organic product development where we accelerate and add resources and acquisition drove that up. Each acquisition was a strategic play to absorb the talent and expertise driving those companies, even at the expense of the company's bottom line. Not all those products are fully ready and we're not being sold. So you end up putting the cost in your balance sheet, but you're not fully getting the benefits of the revenue because you're still in development phase. And we did take our operating margins down as the company's first two or three years and we were operating the high deans and low 20s for the first two years because we were investing in building capability in multiple categories which we didn't exist in before. The strategy proved correct. Under Nikesh's leadership, Palau Alternator X has acquired over 25 companies and released products such as Prisma Cloud and Cortex Cloud, comprehensive cloud native application protection platforms designed to secure applications and data across multi-cloud environments. These innovations gave Palau Alternator X a strategic edge that transformed the company into a comprehensive cybersecurity platform and a leader in the cloud. 2018 in hindsight ended up being a crucible moment for Palau Alternator X because we could have gone down the steady part of continuing to excel in network security and possibly ended up as a large network security company. And at that point in time, we competed with two or three of the biggest players in network security who are still around or the option for us was to see if we can expand to being a much larger player in cybersecurity with the ambition of being the first ever green cybersecurity company. And I think we chose the path that set us on track to be, I hope, which is the first at scale ever green cybersecurity company in the world. And have we not taken that fork in the road? We'd be fine. We wouldn't be done poorly. That kind of those companies have done well. They've succeeded in their space but they have not been able to move into other swim lanes and be successful on other swim ways but that was not their standard ambition. So that's sometimes to say, if you don't declare an ambition, it's hard to get to it because you actually don't know how you're headed there. So it was a crucible moment for us. And in hindsight, it was a bet we made and it worked out. As of October 2025, Palau Alternatrix's market cap is nearly $150 billion. And it employs 16,000 people globally. As cybersecurity moves into the AI era, the company continues to stay nimble in an ever changing industry. Cybersecurity industry is the most innovative industry in the world because the bad guys are always trying to innovate on how to attack our customers, which means we cannot rest on our laurels. We can't live in a world where we're not constantly trying to out-in-oate the bad actors. Today, we talk about how to secure with AI, how to deploy browsers on the world, how to build a common data lake for security and be innovative in the future. So I think we are getting the seat of the table now with our customers to define and help them think through the future cybersecurity architecture. The way I approach Palau Alternatrix today is really thinking about it and always trying to sort of maintain an evergreen philosophy in terms of how we approach product technology, but even go to market and everything else the company does. You can't assume that what got us to our success five years ago is what's going to make a successful day. Or what we're doing today is going to make a successful three or four years from now. And so that evergreen philosophy and always being willing to disrupt ourselves before someone else does is a lot of what I think about every day when I think about the future of health networks. If I look at Palau Alternatrix today, and by the way, I recently announced that I'm going to retire from Palau Alternatrix. And the reason for that is that I think that Palau Alternatrix has finally achieved the vision that I set 20 years ago, meaning recently we announced the 25 or so billion-dollar acquisition of a company called CyberArc, which is in the identity space, they're doing many different things in identity, identity and access management, privilege, access management, and other things. And that, to me, completes the platform, meaning we now provide all the major components of a cybersecurity infrastructure, network security, endpoint security, security operations center, automation, and control, and cloud security, identity and access management. We went into AI security, which is a new space, into email security, which is a traditional space. We went into vulnerability, assessment and vulnerability management, a traditional space. We have all the major components at Palau Alternatrix that an organization would need in order to achieve their cybersecurity goals, which is what I set to do 20 years ago. And now I can retire from Palau Alternatrix with Peace, knowing that I'm leaving a company with all the products and all the technology that it needs, with a great management team, led by Nikesh, and the company in a great financial state, and the company can go and continue to be successful, living without me. My advice to startups that are being disrupted, or companies that are being disrupted by either another company doing the same thing just in a much better way, in a different way, or you're being disrupted by a shift in market dynamics like the cloud, like AI, and so on, my advice to you is embrace the disruption. If you don't embrace the disruption, you will end up like companies that didn't embrace the disruption. So for example, in our case, if you end up like checkpoint, in the case of cell phones, you end up like Nokia, that was disrupted by Apple and later Google, you will get killed by disruption. So always embrace a disruption, despite that disruption, or you embracing it, hurting your business for the short term. If you do it right, you will get out of it on the other side much stronger than you would if you hadn't embraced the disruption. This has been Crucible Moments, a podcast from Sequoia Capital. Crucible Moments is produced by the Epic Stories and Fox Creative Podcast Teams, along with Sequoia Capital. Special thanks to Mirzouk, Ashim Chandra, Jim Gets, Rajiv Batra, Lee Clarich, Mark McLaughlin, and Nikesh Aurora for sharing their stories.

Podcast Summary

Key Points:

  1. Near Zook's journey from Checkpoint to founding Palo Alto Networks.
  2. Development of the next-generation firewall at Palo Alto Networks.
  3. Challenges faced by Palo Alto Networks in disrupting the cybersecurity industry and scaling rapidly.

Summary:

The transcription discusses Near Zook's background, starting from his time at Checkpoint to founding Palo Alto Networks. It details the development of the next-generation firewall at Palo Alto Networks, focusing on its unique features and market strategy. The challenges faced by the company in disrupting the cybersecurity industry and scaling rapidly are highlighted, including competition reactions and the need for organizational changes to achieve rapid growth.

Near's strategic decisions, such as focusing on customer feedback and staying true to the firewall concept, are emphasized as key factors in Palo Alto Networks' success in becoming a global leader in cybersecurity.

FAQs

The founder was frustrated with the cautious cultures of previous companies and wanted to innovate freely in the cybersecurity industry.

Palo Alto Networks introduced a next-generation firewall that unified multiple layers of protection into one intelligent platform, securing more than just web browsing and email.

Palo Alto Networks saw an opportunity to innovate by delivering cybersecurity functions through cloud-based services, despite initial skepticism from the industry.

Despite initial reluctance, Palo Alto Networks decided to call their product a next-generation firewall to establish their position in the market.

Palo Alto Networks engaged with customers extensively, seeking feedback and ensuring that their products were effective in securing customers' networks.

By offering a superior alternative to legacy firewalls and attracting large clients like Citibank, Palo Alto Networks rapidly grew and generated significant revenue.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.